Subscribe Share Full episode and show notes Cloud Security , IoT , AI/ML Cloud Visibility, Fortibleed, hacking things the easy way – Sandy Bird – PSW #932 First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: Help, I am Fortibleeding, Cisco SD-WAN needs help, The secret life of probe requests, Help, I am Squidbleeding, XSS to RCE and why CVSS isn’t the full picture, TVs spy on you, Foundational security practices, Cybersecurity costs money, Happy “Its too late to update your KEK key” day, You don’t have security flaws if no one can report them, Rickrolling FIFA, Domain takeovers, End of life, out of luck, The key to Encryption…. June 25, 2026 This episode is sponsored by Full Segment Notes First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: Help, I am Fortibleeding Cisco SD-WAN needs help The secret life of probe requests Help, I am Squidbleeding XSS to RCE and why CVSS isn't the full picture TVs spy on you Foundational security practices Cybersecurity costs money Happy "Its too late to update your KEK key" day You don't have security flaws if no one can report them Rickrolling FIFA Domain takeovers End of life, out of luck The key to Encryption... Guest Sandy Bird CTO and Cofounder at Sonrai Security Sandy Bird is the co-founder and CTO of Sonrai Security. Sandy was the co-founder and CTO of Q1 Labs, which was acquired by IBM in 2011. At IBM, Sandy became the CTO for the global security business and worked closely with research, development, marketing and sales to develop new and innovative solutions to help the IBM Security business grow to ~$2B in annual revenue. He’s calling us from his home in Fredericton, Canada, he is a car guy, and he’s probably wearing a Carhartt shirt. Hosts Paul Asadoorian @0offset https://securitypodcaster.com David Johnson Jeff Man https://www.obsglobal.com/ Joshua Marpet https://www.cyturus.com Larry Pesce @haxorthematrix https://www.finitestate.io/ https://breakstuffforfun.com/ Lee Neely Announcements Let’s be real. Your scanners are dumping thousands of vulns, half of them noise, and you still don’t know what’s actually exploitable in your environment. Patching everything isn’t possible, and chasing CVSS isn’t working. At the Vulnerability Management Virtual Cybersecurity Summit, learn how to prioritize based on exploitability, reduce false positives, and actually fix what matters. Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW List of Articles Paul Asadoorian Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager In less than a year, there have been 7 vulnerabilities in this product added to the CISA KEV. All exploited in the wild, and almost certain they were all exploited as 0-days. Let that sink in. I'm struggling to come up with great defensive recommendations other than treat all of your Cisco SD-WAN devices as already compromised... An update on FortiBleed — what’s happening with victim orgs There is way too much information both online and in my head about Fortibleed. We could easily dedicate an entire show to this topic. Here's a summary (off the top of my head, NOT AI): Threat actor left all of their tools and data exposed to the Internet The TTPs are many, and include scan, identify, exploit, and capture activities, similar to other campaigns that target the network edge They have a large GPU cluster that cracks SHA-256 hashes They detect honeypots and have some pretty advanced analytics and filtering of the device fingerprints and credentials They lived off the land on Fortinet devices, mostly collecting credentials This is important: If you are running versions of FortiOS PRIOR to 7.2.11, 7.4.8, or 7.6.1, you are storing passwords that can be cracked If you are running FortiOS 7.2.11, 7.4.8, or 7.6.1 or later, you are using PBKDF2, much better, however see next Once you apply the upgrade to FortiOS 7.2.11, 7.4.8, or 7.6.1 or later, the SHA-256 hashes still exist in the full config backup (in case you had to revert, you will still be able to log in) The SHA-256 hash exists in the full config backup until the admin logs in, and not just one admin, but all of the admin accounts CVE-2026-5667: The Secret Life of Probe Requests – Mitsubishi MAC-577IF-2E WiFi Adapter "The researcher noticed Mitsubishi MAC-577IF-2E Wi-Fi adapters (used with air conditioners, water heaters, rice cookers, etc.) broadcasting a probe request for "DefaultSSID" all over the city. Devices that have never been configured by their owners sit in perpetual setup mode, begging for that SSID on-air — indefinitely . The attack chain is straightforward: stand up a rogue AP matching "DefaultSSID," capture the WPA2 half-handshake, crack the (weak default) password offline, then reconnect and hit the device's HTTP interface. Authentication