The Update Was the Backdoor episode artwork

EPISODE · Jun 1, 2026

The Update Was the Backdoor

from CyberPulse · host Tushar Vartak

Attackers hijacked the update infrastructure for Smart Slider 3 Pro (800K+ WordPress installations) and pushed a fully weaponized remote access toolkit through the official update channel for approximately six hours. Adobe released an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution flaw in Acrobat Reader under active exploitation via malicious PDFs. The GlassWorm campaign evolved with a Zig-compiled dropper targeting multiple developer IDEs simultaneously. Google shipped Device Bound Session Credentials (DBSC) in Chrome 146, binding session cookies to hardware TPM to block infostealer session replay. Thousands of internet-exposed Rockwell PLCs were confirmed, expanding the OT attack surface quantification.

Episode metadata supplied by the publisher feed · Published Jun 1, 2026

Embed this episode

NOW PLAYING

The Update Was the Backdoor

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this CyberPulse episode published?

This episode was published on June 1, 2026.

Can I download this CyberPulse episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!