The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
Episodes
17 episodes
Microsoft Entra ID Flaw CVSS 10.0 Already Exploited in the Wild
Here is your briefing for Friday, August 21, 2026. Five stories where cloud identity, code platforms, supply chains, critical infrastructure, and everyday AI tools are all getting tested in production. Microsoft disclosed a maximum-severity remote...
From Zimbra RCE To CDN Tsunami The New Reachable Attack Surface
Here is your briefing for Thursday, August 20, 2026. [pause 1.0] Five stories that turn everyday infrastructure and consumer devices into live attack surfaces. [pause 0.8] A now-patched flaw in Zimbra Collaboration has already seen active explo...
Operation Camera Swarm And The New IoT Reality
Here is your briefing for Wednesday, August 19, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Hunt.io reconstructed a campaign that compromised mo...
How Agent Prompts Became A New Malware Path
Here is your briefing for Tuesday, August 18, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Anthropic and Switzerland's EPFL have demonstrated tha...
From Modems To AI Agents How Assumptions Break
Here is your briefing for Monday, August 17, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers published a two-stage exploit chain that achieves full And...
Patch Tuesday Drops 421 Fixes And Attackers Still Sprint
Here is your briefing for Friday, August 14, 2026. A new malware family called WindRelay has been spotted in the wild. It works with the SpyNote RAT to capture live contactless payment data via NFC and forward it in real time. The malware is si...
State Actors, Zero-Days & NFC Relay Fraud
Here is your briefing for Thursday, August 13, 2026. North Korean IT workers are applying for remote developer jobs, passing interviews, and landing inside government agencies and private companies with legitimate credentials. The FBI is invest...
AI Reasoning Traces Leaked via OpenAI, Anthropic & Google APIs
Here is your briefing for Wednesday, August 12, 2026. Researchers found that hidden reasoning traces passed between API calls at OpenAI, Anthropic, and Google can be replayed and decoded by weaker models in the same family. The attack recovers ...
Malicious SIM Cards Can Run Attacker Code in EV Chargers and Routers
Here is your briefing for Tuesday, August 11, 2026. Malicious SIM Card Can Run Attacker Code Inside Modems Behind Cellular IoT Devices. Researchers showed that a malicious SIM card can force certain cellular modules to execute attacker-su...
Passkey Sync Attacks, Rogue AI Agents & Supply-Chain Threats
Here is your briefing for Monday, August 10, 2026. Researchers disclosed attacks against passkeys that can pull synced private keys from certain implementations or sidestep phishing-resistant MFA entirely. The techniques target how some passwor...
Eighteen-Year-Old Linux SCTP Flaw Hands Local Users Root and Container Escapes
Here is your briefing for Friday, August 7, 2026. Tencent researchers disclosed SCTPhantom, a use-after-free in the Linux kernel's SCTP networking stack that has existed since 2008. With SCTP reachable on the target, it yields full root and let...
Why Exposed PLCs And AI Memory Poisoning Matter
Here is your briefing for Thursday, August 6, 2026. Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities Forescout scanned the internet and found more than four thousand four hundred exposed Rockwell Automation programmable ...
If You Run Langflow Or OpenVSwitch You Need To Act Today
Here is your briefing for Wednesday, August 5, 2026. The U.S. Cybersecurity and Infrastructure Security Agency added three flaws to its Known Exploited Vulnerabilities catalog on August 5, citing evidence of active exploitation in the wild. CVE...
AI Moves From Hype To Budgets
AI is starting to look less like a buzzword and more like a line item, and the market is telling us exactly what it values. We break down why Palantir’s latest quarter reads as a clean signal of enterprise AI adoption moving from pilots into pr...
The Day the Digital World Stood Still: Lessons from the Largest IT Outage in History
What if a single update could bring the world to a standstill? On July 19th, that hypothetical nightmare became a reality when a CrowdStrike sys file update led to the largest IT outage in history. In this episode, we unravel the catastrophic c...
Episode 2: Exploring the Double-Edged Sword of AI in Cybersecurity
Imagine a world where artificial intelligence is not just a tool for progress but a weapon for exploitation. Are we prepared for this ironic twist? Join us as I unpack observations from the recent InfoSec conference in Orlando. The discussion d...
Episode 1: Jackson Mumey - Celebration Bar Review
In my premiere episode, I sit down with Jackson Mumey, the CEO of Celebration Bar Review. We discuss his journey from cassette tapes to the current cloud-delivered platform his business uses. Jackson can be found on his own podcast called The E...