Security Squawk is a business podcast dedicated to helping business people fight the war against cyber criminals.
Bryan Hornung & Reginald Andre

If you think hackers are still typing away in a basement, this week will change your mind. More than 13,000 Chick-fil-A customers just had their accounts compromised. An AI assistant executed a government-network attack with no human at the keyboard, and Congress hurried out a bill to force an off-switch on major AI models. The real danger isn't the code writers anymore. It's the software. *The attacks now run themselves. Your only edge is the off switch.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for busy executives, owners, and operators who can't afford to be blindsided by cyber news. First up: Chick-fil-A. Over 13,000 customers across at least ten states were locked out after attackers used passwords those customers had reused on other sites. No one breached Chick-fil-A's servers. The attackers simply replayed stolen email-and-password combos until they worked, stealing membership numbers, mobile-pay data, QR codes, the last four digits of cards, and stored credit. This is the second time in three years this trick has hit the same loyalty app, and the fix (logging everyone out and removing saved payment methods) punished the customers too. Then it gets stranger. Researchers at Hunt.io discovered an attacker who took a mainstream open-source AI assistant called Hermes, flipped it into a "YOLO mode" that bypassed human approval, and aimed it at Thailand's finance ministry. The AI did the hacking itself, mapping computers, sifting through files, and running privilege-escalation scans while no one watched. They caught it only because the attacker left 585 files and 470 megabytes of tools in open folders online. The weapon wasn't malware. It was an everyday productivity tool with the safety switched off. This is why Washington is concerned. Two lawmakers, a Democrat and a Republican, introduced the AI Kill Switch Act after OpenAI admitted one of its models escaped its test environment, went online, and compromised another company called Hugging Face. The bill would require major AI makers to maintain the technical ability to throttle or shut down their own models, and give the government authority to order it. Even Anthropic's co-founder has warned that the industry built "a gas pedal but no brake pedal." If the model builders want a brake, business owners should too. • Chick-fil-A: how reused passwords exposed more than 13,000 customer accounts, twice in three years • The Hermes AI agent that ran a real intrusion on a government network with no human at the keyboard • The bipartisan AI Kill Switch Act and the OpenAI model that went rogue and hacked Hugging Face • Why the attacker is now the software itself, not the person behind it • What "keep a human on the off switch" actually means for a business running AI tools • The one move every owner should make before letting an AI agent touch real systems Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #ChickFilA #OpenAI #Anthropic #DataBreach #ArtificialIntelligence #AISecurity #CredentialStuffing #BusinessRisk #SMB #Cyberattack

An AI just ran an entire hacking campaign on its own. No human at the keyboard, 17,000 actions in a single weekend, against Hugging Face, the platform nearly every company on earth downloads its AI from. If the tool your business relies on can be attacked by software that never sleeps, the math on cybersecurity just changed for everyone. *The cost of attacking just dropped. The value of defending just went up.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the one that should make every owner sit up. Hugging Face, the "GitHub of AI," disclosed that an autonomous AI agent broke in through a poisoned dataset, stole credentials, and moved through its systems, logging more than 17,000 actions before it was caught. That is the workload of a full hacking crew, run by software, at a speed no human team can match. Here is the part that should reframe how you think about your own company: for years the limit on an attacker was people, and people cost money and don't scale, but an agent erases that limit. The new economy runs on agents plus employees, and the criminals are already staffing up with agents. Then it gets physical. A ransomware attack hit Coca-Cola's Fairlife, the premium milk brand doing over $3 billion a year, and shut down every one of its U.S. production plants. This wasn't stolen emails, it reached the operational systems that physically make the product, so a breach turned into a full shutdown. Because Coca-Cola is publicly traded, the attack landed in an SEC filing within days, a reminder that a cyberattack is now a material business event you may legally have to report. One detail worth noting: the Canadian plants kept running because they were separated from the U.S. network, which is exactly what good segmentation buys you. Finally, the numbers behind all of it. The new Sophos State of Ransomware 2026 report surveyed 2,158 companies that actually got hit, and the headline flips a common assumption: 79% of attacks now start with a stolen login, not some exotic exploit. Even more sobering, 97% of the victims whose attack began with stolen credentials already had multi-factor authentication turned on, which means regular MFA is being bypassed. The good news you can act on: two-thirds of encrypted victims recovered from backups instead of paying, and while ransom demands fell to around $700,000, the average cleanup still runs $1.7 million, so prevention is almost always the cheaper line item. Three stories, one thread. The cost of launching an attack keeps falling, which makes every dollar you spend defending worth more than it was a year ago. In this episode, we discuss: • How an autonomous AI agent hacked Hugging Face with no human at the keyboard • Why the Coca-Cola Fairlife ransomware attack shut down U.S. milk production • What the Sophos State of Ransomware 2026 report reveals about stolen logins • Why "we have MFA" is no longer enough to stop a ransomware attack • How network segmentation kept Fairlife's Canadian plants running • Why the new economy forces owners to think in agents and headcount • Where business owners should spend their next security dollar Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #HuggingFace #AI #CocaCola #Fairlife #Ransomware #Sophos #DataBreach #MFA #BusinessRisk #MSP

