The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
The Matthew Chapman Podcast
Week in Review: Self-Signing Worms, Atlassian, Fake Google Certs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Week in review: the three stories from this week that still need your attention, a self-signing supply-chain worm, an Atlassian bug turned admin factory, and real TLS certificates minted through hijacked country domains.
1. Shai-Hulud worm rides Tensorlake into Claude Code and VS Code
tensorlake 0.5.144 on npm shipped a preinstall credential stealer that republishes victims' packages with Sigstore provenance and plants persistence in .claude and .vscode task files. Revoking the stolen GitHub token first may trigger a destructive payload.
Before the weekend: search repos for unexpected .claude and .vscode task files, clean the machine, then rotate npm, GitHub, and cloud tokens.
Source: The Hacker News
2. Atlassian Data Center flaw went from advisory to attacks in two hours
A 9.3 path traversal in eight self-hosted Data Center products, including Jira, Confluence, Bitbucket, Bamboo, and Crowd, is under exploitation; on Crowd and Jira it leads to admin takeover via crowd.properties. Fix versions differ between the advisory and the CVE record.
CVE: CVE-2026-21589
Before the weekend: upgrade to the fixed release, confirm the build number, and audit for unknown admin accounts.
Sources: The Hacker News (disclosure), The Hacker News (exploitation)
3. Hijacked .gh, .sl, and .as domains produced real certificates for Google
Attackers took over three ccTLDs, rewrote DNS beneath them, and got CAs to issue TLS certificates for Google and other major brands. Chrome blocks the known certificates, but Google can't promise it found them all, and other browsers aren't covered.
Before the weekend: set restrictive CAA records and subscribe to certificate transparency alerts for your domains.
Source: The Hacker News
More from Matt: https://www.mattchapman.net
Kindle: https://www.amazon.com/dp/B0HHMH88H9
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472
Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764