Grafan GitHub extortion, Microsoft rejects Azure report, Funnel Builder flaw

Grafan GitHub extortion, Microsoft rejects Azure report, Funnel Builder flaw

Author: CISO Series May 18, 2026 Duration: 7:51

Grafana GitHub token breach leads to extortion attempt

Microsoft rejects Azure vulnerability report, researcher disputes decision

Funnel Builder flaw actively exploited to steal payment data

Get the show notes here: https://cisoseries.com/cybersecurity-news-grafan-github-extortion-microsoft-rejects-azure-report-funnel-builder-flaw/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.


Keeping up with the constant flow of threats, breaches, and innovations in digital defense can feel like a full-time job. That’s where Cybersecurity Headlines comes in. Produced by the team at CISO Series, this daily audio briefing cuts through the noise to deliver the essential stories from the information security landscape. Each episode focuses on clarity and context, transforming complex technical developments and urgent news into digestible updates you can absorb during your morning routine or commute. You’ll hear a straightforward rundown of the day’s most significant events-whether it’s a newly discovered software vulnerability, a major regulatory shift, or analysis of a trending attack method. This podcast serves as your efficient, reliable starting point, ensuring you’re informed on the critical issues that impact professionals and organizations. For those wanting to explore a topic in greater depth, the conversation continues beyond the audio, with extended analysis and resources available from the creators. Tune in for a concise, no-frills update that helps you stay ahead in a field where yesterday’s news is already ancient history.
Author: Language: English Episodes: 100

Cybersecurity Headlines
Podcast Episodes
Microsoft hits Fox Tempest, robotics OS flaw, CISA admins leaks keys [not-audio_url] [/not-audio_url]

Duration: 6:32
Microsoft disrupts malware-signing-as-a-service Critical flaw found in industrial robot OS CISA admin leaks keys Get the show notes here: https://cisoseries.com/cybersecurity-news-microsoft-hits-fox-tempest-robotics-os-f…
G7 releases AI SBOM, DELL SupportAssist BSOD, Dirty Frag sequel [not-audio_url] [/not-audio_url]

Duration: 8:32
G7 countries release AI SBOM guidance Dell confirms its SupportAssist software causes Windows BSOD crashes Dirty Frag sequel arrives as Fragnesia Get the show notes here: https://cisoseries.com/cybersecurity-news-g7-rele…
Instructure's agreement, Shai Hulud campaign, OpenAI's Daybreak [not-audio_url] [/not-audio_url]

Duration: 7:52
Instructure reaches an "agreement" with ShinyHunters Shai Hulud campaign is back OpenAI launches Daybreak Get the show notes here: https://cisoseries.com/cybersecurity-news-instructures-agreement-shai-hulud-campaign-open…
PAN-OS RCE exploit , Poland water hacks, Ivanti EPMM flaw [not-audio_url] [/not-audio_url]

Duration: 9:02
PAN-OS RCE exploit under active use enabling root access and espionage Polish intelligence says hackers attacked water treatment control systems Ivanti warns of new EPMM flaw exploited in zero-day attacks Get the show no…