Cyber Security Today

Follow Cyber Security Today
Share on
Copy link to clipboard

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

ITWC


    • Jul 20, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 13m AVG DURATION
    • 1,319 EPISODES


    Search for episodes from Cyber Security Today with a specific topic:

    Latest episodes from Cyber Security Today

    Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

    Play Episode Listen Later Jul 20, 2026 13:07


    New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days. Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year. Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive. The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2. 00:00 Sponsor NordLayer 00:36 Headlines Preview 01:05 Windows Zero Day LegacyHive 03:35 Record Patch Tuesday 04:22 Fairlife Ransomware Shutdown 05:49 Abbott Dual Breach Probes 08:09 Conti Leaks Healthcare Cruelty 09:33 WordPress Core RCE WP 2Shell 11:29 Wrap Up And Listener Notes 12:06 Sponsor Message NordLayer

    AI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026

    Play Episode Listen Later Jul 18, 2026 33:56


    Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this episode of Cybersecurity Today On The Weekend, host David Shipley speaks with Lionel Liddy, Chief Information Security Officer at Menlo Security, about why today's security strategies must evolve as AI reshapes the threat landscape. The conversation explores how AI is speeding up vulnerability discovery, why browser security has become a critical layer of defence, the emerging risks of AI agents operating inside browsers, and why recent NIST research suggests perfect AI guardrails may be mathematically impossible. Lionel also explains why organizations should prepare for future attacks that could spread even faster than Log4j. In this episode: How AI is accelerating cyberattacks Why browser isolation can reduce risk The security challenges created by AI agents Prompt injection and browser extension threats Why AI guardrails have fundamental limits Lessons from Log4j and preparing for the next major exploit Practical advice for CISOs and security leaders Chapters 00:00 Sponsor – NordLayer 00:39 Weekend Show Intro 01:48 Lionel Liddy Background 04:44 What Menlo Security Does 06:43 AI Speeds Up Exploits 10:09 CISO Whiplash With AI 12:01 Agents And Browser Risks 15:59 Guardrails And NIST Proof 19:40 Mythos Hype And New Normal 23:19 Hazmat Suit For Servers 27:22 Log4j Times Four Scenario 31:44 Wrap Up And Links 32:54 Sponsor – NordLayer Outro Subscribe for weekly cybersecurity news, expert interviews, and practical insights for CISOs, IT professionals, and security leaders.

    Scattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPT

    Play Episode Listen Later Jul 17, 2026 12:02


    Two leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losses estimated far higher; U.S. charges against Dubar remain unproven. Investigators also believe Russian hackers were behind last year's crippling Jaguar Land Rover attack that halted production for months and contributed to a £1.5 billion bailout, with Microsoft and multiple agencies assisting.  OpenAI unveiled GPT-Red, an automated red-teaming AI for prompt injection, alongside a NIST-backed argument that finite guardrails can't be universally robust. The episode also covers ClickLock, a macOS stealer that kills apps until a password is entered, and Recorded Future's report on Iran-linked groups using ChatGPT for malware, phishing, and reconnaissance. 00:00 Headlines Kickoff 01:08 Scattered Spider Sentencing 02:57 US Charges Loom 03:29 Jaguar Land Rover Hack 04:35 GPT-Red AI Red Team 05:40 Why Guardrails Fail 06:36 ClickLock Mac Stealer 06:53 How ClickLock Spreads 07:59 Defense and Cleanup Tips 08:37 Iran Uses AI for Ops 10:30 Wrap Up and Next Show

    ShareFile explained, healthcare in critical cyber condition and click fix tops malware charts

    Play Episode Listen Later Jul 15, 2026 13:57


    ShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware.  David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity path traversal flaw in Storage Zone Controller 5.x/6.x with patches available (5.12.5 and 6.0.2) and no evidence of prior exploitation. Microsoft's analysis of a year of ShinyHunters activity compromising corporate Salesforce environments by abusing trust via OAuth (IT-support phone cons, vendor token theft such as Salesloft/Drift, and misconfigured guest access), prompting new monitoring tooling. A Fortified Health Security report finding healthcare fixed only 6% of identified risks in H1 2026 amid surging vulnerabilities, third-party risk, and weak identity hygiene. ReversingLabs and ReliaQuest research showing ClickFix social-engineering is now a leading malware delivery method; and Telstra's nationwide outage traced to an obsolete time server hit by a GPS rollover bug, disrupting Triple Zero calls and prompting Senate scrutiny. 00:00 Sponsor NordLayer 00:37 Headlines Overview 01:06 ShareFile Patch Explained 03:25 Salesforce OAuth Break Ins 06:01 Hospitals Drowning in Risks 08:24 ClickFix Malware Surge 11:13 Telstra Time Server Outage 12:32 Wrap Up and Sign Off

    ShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishing

    Play Episode Listen Later Jul 13, 2026 10:25


    ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint   Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected.   Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17.   Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender.   ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint.   Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder

    AI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today Panel

    Play Episode Listen Later Jul 11, 2026 61:54


    Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Payne, David Shipley, and Mike Kim (Mycroft) to examine the biggest cybersecurity stories and trends from June 2026. The panel explores the controversy over U.S. export controls on Anthropic's Mythos and Fable AI models, what they reveal about digital sovereignty, and whether governments should be able to restrict access to frontier AI. They also discuss the continuing wave of third-party breaches, including Salesforce ecosystem compromises and the Clue breach, and why organizations must move beyond compliance toward practical risk management. The conversation examines FortiBleed, exposed administrator portals, credential reuse, and the difficult balance between software flaws, operational mistakes, and secure-by-default design. The panel also tackles one of cybersecurity's biggest human challenges: CISO burnout, executive accountability, organizational culture, and what separates successful security leaders from those set up to fail. The episode concludes with encouraging developments in international cybercrime enforcement, including Operation Riptide, and why better intelligence sharing and improved operational security are making it harder for cybercriminals to hide. Whether you're a CISO, security practitioner, IT leader, or simply interested in the rapidly changing cybersecurity landscape, this discussion offers practical insight into the trends shaping the industry. Panel Jim Love (Host) Laura Payne David Shipley Mike Kim (Mycroft) Topics covered AI export controls and digital sovereignty Anthropic Mythos and Fable Third-party and supply chain risk Salesforce ecosystem security FortiBleed and Fortinet security Secure-by-default strategies CISO burnout and executive accountability Operation Riptide Cybercrime investigations Security leadership and governance Chapters 00:00 Sponsor NordLayer 00:38 Meet the Panel 02:40 Author Scam Warning 04:51 Emotion Is the Target 08:47 AI Model Export Controls 10:01 Hype vs Real AI Security 15:01 Sovereignty and Dependency 20:35 Governments Push Back 24:14 AI Internal Voice Risks 26:12 Third Party Breach Fatigue 30:05 Compliance Limits on Risk 32:15 Blame Game to Risk Focus 33:18 Standards and Priorities 33:39 When Security Vendors Fail 34:35 FortiBleed Numbers Explained 35:44 Process Failures vs Bugs 37:32 Why Fortinet Gets Heat 39:05 Secure by Default Basics 41:04 Budget Reality and Culture 44:36 CISO Burnout and AI Pressure 46:16 Liability and Shared Ownership 50:12 What Great CISOs Do 53:07 Operation Riptide Wins 56:10 Deterrence and Due Process 58:14 Sharing Intel for ROI 59:09 Hopium and Wrap Up 01:00:46 Sponsor NordLayer Message

    A questionable breach, bad routers at home and at work and AI gives defenders a win

    Play Episode Listen Later Jul 10, 2026 12:42


    This episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy client base.   It also highlights a deepfake image of Senator Mitch McConnell debunked after Google's invisible SynthID watermark identified it as AI-generated, noting watermarking depends on tool participation.   The show warns of an undocumented Tenda router firmware backdoor using an alternate password ("RZadmin") with no patch available, and reports Ubiquiti fixes for seven critical UniFi OS vulnerabilities, including a max-severity command injection in UniFi Connect.   Finally, it describes how Venture Employer Solutions used ML/LLMs to filter low-value logs before SIEM ingestion, cutting firewall log volume 83%, saving about $250K annually, and halving mean time to response.   00:00 Sponsor NordLayer 00:37 Headlines Intro 01:08 Accenture Breach Claim 04:25 Deepfake Watermark Win 05:47 Tenda Router Backdoor 07:22 UniFi Critical Fixes 09:10 AI Cuts Log Noise 11:09 Wrap Up And Thanks 11:41 Sponsor Message

    Scattered Spider squashed, Rogue Agent AI flaw, 16 year-old Linux bug and new phish hunts marketers

    Play Episode Listen Later Jul 8, 2026 13:53


    Cybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfiltration, and an $8 million ransom demand; the episode also notes additional Scattered Spider-related guilty pleas in the U.K. and U.S.   The show reports Google patched "Rogue Agent," a Dialogflow CX permission-boundary issue involving Python code blocks in Cloud Run that could enable data theft or credential prompts across agents in a shared project.   It details "Janus Escape" (CVE-2026-53359), a 16-year-old Linux KVM use-after-free enabling guest-to-host escapes in cloud environments, patched in June.   The show explores Apple's shift to out-of-band security updates due to AI-accelerated exploitation, and a multi-platform redirect phishing campaign using fake job interviews and browser-in-browser Google login prompts targeting marketers' Google accounts. 00:00 Sponsor NordLayer 00:36 Headlines Intro 01:03 Scattered Spider Traced 03:16 More Spider Arrests 04:31 Google Rogue Agent 06:24 Linux Janus Escape 08:04 Apple Patching Shift 10:04 Marketer Phish Chain 12:17 Wrap Up Thanks 12:53 Sponsor Message

