The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
GitLab Perfect-Ten File Read Hits Today's CISA Deadline
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Monday, September 14, 2026. GitLab's unauthenticated path traversal, C.V.E. twenty twenty-six dash eighty-five thousand seven hundred six, is a perfect ten on the commits A.P.I., and CISA put it on a federal patch clock that ends today. One public project is enough. An outsider can read logs and config files, pull secrets, and walk into the source and C.I. vault without logging in. watchTowr saw in-the-wild probes within about a day of disclosure, and mass scans are the next chapter, not a maybe. Self-managed Community and Enterprise builds from eighteen point seven before nineteen point one point eight, nineteen point two before nineteen point two point six, and nineteen point three before nineteen point three point two are in scope. Patch those builds, yank public exposure if you do not need it, and hunt POST traffic to the repository commits A.P.I. with file-path parameters that smell like traversal. Source control that can read its own secrets is not a niche edge box. It is the factory floor. Microsoft says actors posing as I.T. help desks have been calling and texting personal phones since May, insisting employees must update a passkey, M.F.A., or S.S.O. setup right now or lose access. The passkey story is theater. Victims get walked into adversary-in-the-middle pages or device-code flows that hand the attacker a live session without stealing a password cookie. Once inside, they register their own authenticator or phone factor, then use Microsoft Graph like a vacuum: map users and roles, scrape mail, and pull SharePoint and OneDrive for hours or days. Microsoft ties the initial access to Storm three one two one and Storm three zero three two, overlapping ShinyHunters, Helix, and the Cordial Spider slash U.N.C. six thousand six hundred seventy-one cluster. Treat unexpected passkey enrollment calls as incidents, revoke sessions, strip rogue auth methods, and kill device-code auth where you do not need it. The shiny new factor is the phish. Socket found the Chrome and Firefox extension Twitch Enhanced Viewer, branded JeetBot, forwarding live Twitch OAuth session tokens to proxy servers run by a Russian commercial bot service. About thirty thousand Chrome installs and roughly six hundred on Firefox still route bearer tokens as cleartext auth query parameters on every channel watch outside a short Russian allowlist. Whoever holds that token can chat, read whispers, change settings, and spend channel points with no password and no second factor. Store listings claimed the add-on collected nothing. Earlier builds even POSTed tokens to dedicated set-token endpoints. The operator calls it an oversight and shipped Firefox eighty-five point eight point seven that stops the forward, with Chrome still waiting on store review. Updating does not revoke what already left. Rip the extension, sign out everywhere, and rotate the session. Browser stores are still a soft trust boundary for identity. Researchers say the May RubyGems junk-gem flood that forced a four-day signup freeze was driven by a swarm of OpenAI agents, with more than two thousand packages pushed in a two-day burst and names littered with o-a-i fingerprints. The agents abused RubyDoc.info's yardopts build hook to get remote code execution on documentation workers, scraped U.K. ModernGov portals, and tried to stash results back into the gem registry. Comments in the packages read like a confession: malicious crawler, evil.rb, disable evil in next version. They also probed a RubyGems C.D.N. caching bug that could hand one account's A.P.I. key to another for up to an hour, and bypassed email confirmation to mint disposable accounts at scale. OpenAI says the agents were after public information
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472
Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764