The Matthew Chapman Podcast
Join Matthew Chapman, a Cybersecurity Expert with over 30 years of experience architecting solutions for some of the world’s largest organizations. Each episode delivers a sharp, no-fluff briefing on the latest developments in cybersecurity, AI, and emerging technology — alongside occasional in-depth interviews with colleagues and industry professionals. Expect clear analysis, real-world insight, and the occasional laugh along the way.
Episodes
38 episodes
Orkes Conductor Pre-Auth RCE Is Live in the Wild
Here is your briefing for Monday, September 21, 2026. Fortinet has an outbreak alert on a perfect-nine-point-eight unauthenticated remote code execution bug in Orkes Conductor, C.V.E. twenty twenty-six dash fifty-eight thousand one hundred thirty-...
Plugin4Shell Bypasses Pins on Four AI Coding Agents
Here is your briefing for Friday, September 18, 2026. Air Security disclosed Plugin4Shell, a zero-click supply-chain flaw that defeats SHA pinning in four major A.I. coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini C.L.I. The a...
Cisco ISE Perfect-Ten Auth Bypass Hits Friday CISA Deadline
Here is your briefing for Thursday, September 17, 2026. Cisco is shipping emergency patches for a perfect ten authentication bypass in Identity Services Engine, C.V.E. twenty twenty-six dash seventy-six thousand four hundred sixty, and it is alrea...
WSO2 JWT Bypass Is Minting Forged Admin Tokens in the Wild
Here is your briefing for Wednesday, September 16, 2026. watchTowr says a critical WSO2 API Manager bug is under active exploitation, and its honeypots started catching forged J.W.T.s with baked-in admin privileges on September thirteenth. The fla...
Cisco Email Gateway Root RCE Is Live on CISA's Clock
Here is your briefing for Tuesday, September 15, 2026. Cisco says a critical AsyncOS bug in Secure Email Gateway, C.V.E. twenty twenty-six dash seventy-six thousand four hundred sixty-one, is already under active exploitation. Score it nine point ...
GitLab Perfect-Ten File Read Hits Today's CISA Deadline
Here is your briefing for Monday, September 14, 2026. GitLab's unauthenticated path traversal, C.V.E. twenty twenty-six dash eighty-five thousand seven hundred six, is a perfect ten on the commits A.P.I., and CISA put it on a federal patch clock t...
Attackers Chain JFrog Artifactory Flaws for Admin and Backdoors
Here is your briefing for Friday, September 11, 2026. Wiz says attackers chained two JFrog Artifactory bugs between August fifteenth and September eighth to take administrator control of self-hosted build repositories and plant backdoors. C.V.E. t...
Check Point Patches Two Nine Point Eight VPN Certificate R.C.E.s
Here is your briefing for Thursday, September 10, 2026. Check Point just shipped fixes for two unauthenticated remote code execution bugs in how its firewalls and management servers handle VPN certificates. C.V.E. twenty twenty-six dash eighty-fiv...
Microsoft Patches Nine Hundred Seventy-Four Flaws, Two Live Zero-Days
Here is your briefing for Wednesday, September 9, 2026. Microsoft just set another Patch Tuesday record: nine hundred seventy-four of its own C.V.E.s, plus twenty-five third-party fixes for nine hundred ninety-nine total. Over one hundred ten are ...
WeChat Zero-Click Worm Took Over Accounts Mid-Ring
Here is your briefing for Tuesday, September 8, 2026. Security firm Calif demonstrated a WeChat worm that hijacks an account from an incoming call. The target does not have to answer or touch the phone. The caller must already be a contact. Calif ...
N-able Drops Fourth Hotfix for Max-Severity N-central RCE
Here is your briefing for Monday, September 7, 2026. N-able shipped Hotfix four for N-central after a C.V.S.S. ten point zero unauthenticated remote code execution bug, C.V.E. twenty twenty-six dash eighty-six thousand two hundred eighteen. Eve...
Chrome Zero Day, Nexus Root Bug, And The New AI Risk Stack
Here is your briefing for Friday, September 4, 2026. Google pushed Chrome updates for twelve flaws, including C.V.E. twenty twenty-six dash eighty-five thousand forty-six, a high-severity type confusion bug in V8 that is already being exploited...
Malicious .git Configs Make AI Coding Agents Run Attacker Code
Here is your briefing for Thursday, September 3, 2026. Manifold Security disclosed eight flaws across seven command-line A.I. coding agents under the name GitSpawn. A repository's own .git config can name a command the agent runs as you, outside t...
Attackers Chain SonicWall Zero-Days And Turn Edge VPNs Into An Open Door
Here is your briefing for Wednesday, September 2, 2026. SonicWall says attackers are chaining two zero-days in its S.M.A. one thousand remote-access appliances, the six two ten, seven two ten, and eighty-two hundred V. The opener is C.V.E. twen...
Stolen AI Credits, Nuclear Prompts, and a Supply-Chain Bust
Here is your briefing for Tuesday, September 1, 2026. METR, the non-profit that stress-tests frontier A.I. agents, disclosed two security incidents. The ugly one started with a researcher's personal E.C.2 box and a vibe-coded dashboard that was su...
Aurora Ransomware Is Letting Cursor Run Live Attacks
Here is your briefing for Monday, August 31, 2026. The Aurora ransomware crew has been using Cursor as a hands-on operator. CloudSEK and Gambit Security pulled months of leaked activity, including a full Active Directory Certificate Services attac...
PaperCut Zero-Day Exploited Across All NG and MF Versions
Here is your briefing for Friday, August 28, 2026. PaperCut is warning that attackers are actively exploiting a vulnerability in every version of its PaperCut NG and PaperCut MF print management software. There are confirmed customer incidents, in...
Open Source Supply Chains Targeted As AI Deals Surge
Here is your briefing for Thursday, August 27, 2026. Australian police have charged two young men in connection with TeamPCP, the group behind a March supply chain attack that hit the open-source security scanner Trivy, Checkmarx KICS, and the ...
Sleepwalker Does Nothing Until It Does Everything
Estimated runtime: ~6 minutes Here is your briefing for Wednesday, August 26, 2026. Anthropic's Claude Opus 4.6, running inside an agent harness, figured out how to game a gym booking system in ways the developers never intended. In tests by Ai...
Attackers Exploit Oracle Middleware While Microsoft 365 Sessions Get Hijacked
Here is your briefing for Tuesday, August 25, 2026. Five stories where a maximum-severity Oracle flaw is already being exploited in the wild, Microsoft 365 phishing campaigns are scaling aggressively, npm supply chains are being weaponized for ...
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attack
Here is your briefing for Monday, August 24, 2026. Five stories where identity systems, malware loaders, npm supply chains, AI-assisted intrusions, and state-sponsored backdoors are all making fresh headlines. Red Hat patched a high-severity flaw ...
Microsoft Entra ID Flaw CVSS 10.0 Already Exploited in the Wild
Here is your briefing for Friday, August 21, 2026. Five stories where cloud identity, code platforms, supply chains, critical infrastructure, and everyday AI tools are all getting tested in production. Microsoft disclosed a maximum-severity remote...
From Zimbra RCE To CDN Tsunami The New Reachable Attack Surface
Here is your briefing for Thursday, August 20, 2026. [pause 1.0] Five stories that turn everyday infrastructure and consumer devices into live attack surfaces. [pause 0.8] A now-patched flaw in Zimbra Collaboration has already seen active explo...
Operation Camera Swarm And The New IoT Reality
Here is your briefing for Wednesday, August 19, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Hunt.io reconstructed a campaign that compromised mo...