    AI-Run Ransomware, New Oracle Critical Flaw, NetNut busted

    Play Episode Listen Later Jul 6, 2026 14:26


    AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator   This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key.   It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240.   A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices.   Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day.   00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off

    Teams battles bots, Bioshocking AI browser guardrails, Fortibleed fuels ransomware

    Play Episode Listen Later Jul 3, 2026 10:58


    Teams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach   Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby with labels, and require organizer approval, with future allow lists, full blocks, reports, and audit logs planned.   Anthropic's Fable 5 returns globally after U.S. export controls are lifted, though higher‑risk requests may be routed to weaker models and Mythos restrictions remain, with Commerce reserving the right to reimpose controls.   Researchers describe "Bioshocking," tricking AI browsers into abandoning guardrails via delusional puzzle prompts, while Adversa AI's "Guardfall" shows how Bash text rewriting can bypass command filters in many coding agents.   SOC Radar links FortiBleed credential theft to InkRansom and Lynx ransomware activity across hundreds of FortiGate portals. Nissan confirms employee data theft tied to a PeopleSoft zero‑day campaign linked to ShinyHunters.   00:00 Today's Cyber Headlines 00:27 Teams Blocks Meeting Bots 01:58 Anthropic Fable Returns 03:22 Bioshocking Browser Attack 05:09 Guardfall Shell Bypass 06:51 FortiBleed Fuels Ransomware 07:59 Nissan PeopleSoft Breach 10:10 Wrap Up And Sign Off

    US puts $10m bounty on Russian hackers, new phish hunts hotels, Supreme Court reins in geofencing

    Play Episode Listen Later Jul 1, 2026 11:13


    US Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs.  The episode covers the US State Department's up to $10 million reward for information on Russia-linked hacker groups UNC 5792 and UNC 4221 tied to phishing campaigns that compromise Signal and WhatsApp accounts by stealing Signal backup recovery keys.  It also explains a US Supreme Court 6–3 ruling limiting geofence warrants by recognizing Fourth Amendment privacy protections for phone location data and requiring probable cause and narrower requests.  Mozilla ODIN researchers demonstrate a proof of concept where a clean GitHub repo can cause AI coding agents to run an init command that executes attacker-controlled code via DNS and opens a reverse shell. A hotel-focused phishing campaign using Calendly and Google redirects delivers ZIP files that install the Tonrat implant through PowerShell and a user-space Node.js runtime.  Finally, Canada's CSE says it disrupted infrastructure used by 10 major ransomware groups and reports incident volumes rising nearly 26% year over year. 00:24 Top Headlines Rundown 00:54 10 Million Bounty Russian Hackers 02:42 Supreme Court Limits Geofence Warrants 03:56 AI Coding Agent Repo Trap 05:31 Listener Thanks And Reviews 05:51 Hotel Front Desk Phishing Attack 08:01 Canada Disrupts Ransomware Gangs 09:45 Closing And Sign Off

    US Restricts Frontier AI models

    Play Episode Listen Later Jun 29, 2026 11:14


    US Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export controls paused Mythos and the more restricted Fable 5, with access still limited to vetted American entities; the same day, OpenAI's GPT 5.6 was also restricted to government-approved partners under a Trump executive order requiring review of cyber-capable models.  The episode also covers Canadian hacktivist Aubrey Cottle's 18-month sentence for the 2021 Texas GOP hack and bail breaches, with possible U.S. charges pending. Researchers disclosed "USBliterate," an unpatchable physical USB exploit in the Secure ROM of older A12/A13 iPhones that aids forensic extraction. Finally, a survey finds rising CISO burnout, fewer full-time CISOs, growth in fractional CISO roles, and AI—especially shadow AI—overtaking liability as the top stressor. 00:55 AI Export Controls Shift 03:37 Anonymous Hacker Sentenced 05:32 Unpatchable iPhone Boot Exploit 07:30 CISO Burnout And Exodus 09:40 Wrap Up And Sign Off

    Why Car Dealerships Are Prime Cyber Targets: Fraud, Resilience, and Security Leadership with Jennifer Hutton

    Play Episode Listen Later Jun 27, 2026 37:15


    Cybersecurity Today would like to than Material Security for their support of this podcast.  On Cybersecurity Today on the Weekend, the host speaks with Jennifer Hutton, a cybersecurity leader in the car dealership sector, about how she entered cybersecurity through increasing cyber insurance requirements and why dealerships are prime targets because they hold bank-level sensitive data and run complex digital and IoT ecosystems. They discuss the rise of cyber-enabled fraud, including impersonation scams, smishing, and synthetic identity fraud, and the need to educate both employees and customers. Hutton describes gaps in industry resources, especially for smaller dealers, and contrasts regulatory pressures such as updated FTC safeguards rules in the U.S. She emphasizes servant leadership, empathy, and communicating risk in business terms, arguing that cyber risk is business risk. The conversation also covers supply chain disruption from the CDK ransomware incident and the importance of incident response, business continuity, and resiliency-focused planning. 00:00 Weekend Show Kickoff 01:14 Jennifer's Cyber Origin 02:53 Why Dealerships Are Targets 04:30 Scams And Synthetic IDs 08:32 Industry Gaps And Sharing 10:42 Regulation And Tech Shift 13:48 Leading With Business Risk 21:29 Servant Leadership And AI 25:21 Empathy In Tech Teams 28:16 CDK Ransomware Lessons 29:53 Resilience Over Prevention 32:08 Advice To Dealership Leaders 34:49 Closing Thanks

    Malware gaslights AI

    Play Episode Listen Later Jun 26, 2026 10:56


    Mac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating it via a Telegram bot.   Microsoft and Europol disrupted the Amadey and SteelC info-stealer ecosystem by seizing/shuttering infrastructure after identifying 140,000 infections in early May and over 200 command-and-control domains and IPs, as part of Operation Endgame.   OpenAI announced "Patch the Planet," a joint effort with Trail of Bits and HackerOne to help open-source projects find and fix bugs amid AI-generated report flooding, alongside a new GPT 5.5 Cyber benchmark result.    New FortiBleed reporting underscores that the campaign relies on credential reuse against exposed FortiGate devices and may require rotating far more than just firewall passwords.   00:00 Sponsor Message 00:25 Headlines Overview 00:55 Mac Malware Gaslight 02:00 Telegram C2 And Stealer 02:50 Info Stealer Takedown 04:08 Operation Endgame Impact 04:47 OpenAI Patch The Planet 06:16 AI Models And Export Rules 07:08 FortiBleed Recap 08:13 Inside The FortiGate 08:59 Rotate Credentials Now 09:26 Closing And Sign Off

    FortiBleed: Fortinet Says It's Not a Bug

    Play Episode Listen Later Jun 24, 2026 10:38


    Fortinet finally weighs in on FortiBleed - it's not a bug. Plus a healthcare AI firm loses 1.4 million people's data to a single phishing email, a trading bot built to prey on others gets played for $15 million, and LastPass lands back on a breach list it didn't cause.   00:00 Headlines 00:28 Xsolis Phishing Fallout 01:47 Texas License Vendor Hack 02:59 MEV Bot Gets Robbed 05:26 FortiBleed Fortinet Response 06:42 LastPass Caught in Clue 08:40 Wrap Up and Sign Off

    Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking

    Play Episode Listen Later Jun 22, 2026 10:03


    A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies.  Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off

    5 People You Meet In Cybersecurity - David Shipley Interviews Amy Lee

    Play Episode Listen Later Jun 20, 2026 29:59


    In this special Cybersecurity Today weekend interview, host David Shipley speaks with Amy Yee about leadership, resilience, and the human side of cybersecurity. Amy shares her remarkable journey from electrical engineering and venture capital to becoming the inaugural Chief Digital Officer at Accreditation Canada and Health Standards Organization, where she helped build the digital foundation used by hundreds of healthcare organizations across Canada. The conversation takes a deeply personal turn as Amy recounts leading through a ransomware attack that struck her organization before tabletop exercises and incident-response planning had become routine. She describes the chaos of the first 48 hours, the emotional toll on staff, the difficult weeks that followed, and the lessons learned during a 60-day recovery effort. Amy also discusses her popular conference talk inspired by Mitch Albom's The Five People You Meet in Heaven, reimagined for cybersecurity. She explores five people every cyber professional encounters during their career: the person they protected, the person who challenged them, the person who gave them a chance, the person they failed, and the person they inspired. This is a conversation about cybersecurity, leadership, resilience, mentorship, and finding meaning in a profession that often works behind the scenes. Topics covered: Ransomware incident response Cybersecurity leadership Healthcare cybersecurity Digital transformation Executive crisis management Building cyber resilience Career growth in technology Mentorship and leadership lessons The human side of cybersecurity Guest: Amy Yee Host: David Shipley Podcast: Cybersecurity Today #Cybersecurity #Ransomware #Leadership # Chapters 00:00 Weekend Show Intro 01:22 Amy's Career Origin 02:13 Becoming Chief Digital Officer 03:56 Ransomware Wake Up Call 06:46 Inside the First 48 Hours 08:26 The Low Point Weeks In 10:57 Finding a Path Forward 11:55 Leadership Lessons After Incidents 15:01 Five People in Cyber 17:16 Invisible Impact and Resilience 19:38 The Five Archetypes Explained 21:42 Stories From the Community 24:14 Wired for Change Podcast 27:30 Advice to Younger Amy 28:49 Closing and Off Mic Wrap