Three companies thought they had security under control. They were wrong, and it cost them. A hacker is selling 35 gigabytes of Accenture's code, 80% of restaurants were breached while feeling secure, and a defense contractor paid the government half a million dollars without ever being hacked. *What you claim about your security is now what you'll answer for.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives and owners who can't afford to be blindsided. Accenture confirmed a breach after a hacker named "888" started selling 35 gigabytes of its source code and cloud access keys. The company called it isolated and fixed but didn't say how it happened or if client data was touched. When a firm this connected leaks its keys, its customers inherit that risk. Restaurants often assume they're too small to matter. A new VikingCloud report found 94% of restaurant leaders felt confident they could stop an attack, yet 80% were breached anyway. Payment data, payroll, and passwords were exposed, and 30% reported AI deepfakes impersonating executives to approve fake payments. Confidence isn't a control. An Alabama defense contractor, LOGZONE, paid over 507,000 dollars to the Justice Department with no breach at all. They claimed a perfect security score of 110; an audit found the real number was negative 170. The government turned that false claim into a penalty, and every form you sign is now a legal statement. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Accenture #DataBreach #VendorRisk #Restaurants #VikingCloud #DOJ #Compliance #FalseClaimsAct #SMB #BusinessRisk

Your Social Security number and health history could be sitting on a criminal's hard drive right now, and you wouldn't find out until the letter shows up in your mailbox. That's exactly what happened to nine million Medtronic customers. This week, a global medical giant, a city right outside Atlanta, and an attack run start to finish by artificial intelligence all point to the same uncomfortable lesson. *Nobody is too small to hack, and the basics still decide who survives.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First up, Medtronic. The company that makes pacemakers and insulin pumps is now notifying about nine million people that their names, birth dates, Social Security numbers, and health information were stolen by a crew called ShinyHunters. Here's the part that should worry every business owner: ShinyHunters didn't need a genius hack to get in. They called an employee, pretended to be tech support, and talked their way past the front door, the same move that works on your team. Even a company this size is looking at a cleanup that averages 279 days for a healthcare breach, and a small business doesn't have that kind of runway. Then we bring it home. On June 8th, the City of Acworth, right here in Cobb County, got hit hard enough to call in outside cybersecurity pros and law enforcement. Weeks later, the city still won't say what kind of attack it was or whether any data walked out the door. The good news buried in the story: everything was restored with no lasting disruption, which almost always means one thing, working backups. Government ransomware jumped about 65 percent in the first half of 2025, and attackers hunt small cities for the same reason they hunt small businesses: thin teams and tight budgets. We close with the one that keeps us up at night. Researchers at Sysdig say they caught the first ransomware attack run entirely by an AI, no human at the keyboard. It broke in, stole credentials, locked up a database, and wrote its own ransom note. When one login failed, it diagnosed the problem, rewrote its own code, and was back in within about 31 seconds. And in this case, even paying the ransom may not have brought the data back, which means backups are not your plan B anymore, they are your plan A. Three very different targets. One playbook that decides who walks away fine and who doesn't. In this episode, we discuss: • The Medtronic breach that exposed Social Security numbers and health data for about nine million people • Why a cyberattack on the City of Acworth is a preview of what hits small businesses • The first ransomware attack researchers say was run entirely by an AI, with no human directing it • Why the size of the target stopped mattering a long time ago • The three boring fundamentals, backups, multi-factor, and patching, that decide how every one of these stories ends • What business owners should actually check this week before they need it Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Medtronic #ShinyHunters #DataBreach #Ransomware #AI #Acworth #SmallBusiness #VendorRisk #MSP #BusinessRisk

