EPISODE · Apr 29, 2026 · 17 MIN
2026-04-29: CISA adds exploited ConnectWise and Windows flaws to KEV catalog
from Cyber Threat Brief
Show Notes - 2026-04-29 Stories Covered: - Today: - CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV (CVE-2024-1708, CVE-2026-32202) (https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html) - Critical GitHub Vulnerability Exposed Millions of Repositories (CVE-2026-3854) (https://thehackernews.com/2026/04/researchers-discover-critical-github.html) - LiteLLM SQL Injection Exploited Within 36 Hours (CVE-2026-42208) (https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html) - VECT 2.0 Ransomware Acts as Data Wiper for Large Files (https://thehackernews.com/2026/04/vect-20-ransomware-irreversibly.html) - Feuding Ransomware Groups Leak Each Other's Data (https://www.darkreading.com/threat-intelligence/feuding-ransomware-groups-leak-data) - Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain (https://www.darkreading.com/application-security/fresh-glassworm-vs-code-extensions-supply-chain) - Cyber Insurance Data Highlights MFA Misconfiguration as Top Loss Driver (https://www.securityweek.com/cyber-insurance-data-gives-cisos-new-ammo-for-budget-talks/) - Microsoft Outlook for iOS Still Down After Service Change (https://go.theregister.com/feed/www.theregister.com/2026/04/28/a_service_change_takes_down/) - Microsoft Teams Free Backend Change Broke Chat and Calls (https://www.bleepingcomputer.com/news/security/microsoft-says-backend-change-broke-teams-free-chat-and-calls/) - OpenAI Models Now Available on AWS Bedrock (https://go.theregister.com/feed/www.theregister.com/2026/04/28/openai_climbs_into_amazons_bedrock/) - Critical Unpatched Flaw in Hugging Face LeRobot (CVE-2026-25874) (https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html) - Microsoft to Deprecate Legacy TLS in Exchange Online Starting July (https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-legacy-tls-in-exchange-online-starting-july/) CVEs Referenced: CVE-2024-1708, CVE-2024-1709, CVE-2026-21510, CVE-2026-21513, CVE-2026-25874, CVE-2026-32202, CVE-2026-3854, CVE-2026-42208 Indicators of Compromise: IPs: 65.111.27.132 Full brief: https://carolinacleartech.com/brief/2026-04-29/
Embed this episode
What this episode covers
Show Notes - 2026-04-29 Stories Covered: - Today: - CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV (CVE-2024-1708, CVE-2026-32202) (https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html) - Critical GitHub Vulnerability Exposed Millions of Repositories (CVE-2026-3854
NOW PLAYING
2026-04-29: CISA adds exploited ConnectWise and Windows flaws to KEV catalog
No transcript for this episode yet
Similar Episodes
No similar episodes found.