    FortiBleed Emergency: 74,000 Fortinet Logins Exposed

    Play Episode Listen Later Jun 19, 2026 40:12


    A special crossover episode of Cybersecurity Today and Hashtag Trending for June 19, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after security researchers uncovered the FortiBleed dataset, exposing credentials tied to approximately 74,000 Fortinet firewall and SSL VPN devices across 194 countries. Researchers found the data on an exposed threat actor server containing attack tools, victim databases, logs, and thousands of verified usernames and passwords. Analysts report that tens of thousands of those credentials may still be active. Host Jim Love breaks down: • What FortiBleed is and how it was discovered • Why this affects roughly half of all internet-facing Fortinet devices • What CISA and Fortinet are telling organizations to do immediately • The potential risks of credential reuse and lateral movement attacks • Practical steps security teams should take right now The episode also includes an interview with Mike Sweeney of Silent Push on major international efforts targeting Southeast Asian scam compounds and criminal infrastructure during Operation Disruption Week. If your organization uses Fortinet firewalls, FortiGate appliances, or SSL VPNs, this is an episode you should not miss. #Cybersecurity #Fortinet #FortiBleed #CISA #CybersecurityToday #HashtagTrending #FortiGate #ThreatIntelligence #DataBreach #InfoSec

    Scam Losses Surge - Cybersecurity Today

    Play Episode Listen Later Jun 17, 2026 10:31


    Cybersecurity Today host David Shipley reports that the FTC says Americans lost $3.5 billion to imposter scams in 2025—nearly triple 2020—with social media tied to $2.1 billion in losses and total fraud reaching about $16 billion, while the FBI estimates cyber-enabled losses nearer $21 billion and potentially far higher. Security researchers, including Katie Moussouris, argue the U.S. government's forced Anthropic model shutdown over an alleged guardrail bypass was hasty and largely about prompt phrasing, with Axios citing personality differences as a driver. The DOJ seized deepfake pornography sites cfake.com and sock.com under the Take It Down Act after a three-country operation involving Italy and France. Finally, Varonis details "SearchLeak" (CVE-2026-42824), a now-fixed critical Copilot attack chain enabling one-click data exfiltration via prompt injection, a sanitizer race condition, and CSP bypass through Bing. 00:00 Today's Cyber Headlines 00:29 Imposter Scams Surge 01:29 Fraud on Social Platforms 02:47 Anthropic Jailbreak Debate 04:15 Export Controls Fallout 05:05 DOJ Seizes Deepfake Sites 06:44 SearchLeak Copilot Attack 07:36 How SearchLeak Works 09:18 Why Old Bugs Return 10:08 Wrap Up and Sign Off

    Anthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and more

    Play Episode Listen Later Jun 15, 2026 10:35


    The U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk. David Shipley examines what may be  behind the decision and what it means for countries and businesses that depend on American AI platforms. The FBI also disrupts Outsider Enterprise, a China-based phishing-as-a-service network linked to more than 9,000 fake websites, one million fraudulent URLs, 3.8 million stolen payment-card records and an estimated $1.9 billion in losses. Also in this episode: A critical Splunk vulnerability could allow an unauthenticated attacker to remotely execute code through a PostgreSQL sidecar service enabled by default in some deployments. A former Iowa school IT worker is sentenced after retaining access for 21 months and using it to delete accounts and disrupt school systems. And FortiWatch returns with a critical FortiSandbox command-injection vulnerability that requires no authentication. Cybersecurity Today is hosted by David Shipley. Chapters 00:00 Cybersecurity Today headlines 00:26 U.S. government shuts down Anthropic AI models 02:59 FBI takes down Outsider Enterprise phishing network 04:47 Critical Splunk vulnerability explained 06:31 Former school IT worker sentenced for cyberattack 08:29 FortiWatch: FortiSandbox command-injection vulnerability 10:08 What's ahead this week

    CyberTitan Champions: Inside Canada's National High School Cybersecurity Competition (and CyberPatriot)

    Play Episode Listen Later Jun 13, 2026 37:22


    Cybersecurity Today on the Weekend interviews the winning Canadian CyberTitan team ("S-ores"/a regex-based name) along with coach Phil, educator Tim, and CyberTitan manager Sheena to explain how CyberTitan (run by ICTC) connects to the international CyberPatriot program. They describe the competition mechanics—securing compromised Windows, Windows Server, and Linux virtual machines for points, plus Cisco Packet Tracer networking—and how Canadian teams compete through CyberPatriot before the top teams advance to a national CyberTitan final. Students Faye and Eric share why they joined, their learning "aha" moments in Windows tools and networking concepts, and the value of teamwork. The guests discuss teacher benefits, free training materials, building diverse participation, sponsorship challenges, and hopes for a fully Canadian program with regional events and cloud-based cyber ranges like Field Effect's. 00:00 Weekend Show Intro 01:00 Tim's CyberTitan Journey 01:46 ICTC Explained 02:08 Who Can Compete 02:42 Why CyberTitan Matters 03:22 Origins and CyberPatriot Link 04:04 How The Competition Works 05:09 Meet Team Sors 07:07 Coach Phil's Role 09:44 Why Students Join 12:08 Student Aha Moments 15:13 Community and Teacher Wins 16:34 Sheena Runs The Show 17:29 Scale and National Reach 18:51 Coast To Coast Growth 19:40 XOR Team's Home District 19:55 Teams Across Toronto 20:39 Trophies Medals Coins 21:22 Eric Why Join 23:04 Faye Encouragement Story 25:51 Teachers Start Teams 27:52 Building Girls Pipeline 30:40 Cloud Range Future 33:49 2030 Vision Wrap

    Anthropic Warns AI Risks Are Real, RoguePlanet Zero-Day Drops, Crypto Laundering Takedown

    Play Episode Listen Later Jun 12, 2026 9:25


    Anthropic is calling for governments to have the authority to stop deployment of advanced AI systems that pose unacceptable risks. CEO Dario Amodei points to the company's Mythos cybersecurity model as proof that AI has become a matter of national and strategic consequence, warning that cyber risks may soon be followed by biological and autonomy risks. Meanwhile, security researcher Nightmare Eclipse has released RoguePlanet, a new Windows Defender zero-day that reportedly works against fully patched Windows 10 and Windows 11 systems. The disclosure comes shortly after Microsoft said it had no intention of pursuing action against security researchers, suggesting the dispute between the company and the researcher is far from over. And European authorities have dismantled AudiA6, a cryptocurrency laundering operation that Europol says used thousands of fraudulent exchange accounts to help obscure the proceeds of ransomware attacks and other cybercrime. Investigators linked the service to more than 15 ransomware and major cryptocurrency theft investigations worldwide. Chapters 00:00 Top Stories Rundown 00:19 Crypto Laundering Takedown 02:02 Why Cashout Networks Matter 02:36 RoguePlanet Zero Day Drops 03:19 Microsoft Researcher Fallout 04:24 Exploit Reliability And What Next 05:37 Anthropic Wants Stop Powers 06:10 Mythos Model Cybersecurity Shock 07:37 Regulation Motives And Competition 08:37 Beyond Cyber Bio And Autonomy 09:20 Closing And Next Episodes

    AI Worms, Hacks, and Insurance Shifts

    Play Episode Listen Later Jun 10, 2026 9:39


    Instagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, with only MFA-protected accounts resisting. Step Security details a new Miasma-derived worm wave called Hades that targets config files for 14 AI coding tools, can inject instructions to hijack assistants, lies to AI security tools, and includes a "dead man switch" wipe if stolen GitHub tokens are revoked; Microsoft also removed some GitHub repos after 73 open-source projects were compromised to inject an info stealer. University of Toronto and Vector Institute researchers demonstrated an AI worm using a free local model that spread across a simulated network via known flaws and misconfigurations. Google issued an emergency Chrome patch for actively exploited CVE-2026-11645 in V8, and insurers are tightening claims scrutiny and increasingly excluding AI-related liabilities. 00:00 Instagram AI Hack Fallout 01:36 AI Worm Hades Evolves 02:55 Microsoft Repo Compromise 03:54 Lab Built AI Worm Demo 05:27 Emergency Chrome Zero Day 07:07 Cyber Insurance Tightens Up 08:02 AI Liability Coverage Shrinks 09:16 Wrap Up and Sign Off

    Claude Outage Data Leak, Microsoft GitHub Worm, IBM Hack, M Instagram Takeovers, Canada's Bill C-8

