Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581

Security Weekly News (Audio)33mMay 15, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581” inside PodZeus.

AI-Generated Summary

The cybersecurity world is facing a perfect storm of vulnerabilities, with AI-driven discovery accelerating threat landscapes at an unprecedented pace. A critical CVSS 10 flaw in Cisco’s SD-WAN controllers allows unauthenticated attackers to gain full admin access—already being exploited in the wild. Simultaneously, the massive education platform Canvas suffered a ransomware attack that crippled 9,000 institutions, exposing 275 million users’ data and raising alarms about supply chain risks in critical infrastructure. Microsoft’s Patch Tuesday delivered 118 CVEs, including 16 criticals, marking the first in two years without emergency zero-day fixes—evidence that AI is overwhelming traditional patch cycles. Meanwhile, a stealthy NPM backdoor in Node IPC packages exfiltrated 90 types of developer credentials, and a BitLocker bypass in WinRE allows full data recovery from discarded laptops. The real turning point? AI isn’t just finding vulnerabilities—it’s predicting them. Models like GPT-5.5 and Anthropic’s Mythos are now being used by security teams to uncover flaws faster than ever, but their public availability raises urgent ethical questions: should such powerful tools be accessible to everyone, or only the good guys? The answer, as one host argues, is both—because hiding flaws doesn’t make them secure, only invisible.

Key Takeaways
1

Cisco SD-WAN controllers with CVSS 10 flaws are actively exploited; patch immediately or risk full admin takeover.

2

Canvas ransomware attack exposed 275 million users and highlights systemic risk in centralized education SaaS platforms.

3

BitLocker bypass via WinRE allows full data recovery from discarded laptops—even with TPM + PIN protection.

4

NPM backdoor in Node IPC 9.1.6, 9.2.3, and 12.0.1 steals AWS, Azure, GitHub, and Kubernetes credentials—update to 9.2.1 or 12.0.0.

5

AI is now predicting vulnerabilities, not just discovering them—making zero days more common and patch cycles obsolete.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

Welcome & Episode Overview

Josh Marpet introduces himself as the sole host for this episode, setting the tone with humor and urgency. He previews a packed agenda covering major zero-day exploits, supply chain attacks, and AI-driven security shifts.

2:15
3 min

Cisco SD-WAN CVSS 10 Zero-Day

There's literally nothing worse... unauthenticated attackers gaining admin. So privilege escalation from unauthenticated to admin in one shot.

Highlight
5:30
5 min

Canvas Ransomware & Supply Chain Collapse

This entire system going down... is an issue. There's issues in... Is this a supply chain issue? Is this a single... SaaS app issue. I'm going to call this a supply chain issue.

Highlight
10:00
5 min

On-Prem Microsoft Exchange Exploit

A crafted email exploits CVE-2026-42897 in on-prem Exchange, enabling arbitrary JavaScript execution via Outlook Web Access. Microsoft offers a temporary mitigation but no permanent fix yet.

14:30
4 min

BitLocker Bypass via WinRE

Oh my God, it's insane and ridiculous what we have now. So it's crazy.

Highlight
High-Impact Quotes
The quality of the vulnerabilities that get out of Mythos is about the same as you would get out of the person. It just makes them incredibly more efficient.
Josh Marpet32:53
Viral: 90.0
There's literally nothing worse... unauthenticated attackers gaining admin. So privilege escalation from unauthenticated to admin in one shot.
Josh Marpet1:17
Viral: 88.0
Disclosure to exploit is minutes to hours now. Threat intel just went down in terms of value.
Josh Marpet26:44
Viral: 87.0
Speakers

Host

Josh Marpet
Topics Discussed
zero-day exploits95%supply chain attacks92%AI vulnerability discovery90%BitLocker bypass88%NPM package security85%Microsoft Patch Tuesday83%ransomware in education80%GPT-5.5 security implications78%
People & Brands

Cisco Catalyst SD-WAN

product

8xNegative

Canvas

product

7xNegative

Microsoft Exchange

product

6xNegative

Node IPC

other

5xNegative

BitLocker

product

5xNegative

Praise on AI

other

4xNegative

GPT-5.5

other

4xMixed

Mythos

other

4xPositive

OpenAI

organization

3xNeutral

Anthropic

organization

3xPositive

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime