Ep.624 - RadioCSIRT Édition Française - flash info cybersécurité du jeudi 9 avril 2026
·9 min
The episode opens with Marc-Frédéric Gomez introducing the daily cybersecurity flash info for Thursday, April 9, 2026. He immediately lists five major security developments. First, CISA has added CVE-2026-1340 to its CAVE catalog, a code injection vulnerability actively exploited in Ivanti EPMM mobile management systems. Second, Google Chrome has released a massive update addressing over 50 CVEs, though Google hasn't detailed the specific impacts. Third, GenFlatlabs researchers published analysis of Remus, a 64-bit variant of LumaStealer first observed in February 2026 campaigns. Remus introduces Ether-Hiding, which uses Ethereum smart contracts to store C2 addresses, making infrastructure takedowns extremely difficult. It also includes a Chrome Bound Encryption bypass via shellcode injection. Fourth, Vulncheck researcher Kathleen Condon detected active exploitation of CVE-2025-59528, a CVSS-10 vulnerability in Flowwise that allows arbitrary JavaScript execution via insecure parameter evaluation in MCP custom nodes. Between 12,000 and 15,000 Flowwise instances are exposed on the internet. Fifth, Sense ISC researcher Xavier Martins documented a complete infection chain delivered via phishing, involving a 10MB obfuscated JavaScript file that uses encrypted PNG containers and memory patching to deploy Formbook infostealer. The episode concludes with personal news about the host gaining his first YouTube editor after ten years, who suggests AI could improve the show. Gomez encourages listeners to patch systems and provide feedback.