was just HTTP Basic Auth, with credentials stored in a public GitHub repo. At that point, a Python library by a prior researcher gave full control — power on/off, temperature changes — the whole stack ." Squidbleed (CVE-2026-47729) Pretty amazing vulnerability find that slipped past humans for 29 years, then uncovered by Mythos. It requires certain conditions to work. Not sure the use case for Squid proxies today, but we used to use it to save bandwidth back in the day in addition to monitoring for URLs that people visited and could enforce rules. We ran it on FreeBSD, and had T1s to provide Internet access at the time. CVE-2026-25860 – OpenClinic GA Reflected XSS to RCE This still carries a 5.8 Medium CVSS, and is an example of why you can't rely on CVSS alone. You need enrichment and threat intel. And here's how an XSS turns into RCE: "This is where it gets good. Because the XSS executes within an authenticated session, the injected JavaScript abuses a misconfigured admin settings page (configparameters.jsp) to overwrite the readPictureApplication parameter, a command string later passed to another function. One POST to set the command, one GET to pull the trigger. That's your RCE." How Cloudflare responded to the “Copy Fail” Linux vulnerability "Cloudflare published a great writeup on "Copy Fail" (CVE-2026-31431), a Linux local privilege escalation in the kernel crypto API where an out-of-bounds write in algif aead lets any unprivileged user open an AF ALG socket, splice in a setuid binary like /usr/bin/su, and write shellcode into it 4 bytes at a time to get root, and the root cause traces back to a 2017 optimization that never enforced write boundaries. The slick part is the response: before the kernel patch was ready, they shipped an eBPF-LSM program to block AF ALG bind calls for everything except an allow-list, and their behavioral detection flagged exploit attempts within minutes with no signature update. The takeaway is to disable algif aead if you don't need it, and to stop letting unprivileged users reach kernel attack surface like the crypto API by default." Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs This is so shady: "Spur Intelligence Labs scanned 6,038 apps across LG webOS and Samsung Tizen platforms and found that 2,058 of them contain embedded residential proxy SDKs . In plain terms, these apps quietly route third-party internet traffic through your home TV and its IP address, without most users ever realizing it. The apps involved are not the kind you would think to audit. Screensavers, fish tanks, clocks, casual games. Thin, low-friction apps that are designed to blend into the background. Under that surface, SDKs from companies like Bright Data, Massive, and Honeygain (an Oxylabs subsidiary) are monetizing the TV's internet connection in the background . Bright Data alone is tied to 367 proxy-flagged apps in the dataset, and in many cases the proxy company itself appears to be the publisher, shipping lightweight apps at scale as a distribution vehicle for its SDK ." - Its a clear indicator that attackers are poised to live in areas we don't, under normal circumstances, control or have visibility into. They chose LG and Samsung because those companies try to run a locked down environment and don't have good policies about what apps can do. They also don't want users messing around with the device or having control, e.g. ever tried to remove apps only to have your TV tell you to pound sand? I Accidentally Logged as Admin Into a Threat Actor Website Pretty neat, love it when this happens, its great intel. Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) This comment speaks volumes: "If you are out of luck and running an End-Of-Support version, you get what you deserve as a former paying customer: no hotfix at all." 2021 Honda Civic infotainment system can be jailbroken via USB Test keys strike again. When the keys are public, it defeats the purpose. TP-Link Domain Takeover: How We Captured Enterprise Network Traffic via an Unregistered Domain Sometimes it's this easy, not that analyzing all the firmware is that easy, but security comes down to the management of assets. It's super easy to forget about a domain, and attackers are there to take advantage of that. In this case, thankfully, it was a researcher who reported it responsibly and even transferred the domain back to them. Nice work! The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds Boot Naked Linux · … and another thing … Proxmox secure boot: June apocalypse A washing machine story vemu – Multi-Architecture Embedded System Emulator We May Be Living Through the Most Consequential Hundred Days in Cyber History, and Almost Nobody Has Noticed GreatXML a bitlocker