EPISODE · Jun 1, 2026
The Update Was the Backdoor
from CyberPulse · host Tushar Vartak
Attackers hijacked the update infrastructure for Smart Slider 3 Pro (800K+ WordPress installations) and pushed a fully weaponized remote access toolkit through the official update channel for approximately six hours. Adobe released an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution flaw in Acrobat Reader under active exploitation via malicious PDFs. The GlassWorm campaign evolved with a Zig-compiled dropper targeting multiple developer IDEs simultaneously. Google shipped Device Bound Session Credentials (DBSC) in Chrome 146, binding session cookies to hardware TPM to block infostealer session replay. Thousands of internet-exposed Rockwell PLCs were confirmed, expanding the OT attack surface quantification.
Embed this episode
NOW PLAYING
The Update Was the Backdoor
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.