RadioCSIRT - Edition Française · Marc Frédéric GOMEZ

Ep.625 - RadioCSIRT Édition Française - flash info cybersécurité du vendredi 10 avril 2026

·10 min
The episode opens with Google's deployment of Device Bound Session Credentials in Chrome 146 on Windows, which cryptographically anchors session cookies to the terminal's TPM to prevent theft by info-stealers. This feature has already reduced theft cases since its beta launch and is planned for macOS. Next, a supply-chain attack compromised the update infrastructure of the Smart Slider 3 Pro WordPress plugin, distributing a trojanized version via the official channel for about six hours. The payload includes a multi-layer persistence toolkit, arbitrary code execution via HTTP headers, and creation of a hidden administrator account. The plugin has over 800,000 active installations, and version 3.5.1.36 fixes the issue. An unpatched zero-day in Adobe Reader has been actively exploited since at least November 2025, abusing privileged APIs to read local files and exfiltrate data to a remote server. The exploit targets the oil and gas sector, with Russian-language indicators, and Adobe has not yet patched it. A new ransomware, analyzed by researcher Abdullah Islam, targets VMware ESXi environments using an ELF64 binary that combines Curve 25519 ECDH with Chacha 20 encryption. It dynamically selects CPU variants for speed, stops VMs before encryption, and targets files over 5 GB, with ransom notes replacing ESXi welcome files. The FBI recovered deleted Signal messages from an iPhone without breaking encryption by exploiting iOS's push notification database, which persists after app uninstallation. This method captures incoming messages even with self-destruction timers and is not specific to Signal. The episode concludes with sources available in the description.
Listen to the show on