
Blumira Briefings
Staying on top of security news shouldn't be another full-time job.
Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you might have missed, and explain what they actually mean for your security practice! π
Each week, join a lineup of different Blumira experts (and sometimes special guests!) who will:
- Share the top threats, suspects, and risks we're seeing across our detection and response platform
- Discuss significant security stories and what they mean for YOU
- Provide practical advice you can actually implement right away
β’β’Keep it conversational, informative, and under 30 minutes
Blumira Briefings
π¦ Blumira Briefings Ep. 11: Cloud ISE Cred Twinsies, Windows 0day Exploited, and Play Ransomware Updates
This week on Blumira Briefings, join our "Oops! All Detection Engineers" episode as Zoe hosts Jake and Justin to break down the most critical security headlines of the week with practical context you can actually use!
π What We Cover This Week:
π©οΈ Cisco ISE credential vulnerability affecting cloud deployments on AWS, Azure & Oracle (CVE-2025-20286)
π SAP NetWeaver critical missing authorization bug in RFC framework (CVE-2025-42989)
π Our most changed security trends of the week - what's suddenly spiking across our detection data
πͺ Windows WebDAV zero-day exploited against Turkish defense organization (CVE-2025-33053)
π§© Popular Chrome extensions leaking data through unencrypted HTTP connections
π Updated CISA guidance on Play Ransomware with new attack details
π‘ Quick tip of the week: Validate your security controls by testing them regularly - have you tried restoring from your backups recently to confirm they actually work?
Plus, Expert Insights On:
π Why "randomly generated" credentials are just default credentials with extra steps
βοΈ How to protect cloud infrastructure from credential vulnerabilities
β±οΈ Why the time between vulnerability disclosure and broader exploitation keeps shrinking
π The security risks of browser extensions and VPN services
π‘οΈ The importance of using phishing-resistant MFA with secure backup options
π LINKS:
CVSS Base Score Metrics: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Pyramid of Pain: https://www.attackiq.com/glossary/pyramid-of-pain/
π€« SUPER EXTRA BONUS DEFENDER RESOURCE:
π΅ Monkey365 β PS Scanner for M365, Azure, and Entra: https://github.com/silverhack/monkey365