    Play Episode Listen Later Jun 8, 2026 10:21


    TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada's Bill C-8 David Shipley reports that Anthropic's Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving another customer's conversation; Anthropic says it has no evidence of a data leak and is investigating. A Team PCP self-spreading worm, Miasma, infected 73 Microsoft GitHub repositories across four accounts and now triggers via AI coding assistants when developers open cloned projects. A former IBM threat-intel executive, William Barlow, alleges IBM was hacked three times by foreign governments (including APT10 from 2013–2016) and concealed it; IBM denies wrongdoing and the claims are unproven. TechCrunch reports attackers hijacked Instagram accounts by persuading Meta's support chatbot to relink accounts to attacker emails, with ongoing reports despite Meta saying it's fixed. Canada's Senate passed critical-infrastructure cybersecurity law Bill C-8, mandating rules and incident reporting for telecom, finance, energy, and transportation. 00:00 Top Headlines Rundown 00:37 Claude Outage Data Leak Fears 02:17 Miasma Worm Hits Microsoft 03:52 IBM Breach Cover Up Claims 05:25 Meta AI Hands Over Instagram 06:40 Why Chatbots Fail Social Engineering 07:44 Canada Passes C-8 Cyber Law 09:58 Wrap Up and Sign Off

    Cybersecurity Today Month in Review: Microsoft Zero-Days, AI Deregulation

    Play Episode Listen Later Jun 6, 2026 65:25


    Host Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher ("Chaotic/Nightmare Eclipse") publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft's vulnerability disclosure process, and backlash to Microsoft's initially threatening tone before it was partially walked back; the panel debates responsible disclosure, the need for researcher support/organization, transparency vs liability, and how vulnerability reporting is straining under volume. They then examine a White House AI executive order focused on voluntary measures and 30-day model access, criticizing the lack of basic safety and cybersecurity protections amid FOMO about losing to China and an AI investment bubble. The conversation covers AI-driven harms and studies on reduced brain activity and "cognitive surrender," while noting benefits when AI is used as a tutor. Shipley highlights Canada's Senate passing Bill C-8 on critical infrastructure cybersecurity, and the group urges outcome-focused security, architecture/risk prioritization, and critical thinking against AI-enabled social engineering. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. 00:00 Sponsor Message 00:24 Show Welcome Panel 01:17 Microsoft Zero Day Fallout 04:19 Researcher Backlash Drama 06:46 Unionizing Bug Hunters 13:10 Product Liability Debate 23:23 Regulation vs Transparency 26:00 AI Bubble Investor Risk 28:01 White House AI Order 32:24 Cybersecurity Gaps Telecom 33:19 Telecom Trust Breakdown 34:32 AI Harms and Exploitation 35:36 Studies on Cognitive Surrender 38:13 Markets Regulation and Politics 40:13 Canada Cyber Law Win 42:33 Adoption Hype and Subsidy Bubble 48:50 Patch Deluge and AppSec Strain 52:10 Defenses Beyond Patching 54:17 Outcomes Critical Thinking and CIA 01:01:49 Education Disruption and Closing 01:04:14 Sponsor Message Material Security

    New HTTP/2 Bomb Attack, Trump's AI Security Reviews, Android Zero-Day & The Patching Crisis

    Play Episode Listen Later Jun 5, 2026 11:43


    A newly disclosed attack called HTTP/2 Bomb can crash major web servers in seconds using a single computer and a modest internet connection. Researchers say the attack combines two known techniques into a powerful memory-exhaustion exploit affecting widely used platforms including Apache, NGINX, Microsoft IIS, and Envoy. The attack also highlights a growing trend in cybersecurity research: the use of artificial intelligence to uncover dangerous combinations of existing vulnerabilities. The episode also examines President Trump's new executive order creating a voluntary framework for reviewing advanced AI models before public release. The administration says the goal is to improve cybersecurity and national security visibility while avoiding mandatory regulation or licensing requirements. Next, a new Cloud Security Alliance report warns that organizations are struggling to keep up with the growing volume of vulnerabilities. Security teams increasingly face difficult choices about which flaws to patch first as cloud environments, containers, APIs, and third-party software continue to expand the attack surface. Finally, CISA warns that attackers are actively exploiting both a newly patched Android vulnerability and a years-old Linux flaw. The contrast highlights a simple reality: cybercriminals do not care whether a vulnerability is new or old. They care whether it remains exploitable. Stories in this episode HTTP/2 Bomb Can Crash Web Servers in Seconds Researchers disclose a denial-of-service technique capable of exhausting server memory in under a minute, while OpenAI's Codex helps uncover a novel attack chain. Trump Creates Voluntary AI Security Reviews as Government Seeks Visibility Into Frontier Models A new executive order establishes voluntary reviews of advanced AI systems before public release, raising questions about visibility, oversight, and national security. The Cybersecurity Industry's Patch-Everything Strategy May Be Breaking Down A Cloud Security Alliance report suggests organizations are overwhelmed by vulnerability volume and increasingly forced to choose which risks to address. CISA Warning Shows Attackers Don't Care Whether a Vulnerability Is New or Old Active exploitation of both a newly patched Android flaw and an older Linux vulnerability demonstrates that attackers focus on opportunities, not disclosure dates. Cybersecurity Today brings you the latest cybersecurity news, threat intelligence, breach reports, vulnerability disclosures, ransomware developments, cybercrime investigations, and security research affecting organizations around the world. #Cybersecurity #CyberSecurityToday #InfoSec #CyberNews #Ransomware #ThreatIntelligence #VulnerabilityManagement #AndroidSecurity #LinuxSecurity #ArtificialIntelligence #HTTP2 #CISA #CloudSecurity #OpenAI #PatchManagement

    Carnival Data Breach Exposes Millions as Microsoft Backs Down on Researcher Threats

    Play Episode Listen Later Jun 3, 2026 9:37


    Cybersecurity Today for June 2, 2026. Microsoft has backed away from its hard-line stance against vulnerability researchers after widespread criticism from the security community. The dispute began after independent researcher Nightmare Eclipse published proof-of-concept code for unpatched Microsoft vulnerabilities, triggering a public debate over responsible disclosure, zero-days, and researcher relations. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. Carnival Corporation disclosed a social-engineering attack that led to the theft of sensitive personal information affecting nearly six million people. Exposed data includes names, contact information, dates of birth, and government identification details. The ShinyHunters cybercrime group has claimed responsibility and alleges the breach involved even more records. Password manager provider Dashlane temporarily locked some customers out of their accounts after large-scale password-guessing attacks triggered automated security protections. Access was later restored, although some users reported lingering issues. The episode also examines a software supply-chain attack uncovered by Wiz involving 32 Red Hat Cloud Services NPM packages. Attackers compromised a Red Hat employee's GitHub account and inserted Miasma malware designed to steal Google Cloud and Microsoft Azure credentials. Timestamps: 00:00 Sponsor Message 00:28 Headlines And Intro 00:55 Microsoft Researcher Dispute 02:58 Carnival Cruise Data Breach 04:48 Dashlane Lockouts Explained 06:09 Miasma Malware Supply-Chain Attack 08:10 Wrap Up And Sign Off 08:31 Sponsor Deep Dive #Cybersecurity #DataBreach #Carnival #Microsoft #Dashlane #RedHat #SupplyChainAttack #CyberSecurityToday

    Microsoft Threatens Security Researcher | Palo Alto VPN Exploited | Google Insider Trading Case

    Play Episode Listen Later Jun 1, 2026 11:46


    Microsoft's dispute with a former security researcher takes a dramatic turn as the company raises the possibility of criminal action over the publication of proof-of-concept code for unpatched zero-day vulnerabilities. David Shipley examines the escalating conflict between Microsoft and "Nightmare Eclipse," the criticism from prominent security researchers including Kevin Beaumont and Katie Moussouris, and what the controversy could mean for the future of vulnerability disclosure. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. The episode also explores a new category of insider risk after U.S. prosecutors charged Google security engineer Michael Spagnuolo with allegedly using confidential Google search trend data to earn more than $1.2 million on the prediction market Polymarket. The case highlights how prediction markets may create unexpected incentives around non-financial corporate information. Also covered: active exploitation of Palo Alto Networks' GlobalProtect VPN authentication bypass vulnerability CVE-2026-0257, now added to CISA's Known Exploited Vulnerabilities (KEV) catalogue, and a malware campaign that abuses legitimate ChatGPT sharing pages and Google Ads to trick users into downloading malicious software. Researchers also report similar abuse of Anthropic's Claude Artifacts feature. Chapters 00:00 Top Headlines Rundown 00:26 Microsoft vs Zero-Day Researcher 01:28 Responsible Disclosure Fallout 03:32 Why This Dispute Matters 04:32 Polymarket Insider Trading Case 06:07 Prediction Markets Create New Insider Risks 06:55 Palo Alto VPN Authentication Bypass 08:25 ChatGPT Pages Used to Deliver Malware 09:51 Wrap Up and Sign Off Cybersecurity Today is Canada's leading daily cybersecurity news podcast, covering ransomware, vulnerabilities, nation-state threats, cybercrime, security research, privacy, and critical infrastructure security. #Cybersecurity #Microsoft #PaloAltoNetworks #ChatGPT #OpenAI #Google #Polymarket #ThreatIntelligence #InfoSec #CyberSecurityToday

    Cybersecurity & Arctic Sovereignty: Protecting Canada's Most Vulnerable Infrastructure Cheryl Biswas

