The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
VeloCloud Perfect-Ten Orchestrator Flaw Is Under Active Attack
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Tuesday, September 22, 2026. Arista says attackers are already hitting a perfect-ten flaw in on-prem VeloCloud Orchestrator, C.V.E. twenty twenty-six dash ninety-three thousand nine hundred fifty-two. No login required. If your orchestrator authenticates Edges with certificates and the web interface is reachable, a remote attacker can privilege internal functions, own the host, and from there reach the Edge devices that orchestrator manages. Fixes are out for the five point two and six point four trains. Six point one and seven point oh still wait. Hosted and Dedicated got patched server-side. Arista published webshell and backdoor indicators, including a vc-sysmond binary and a few DigitalOcean I.P.s. If you run certificate-mode V.C.O., lock the admin U.I. to trusted nets, hunt those I.O.C.s, and do not sit on six point one hoping a brochure will patch it. Patrick Wardle dropped a proof-of-concept showing malware already on a Mac can flip a hidden Muse setting so spoken prompts leave the microphone and land with the attacker instead of Meta. Muse is Meta's new personal A.I. agent with access to files, email, messages, calendar, shopping, and smart-home apps, so hijacking the prompt path hijacks whatever privileges the user already granted. It is not a drive-by. You need code as the logged-in user first, or a ClickFix lure that tricks someone into pasting one command. Ars Technica called it a serious zero-day for an extraordinarily privileged assistant. If Muse is on your fleet Macs, treat mic-dictation trust and local malware like the same problem, because that is how Wardle chained it. Cisco Talos open-sourced C.A.I.R.N., a framework for fingerprinting A.I.-integrated malware, and immediately found something uglier than a chatbot bolted onto a stealer. CLOSEDQUORUM is Windows malware that polls DeepSeek, Qwen, Mistral, and Google Gemini for a consensus on what to do next, with no human operator in the loop. Credentials and crypto wallets are the prize. Even if one model is down, the others keep the hive alive. Talos ties forum chatter to carding back to twenty twenty-five, but has not confirmed real-world campaigns yet. Still, autonomous C-two by L.L.M. committee is no longer a slide deck. Indicator hunting has to include A.P.I. calls to model providers, not just classic panel domains. A new Linux kernel K.V.M. bug on ARM sixty-four, C.V.E. twenty twenty-six dash eighty-nine thousand seven hundred seventy-five, can leave freed host memory exposed to a guest when nested virtualization is on. The researcher who found it says that is enough to escape the guest and run code on the host. Fixes landed in six point eighteen point fifty-one, seven point two point five, and seven point three R.C. one. Nested virt is off by default and needs Armv eight point four hardware with F.E.A.T. underscore N.V. two, so a plain ARM sixty-four K.V.M. host that never enables it sits outside the reported path. Clouds and labs that do nest hypervisors on Apple Silicon class iron should patch and confirm nested mode was intentional, not a leftover boot flag. CISA put a patched Zyxel GS nineteen hundred stack overflow, C.V.E. twenty twenty-six dash seven thousand two hundred seventy-three, on the Known Exploited list. GreyNoise says a suspected Chinese-speaking actor has been weaponizing it since mid-August, hitting nine hundred ninety-six switches across forty-eight countries and pulling configs plus hashed root credentials over T.F.T.P. Federal agencies have until September twenty-fourth. Same morning, Arctic Wolf warned of live abuse of a Veeam Agent for Windows local privilege escalation, C.V.E. twenty twenty-six dash thirty-two thousand nine hundred ninety-six, that turns a readable session U.I.D. in a ProgramData log into SYSTEM over a named pipe. Switch firmware and backup agents are not glamorous, which is exactly why they keep paying. Patch the GS nineteen hundreds and the Veeam agent before the KEV calendar does it for you. A perfect-ten VeloCloud orchestrator bug already in the wild, Muse turned into a local backdoor for its own privileges, malware that takes orders from four L.L.M.s, an ARM sixty-four K.V.M. nested escape, and actively exploited Zyxel plus Veeam flaws. S.D.-WAN control planes, A.I. assistants, autonomous implants, hypervisors, and backup agents all got louder overnight. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472
Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764