Fibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610
Aug 25, 2026 · 35m
Summary
Security Weekly News episode 610 covers a Zimbra command injection flaw actively exploited in the wild, alongside a Microsoft Entra ID deserialization bug that was initially reported as exploited before being retracted. The episode details a sophisticated social engineering attack on Apollo Global Management, where attackers bypassed help desk protocols via phone calls to steal credentials and exfiltrate data. Additional topics include a malicious fake Codex installer using sponsored search ads, a quantum battery prototype from Australia, and AliExpress’s use of inaudible sound waves for us…
Topics discussed
Intro: Fibonacci Episode 610 and Unhappy Numbers
Threat Intelligence Virtual Cyber Summit Promo
Microsoft Teams Bot Blocking Policy Update
Sponsor: ThreatLocker and InfoSec World
Zimbra ZCS Critical Vulnerability and Exploitation
ClickFix Attack Using Fake Codex Installer
IntelliJ IDEA Deserialization Flaw and CVE Revisions
The Return of Physical Password Books
Open-Weight AI Models and Rogue Agents
Quantum Battery Prototype from Australia
Sponsor: Tanium Atlas
Apollo Global Management Breach via Social Engineering
Listener Experience with Scam Calls and Phishing
AliExpress Inaudible Sound Fingerprinting
Outro and Subscription Info
Listen ad-free on Castria