Cyber Security Headlines

Follow Cyber Security Headlines
Share on
Copy link to clipboard

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

CISO Series


    • Sep 3, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 10m AVG DURATION
    • 1,831 EPISODES


    Search for episodes from Cyber Security Headlines with a specific topic:

    Latest episodes from Cyber Security Headlines

    153M licenses for sale, Anthropic reverses course, Astra enters the red zone

    Play Episode Listen Later Sep 3, 2026 7:21


    Dark web shop stocks 153 million driver's licenses Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals. IDScan says it's investigating and hasn't determined the breach's nature or scope. The FBI's New Orleans office has opened an inquiry. (KrebsOnSecurity) Anthropic puts 30-day data retention in reverse After customer pushback, Anthropic is revising a policy that stored 30 days of traffic from its Fable and Mythos models. Under new Enterprise Frontier Safeguards, customers can keep data in their own cloud and block Anthropic employees from reviewing it while automated abuse monitoring continues. Anthropic calls that privacy equivalent to zero data retention. Developed with more than 100 customers, including Salesforce, the system is due later this year. (CNBC) Astra enters OpenAI's cyber red zone OpenAI says Astra is its first model to reach a "Critical" cybersecurity threshold, meaning it can find unknown flaws and build exploits across well-defended systems without step-by-step human help. It's due soon, but the advanced cyber capabilities will start with a small test group before expanding through Daybreak Blue. OpenAI says Astra refused 91.5% of cyber jailbreak requests, versus 59% for GPT-5.6 Sol, and monitoring can pause suspicious activity. The Information reports Astra's latent reasoning may hide parts of its process, raising doubts about chain-of-thought monitoring. (WIRED, The Information) Get the full show notes here: https://cisoseries.com/153m-licenses-for-sale-anthropic-reverses-course-astra-red-zone/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

    Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability

    Play Episode Listen Later Sep 2, 2026 8:38


    Anthropic announces safety changes and new models USPS installs "untested" IT systems for mail-in ballots Thousands of Exchange servers vulnerable to hijacks Get the full show notes here: https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/  Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

    Claude sessions hijacked, AI jolts global finance, agents get too many keys

    Play Episode Listen Later Sep 1, 2026 6:06


    Claude sessions get hijacked Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions. (BleepingComputer) AI could jolt global finance Bank of England governor Andrew Bailey is warning G20 officials that frontier AI could destabilize the global financial system by making cyberattacks faster, cheaper and easier to scale across borders. Bailey says many countries still lack protocols for how advanced models are developed and released. He also warned that a successful attack on a small number of heavily used technology providers could undermine confidence across the entire system. (The Guardian) AI agents get too many keys New research from Cequence Security and Enterprise Management Associates found a sizable confidence gap around AI agent permissions. 94% of surveyed organizations believe their agents don't have more access than necessary, but only 33% actually enforce least privilege. 65% have seen an agent act outside its intended role, and 29% say that caused measurable business impact. (Security Magazine) Get the full show notes here: https://cisoseries.com/claude-sessions-hijacked-ai-jolts-global-finance-agents-get-too-many-keys/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

    ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach

    Play Episode Listen Later Aug 31, 2026 7:31


    ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

    The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

    Play Episode Listen Later Aug 28, 2026 33:15


    Read the full stories at CISOSeries.com.  This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

    Manchester Airports breach, ATF agency breach, clothier Carhartt breach

    Play Episode Listen Later Aug 28, 2026 7:55


    Manchester Airports Group suffers cyber incident ATF suffers data breach Clothing retailer Carhartt suffers data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-manchester-airports-breach-atf-agency-breach-clothier-carhartt-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

    Chinese hackers hit US agencies, Ring locks out police, Boston Scientific feels cyber pain

    Play Episode Listen Later Aug 27, 2026 6:10


    China contractor hack hits US agencies Ring throws away the key Boston Scientific feels cyber pain Get the show notes here: https://cisoseries.com/cybersecurity-news-august-27-2026/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

    China's hackers pick DeepSeek, OpenAI blocks Russian influence push, webpages mess with local AI

    Play Episode Listen Later Aug 26, 2026 6:39


    China's hackers pick DeepSeek OpenAI blocks a Russian influence push A webpage can mess with local AI Get the show notes here: https://cisoseries.com/cybersecurity-news-august-26-2026/ Huge thanks to our episode sponsor, ThreatDown If your current security posture is struggling to keep pace with fast-moving, identity-based threats, your business is exposed. Today's security expertise gap is real, but it doesn't have to be a permanent vulnerability. ThreatDown helps SMBs move from reactive defense to proactive, 24/7 intelligence, delivering enterprise-grade protection without the headcount. Enterprise-grade defense. Built for businesses like yours.

    SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing

    Play Episode Listen Later Aug 25, 2026 6:30


    SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here: https://cisoseries.com/cybersecurity-news-august-25-2026/ Huge thanks to our episode sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

    UK power plant hack, AI zero click, children's hospital breach

    Play Episode Listen Later Aug 24, 2026 8:17


    UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context injection Canada's Hospital for Sick Children suffers another cyberattack Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

    The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks

    Play Episode Listen Later Aug 21, 2026 34:37


    Read the full sotry at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, Vanta   Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here. 

    CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach

    Play Episode Listen Later Aug 21, 2026 8:58


    CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company CareCloud confirms millions affected by breach Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/ Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed

    Play Episode Listen Later Aug 20, 2026 6:55


    OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

    AI "mind virus," malware living off Azure, an Irregular post-mortem

    Play Episode Listen Later Aug 19, 2026 8:11


    Persistent prompts prove potentially pernicious  The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/  Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

    North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down

    Play Episode Listen Later Aug 18, 2026 7:14


    Federal agency hires North Korean IT worker Millions of Azure records allegedly for sale GitHub outage hits Actions and Copilot Get the show notes here: https://cisoseries.com/cybersecurity-news-north-korean-it-worker-lands-federal-job-azure-records-go-up-for-sale-github-goes-down/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

    SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach

    Play Episode Listen Later Aug 17, 2026 8:06


    Max severity SAP Commerce Cloud flaw now targeted in attacks New Mirai variant adds stealth capabilities to botnet code Shell investigates potential incident after Clop data theft claims Get the show notes here: https://cisoseries.com/cybersecurity-news-sap-commerce-flaw-exploited-mirai-boosts-capabilities-shell-investigates-breach/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

    The Department of Know: Ransomware gangs, Copilot apps, and drones phone home

    Play Episode Listen Later Aug 14, 2026 33:20


    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

    Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy

    Play Episode Listen Later Aug 14, 2026 8:38


    Akira affiliate's innovative "crash mode" attack almost worked WhatsApp rolls out scam alert feature White House looks to private sector for help against offensive hacking Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/ Huge thanks to our sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

    UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON

    Play Episode Listen Later Aug 13, 2026 7:34


    UK eyes AI gene-synthesis guardrails DeadLock puts ransomware on the blockchain An evil twin flies home from DEF CON Episode show notes: https://cisoseries.com/uk-tackles-ai-bioweapon-risk-deadlock-goes-on-chain-evil-twin-flies-home-from-def-con/ Huge thanks to our sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

    Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline

    Play Episode Listen Later Aug 12, 2026 6:59


    Water systems get a federal cyber lifeline Hackers jump into Polish power plant Cyberattacks knock local governments offline Episode show notes:  https://cisoseries.com/water-systems-cyber-lifeline-hackers-polish-power-plant-local-governments-offline/ Huge thanks to our sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

    Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits

    Play Episode Listen Later Aug 11, 2026 6:39


    OpenAI loosens cyber limits for vetted defenders Sandworm's fake recruiters plant a poisoned VPN Royal Navy drones phone home to China Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/ Huge thanks to our sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

    OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady

    Play Episode Listen Later Aug 10, 2026 7:44


    OpenAI slows release of Astra model citing cyber capabilities Irregular won't say if there were more rogue incidents U.S. cyber ambassador nominee Cassady confirmed in Senate Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/ Huge thanks to our sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso. 

    Faked bug reports, Meta's rogue AI, China investigates Palo Alto

    Play Episode Listen Later Aug 7, 2026 8:28


    Apple's bug bounty program overwhelmed by fake AI generated reports China launches cybersecurity review into Palo Alto Networks products Meta AI hacks external systems during cybersecurity testing Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

    AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon

    Play Episode Listen Later Aug 6, 2026 6:33


    AI safety tests spill onto the real internet Private Relay flaw unmasks IP addresses Weak telcos left door open for Salt Typhoon Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/ Huge thanks to our episode sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.  

    ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa

    Play Episode Listen Later Aug 5, 2026 8:16


    ChainDrop attack hits npm Pass-ta-key attacks target passkeys  AI accounts for most cybercrime in Africa Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/  Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.  

    License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window

    Play Episode Listen Later Aug 4, 2026 6:43


    When license plate readers become stalking tools ExfilSquad dumps UK police contact data China-linked hackers shrink the patch window Get the show notes here: https://cisoseries.com/cybersecurity-news-license-plate-readers-as-stalking-tools-exfilsquad-dumps-uk-police-data-the-ever-shrinking-patch-window/ Huge thanks to our episode sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.  

