EPISODE · Jun 27, 2025 · 52 MIN
🦔 Blumira Briefings Ep. 13: Critical Veeam RCE, NetScaler Vulns, & Zero-Click Copilot Data Theft
from Blumira Briefings · host Blumira
🔔 Welcome back for this week’s episode and your weekly security download! We're joined by Jake Ouellette, Taylor Jacobson, and Amanda Berlin to break down the week's most important security headlines with context you can actually use. 🔔What We Cover This Week:📊 Most changed weekly trends, including recurring process dumps for credential theft and suspicious IAM behavior🔧 Critical Veeam RCE vulnerability (CVE-2025-23121) with a 9.9 CVSS score - make sure to patch this one immediately!🌐 NetScaler ADC and Gateway vulnerabilities allowing token theft from internet-facing devices📲 Cisco Meraki MX and Z device vulnerability can DoS VPN connections 💼 Identity theft report showing 148% surge in impersonation scams, with businesses as primary targets 🤖 First-ever zero-click AI data leak vulnerability in Microsoft 365 Copilot dubbed "EchoLeak"Document your recovery processes so anyone can perform them if the primary person is unavailable - don't create single points of failure in your incident response teamPlus, Expert Insights On:How to handle emergency patches outside normal change control cyclesWhy testing backup restoration is more critical than just having backupsPractical ways to run tabletop exercises even with limited resourcesStrategies for businesses to prevent impersonation attacksHow organizations can manage AI access to reduce risksNOTE: We'll be on hiatus next week due to the July 4th holiday -- we'll be back on July 11th with more security insights!📰 SOURCES:Veeam RCE Vulnerability: https://thehackernews.com/2025/06/veeam-patches-cve-2025-23121-critical.htmlCitrix NetScaler Vulnerabilities: https://www.darkreading.com/vulnerabilities-threats/citrix-patches-vulns-netscaler-adc-gatewayCisco & Atlassian Patches: https://www.securityweek.com/high-severity-vulnerabilities-patched-by-cisco-atlassian/Identity Impersonation Scams: https://www.infosecurity-magazine.com/news/reported-impersonation-scams-surge/Zero-Click AI Data Leak: https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/🔗 LINKS:Veeam Advisory: https://www.veeam.com/kb4743Rapid7 Emergent Threat Response: https://www.rapid7.com/blog/post/etr-critical-veeam-backup-replication-cve-2025-23121/Citrix Security Bulletin CTX693420: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420OWASP Top 10 for LLM Applications 2025: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/Defensive Security Handbook: https://www.oreilly.com/library/view/defensive-security-handbook/9781098127237/
Embed this episode
What this episode covers
🔔 Welcome back for this week’s episode and your weekly security download! We're joined by Jake Ouellette, Taylor Jacobson, and Amanda Berlin to break down the week's most important security headlines with context you can actually use. 🔔 What We Cover This Week: 📊 Most changed weekly trends, including recurring process dumps for credential theft and suspicious IAM behavior 🔧 Critical Veeam RCE vulnerability (CVE-2025-23121) with a 9.9 CVSS score - make sure to patch this one immediately! 🌐 N...
NOW PLAYING
🦔 Blumira Briefings Ep. 13: Critical Veeam RCE, NetScaler Vulns, & Zero-Click Copilot Data Theft
No transcript for this episode yet
Similar Episodes
No similar episodes found.