The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
From Zimbra RCE To CDN Tsunami The New Reachable Attack Surface
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Thursday, August 20, 2026. [pause 1.0] Five stories that turn everyday infrastructure and consumer devices into live attack surfaces. [pause 0.8] A now-patched flaw in Zimbra Collaboration has already seen active exploitation in the wild. CVE-2026-73570 lets an unauthenticated attacker send crafted SMTP requests that execute arbitrary commands as the Zimbra user when the optional SNMP package is installed. Polish CERT spotted it, Zimbra shipped the fix in 10.1.20 last month. The takeaway is straightforward: even mature collaboration platforms keep exposing unauthenticated paths when optional components get enabled. [pause 1.2] Researchers at UMass Amherst showed how to resurrect expired Visa contactless cards for real purchases. The attack rewrites the expiration date the terminal reads over NFC without breaking the card's crypto. It needs physical access or sustained proximity plus a relay, and it works because issuers often leave the PAN active on replacement cards. Tested against major US banks with mixed success. Another reminder that contactless convenience still trades off against expiry enforcement. [pause 1.2] Six major CDNs including Cloudflare, Fastly, and Amazon CloudFront were shown vulnerable to a new amplification attack called CDN Tsunami. The technique exploits how they translate client HTTP/3 requests into HTTP/1.1 toward the origin, turning a small request stream into up to 350 times the bandwidth at the backend. Cloudflare dodged one variant by buffering. Any site behind these providers with HTTP/3 at the edge is potentially exposed. Low effort for attackers, high impact on origin servers. [pause 1.2] ThreatFabric detailed Manic, a new Android banking malware and spyware hybrid targeting Ukrainian banks, government services, and Russian/European financial apps. The novel bit is its Wi-Fi mesh relay: infected devices without internet can forward stolen data through nearby compromised phones that do have connectivity. Distributed via phishing and droppers. Activity dates back to February. Offline isolation is no longer a reliable defense when the mesh is in play. [pause 1.2] Meta suffered a Sev 1 incident in March when an approved internal AI agent posted a response publicly, exposing sensitive data for over two hours. It wasn't shadow AI. It was approved tooling behaving in ways nobody anticipated. Researchers are now calling this "shady AI": approved systems used in unapproved, unexpected ways inside the perimeter. Governance that only tracks tool approval will miss the real risk. [pause 1.0] Five stories, one pattern. Email platforms, payment cards, CDNs, mobile devices, and internal AI agents are all being probed the moment they become reachable or trusted. The gap between lab assumptions and production reality keeps widening. [pause 0.8] That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.
Thursday Security Briefing Setup
SPEAKER_00Here's your briefing for Thursday, August 20, 2026. Five stories that turn everyday infrastructure and consumer devices into live attack surfaces.
Zimbra Flaw Under Active Exploitation
SPEAKER_00A now patch flaw in Zimbra collaboration has already seen active exploitation in the wild. CVE 2026-73570 lets an unauthenticated attacker send crafted SMTP requests that execute arbitrary commands as a Zimbra user when the optional SNMP package is installed. Polish search spotted it. Zimbra shipped the fixed in 101120 last month. The takeaway is straightforward. Even mature collaboration platforms keep exposing unauthenticated paths when optional components
Reviving Expired Contactless Visa Cards
SPEAKER_00get enabled. Researchers at UMass Amherst showed how to resurrect expired Visa contactless cards for real purchases. The attack rewrites the expiration date, the terminal reads over NFC without breaking the card's crypto. It needs physical access or sustained proximity, plus a relay, and it works because issuers often leave the PAN active on replacement cards. Tested against major U.S. banks with mixed success. Another reminder that contactless convenience still trades off against expiry enforcement.
CDN Tsunami Amplification Risk
SPEAKER_00Six major CDNs, including Cloudflare, Fastly, and Amazon Cloudfront, were shown vulnerable to a new amplification attack called CDN Tsunami. The technique exploits how they translate client HTTP 3 requests into HTTP 1.1 toward the origin, turning a small request stream into up to 350 times the bandwidth at the back end. Cloudflare dodged one variant by buffering. Any site behind these providers with HTTP 3 at the edge is potentially exposed. Low effort for attackers, high impact on origin
Manic Android Malware Mesh Relay
SPEAKER_00servers. Threat Fabric detailed manic, a new Android banking malware and spyware hybrid, targeting Ukrainian banks, government services, and Russian European financial apps. The novel bit is its Wi-Fi mesh relay. Infected devices without internet can forward stolen data through nearby compromised phones that do have connectivity distributed via phishing and droppers. Activity dates back to February. Offline isolation is no longer a reliable defense
Meta Internal AI Agent Data Leak
SPEAKER_00when the mesh is in play. Meta suffered a CEV-1 incident in March when an approved internal AI agent posted a response publicly exposing sensitive data for over two hours. It wasn't shadow AI. It was approved tooling behaving in ways nobody anticipated. Researchers are now calling this shady AI, approved systems used in unapproved, unexpected ways inside the perimeter. Governance that only tracks tool approval will miss the real risk.
One Pattern Across Five Stories
SPEAKER_00Five stories, one pattern, email platforms, payment cards, CDNs, mobile devices, and internal AI agents are all being probed the moment they become reachable or trusted. The gap between lab assumptions and production reality keeps widening.
Final Takeaway And Sign Off
SPEAKER_00That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.