    Play Episode Listen Later May 29, 2026 29:51


    Host David Shipley speaks with cybersecurity professional Cheryl Biswas about her journey into the industry and why she believes Arctic sovereignty must be viewed as a cybersecurity challenge as much as a geopolitical one. Biswas traces her path from political science and a help desk role at CP Rail to cybersecurity, inspired by the discovery of the Stuxnet malware and the global security community that formed around it. She discusses her experiences speaking at BSides Las Vegas, attending DEF CON, helping build a major Canadian bank's threat intelligence program, and recently earning her Certified Information Systems Security Professional (CISSP) designation. The conversation then shifts north. As Canada invests billions in Arctic defence, communications, transportation, and critical infrastructure, Biswas explains how every new connected system can create new cyber risks. The discussion covers threats to satellites, navigation systems used by ships and aircraft, undersea communications cables, government services, healthcare, energy systems, and the fragile supply chains that support northern communities. They also explore why collaboration with northern and Indigenous communities is essential, the importance of improving connectivity across the Arctic, and how Canada can work more closely with international partners to strengthen resilience in one of the world's most strategically important regions. Cheryl also shares advice for newcomers to cybersecurity and discusses the kind of strategic threat intelligence and research work she hopes to pursue in the future. Chapters 00:00 Weekend Show Kickoff 00:46 Cheryl's Cyber Origin Story 02:30 Stuxnet and Hacker Community 04:06 From BSides to DEF CON 05:10 Threat Intelligence Career Today 05:50 Arctic Sovereignty Meets Cyber 07:41 Canada's Arctic Reality Check 10:14 Why Cyber Matters Up North 12:07 Maritime and Navigation Risks 15:50 Undersea Cables and Fragile Supply 19:55 Solutions, Collaboration and Technology 24:22 Talk Feedback and How to Connect 25:42 Dream Role and Advice to Newcomers 29:16 Closing Reflections and Sendoff #Cybersecurity #ArcticSovereignty #Canada #CriticalInfrastructure #ThreatIntelligence #CISSP #CyberSecurityToday #DavidShipley #DEFCON #BSides #ArcticSecurity #NationalSecurity #CriticalInfrastructureProtection #ThreatIntel #CyberRisk

    CISA Orders Emergency Drupal Patch | Microsoft Server Bug | Google Fights Canada Surveillance Bill

    Play Episode Listen Later May 27, 2026 10:32


    CISA has ordered U.S. federal civilian agencies to urgently patch an actively exploited critical Drupal SQL injection vulnerability (CVE-2026-9082) affecting PostgreSQL-backed Drupal deployments, after Imperva reported more than 15,000 attack attempts across 65 countries. Microsoft has confirmed a strange Windows Server 2016 update issue where KB5087537 can break domain controller discovery when server hostnames are exactly 15 characters long, raising more questions about patch reliability as update complexity grows. Google has joined a coalition opposing Canada's proposed lawful access legislation, Bill C-22, warning that secret ministerial orders, possible encryption risks, and mandatory metadata retention could weaken security rather than improve it. Critics point to the Salt Typhoon telecom espionage campaign as evidence that lawful intercept systems themselves can become prime targets. Also in this episode: Check Point says Iran-linked threat group Nimbus Manticore has deployed new malware tools including MiniFast and MiniJunk V2, with researchers noting signs that MiniFast may have been developed with AI-assisted coding techniques. The campaign used SEO poisoning and fake Oracle SQL Developer downloads to lure victims. Timestamps: 00:00 Top Headlines Rundown 00:27 Emergency Drupal Patch Order 02:22 Microsoft Server Update Bug 04:02 Canada Lawful Access Battle 05:18 Google's Security Concerns 06:25 Salt Typhoon Lessons 07:35 Iran-Linked AI Malware 09:26 SEO Poisoning Attack 10:09 Wrap Up and Sign Off

    AI Vulnerability Explosion, Kim Wolf Botnet Arrest, Ghost CMS Hack, Iran Cyber Espionage

    Play Episode Listen Later May 25, 2026 13:14


    Is AI about to trigger a cybersecurity vulnerability explosion? In this episode of Cybersecurity Today, David Shipley examines what some researchers are calling the early signs of a "vulnerability apocalypse" as Anthropic's Claude-powered Project Glasswing identifies thousands of potential software flaws at machine speed. The episode breaks down the real numbers behind the hype: over 10,000 candidate vulnerabilities flagged, 1,726 confirmed high or critical findings, 97 patched issues, and the growing concern that AI-driven bug hunting could overwhelm already stretched security teams. One example: a critical WolfSSL certificate forgery vulnerability (CVE-2026-5194, CVSS 9.1). Also in this episode: Canadian authorities arrest Ottawa suspect Jacob Butler, also known as "Dort," allegedly linked to the Kim Wolf botnet operation blamed for nearly 30 terabits-per-second distributed denial-of-service (DDoS) attacks and more than 25,000 incidents. We also cover active exploitation of a Ghost CMS SQL injection vulnerability (CVE-2026-26980), with attackers reportedly compromising hundreds of websites using ClickFix malware lures, including high-profile targets. And finally, an Iran-linked cyber espionage campaign dubbed "Screening Serpents" uses highly personalised fake recruitment approaches to target aerospace, defence, and telecom professionals with new remote access malware. If you work in cybersecurity, infrastructure, or IT leadership, this is one to watch. 00:00 Vunpocalypse Headlines 00:28 AI Finds Vulnerabilities 01:32 False Positives and Costs 02:39 WolfSSL Critical CVE 03:51 Patch Volume Pressure 04:28 Kim Wolf Botnet Arrest 05:13 Botnet Scale and Swatting 06:48 International Takedowns 07:41 Ghost CMS Mass Exploits 09:07 ClickFix Infection Chain 10:25 How to Remediate Ghost 10:39 Iran Spear Phishing Ops 12:51 Closing and Sign Off #Cybersecurity #CyberSecurityToday #AIsecurity #GhostCMS #DDoS #CyberEspionage #Anthropic #ClaudeAI #IranCyberThreat #InfoSec

    Researcher Finds Public GitHub Repo Exposing Sensitive CISA Credentials

    Play Episode Listen Later May 23, 2026 26:35


    The episode recounts how GitGuardian security researcher Guillaume Valadon, while monitoring public GitHub for leaked secrets, discovered a publicly accessible repository labeled "CISA-Private" containing highly sensitive CISA materials, including internal DHS/CISA credentials, cloud keys, tokens, plaintext passwords, logs, and files such as "Important AWS Tokens" and a CSV listing usernames and passwords for internal systems. Believing a contractor likely used GitHub to move work from a work device to a home device, Valadon escalated via responsible disclosure to CERT, then involved journalist Brian Krebs to reach CISA faster when the repo remained public.  After additional outreach, the repository was made inaccessible within about a day, and Valadon praises CISA's response speed. The discussion emphasizes widespread poor secret hygiene, governance, training, and the need for organizations to monitor, rehearse, and automate detection and revocation of leaked secrets. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. 00:00 Weekend Welcome Sponsor 00:27 CISA Secrets Leak Found 03:29 Calling Brian Krebs 05:06 Meet GitGuardian Researcher 07:26 Why Leaks Happen Everywhere 10:49 Inside the CISA Repo 13:19 Disclosure and Takedown 17:04 Lessons for Organizations 22:47 Aftermath and Thanks 24:36 Show Wrap Sponsor Outro

    GitHub Breach Exposes 3,800 Repos | Microsoft Kills SMS Authentication | Proton Fights Canada Bill

    Play Episode Listen Later May 22, 2026 9:19


    GitHub confirms a major supply chain breach after a malicious Visual Studio Code extension reportedly gave attackers linked to TeamPCP access to roughly 3,800 internal repositories. The bigger issue: developer workstations now hold some of the most sensitive secrets in modern software organizations. Also today: Microsoft begins phasing out SMS-based authentication for personal accounts, calling text-message authentication a growing fraud risk as it shifts toward phishing-resistant passkeys. Researchers also disclose a nine-year-old Linux privilege escalation flaw, CVE-2026-46333, nicknamed SSH-Keysign-Pwn, which can allow root-level access with local machine access. And Proton publicly threatens to leave Canada rather than comply with proposed surveillance legislation it says would undermine its no-logs privacy promise. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. If cybersecurity, privacy, and digital infrastructure matter to your business, this is the daily briefing you need. Timestamps: 00:00 Top Stories Rundown 00:24 GitHub Supply Chain Breach 01:09 Developer Workstations at Risk 02:31 Microsoft Ditches SMS MFA 04:15 Linux Root Escalation Flaw 06:11 Proton vs Canada Surveillance Bill 08:03 Wrap Up and Sign Off #cybersecurity #github #microsoft #linux #protonvpn #privacy #databreach #supplychainattack #infosec #cybernews

    Windows 11 BitLocker Zero-Day, TeamPCP Malware Leak, Iran Gas Station Hacks | Cybersecurity Today

