Weekly Brief

SOC Minute Weekly

This week, attackers target exposed edge infrastructure, compromise trusted software distribution, steal authenticated sessions and cloud credentials, exploit familiar work flows, and turn third-party access into large-scale data exposure.

Weekly Episode
Duration
22:38
Stories
23 stories
Published
Watch on YouTube

About this episode

This week, attackers target exposed edge infrastructure, compromise trusted software distribution, steal authenticated sessions and cloud credentials, exploit familiar work flows, and turn third-party access into large-scale data exposure.

This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.

Play the episode, then review the stories and chapter list for the reporting and topics covered.

Stories covered this week

Chapters

  1. Opening
  2. Active Attacks Exploit Critical Citrix NetScaler Auth Bypass
  3. Attackers Exploit Two SonicWall SMA 1000 Zero-Days
  4. China-Linked Fire Ant Targets Cisco Routers to Steal Credentials
  5. Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Run Code as Root
  6. New 'Ted' Backdoor Hides in HAProxy to Intercept Web Traffic
  7. Critical JFrog Artifactory Flaw Exploited Days After Patch
  8. Coder’s registry compromised to distribute malicious Terraform modules
  9. BGP Hijack Delivers Malicious Virtualizor Update with Root Access
  10. CISA Adds Critical Chromium V8 Vulnerability to Exploited Catalog
  11. GiveWP WordPress Plugin Flaw Lets Hackers Execute Server Commands
  12. Critical Elementor Pro Flaw Enables Takeover of WordPress Sites
  13. Critical Langflow Flaw Exploited to Steal OpenAI and AWS Keys
  14. Anthropic warns of infostealer malware hijacking Claude AI sessions
  15. The Coding-Agent Trap: Malicious Use of Free LLM Endpoints Exposed
  16. Microsoft alerts on TerminalFix attacks using reverse tunnels
  17. ASCII Smuggling Technique Evolves from AI Prompt Injection to Phishing Evasion
  18. Guildma (Astaroth) Malware Infection via Brazilian Portuguese Email
  19. Iranian Hackers Use Coding Tests to Deliver Cross-Platform RATs
  20. US Charges Russian for Malware Campaign Targeting 80,000 Freelancers
  21. BraZetsu Malware Turns Windows Hosts Into Underground Marketplace Assets
  22. McKesson Breach Exposes 284 Million Patient Records, ShinyHunters Claims Theft
  23. Aesto Health Data Breach Exposes Over 9.5 Million Patients
  24. IDScan sued over breach exposing 153 million driver’s licenses
  25. Closing