A North Korean supply chain campaign used public blockchains as unkillable C2 infrastructure, while Ernst & Young confirmed a three-week-blind tax records breach and SonicWall's CVSS 10.0 zero-day chain gave attackers root access before any patch existed. Today's briefing also covers 570 Microsoft fixes, WordPress RCE risk across 500 million sites, and AI attack costs hitting single-digit dollars.
Audio is available on Spreaker — see link below.
A threat actor had root access to SonicWall VPN appliances for over three weeks before any patch existed. That's the lead, and it's worth sitting with for a moment.
Microsoft's July fourteenth Patch Tuesday addressed five hundred and seventy vulnerabilities. That number is large enough to be almost meaningless on its own, so here's what actually matters: two of those CVEs were already being actively exploited before the patches shipped.
Seven malicious npm packages targeting Vite developers were published between June twenty-ninth and July third. They impersonated legitimate scoped packages under the @vitejs namespace.
Ernst and Young confirmed a breach of its IT support ticket platform that ran from March twenty-eighth through April twelfth. Client tax records and investment-holding documents were exposed.
Two CVEs, numbered CVE-2026-60137 and CVE-2026-63030, enable unauthenticated REST API batch-route SQL injection on WordPress, leading to full code execution. The exposed population is over five hundred million installations.
The UK's AI Safety Institute published benchmarks showing that DeepSeek V4-Pro and GLM-5.2 now match four-month-old frontier model capabilities for autonomous cyberattacks. The cost to run those attacks on downloadable open-weight models: single-digit dollars.
Two smaller items worth tracking. A researcher published a proof-of-concept showing Windows User Profile Service can be abused to load unpatched registry hives as a standard user, bypassing July twenty twenty-six security updates on fully-patched systems.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.