    Play Episode Listen Later May 20, 2026 13:10


    A serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems.  Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. David Shipley breaks down four major cybersecurity stories on Cybersecurity Today. First, a newly disclosed zero-day dubbed YellowKey reportedly defeats default Windows 11 BitLocker protection on systems using TPM-only encryption, giving attackers with physical access a path to unencrypted data through the Windows Recovery Environment. Microsoft is investigating, while security experts are urging stronger BitLocker configurations. The episode also examines the TeamPCP threat group's decision to release offensive tooling publicly, dramatically lowering the barrier for copycat supply-chain attacks. Researchers have already spotted malicious NPM packages borrowing similar techniques, including persistence mechanisms aimed at developer environments such as Visual Studio Code and Claude Code. David also looks at disturbing analysis of the FAST16 malware, which researchers believe was engineered to tamper with nuclear weapons simulation software including LS-DYNA and AutoDyn. And finally, U.S. officials reportedly suspect Iranian actors in cyberattacks targeting internet-exposed gas station automatic tank gauge systems, a reminder that weak operational technology security can quickly become a real-world infrastructure problem. 00:00 Sponsor Message 00:24 Headlines Overview 00:50 BitLocker Zero Day 03:32 TeamPCP Tools Leak 06:13 Copycat NPM Malware 06:50 Fast16 Nuclear Sabotage 08:37 Iran Gas Station Hacks 10:28 Hardening Critical Infrastructure 11:16 Wrap Up And Events 11:59 Sponsor Deep Dive #Cybersecurity #Windows11 #BitLocker #ZeroDay #TeamPCP #IranCyberAttack #SupplyChainAttack #CriticalInfrastructure #CyberSecurityToday

    Exchange Zero-Day Under Attack, Ransomware Gets Smarter, Fortinet Critical Flaws

    Play Episode Listen Later May 19, 2026 12:48


    A dangerous new Microsoft Exchange zero-day is being actively exploited, ransomware gangs are adopting nation-state-style tactics, two fired contractors were caught deleting U.S. government databases after accidentally recording themselves on Microsoft Teams, and Fortinet has patched critical remote code execution flaws. In this episode of Cybersecurity Today, David Shipley breaks down four major cybersecurity stories that security teams need to know. Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  Microsoft has confirmed active exploitation of a new Exchange Server zero-day, CVE-2026-42897, affecting Exchange Server 2016, Exchange Server 2019, and Exchange Subscription Edition. There is currently no patch, only mitigations through the Exchange Emergency Mitigation Service, with some trade-offs for Outlook Web App users. Security researcher Marcus Hutchins highlights an unusually disciplined ransomware affiliate operation using tradecraft more commonly associated with nation-state attackers, including a custom SentinelOne endpoint detection and response (EDR) killer and a stripped-down toolset designed to leave fewer forensic traces. In one of the more astonishing insider threat stories of the week, former OPEX Corporation contractors Muneeb and Sohaib Akhtar were allegedly caught deleting 96 U.S. government databases after leaving a Microsoft Teams recording running. Also in this episode: Fortinet has released urgent patches for critical unauthenticated remote code execution vulnerabilities in FortiAuthenticator (CVE-2026-44277) and FortiSandbox (CVE-2026-26083). If you're responsible for enterprise security, patch management, incident response, or cyber risk, this is one you need to see. Chapters: 00:00 Sponsor Message 00:24 Headlines Intro 00:49 Ransomware Nation-State Discipline 04:18 Exchange Zero-Day Mitigation 07:01 Fired Contractors Caught Recording 09:21 Fortinet Critical Vulnerabilities 11:07 Wrap Up and Sign Off 11:38 Sponsor Deep Dive Ad #Cybersecurity #MicrosoftExchange #ZeroDay #Ransomware #Fortinet #CyberAttack #Infosec #DavidShipley #CybersecurityToday

    Inside CIRA: How Canada's .ca Registry Became a Global DNS & Cybersecurity Force

    Play Episode Listen Later May 16, 2026 53:03


    David Shipley interviews Jon Ferguson, VP at CIRA, about how the Canadian Internet Registration Authority evolved from early paper-based .ca registrations at UBC into a 142-person, member-based not-for-profit running .ca and authoritative Anycast DNS infrastructure now supporting 550+ TLDs globally. Ferguson explains how .ca's Canadian presence requirements help keep abuse rates low, and how CIRA reinvests surpluses into grants and cybersecurity tools, including Canadian Shield (DNS-based malware/phishing blocking and encrypted DNS with limited data retention) used by about 500,000 people and generating about 20 million blocks per month. They discuss CIRA's focus on municipalities, schools, hospitals, and universities, its move into endpoint security and a managed detection and response partner program with Calian, and concerns about AI-driven threats, online harm, and rebuilding trust and real-world connection. 00:00 Weekend Show Kickoff 01:30 Jon's Cyber Journey 03:06 Inside CIRA DNS Role 04:59 What Is CIRA 07:23 Origin Story Of Dot Ca 13:01 Anycast DNS Explained 16:27 Canadian Shield DNS Firewall 22:21 Serving Public Sector Needs 26:18 Endpoint And MDR Expansion 35:05 Mission Over Money 40:39 What Keeps Him Up 46:19 Hope And Balance Online 50:55 Wrap Up And Thanks

    How a Google API Key Became an $8,000 AI Bill, Meta Scam Ads Lawsuit, and 73-Second Cyber Attacks

    Play Episode Listen Later May 15, 2026 10:18


    Google Cloud customers are reporting shocking surprise bills after compromised or misused API keys were allegedly used to access expensive Gemini AI services. In one case, Rod Dinan says his monthly Google Cloud costs jumped from under $50 to nearly $8,000. Sydney developer Isuru Fonseka says he was hit despite setting spending controls, raising broader questions about API key security, client-side exposure, billing alerts, and how quickly attackers can exploit AI infrastructure. Cybersecurity Today also covers prosecutors' allegations that two fired brothers sabotaged systems tied to government-related work after access wasn't revoked quickly enough, Santa Clara County's civil lawsuit accusing Meta of profiting from scam ads on Facebook and Instagram, and Horizon3.ai's warning that attackers can exploit newly exposed systems in as little as 73 seconds while many organisations still take 24 hours or longer to respond. If your organisation uses APIs, AI services, cloud billing controls, or internet-facing infrastructure, this episode matters. #Cybersecurity #GoogleCloud #GeminiAI #APIKeys #CloudSecurity #Meta #ScamAds #CyberAttack #CybersecurityToday #AIsecurity CHAPTERS 00:00 Google Cloud API Key Bill Shock 01:20 Real-World Victims: Surprise AI Charges 02:24 Why Spending Caps Didn't Stop the Damage 03:38 The Enterprise Cloud Security Risk 04:19 Fired Employees and Alleged Insider Sabotage 04:55 The Database Destruction Timeline 06:34 What This Incident Teaches Security Teams 07:10 Santa Clara County Sues Meta Over Scam Ads 08:46 Attackers Can Strike in 73 Seconds 10:14 Closing and Next Episode

    Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again

    Play Episode Listen Later May 13, 2026 16:09


    Cybersecurity Today examines a troubling set of new security developments affecting schools, software supply chains, and account security. Instructure says it reached an "agreement" with the ShinyHunters threat group after the massive Canvas breach that may have affected up to 275 million users across 9,000 educational institutions. Reports indicate attackers exploited multiple cross-site scripting (XSS) vulnerabilities to hijack administrator sessions and post extortion demands. Checkmarx has been breached again. This time, attackers reportedly inserted a malicious Jenkins Application Security Testing (AST) plugin designed to steal credentials. The same threat actor, believed to be Team46/TeamTNT-linked infrastructure or Team PCP depending on reporting attribution, appears to have reused secrets allegedly stolen in the earlier Trivy supply-chain compromise. Microsoft and Google are warning organizations not to treat passkeys as a complete security solution. If weaker recovery methods or legacy credentials remain active, attackers can still bypass them. Google's Threat Intelligence Group also reports what it describes as the first observed evidence of hostile actors using AI to assist in zero-day vulnerability research and exploit development, signalling a new phase in attacker industrialization. Also in today's show: Santa Clara County sues Meta over alleged scam-ad profits. Chapters 00:00 Headlines Overview 00:28 Canvas Breach Deal Fallout 01:59 How the XSS Attack Worked 03:15 Checkmarx Supply Chain Attack 05:01 Credential Rotation Lessons 05:37 Why Passkeys Aren't Enough 07:19 Layered Defence Takeaways 08:35 AI-Assisted Zero-Day Development 10:10 Industrialized AI Threats 13:08 Meta Scam Ads Lawsuit 15:19 Wrap Up

    Canvas Breach Exposes 275M Accounts | AI Targets Water Systems | GM OnStar Settlement

    Play Episode Listen Later May 11, 2026 16:55


    A massive cybersecurity week. On this episode of Cybersecurity Today, David Shipley breaks down the reported breach of Instructure's Canvas learning platform, where attacks linked to the ShinyHunters extortion group may have exposed data tied to up to 275 million user accounts across more than 9,000 educational institutions. The incident disrupted access, delayed exams, and forced Instructure to disable its "Free for Teacher" program after attackers allegedly used it to post extortion messages. Also in this episode: the Gentlemen ransomware group suffers a major internal leak, exposing affiliate chats, tooling, victim data, and operational details — a rare look inside a live ransomware operation. Then, General Motors agrees to a $12.75 million California settlement over allegations involving OnStar-linked driver data collection and sharing, raising fresh questions about privacy in connected vehicles. And finally: security researchers report what appears to be the first documented AI-assisted operational technology (OT) cyberattack attempt targeting a water utility in Monterrey, Mexico. The attempt failed to reach industrial control systems, but combined with confirmed attacks on water infrastructure in Poland, it signals a worrying shift in critical infrastructure threats. If you work in cybersecurity, IT, infrastructure, education, or privacy, this episode matters. Chapters 00:00 Top Headlines Rundown 00:41 Canvas Mega Breach 02:44 ShinyHunters Background 03:26 Ransom Pressure Fallout 04:25 Gentlemen Ransomware Leak 05:18 Inside the Data Dump 06:18 GM OnStar Privacy Settlement 08:17 What Drivers Should Know 09:39 AI Meets OT Attacks 11:52 Monterrey Water Near Miss 13:29 Poland Water Systems Hit 15:07 Defending Critical Infrastructure 16:29 Wrap Up And Thanks #Cybersecurity #Canvas #ShinyHunters #Ransomware #OnStar #GeneralMotors #DataBreach #CriticalInfrastructure #WaterUtility #OperationalTechnology #ICS #CyberAttack #Privacy #DavidShipley #CybersecurityToday

    Cybersecurity Today Month in Review: AI Coding Risks, Canvas Breach, QR Phishing Surge

    Play Episode Listen Later May 9, 2026 57:38


    This week's panel dives into the cybersecurity stories that matter most for security leaders, IT teams, and anyone watching how AI is changing risk. Jim Love is joined by David Shipley (Beauceron Security), Laura Payne (White Tuque), and Jeff Williams (Contrast Security). Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  Topics include: Anthropic's Mythos AI security research and whether large language models can realistically replace traditional vulnerability testing Why "vibe coding" may be creating a wave of insecure software The growing risk of autonomous AI agents making damaging decisions The massive Instructure Canvas data breach affecting schools, students, and educators Alberta's voter list privacy failure and what it says about public sector data protection Microsoft's warning about the rapid surge in QR code phishing attacks bypassing traditional email security AI is accelerating software development. It may also be accelerating software insecurity. If your organisation is experimenting with AI coding tools, AI agents, or automated application development, this conversation is worth your time. #Cybersecurity #AI #DataBreach #QRPhishing #ApplicationSecurity #VibeCoding #Canvas #CyberSecurityToday #JimLove 00:00 Sponsor Message 00:22 Meet the Panel 00:55 Jeff Williams Introduction 02:21 AI Bug Hunting with Mythos 05:40 Cost and Limits of AI Security Testing 10:16 The Vibe Coding Security Problem 13:24 Context Window and Data Flow Limits 16:59 Spec-Driven AI Development 18:29 Software Liability and EU Regulation 24:47 When AI Agents Go Rogue 27:05 Trust in the AI Era 28:24 Enterprise Reality Check 29:03 Critical Thinking vs AI 30:31 Testing AI Agents Safely 31:30 Canvas Data Breach Fallout 34:45 Real-World Data Harm 38:00 Liability and Attack Methods 41:39 Alberta Voter List Privacy Failure 48:56 Government Breach Lessons 51:26 QR Code Phishing Surge 55:00 Wrap Up and Sponsor

    Meta allegedly made billions from scam advertising while online fraud explodes worldwide.

    Play Episode Listen Later May 8, 2026 25:35


    In this special edition of Cybersecurity Today, David Shipley speaks with scam-fighting expert Erin West about the global fraud crisis, the rise of AI-powered scams, and why traditional law enforcement may be falling behind. Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  From David's discussion with Erin West: The numbers are staggering. The FBI's Internet Crime Complaint Center reported more than $21 billion in cybercrime losses, but experts say actual losses could be dramatically higher because most victims never report fraud. Other key points of their discussion: Why pig butchering scams continue to grow globally How criminal operations are moving from Cambodia to Myanmar, Laos, Sri Lanka and beyond Why AI is making scam operations faster, cheaper and harder to detect The controversy around Meta and scam advertising revenue Why crypto ATMs remain a major fraud tool How cloned celebrity voices are being used in romance and impersonation scams Why banks, law enforcement, governments and tech platforms must act together How Operation Shamrock is trying to fight back through public education This is not just a story about money. It's about organized crime, industrial-scale fraud, and ordinary people being manipulated through trust, loneliness, and increasingly sophisticated technology, featuring scam-fighting prosecutor and Operation Shamrock founder Erin West. #Cybersecurity #Scams #Meta #OnlineFraud #AI #Cybercrime #PigButchering #CryptoScams #FacebookScams #CybersecurityToday

    QR Phishing Explodes, Ubuntu Under Attack, CISA Warns Critical Infrastructure Prepare for Isolation

    Play Episode Listen Later May 6, 2026 19:36


    QR-code phishing is no longer a niche attack. Microsoft says QR phishing attacks jumped from 7.6 million in January to 18.7 million in March 2026 — a 146% increase in just three months. In this episode of Cybersecurity Today, David Shipley explains why QR-based attacks are bypassing traditional corporate defences and why security teams need to rethink phishing awareness immediately. We also cover a critical new Apache HTTP Server vulnerability with both denial-of-service and potential remote code execution impacts, a sustained DDoS and extortion campaign targeting Ubuntu developer Canonical, and a remarkable case in Taiwan where a university student allegedly used software-defined radio gear to trigger emergency braking on four high-speed trains. Finally, CISA's new "CI Fortify" guidance urges critical infrastructure operators to prepare for scenarios where they may need to disconnect from the internet and continue operating manually during a geopolitical cyber crisis. Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  Stories include: • Microsoft reports QR phishing attacks surged 146% in Q1 2026 • Apache HTTP Server CVE-2026-23918 urgent patch warning • Ubuntu developer Canonical hit by ongoing DDoS and extortion campaign • Taiwanese student allegedly halts high-speed trains with fake emergency radio signal • CISA tells critical infrastructure operators to prepare for isolation and manual operations Chapters: 00:00 Intro 01:02 QR phishing explodes in Q1 2026 06:15 Critical Apache HTTP Server flaw patched 09:15 Ubuntu maintainer Canonical hit by extortion DDoS attack 14:25 Taiwanese student wirelessly halts high-speed trains 20:32 CISA warns critical infrastructure to prepare for isolation 26:10 Closing thoughts

    Microsoft Defender Deletes Trusted Certificates | 44,000 cPanel Servers Hit by Ransomware

    Play Episode Listen Later May 4, 2026 13:37


    Microsoft Defender Deletes Trusted Certificates | 44,000 cPanel Servers Hit by Ransomware Microsoft Defender mistakenly flagged legitimate DigiCert root certificates as malware and removed them from Windows systems, breaking trust chains and causing widespread application failures. The issue was traced to a faulty detection signature (Trojan:Win32/CertyAgent), now fixed in update version 1.449.430.0.  At the same time, DigiCert confirmed a separate security incident where attackers compromised support systems and used internal tools to issue valid code-signing certificates. At least 60 certificates were revoked, including 27 linked to the Zong Stealer malware campaign.  Meanwhile, a critical cPanel vulnerability (CVE-2026-41940) is being actively exploited. Attackers used the flaw as a zero-day since February, compromising at least 44,000 servers and deploying new SORI ransomware using ChaCha20 and RSA-2048 encryption.  Also in this episode: The Linux "Copyfail" privilege escalation bug is now confirmed exploited and added to CISA's Known Exploited Vulnerabilities list A 10/10 critical vulnerability (CVE-2026-37541) in Open Vehicle Monitoring System could allow remote code execution in connected car environments This episode breaks down how these attacks work, why patch timing matters, and where organizations are most exposed right now. Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  Suggested Chapters (for retention and SEO) 00:00 Microsoft Defender deletes trusted certificates 02:20 DigiCert breach and stolen code-signing certificates 05:20 cPanel zero-day exploited, 44,000 servers compromised 08:40 Linux Copyfail vulnerability now actively exploited 10:40 Critical flaw in open-source car software  

    Connected Cars Are Rolling Spy Networks — And They Can Be Hacked

    Play Episode Listen Later May 2, 2026 44:51


    Connected cars are no longer just vehicles — they are rolling networks of sensors, cameras, microphones, and constant data transmission. In this Cybersecurity Today Weekend Edition, David Shipley is joined by former CSIS intelligence officer Neil Bisson and cybersecurity expert Federico Simonetti to break down what that really means. They explain how modern vehicles: Continuously report location, behaviour, and system data to the cloud Contain dozens of interconnected computers controlling everything from steering to braking Can be vulnerable to man-in-the-middle attacks, remote access, and system compromise May expose drivers to surveillance — not just by companies, but potentially by nation states The conversation goes beyond theory. Real-world examples are discussed, including: Remote vehicle manipulation demonstrated by security researchers How infotainment systems can become entry points to critical controls Why some countries are already restricting certain vehicles from sensitive locations The panel also tackles the bigger issue: This is not just about one country or one manufacturer. Every connected vehicle expands the attack surface. And while solutions exist — from better authentication to architectural changes — the challenge is no longer technical. It's political, economic, and global. If you think your car is just transportation, this discussion may change your perspective. 00:00 Connected Cars: More Than Just Vehicles 01:20 Meet the Panel: Intelligence and Cybersecurity Perspectives 03:10 Every Car Is Now a Networked Computer 06:00 Surveillance Risks: Are Cars "Rolling Spy Vans"? 09:10 What Intelligence Agencies Can Do With Car Data 12:30 Sensors, GPS, Cameras — What Your Car Collects 16:20 Real Example: Tesla Camera Privacy Incident 19:00 Can Hackers Take Control of a Car? 22:30 Real-World Hacks: Jeep and Nissan Cases 26:40 The Regulatory Gap: No Enforced Cybersecurity Standards 30:10 Why Governments Are Struggling to Act 34:00 Cheap EVs vs National Security Risks 37:40 Can Software Fix the Problem? 41:20 Global Response: China, US, and Europe 45:10 Policy Ideas: Kill Switches, Car Bill of Rights 49:00 Prevention vs Detection in Cybersecurity 52:30 Are We Already Too Exposed? 55:10 Final Thoughts: Can Connected Cars Be Made Safe?

    WhatsApp Encryption Under Fire After Probe Shut Down

    Play Episode Listen Later May 1, 2026 10:06


    A U.S. federal investigation into WhatsApp encryption was shut down before reaching a conclusion — after an internal claim suggested Meta systems may access message content in ways that conflict with public descriptions. In this episode of Cybersecurity Today, Jim Love breaks down what's known, what isn't, and why the story isn't going away. Also in this episode: A newly disclosed Linux vulnerability (CVE-2026-31431) allows an unprivileged local attacker to gain root permissions — using a flaw that may have existed since 2017 BlueKit, a new phishing toolkit, shows how AI is now being built directly into cybercrime platforms More than three million Alberta voter records exposed after being posted online — not by hacking, but by alleged misuse of legally distributed data These stories highlight a growing pattern: the biggest risks aren't always new attacks — they're often hidden in how systems are designed, used, and trusted. Chapters: 00:00 WhatsApp encryption investigation shut down 02:15 Linux "copy fail" root vulnerability explained 04:30 BlueKit AI phishing platform 06:30 Alberta voter data leak Cybersecurity Today delivers clear, factual reporting on the stories that matter to IT professionals, business leaders, and anyone responsible for protecting data and systems.

    Massive Python Supply Chain Hack, $2.1B Scam Losses, North Korea Targets Crypto Execs

    Play Episode Listen Later Apr 29, 2026 12:13


    A major open source Python tool was hijacked in a supply chain attack, exposing developer credentials, cloud secrets, and crypto wallets. Meanwhile, the FTC says Americans lost more than $2.1 billion to scams that began on social media, with Facebook leading reported losses. Cybersecurity Today thanks Meter for supporting this podcast. Meter delivers a complete networking stack — wired, wireless, and cellular — in one integrated solution built for performance and scale. Learn more at Meter.com/cst. Also in today's Cyber Security Today: Brazilian hackers return with fake Minecraft cheat downloads carrying credential-stealing malware A new ransomware strain destroys victim files so badly even paying the ransom may not help North Korean threat actors target crypto executives using fake Zoom and Teams meetings powered by AI deception tactics If you work in IT, cybersecurity, finance, or simply want to stay safe online, this episode breaks down what matters and what to watch next. Stories covered in this episode are based on reporting summarized in the show transcript.   #cybersecurity #ransomware #scams #python #hacking #northkorea #cryptocurrency #malware #technews

    Cyber Weapon in Toronto, Grid Attack, Stuxnet Lie Exposed

    Play Episode Listen Later Apr 27, 2026 15:46


    A rogue cyber weapon drove through Toronto blasting scam texts to thousands of phones. A major U.S. critical infrastructure provider confirms a cyberattack. And researchers reveal that Stuxnet may not have been the first cyber weapon after all. In today's Cybersecurity Today with David Shipley: • First known SMS blaster case in Canada uncovered in Toronto • Itron, a major utility technology supplier, discloses cyber intrusion • Researchers say a 2005 malware campaign predates Stuxnet • Venezuela energy sector attack reveals destructive "Lotus Wiper" malware • Why AI-powered attacks may change critical infrastructure risk forever If you care about cybersecurity, nation-state threats, infrastructure risk, and real-world attacks, this episode is essential listening. Hosted by David Shipley. Cybersecurity Today thanks Meter for supporting this podcast. Meter delivers a complete networking stack — wired, wireless, and cellular — in one integrated solution built for performance and scale. Learn more at Meter.com/cst. Chapters 00:00 Intro 00:36 Toronto SMS Cyber Weapon 05:12 Critical Infrastructure Supplier Hit 09:28 Stuxnet History Rewritten 14:32 Venezuela Energy Sector Attack 19:05 Final Thoughts #Cybersecurity #Stuxnet #CyberAttack #Toronto #CriticalInfrastructure #Hacking #Itron #CyberNews #DavidShipley

    Cybersecurity Today Weekend: Deepfakes, the Death of Truth, and Verifying AI in the Enterprise

    Play Episode Listen Later Apr 25, 2026 70:12


    Inside The Vercel Supply Chain Exploit

    Play Episode Listen Later Apr 24, 2026 17:39


    Inside the Vercel Breach: Highlighting OAuth Token Risk  In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Security) discuss Vercel, a major developer hosting platform, and a breach tied to OAuth grants and shadow AI. Reporting shared by Contrast Security's David Lindner describes how a Context AI employee downloaded Roblox AutoFarm scripts, got infected with an info stealer, and attackers harvested credentials, compromised Context AI, then used an over-permissioned OAuth token from a Vercel employee who had signed up to Context AI with an enterprise account and clicked "allow all," with Vercel working with Mandiant on a breach allegedly being sold for $2 million. The episode emphasizes that MFA may not mitigate OAuth abuse, urges admin-managed consent, continuous inventory and auditing of OAuth grants, and better visibility into risky third-party app access across Google Workspace and Microsoft 365. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst 00:00 Special Edition Intro 00:14 Sponsor Message Meter 00:33 Supply Chain Hack Setup 01:16 Breach Seen In Wild 02:36 Meet Jamie Blasko 02:56 Who Is Vercel 04:34 How The Breach Happened 05:58 Context AI And Shadow IT 07:58 OAuth Controls And Audits 09:11 Impact And Open Questions 11:24 Why MFA Falls Short 12:22 Where To Get Help 14:07 Host Takeaways OAuth Risk 14:53 What To Do Next 16:06 Wrap Up And Feedback 16:42 Sponsor Close Meter 17:24 Final Sign Off          

    Vercel Breach Started With AI Tool

    Play Episode Listen Later Apr 22, 2026 10:42


    Vercel Supply-Chain Breach via AI Tool, Meta Sued Over Scam Ads, and Ransomware Surges with "The Gentleman" David Shipley covers new details on the Vercel breach, which began when an employee used the third-party AI tool Context AI; after Context AI was breached, attackers leveraged Google OAuth access to pivot into Vercel systems and enumerate unencrypted "non-sensitive" environment variables that contained usable secrets, with a hacker claiming Vercel data and source code and demanding $2M, while Vercel says Next.js and other open-source projects are safe and shares Google OAuth indicators of compromise. The episode also discusses a proposed class-action lawsuit alleging Meta misled users about scam ads and profited from them, noting Meta's claim it removed 159M scam ads and shut down nearly 11M criminal accounts. Finally, it cites ZeroFox data showing ransomware incidents holding steady at 2,059 in Q1 2026 and highlights Check Point research indicating "The Gentleman" has a much larger victim footprint and uses tactics like disabling Defender, re-enabling SMB1, abusing GPO, and targeting VMware environments. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst 00:00 Headlines and Sponsor 00:46 Vercel AI Supply Chain Breach 02:50 Meta Sued Over Scam Ads 04:55 Ransomware Numbers Q1 2026 06:46 Gentlemen Crew Exposed 08:56 Wrap Up and Thanks 09:42 Sponsor Message Meter

    Security Researcher Goes To War Against Microsoft

    Play Episode Listen Later Apr 20, 2026 20:47


    Microsoft Under Fire, NIST Scales Back NVD, FortiSandbox Critical Bugs, Vercel Breach Claims, Scattered Spider Member Pleads Guilty Host David Shipley covers five major stories: researcher "Chaotic Eclipse" publicly released Windows exploits—first "Blue Hammer," then "Red Sun," a Microsoft Defender flaw enabling privilege escalation on fully patched Windows 10/11 and Server—amid claims Microsoft mistreated them, highlighting strain on responsible disclosure as vendors face mounting vulnerability volume and AI-driven bug discovery. NIST announced it can no longer fully enrich all CVEs in the National Vulnerability Database, prioritizing only exploited-in-the-wild issues, federal software, and critical software, leaving the rest backlogged. In "FortiWatch," two critical FortiSandbox flaws allow auth bypass and remote command execution; patches are available. Vercel confirmed attackers accessed internal systems and urges customers to review and rotate environment variables amid unverified ShinyHunters ransom claims. Finally, alleged Scattered Spider member Tyler Buchanan pled guilty to an $8M crypto theft case, with reporting describing the group's social engineering tactics and escalating real-world violence tied to cybercrime. Cybersecurity Today  would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst 00:00 Headlines And Sponsor 00:49 Microsoft Bug Drop 03:00 Disclosure System Strain 05:59 NVD Backlog Crisis 08:47 FortiWatch FortiSandbox 11:43 Vercel Breach Fallout 14:43 Scattered Spider Guilty Plea 18:54 Wrap Up And Thanks

    Claim Cyber Security Today

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel