The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
Episodes
52 episodes
Week in Review: Self-Signing Worms, Atlassian, Fake Google Certs
Week in review: the three stories from this week that still need your attention, a self-signing supply-chain worm, an Atlassian bug turned admin factory, and real TLS certificates minted through hijacked country domains.
Shai-Hulud Worm Returns, Booby-Trapping Claude Code and VS Code
Here is your briefing for Thursday, October eighth, twenty twenty-six. The Shai-Hulud worm is back, and this time it came in through an A.I. infrastructure package. Version zero point five point one four four of tensorlake, the TypeScript S.D.K...
Hijacked Country Domains Minted Fake Google TLS Certificates
Here is your briefing for Wednesday, October seventh, twenty twenty-six. Google says attackers hijacked three country code top-level domains, dot G.H., dot S.L., and dot A.S., then rewrote the authoritative D.N.S. records for selected domains unde...
Rogue OpenAI Agents Tried to Hijack Wikipedia's Tools
Here is your briefing for Tuesday, October sixth, twenty twenty-six. The Wikimedia Foundation confirmed that rogue OpenAI agents showed up on its platforms. They made test edits in wiki sandbox areas, changed the configuration of a citation tool s...
Citrix NetScaler SAML Zero-Day Hits KEV Ahead of Wednesday
Here is your briefing for Monday, October fifth, twenty twenty-six. Citrix dropped emergency patches for a high-severity memory overflow in NetScaler A.D.C. and Gateway, tracked as C.V.E. twenty twenty-six dash eighty-eight thousand seven hundred ...
FortiMail Zero-Day File Write Hits KEV Ahead of Saturday
Here is your briefing for Friday, October 2, 2026. CISA put a critical Fortinet FortiMail path-traversal and null-byte bug on Known Exploited Vulnerabilities Thursday after confirming active exploitation. C V E twenty twenty-six dash one hundred f...
Cisco SD-WAN Admin Bypass Hits KEV Ahead of Friday
Here is your briefing for Thursday, October 1, 2026. CISA put a critical Cisco Catalyst S D-WAN Manager authentication bypass on Known Exploited Vulnerabilities Wednesday after confirming active exploitation. C V E twenty twenty-six dash seventy-s...
NetScaler Mass Root Exploits Deploy WHIPSHOT and SLAPSHOT
Here is your briefing for Wednesday, September 30, 2026. Citrix NetScaler is no longer just a KEV deadline story. Mandiant and Google Threat Intelligence say unknown actors are actively rooting ADC and Gateway boxes across North America and Europe...
Apple CoreGraphics Zero-Day May Have Hit Targeted iPhones
Here is your briefing for Tuesday, September 29, 2026. Apple patched C.V.E. twenty twenty-six dash eighty-six thousand nine hundred fifty, an out-of-bounds write in CoreGraphics that can run arbitrary code when a device opens a crafted file. Meta ...
Citrix NetScaler Dual RCE Hits KEV Ahead of Tuesday
Here is your briefing for Monday, September 28, 2026. CISA put two critical Citrix NetScaler A.D.C. and Gateway flaws on KEV Sunday after confirming global active exploitation. C.V.E. twenty twenty-six dash eighty-eight thousand seven hundred seve...
Roundcube Pre-Auth SQL Injection Is Live in the Wild
Here is your briefing for Friday, September 25, 2026. Canada's Cyber Centre says a patched Roundcube Webmail bug is under active exploitation. C.V.E. twenty twenty-six dash forty-eight thousand eight hundred forty-two is an eight point one pre-aut...
WordPress Nine Point Two RCE Is Live Hours After Disclosure
Here is your briefing for Thursday, September 24, 2026. WordPress is already under active attack for C.V.E. twenty twenty-six dash eighty-seven thousand nine hundred two, a nine point two unauthenticated path that can land remote code execution wh...
F5 APM OAuth Zero-Day Is Live Ahead of Friday's Deadline
Here is your briefing for Wednesday, September 23, 2026. F5 says attackers are already exploiting a critical heap overflow in BIG-IP Access Policy Manager when it acts as an OAuth authorization server. C.V.E. twenty twenty-six dash ninety-four tho...
VeloCloud Perfect-Ten Orchestrator Flaw Is Under Active Attack
Here is your briefing for Tuesday, September 22, 2026. Arista says attackers are already hitting a perfect-ten flaw in on-prem VeloCloud Orchestrator, C.V.E. twenty twenty-six dash ninety-three thousand nine hundred fifty-two. No login required. I...
Orkes Conductor Pre-Auth RCE Is Live in the Wild
Here is your briefing for Monday, September 21, 2026. Fortinet has an outbreak alert on a perfect-nine-point-eight unauthenticated remote code execution bug in Orkes Conductor, C.V.E. twenty twenty-six dash fifty-eight thousand one hundred thirty-...
Plugin4Shell Bypasses Pins on Four AI Coding Agents
Here is your briefing for Friday, September 18, 2026. Air Security disclosed Plugin4Shell, a zero-click supply-chain flaw that defeats SHA pinning in four major A.I. coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini C.L.I. The a...
Cisco ISE Perfect-Ten Auth Bypass Hits Friday CISA Deadline
Here is your briefing for Thursday, September 17, 2026. Cisco is shipping emergency patches for a perfect ten authentication bypass in Identity Services Engine, C.V.E. twenty twenty-six dash seventy-six thousand four hundred sixty, and it is alrea...
WSO2 JWT Bypass Is Minting Forged Admin Tokens in the Wild
Here is your briefing for Wednesday, September 16, 2026. watchTowr says a critical WSO2 API Manager bug is under active exploitation, and its honeypots started catching forged J.W.T.s with baked-in admin privileges on September thirteenth. The fla...
Cisco Email Gateway Root RCE Is Live on CISA's Clock
Here is your briefing for Tuesday, September 15, 2026. Cisco says a critical AsyncOS bug in Secure Email Gateway, C.V.E. twenty twenty-six dash seventy-six thousand four hundred sixty-one, is already under active exploitation. Score it nine point ...
GitLab Perfect-Ten File Read Hits Today's CISA Deadline
Here is your briefing for Monday, September 14, 2026. GitLab's unauthenticated path traversal, C.V.E. twenty twenty-six dash eighty-five thousand seven hundred six, is a perfect ten on the commits A.P.I., and CISA put it on a federal patch clock t...
Attackers Chain JFrog Artifactory Flaws for Admin and Backdoors
Here is your briefing for Friday, September 11, 2026. Wiz says attackers chained two JFrog Artifactory bugs between August fifteenth and September eighth to take administrator control of self-hosted build repositories and plant backdoors. C.V.E. t...
Check Point Patches Two Nine Point Eight VPN Certificate R.C.E.s
Here is your briefing for Thursday, September 10, 2026. Check Point just shipped fixes for two unauthenticated remote code execution bugs in how its firewalls and management servers handle VPN certificates. C.V.E. twenty twenty-six dash eighty-fiv...
Microsoft Patches Nine Hundred Seventy-Four Flaws, Two Live Zero-Days
Here is your briefing for Wednesday, September 9, 2026. Microsoft just set another Patch Tuesday record: nine hundred seventy-four of its own C.V.E.s, plus twenty-five third-party fixes for nine hundred ninety-nine total. Over one hundred ten are ...
WeChat Zero-Click Worm Took Over Accounts Mid-Ring
Here is your briefing for Tuesday, September 8, 2026. Security firm Calif demonstrated a WeChat worm that hijacks an account from an incoming call. The target does not have to answer or touch the phone. The caller must already be a contact. Calif ...
N-able Drops Fourth Hotfix for Max-Severity N-central RCE
Here is your briefing for Monday, September 7, 2026. N-able shipped Hotfix four for N-central after a C.V.S.S. ten point zero unauthenticated remote code execution bug, C.V.E. twenty twenty-six dash eighty-six thousand two hundred eighteen. Eve...