The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
Cisco SD-WAN Admin Bypass Hits KEV Ahead of Friday
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Here is your briefing for Thursday, October 1, 2026. CISA put a critical Cisco Catalyst S D-WAN Manager authentication bypass on Known Exploited Vulnerabilities Wednesday after confirming active exploitation. C V E twenty twenty-six dash seventy-six thousand five hundred four is a nine point eight hex-encoding bug. An unauthenticated attacker who can reach the Manager A P I sends a crafted H T T P request, skips the session auth rule meant to protect j underscore security underscore check, and lands with admin privileges. Cisco P S I R T says it saw exploitation in September. There is no workaround. Federal civilian agencies have until October third. Fixed trains include twenty point nine point ten point one, twenty point twelve point eight point two, twenty point fifteen point six point one, twenty point eighteen point four point one, twenty-six point one point two point one, and twenty-six point two point one. watchTowr notes this is the eighth Cisco S D-WAN C V E on KEV in twenty twenty-six alone. Hunt U R L-encoded j underscore security underscore check posts and viptela-reserved accounts in the Manager logs, then upgrade. Your single pane of glass for the whole W A N is someone else's single pane of glass for you. OpenAI says it disrupted a coordinated adversarial distillation campaign that tried to extract protected reasoning from its models at scale. A core cluster dating to early July is attributed to individuals associated with Moonshot A I, the Beijing lab behind Kimi. Operators did not break encryption or breach a database. They manipulated interactions so hidden reasoning showed up in forms the requester could see, violating terms of service. Traffic started small on July first, spiked to sixteen thousand extraction-pattern attempts from over four thousand users on July twenty-fourth and twenty-fifth, and tied to prompt patterns across more than fifteen thousand accounts before a July twenty-eighth shutdown. OpenAI banned the accounts, closed a replay path for stolen encrypted reasoning, and added checks on streamed output. Researchers earlier showed encrypted reasoning traces can be swapped across sessions and weaker sibling models to force plaintext decode. Distillation without the original safeguards is how you get a capable model that skipped the safety tax. Crypto exchange Bitget confirmed attackers who stole three hundred eighty-seven point five million dollars last week used a zero-day in third-party security products, citing SlowMist and Mandiant. The actors hit security appliances labeled Product A and Product B, planted a web shell, moved laterally into Bitget's wallet job server, and ran a custom tool tuned to the withdrawal logic starting at one forty-nine A M on September twenty-fifth. Compromise of the Product A service environment reaches back to August thirty-first. Eleven chains were hit, from Ethereum and X R P Ledger to Tron, Base, and Celestia. About one point one million dollars has been frozen by Circle, Tether, and N E A R Intents. Bitget points at North Korean actors based on I P patterns and wallet overlaps tracked by Elliptic and T R M Labs. Your wallet controls are only as strong as the security appliances sitting in front of them, and those appliances just became the front door. Google announced Gemini 4 Argon, a frontier model it is rolling first to trusted cyber defenders in its Fairwind Program. Koray Kavukcuoglu says it hits complex software engineering, legal and finance workflows, and cybersecurity defense. Argon is rated highly capable at finding, validating, and patching critical bugs, including a previously unknown critical flaw that exposed personal data in healthcare software used by hospitals worldwide. Google did not name the product. Wiz is already using it. Google claims leaps over Gemini three point eight Flash Cyber on attack-surface discovery and proof-of-concept generation, plus a top score on Gray Swan's indirect prompt injection benchmark. It plans a version without cyber guardrails for trusted defenders and internal teams, while shipping chain-of-thought monitors that can halt misaligned actions. After a summer of rogue-agent headlines, Google is betting transparency plus kill switches beats another silent sandbox escape. Broader access comes later, starting with paid A P I and A I Ultra. Microsoft says attackers have been weaponizing Zimbra Collaboration Suite C V E twenty twenty-six dash seventy-three thousand five hundred seventy, an eight point nine unauthenticated command injection that fires through a crafted email when zimbra-snmp is installed and S N M P notifications are on. No login, no click, just S M T P against an exposed mail server. Post-exploit work includes J S P web shells in Jetty and mailboxd paths, reverse shells, privilege escalation, memory-backed execution, and harvesting of authentication and mailbox data. Shadowserver has counted hundreds of compromised instances among roughly ten thousand still-visible Zimbra servers. The patch landed in ten point one point twenty on July twentieth
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472