Subscribe Share Full episode and show notes Vulnerability Management , AI/ML , Phishing Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland – SWN #576 Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Entrepreneurs, Sararimen, Aaran Leyland, and More on the Security Weekly News. April 28, 2026 Full Segment Notes Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Entrepreneurs, Sararimen, Aaran Leyland, and More on the Security Weekly News. Hosts Doug White https://securedigitallife.com/ Aaran Leyland @aaran#2621 List of Articles Doug White PyPI package with 1.1M monthly downloads hacked to push infostealer FTC: Americans lost over $2.1 billion to social media scams in 2025 GlassWorm attackers activate new ‘sleeper’ extensions on Open VSX Medtronic says cyberattack did not disrupt its operations Microsoft’s GitHub shifts to metered AI billing OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years More Harvard Business School students are opting for startups. Why? – The Boston Globe Meet the players who lost big money on Peter Molyneux’s failed Legacy Aaran Leyland AI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP Warns Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Application security Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 – James Kettle – ASW #380 Vulnerability Management Scylla &Charybdis, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland – SWN #575 Vulnerability Management Back to (or Start) Fundamentals? – Rajesh Khazanchi – PSW #923 Related Content AI/ML AI adoption brings back old security gaps, says Mandiant Security Operations Microsoft Entra ID vulnerability allowed global admin impersonation Email security Thousands of Zimbra servers vulnerable to actively exploited flaw You can skip this ad in 5 seconds
This article highlights a critical OpenSSH vulnerability (CVE not provided) that allows full root shell access and had gone undetected for approximately 15 years. The article also covers a PyPI package with over 1.1 million monthly downloads being compromised to distribute an infostealer, and Mandiant's warning that rapid AI adoption is reviving classic security mistakes. Specific version ranges, CVSS scores, and patch details for these issues are not provided in the source material.