Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE

David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days.

Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year.

Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive.

The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2.

00:00 Sponsor NordLayer
00:36 Headlines Preview
01:05 Windows Zero Day LegacyHive
03:35 Record Patch Tuesday
04:22 Fairlife Ransomware Shutdown
05:49 Abbott Dual Breach Probes
08:09 Conti Leaks Healthcare Cruelty
09:33 WordPress Core RCE WP 2Shell
11:29 Wrap Up And Listener Notes
12:06 Sponsor Message NordLayer

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(100)

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—for...

22 Aug 36min

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA ...

21 Aug 14min

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where V...

19 Aug 12min

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 lead...

17 Aug 9min

Cybersecurity Today Weekend Month in Review: August 2026

Cybersecurity Today Weekend Month in Review: August 2026

AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July devel...

15 Aug 56min

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that explo...

14 Aug 11min

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carr...

12 Aug 9min

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulner...

10 Aug 16min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
dine-penger-pengeradet
nokon-ma-ga
rss-gukild-johaug
det-store-bildet
rss-espen-lee-usensurert
hanna-de-heldige
rss-ness
rss-penger-polser-og-politikk
aftenbla-bla
lydartikler-fra-aftenposten
e24-podden
frokostshowet-pa-p5
rss-borsmorgen-okonominyhetene
grasoner-den-nye-kalde-krigen