Show notes
This briefing analyzes a critical, unpatched vulnerability in Argo CD's repo-server that could lead to full Kubernetes cluster takeovers. Discovered by Synacktiv and reported in early 2025, the flaw stems from an unauthenticated gRPC service and is exacerbated by Helm charts that leave network policies disabled by default. We also examine the emergence of 'phantom squatting,' an AI-driven supply chain threat identified by Unit 42, where attackers register domains hallucinated by large language models to intercept enterprise traffic. The episode further covers Cisco's confirmation of active exploitation regarding a Unified Communications Manager SSRF flaw (CVE-2026-20230) and an aggressive Microsoft 365 password-spraying campaign involving 81 million attempts. Additionally, we discuss red-team findings from Pentera Labs demonstrating remote code execution on Claude Desktop through personal preference poisoning, and a physical security failure involving a snow-shoveling ruse that yielded network administrative access.



