Weekly Brief

SOC Minute Weekly

This week, trusted identity and familiar applications become entry points, exposed enterprise platforms face active exploitation, critical infrastructure reveals persistent visibility gaps, and AI appears as both an attack accelerator and a security boundary of its own.

Weekly Episode
Duration
21:28
Stories
22 stories
Published
Watch on YouTube

About this episode

This week, trusted identity and familiar applications become entry points, exposed enterprise platforms face active exploitation, critical infrastructure reveals persistent visibility gaps, and AI appears as both an attack accelerator and a security boundary of its own.

This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.

Play the episode, then review the stories and chapter list for the reporting and topics covered.

Stories covered this week

Chapters

  1. Opening
  2. Critical Keycloak Password Reset Flaw Could Let Attackers Hijack Any Account
  3. 19 Chrome and Edge Extensions Found Stealing Crypto Wallets
  4. ToxicPanda Android Malware Uses VPN Permissions to Block Google Play
  5. SynkLoader Malware Spreads via Microsoft Teams Phishing Campaign
  6. Critical Avada WordPress Theme Flaw Enables Zero-Click Remote Code Execution
  7. Critical Gitea Vulnerability Exploited in Active Code Injection Attacks
  8. PaperCut NG and MF Zero-Day Flaw Actively Exploited in Attacks
  9. PaperCut issues second emergency patch for exploited NG and MF flaws
  10. Critical cPanel Flaw Lets Single Hosting Customer Gain Root Access
  11. Critical ownCloud Flaw Exploited to Steal Nuclear Records in Philippines
  12. Three CVSS 10.0 ServiceNow Flaws Enable Code Execution and SQL Injection
  13. Critical Vulnerabilities Found in Ebyte NE2-D11 Firmware
  14. Critical Vulnerabilities Found in Xiiaozet LK100W Devices
  15. 296K IoT Botnet, 100+ Water Systems Targeted, New SharePoint RCE Chain
  16. US Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
  17. Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler
  18. FBI Disrupts China-Linked QTFY Platforms Targeting U.S. Infrastructure
  19. UAT-10147 Uses AI to Scale Server Attacks and Deploys Advanced Linux Rootkit
  20. OpenAI Reveals Reward Hacking Drove AI Agents to Breach Hugging Face
  21. Securing AI Infrastructure: Protecting Gateways and Control Points
  22. Malicious Webpage Can Poison Local AI Models via NVIDIA NemoClaw
  23. CISA Red Team Tests Expose Critical SOC and Cloud Security Gaps
  24. Closing