The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
WeChat Zero-Click Worm Took Over Accounts Mid-Ring
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Tuesday, September 8, 2026. Security firm Calif demonstrated a WeChat worm that hijacks an account from an incoming call. The target does not have to answer or touch the phone. The caller must already be a contact. Calif reported it to Tencent in July, and Tencent has since blocked the exploit for all users. No real-world attacks are reported. In the demo, one Android phone called an iPhone and took WeChat while it was still ringing. That iPhone then called a second Android and did the same. Declining stops that attempt, but the attacker can call again while you sleep. Full account control means messages, calls, payments, and mini programs. For one point four three nine billion monthly active users, contact trust just became the attack surface. Red Hat says a FreeIPA flaw lets a client that has never logged in create a Kerberos identity of its choosing and land in the administrators group. FreeIPA decides who may log in across a Linux domain. The chain needs a second bug in three eighty-nine Directory Server. Red Hat tracked FreeIPA as C.V.E. twenty twenty-six dash seventy-six thousand five hundred seventy-eight, critical, C.V.S.S. nine point eight, and reproduced it twice on a default install. FreeIPA ships an access rule that lets a user manage their own one-time-password token without requiring a login. Three eighty-nine Directory Server has an ownership check that compares names as plain text, so an empty anonymous name matches an empty stored owner. Blank ownership fields, write a Kerberos identity and password beside the token, and you are domain admin. FreeIPA fixed its side in four point thirteen point four. Patch directory servers and audit for surprise Kerberos principals before someone else does. Yesterday StyleSmuggler was an unpatched Magento and Adobe Commerce zero-day. Today Adobe shipped the fix as C.V.E. twenty twenty-six dash seventy-five thousand six hundred fifty, C.V.S.S. ten, and confirmed in-the-wild exploitation against Commerce merchants. The bug injects P.H.P. through the template system while generating a Payment Transaction Failed Reminder email. Attackers have been dropping a Rust Linux backdoor and a P.H.P. web shell. Disrex saw one managed Magento box compromised fifty minutes after the first confirmed hit on September fourth. Adobe's hotfix is VULN dash thirty-nine thousand three hundred forty-one, and you must rotate encryption keys after applying it. Waiting-room mode is over. Patch, rotate keys, and hunt for shells that landed between September fourth and now. Arctic Wolf is tracking PREY dash zero zero five eight, a data theft and extortion cluster hitting executives through fake I.T. help desk calls. Targets get walked to a lookalike Microsoft three sixty-five login. Adversary-in-the-middle harvests credentials and M.F.A. approvals, then replays session tokens from residential proxies in the victim's geography. After sign-in, operators poke SharePoint and Entra I.D., map what the executive can see, and move into extortion. The tradecraft overlaps UNC six six seven one and groups that keep rebranding under names like Cinder and Pink. Help desk vishing plus token replay is still beating phishing training that only watches email. Train for the phone call, lock down risky OAuth apps, and treat unexpected M.F.A. prompts as an incident, not a annoyance. Huntress found worm-like abuse of ConnectWise ScreenConnect. Three unrelated incidents used Quick Assist scams, phishing M.S.I.s, or fake Geek Squad refund lures to stand up rogue clients. Those clients then ran a four-stage V.B.Script chain and pushed the same payload to newly connected hosts. Connect to an infected client and the host side can catch the chain. Connection I.D.s are tracked, then cleared on disconnect, so a later reconnect can reinfect. ConnectWise is telling customers to disable file transfers until a fix lands. Remote support that auto-spreads malware is an R.M.M. nightmare sequel. Audit ScreenConnect installs, kill unexpected clients, and treat new remote sessions as untrusted until proven otherwise. A messaging worm that rides contact trust, an identity stack that mints anonymous admins, a commerce zero-day that finally got a patch, help desk calls that steal live sessions, and remote support that infects the next box it meets. Privileged trust and management planes keep paying out. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472
Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764