The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
Patch Tuesday Drops 421 Fixes And Attackers Still Sprint
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Friday, August 14, 2026. A new malware family called WindRelay has been spotted in the wild. It works with the SpyNote RAT to capture live contactless payment data via NFC and forward it in real time. The malware is sideloaded silently after initial RAT access and requires no screen sharing or user interaction beyond the initial foothold. Attacks typically begin with phishing or smishing. That's the headline from Help Net Security, and it shows how the contactless payment surface remains an attractive, under-defended channel even as mobile security tooling improves. Security researchers at pwn.ai disclosed a pre-authentication exploit chain that turns a simple cross-site scripting flaw into remote code execution on WordPress Core. The vulnerability, tracked as CVE-2026-64638, has been present since version 4.7 and affects the vast majority of the 43% of the web that runs on WordPress. A publicly available exploit is already circulating. That's the headline from multiple sources this week, and it is a reminder that even the most widely used platforms can carry long-lived sanitization discrepancies that only surface under determined research. Microsoft released its August 2026 Patch Tuesday updates, addressing 421 vulnerabilities. At least one elevation-of-privilege flaw was being exploited as a zero-day in the wild before the patch was available. The volume of fixes continues the trend of large monthly security updates. That's the headline from SecurityWeek, and it underscores how quickly sophisticated actors weaponize public or privately discovered flaws once they appear. AWS announced that email-validated certificates in Certificate Manager will no longer support automated renewals after 2027. Organizations relying on this validation method will need to migrate to DNS-validated certificates to maintain continuity. That's the headline from Help Net Security, and it is another incremental step toward stronger domain control validation practices across the industry. The Storm-1175 ransomware group exploited a critical vulnerability in N-able’s N-central management platform within hours of disclosure. The speed of weaponization highlights how ransomware operators continue to monitor vendor disclosures for high-value targets. That's the headline from the cybersecurity press, and it shows the persistent gap between patch availability and actual deployment in managed service environments. Five stories, one recurring theme. Mobile payment fraud tooling is becoming more specialized. Long-lived web platform vulnerabilities continue to surface. Large vendors are still shipping exploited zero-days. Cloud providers are tightening validation requirements. And ransomware groups remain extremely fast at turning disclosures into campaigns. The through-line is familiar: the abstractions and platforms we rely on keep leaking under pressure, and the organizations that treat every new integration and every new disclosure as potentially hostile will be the ones that stay ahead. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.
Friday Security Briefing Kickoff
SPEAKER_00Here is your briefing for Friday, August 14, 2026.
WinRelay Targets NFC Payment Data
SPEAKER_00A new malware family called WinRelay has been spotted in the wild. It works with the SpyNote RAT to capture live contactless payment data via NFC and forwarded in real time. The malware is side-loaded silently after initial RAT access and requires no screen sharing or user interaction beyond the initial foothold. Attacks typically begin with phishing or smishing. That's the headline from Helpnet Security. And it shows how the contactless payment surface remains an attractive, underdefended channel even as mobile security tooling improves.
WordPress XSS Turns Into RCE
SPEAKER_00Security researchers at PODNAI disclosed a pre-authentication exploit chain that turns a simple cross-site scripting flaw into remote code execution on WordPress core. The vulnerability, tracked as CVE 2026-64638, has been present since version 4.7 and affects the vast majority of the 43% of the web that runs on WordPress. A publicly available exploit is already circulating. That's the headline from multiple sources this week. And it is a reminder that even the most widely used platforms can carry long-lived sanitization discrepancies that only surface under determined
Microsoft Patch Tuesday And Zero-Day
SPEAKER_00research. Microsoft released its August 2026 Patch Tuesday updates addressing 421 vulnerabilities. At least one elevation of privilege flaw was being exploited as a zero day in the wild before the patch was available. The volume of fixes continues the trend of large monthly security updates. That's the headline from Security Week, and it underscores how quickly sophisticated actors weaponize public or privately discovered flaws once they
AWS Certificate Renewal Policy Shift
SPEAKER_00appear. AWS announced that email validated certificates in Certificate Manager will no longer support automated renewals after 2027. Organizations relying on this validation method will need to migrate to DNS validated certificates to maintain continuity. That's the headline from HelpNet Security, and it is another incremental step towards stronger domain control validation practices across
Ransomware Weaponizes New Disclosure Fast
SPEAKER_00the industry. The Storm 1175 Ransomware Group exploited a critical vulnerability in Enables and Central Management Platform within hours of disclosure. The speed of weaponization highlights how ransomware operators continue to monitor vendor disclosures for high value targets. That's the headline from the Cybersecurity Press, and it shows the persistent gap between patch availability and actual deployment in managed service environments.
The Through Line Across Five Stories
SPEAKER_00Five stories, one recurring theme. Mobile payment fraud tooling is becoming more specialized. Long-lived web platform vulnerabilities continue to surface. Large vendors are still shipping exploited zero days, cloud providers are tightening validation requirements, and ransomware groups remain extremely fast at turning disclosures into campaigns. The through line is familiar, the abstractions and platforms we rely on keep leaking under pressure, and the organizations that treat every new integration and every new disclosure as potentially hostile will be the ones that stay
Closing Advice: Patch And Stay Sharp
SPEAKER_00ahead. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.