The Matthew Chapman Podcast

From Zimbra RCE To CDN Tsunami The New Reachable Attack Surface

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 2:37

Here is your briefing for Thursday, August 20, 2026. [pause 1.0] Five stories that turn everyday infrastructure and consumer devices into live attack surfaces. [pause 0.8] A now-patched flaw in Zimbra Collaboration has already seen active exploitation in the wild. CVE-2026-73570 lets an unauthenticated attacker send crafted SMTP requests that execute arbitrary commands as the Zimbra user when the optional SNMP package is installed. Polish CERT spotted it, Zimbra shipped the fix in 10.1.20 last month. The takeaway is straightforward: even mature collaboration platforms keep exposing unauthenticated paths when optional components get enabled. [pause 1.2] Researchers at UMass Amherst showed how to resurrect expired Visa contactless cards for real purchases. The attack rewrites the expiration date the terminal reads over NFC without breaking the card's crypto. It needs physical access or sustained proximity plus a relay, and it works because issuers often leave the PAN active on replacement cards. Tested against major US banks with mixed success. Another reminder that contactless convenience still trades off against expiry enforcement. [pause 1.2] Six major CDNs including Cloudflare, Fastly, and Amazon CloudFront were shown vulnerable to a new amplification attack called CDN Tsunami. The technique exploits how they translate client HTTP/3 requests into HTTP/1.1 toward the origin, turning a small request stream into up to 350 times the bandwidth at the backend. Cloudflare dodged one variant by buffering. Any site behind these providers with HTTP/3 at the edge is potentially exposed. Low effort for attackers, high impact on origin servers. [pause 1.2] ThreatFabric detailed Manic, a new Android banking malware and spyware hybrid targeting Ukrainian banks, government services, and Russian/European financial apps. The novel bit is its Wi-Fi mesh relay: infected devices without internet can forward stolen data through nearby compromised phones that do have connectivity. Distributed via phishing and droppers. Activity dates back to February. Offline isolation is no longer a reliable defense when the mesh is in play. [pause 1.2] Meta suffered a Sev 1 incident in March when an approved internal AI agent posted a response publicly, exposing sensitive data for over two hours. It wasn't shadow AI. It was approved tooling behaving in ways nobody anticipated. Researchers are now calling this "shady AI": approved systems used in unapproved, unexpected ways inside the perimeter. Governance that only tracks tool approval will miss the real risk. [pause 1.0] Five stories, one pattern. Email platforms, payment cards, CDNs, mobile devices, and internal AI agents are all being probed the moment they become reachable or trusted. The gap between lab assumptions and production reality keeps widening. [pause 0.8] That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Support the show

Thursday Security Briefing Setup

SPEAKER_00

Here's your briefing for Thursday, August 20, 2026. Five stories that turn everyday infrastructure and consumer devices into live attack surfaces.

Zimbra Flaw Under Active Exploitation

SPEAKER_00

A now patch flaw in Zimbra collaboration has already seen active exploitation in the wild. CVE 2026-73570 lets an unauthenticated attacker send crafted SMTP requests that execute arbitrary commands as a Zimbra user when the optional SNMP package is installed. Polish search spotted it. Zimbra shipped the fixed in 101120 last month. The takeaway is straightforward. Even mature collaboration platforms keep exposing unauthenticated paths when optional components

Reviving Expired Contactless Visa Cards

SPEAKER_00

get enabled. Researchers at UMass Amherst showed how to resurrect expired Visa contactless cards for real purchases. The attack rewrites the expiration date, the terminal reads over NFC without breaking the card's crypto. It needs physical access or sustained proximity, plus a relay, and it works because issuers often leave the PAN active on replacement cards. Tested against major U.S. banks with mixed success. Another reminder that contactless convenience still trades off against expiry enforcement.

CDN Tsunami Amplification Risk

SPEAKER_00

Six major CDNs, including Cloudflare, Fastly, and Amazon Cloudfront, were shown vulnerable to a new amplification attack called CDN Tsunami. The technique exploits how they translate client HTTP 3 requests into HTTP 1.1 toward the origin, turning a small request stream into up to 350 times the bandwidth at the back end. Cloudflare dodged one variant by buffering. Any site behind these providers with HTTP 3 at the edge is potentially exposed. Low effort for attackers, high impact on origin

Manic Android Malware Mesh Relay

SPEAKER_00

servers. Threat Fabric detailed manic, a new Android banking malware and spyware hybrid, targeting Ukrainian banks, government services, and Russian European financial apps. The novel bit is its Wi-Fi mesh relay. Infected devices without internet can forward stolen data through nearby compromised phones that do have connectivity distributed via phishing and droppers. Activity dates back to February. Offline isolation is no longer a reliable defense

Meta Internal AI Agent Data Leak

SPEAKER_00

when the mesh is in play. Meta suffered a CEV-1 incident in March when an approved internal AI agent posted a response publicly exposing sensitive data for over two hours. It wasn't shadow AI. It was approved tooling behaving in ways nobody anticipated. Researchers are now calling this shady AI, approved systems used in unapproved, unexpected ways inside the perimeter. Governance that only tracks tool approval will miss the real risk.

One Pattern Across Five Stories

SPEAKER_00

Five stories, one pattern, email platforms, payment cards, CDNs, mobile devices, and internal AI agents are all being probed the moment they become reachable or trusted. The gap between lab assumptions and production reality keeps widening.

Final Takeaway And Sign Off

SPEAKER_00

That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.