Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581” inside PodZeus.
The cybersecurity world is facing a perfect storm of vulnerabilities, with AI-driven discovery accelerating threat landscapes at an unprecedented pace. A critical CVSS 10 flaw in Cisco’s SD-WAN controllers allows unauthenticated attackers to gain full admin access—already being exploited in the wild. Simultaneously, the massive education platform Canvas suffered a ransomware attack that crippled 9,000 institutions, exposing 275 million users’ data and raising alarms about supply chain risks in critical infrastructure. Microsoft’s Patch Tuesday delivered 118 CVEs, including 16 criticals, marking the first in two years without emergency zero-day fixes—evidence that AI is overwhelming traditional patch cycles. Meanwhile, a stealthy NPM backdoor in Node IPC packages exfiltrated 90 types of developer credentials, and a BitLocker bypass in WinRE allows full data recovery from discarded laptops. The real turning point? AI isn’t just finding vulnerabilities—it’s predicting them. Models like GPT-5.5 and Anthropic’s Mythos are now being used by security teams to uncover flaws faster than ever, but their public availability raises urgent ethical questions: should such powerful tools be accessible to everyone, or only the good guys? The answer, as one host argues, is both—because hiding flaws doesn’t make them secure, only invisible.
Cisco SD-WAN controllers with CVSS 10 flaws are actively exploited; patch immediately or risk full admin takeover.
Canvas ransomware attack exposed 275 million users and highlights systemic risk in centralized education SaaS platforms.
BitLocker bypass via WinRE allows full data recovery from discarded laptops—even with TPM + PIN protection.
NPM backdoor in Node IPC 9.1.6, 9.2.3, and 12.0.1 steals AWS, Azure, GitHub, and Kubernetes credentials—update to 9.2.1 or 12.0.0.
AI is now predicting vulnerabilities, not just discovering them—making zero days more common and patch cycles obsolete.
…and 3 more takeaways available in PodZeus
Welcome & Episode Overview
Josh Marpet introduces himself as the sole host for this episode, setting the tone with humor and urgency. He previews a packed agenda covering major zero-day exploits, supply chain attacks, and AI-driven security shifts.
Cisco SD-WAN CVSS 10 Zero-Day
“There's literally nothing worse... unauthenticated attackers gaining admin. So privilege escalation from unauthenticated to admin in one shot.”
Canvas Ransomware & Supply Chain Collapse
“This entire system going down... is an issue. There's issues in... Is this a supply chain issue? Is this a single... SaaS app issue. I'm going to call this a supply chain issue.”
On-Prem Microsoft Exchange Exploit
A crafted email exploits CVE-2026-42897 in on-prem Exchange, enabling arbitrary JavaScript execution via Outlook Web Access. Microsoft offers a temporary mitigation but no permanent fix yet.
BitLocker Bypass via WinRE
“Oh my God, it's insane and ridiculous what we have now. So it's crazy.”
“The quality of the vulnerabilities that get out of Mythos is about the same as you would get out of the person. It just makes them incredibly more efficient.”
“There's literally nothing worse... unauthenticated attackers gaining admin. So privilege escalation from unauthenticated to admin in one shot.”
“Disclosure to exploit is minutes to hours now. Threat intel just went down in terms of value.”
Host
Cisco Catalyst SD-WAN
product
Canvas
product
Microsoft Exchange
product
Node IPC
other
BitLocker
product
Praise on AI
other
GPT-5.5
other
Mythos
other
OpenAI
organization
Anthropic
organization
DexterBot, Darksword, Eviltokens, Tubular Bells, Claude, Drift, Gmail, Josh Marpet... - SWN #569
Security Weekly News (Audio) • 32m • 4/3/2026
Staypuft, Claude, One Pixel, deepfakes, Raccoon, BOFH, Satoshi Nakamoto, Josh Marpet. - SWN #571
Security Weekly News (Audio) • 30m • 4/10/2026
Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572
Security Weekly News (Audio) • 36m • 4/14/2026
Dougbot, RedSun, ATHR, Vishing, Cisco, Google, Chrome, Severance, Shor, Josh Marpet.. - SWN #573
Security Weekly News (Audio) • 33m • 4/17/2026
Robosawmill, Gentleman, Vercel, GitHub, Claude, RS232, Josh Marpet, and More... - SWN #574
Security Weekly News (Audio) • 32m • 4/21/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