    UK investments agency breach, CISA water warning, Anthropic rogue threesome

    Play Episode Listen Later Aug 3, 2026 7:36


    UK's state investments agency suffers data breach CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks Anthropic says its AI hacked real-world companies in three incidents Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.  

    The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face

    Play Episode Listen Later Jul 31, 2026 30:24


    This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

    Analog Devices breach, Copilot AI worm, Teams ransomware vishing

    Play Episode Listen Later Jul 31, 2026 9:03


    Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead to Chaos ransomware attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers.   This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing.   It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.  

    OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money

    Play Episode Listen Later Jul 30, 2026 8:00


    OpenAI agent's escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/ Huge thanks to our sponsor, Pindrop TIME named Pindrop one of the 10 Most Influential Software Companies of 2026.   Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended.   Don't wait for an incident report. Visit pindrop.com.  

    Leaky BMCs, Claude finds encryption flaws, Google's new names

    Play Episode Listen Later Jul 29, 2026 8:41


    Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/  Huge thanks to our sponsor, Pindrop AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up?   Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report.   Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.  

    Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data

    Play Episode Listen Later Jul 28, 2026 7:55


    Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers.   This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing.   It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.  

    Iran infrastructure warning, ChatGPT global outage, self-assembling malware

    Play Episode Listen Later Jul 27, 2026 8:17


    U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks.    Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings.    Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.

    The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown

    Play Episode Listen Later Jul 24, 2026 34:41


    This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.

    AI agents risk, Upbound Group breach, Dolphin X Stealer

    Play Episode Listen Later Jul 24, 2026 8:21


    AI Agents become fastest growing exposed attack surface Consumer finance company Upbound Group blames data breach for millions in losses Dolphin X Stealer uses AI profiling to prioritize targets Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

    OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp

    Play Episode Listen Later Jul 23, 2026 8:16


    OpenAI behind Hugging Face hack TrickBot tunnels through DNS Acrobat extension opens WhatsApp Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

    Bit2Watt instability, AI models cheat, Chinese LLM ban

    Play Episode Listen Later Jul 22, 2026 8:38


    Bit2Watt threatens power stability All AI models cheat at cyber evaluations US weighing Chinese LLM ban Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/  Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

    Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race

    Play Episode Listen Later Jul 21, 2026 8:07


    Hugging Face fights AI hacks with AI World Cup streamers get a red card WordPress enters a patching race Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

    Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents

    Play Episode Listen Later Jul 20, 2026 8:02


    Dairy company Fairlife suffers cyberattack Microsoft warns of surge in ACR Stealer attacks on customers Abbott Labs investigates two cyber incidents amid extortion claims Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

    The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

    Play Episode Listen Later Jul 17, 2026 42:58


    "Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/  This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines.  Because security works best when innovation and control move together.

    ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login

    Play Episode Listen Later Jul 17, 2026 8:43


    ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

    Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill

    Play Episode Listen Later Jul 16, 2026 8:45


    Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

    CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing

    Play Episode Listen Later Jul 15, 2026 7:59


    Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran "Context Bombing" flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/  Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

    Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice

    Play Episode Listen Later Jul 14, 2026 7:24


    Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

    Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning

    Play Episode Listen Later Jul 13, 2026 8:20


    Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers  Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

    The Department of Know: France gets ready for quantum, JadePuffer ransomware, UK's Cyber Shield

    Play Episode Listen Later Jul 10, 2026 39:35


    Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    Interpol's global fraud sweep, China's Claude Code flag, old Github account tricks

    Play Episode Listen Later Jul 10, 2026 7:21


    Interpol's fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    Mexico's big cyber test, Roundcube mailserver snooped on, Cash App found lax

    Play Episode Listen Later Jul 9, 2026 7:48


    Mexico's first cyber test gets tested Snoops break into Roundcube mailservers Cash App owner pays up over lax security Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    UK Cyber Shield, Japanese telco attack, China AI model limits

    Play Episode Listen Later Jul 8, 2026 7:50


    The UK's Cyber Pledge and Cyber Shield Millions exposed in Japanese telco attack China looking to curb overseas model access Get the show notes here: Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    India tax RAT, prompt injection crypto scam, France pushes quantum-safe

    Play Episode Listen Later Jul 7, 2026 8:35


    Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT Prompt injection attacks trick AI Agents into making crypto payments France to stop certifying products without quantum-safe encryption Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    First AI ransomware, AdaptHealth suffers cyberattack, UK cyber plan delayed

    Play Episode Listen Later Jul 6, 2026 8:02


    JadePuffer ransomware used AI agent to automate entire attack AdaptHealth suffers cyberattack UK's National Cyber Action Plan launch delayed by political leadership crisis Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines. 

    Claim Cyber Security Headlines

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel