Weekly Brief

SOC Minute Weekly

This week follows a chain of exploited trust: identity and gateway abuse, stolen cloud access, actively exploited services, industrial and engineering systems, repurposed infrastructure, software supply-chain attacks, endpoint control, and AI as both an attack surface and a SOC tool.

Weekly Episode
Duration
22:09
Stories
21 stories
Published
Watch on YouTube

About this episode

This week follows a chain of exploited trust: identity and gateway abuse, stolen cloud access, actively exploited services, industrial and engineering systems, repurposed infrastructure, software supply-chain attacks, endpoint control, and AI as both an attack surface and a SOC tool.

This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.

Play the episode, then review the stories and chapter list for the reporting and topics covered.

Stories covered this week

Chapters

  1. Opening
  2. CVE-2026-54121: Enterprise CA Privilege Escalation Risk
  3. Critical NetScaler Flaw Can Bypass Authentication on Gateway Servers
  4. Suspected Russian Hackers Exploit Google OAuth and WhatsApp for Account Hijacking
  5. Thousands of Active Leaked AWS Keys Expose Corporate Accounts
  6. Hacker Claims 3.6M Azure Account Records Stolen from Major Companies
  7. CareCloud Data Breach Exposes Records of 3.7 Million Patients
  8. Critical RCE Flaw in Windows IKE Extension Actively Exploited
  9. CISA: Ransomware Gangs Exploiting Windows Task Host Flaw
  10. CISA Adds Critical Zimbra OS Command Injection to Known Exploited Vulnerabilities
  11. CISA Warns of Active Exploitation of Critical MLflow Vulnerability
  12. Critical Out-of-Bounds Read Vulnerability in Siemens Parasolid
  13. Active Cyber Threat Targets Siemens S7 PLCs Using AI-Generated Exploits
  14. Clop Gang Uses Custom Web Shell for Targeted Windchill Data Theft
  15. Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes
  16. StopAndProtect Uses 2,000 Hacked WordPress Sites to Spread Malware
  17. Hackers Compromise Rust Crate to Deliver Infostealer Malware
  18. Trojanized npm Packages Deploy AI-Powered RedC2 4.0 Linux Backdoor
  19. SilkParasite Espionage Targets Central Asian Governments with Five New RATs
  20. AmnesiaStealer macOS Malware Hijacks Browsers via Remote Control
  21. AI ‘Mind Viruses’ Can Spread Between Agents Via Persistent Prompt Files
  22. Wazuh Integrates AI to Enhance SOC Workflows
  23. Closing