malware Podcast Summaries
malware on Yedapo: 3 summarized podcast and YouTube episodes. Each includes key takeaways, core concepts and notable quotes with timestamps.

Twoja wtyczka wie więcej, niż Ci się wydaje
Mateusz Chrobok
Jul 12, 2026
Popularne rozszerzenia do przeglądarek stały się głównym wektorem ataków typu 'extension spraying' oraz 'Clickfix', pozwalając hakerom na kradzież danych sesji i plików. Cyberprzestępcy przejmują zaufane wtyczki, by po cichu wykradać poufne dokumenty i hasła, wykorzystując zaufanie użytkowników do sklepu Chrome Web Store.
Key insight: Technika 'Clickfix' zmusza użytkownika do samodzielnego wklejenia złośliwego kodu PowerShell w systemie, udając przy tym standardową weryfikację CAPTCHA, co omija większość zabezpieczeń antywirusowych.

the WORST hack of 2026
NetworkChuck
Mar 31, 2026
A sophisticated supply chain attack compromised the Axios HTTP library, allowing attackers to deploy remote access Trojans via a malicious dependency. By hijacking a maintainer's NPM token, the attackers bypassed standard security guardrails to infect systems in under 1.1 seconds, leaving no trace behind after self-deleting the malicious code.
Key insight: The average NPM project trusts between 200 and 2,100 strangers with code execution, creating a massive, invisible attack surface where a single compromised dependency can grant attackers total system access.

Le téléchargement illégal cache-t-il vraiment des virus ?
Micode
Nov 16, 2023
Le téléchargement illégal de fichiers vidéo expose les utilisateurs à des vecteurs d'attaque sophistiqués, allant de l'exploitation de vulnérabilités mémoires (buffer overflow) dans les lecteurs multimédias à l'abus de fonctionnalités légitimes comme les systèmes de gestion de codecs. Ces menaces contournent souvent la vigilance des utilisateurs en exploitant des fichiers qui semblent inoffensifs.
Key insight: Les pirates ont longtemps utilisé une fonctionnalité légitime du format WMV, conçue pour rediriger vers une page d'achat de licence, pour afficher de fausses alertes de codecs et inciter les utilisateurs à installer des logiciels malveillants.