{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"The Cybersecurity Defenders Podcast","title":"Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/60500cfb\"></iframe>","width":"100%","height":180,"duration":1801,"description":"Matt and Chris break down four stories from the week in threat intel:\n\n• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.\n• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.\n• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.\n• Varonis Threat Labs phishing an AI email agent (\"Pinchy\") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.","thumbnail_url":"https://img.transistorcdn.com/sQVL4Dw1YKvU3ChkRRBR7pa4FGTwkeVb6_WJLMwkgNA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}