RadioCSIRT - Edition Française · Marc Frédéric GOMEZ

Ep.588 - RadioCSIRT Édition Française – Votre actualité Cybersécurité du samedi 28 février 2026

·21 min·2 clips
A critical AI platform vulnerability allows remote code execution as Iran suffers a near-total internet blackout during military strikes.
The episode opens with host Marc-Frédéric Gomez summarizing the day's cybersecurity headlines. He first addresses a critical vulnerability (CVE-2026-142) in ServiceNow's AI Platform that allows remote code execution via sandbox escape, affecting Zurich, Yokohama, Xanadu, and Australia branches with patches in various stages. Gomez then reports that over 900 Sangoma FreePBX instances remain compromised by webshells from a campaign exploiting CVE-2025-64-328, with the US, Brazil, Canada, Germany, and France having the most infections. He describes an almost total internet blackout in Iran, where connectivity dropped to 4% amid Israeli and American military strikes, accompanied by significant cyberattacks on Iranian media. The host analyzes the Rubyjumper campaign attributed to North Korean group APT37, which uses a five-component toolkit including TUMB BSBD to turn USB drives into bidirectional command relays. Gomez details 17 malicious NPM packages deployed by Famous Sholima that use an unprecedented technique of textual steganography on pass-bind to hide C2 infrastructure. He discusses the 2026 OSSRA report by Black Duck, which found a 107% rise in open-source vulnerabilities per codebase, largely due to AI coding assistants, with 87% of audited codebases containing vulnerabilities. The episode includes two listener messages: Patrick offers support to the host, and Frédéric comments on the utility of the podcast's hotline. Gomez responds to feedback about moving from Gmail to a European messaging system. He concludes with a personal anecdote about recording issues and dinner plans, encouraging listeners to send feedback.
Listen to the show on