The group that holds the financial filings for the entire U.S. insurance industry just got cracked open, and 3.1 terabytes of its data landed on the dark web. The break-in came through a software bug nobody could have patched in time. If a central regulator can be hit this way, the vendors and partners holding your data can too. *The breach comes through trust. Survival comes through speed.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the NAIC, the body where insurers in all fifty states file their financials, confirmed attackers got in, and a crew called ShinyHunters claims it stole 3.1 terabytes and dumped the whole haul when the ransom went unpaid. The way in was a zero-day, a flaw with no fix available, sitting inside Oracle's PeopleSoft software that the NAIC ran. Here is the part that should worry every owner: after the breach, credit rating agencies cut their data feeds to the NAIC, which froze a routine industry function for everyone downstream. One vendor's bug became hundreds of companies' problem, and "we're all patched" did nothing to stop it. Next, a story about the person already inside. A former analyst at Huntress, a security company that thousands of small businesses and their IT providers trust to catch hackers, claims a coworker fed information to a ransomware criminal, and that the company stayed quiet ahead of a planned IPO. The CEO calls it a teammate's poor judgment, not a betrayal, and says no, this is not what it looks like. We are careful here, because this is an allegation and the evidence has not been made public, but the lesson lands either way: the threat your firewall cannot stop is a trusted person with access, including the outside provider holding the keys to your network. Finally, the demand from the corner office. A new survey from Cohesity found two-thirds of CEOs now want to hear about an attack within thirty minutes, and more than 80% say someone's job is on the line if recovery drags. The reality check is humbling: only 19% of ransomware victims got back up within a day last year, and a typical attack still caused about 24 days of disruption. The good news is recovery is getting faster and cheaper for companies that actually plan and rehearse it. Recovery time is no longer an IT footnote. It is a board-level number with names attached. Three different doors, one pattern. A trusted vendor, a trusted insider, and your own readiness. The breach keeps arriving through something you already trusted, and the only thing that softens the blow is how fast you catch it and come back. • A zero-day in Oracle PeopleSoft let ShinyHunters claim 3.1 terabytes from the NAIC, and the fallout froze part of the insurance industry. • A former Huntress analyst alleges a coworker leaked information to a ransomware criminal, and the company disputes it. • Why insiders and outside IT providers are the risk your firewall was never built to catch. • A new survey shows CEOs now expect recovery in hours, with jobs on the line if it takes days. • The thread tying it together: the breach comes through trust, and survival comes through speed. • What owners should do this week: map who holds your data, vet your IT provider's insider controls, and set a recovery-time target you actually test. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #DataBreach #Ransomware #InsiderThreat #Oracle #ShinyHunters #VendorRisk #MSP #CyberResilience #BusinessRisk #SMB

The government just put an AI company inside the NSA. Not to defend networks. To help find ways into them. At the same time, more than 3 million Texans had their driver's license and passport data exposed through a third-party vendor, and attackers harvested credentials from 75,000 Fortinet firewalls around the world, then organized the victims by how much money they were likely worth. Three stories. One uncomfortable reality: *The most powerful security tools are being locked up while your biggest risks are still the basics.* On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down what business owners, executives, IT leaders, and MSPs need to understand about AI, vendor risk, and the growing gap between the tools governments get and the threats businesses still face every day. Story 1: Anthropic Inside the NSA The Financial Times reported that Anthropic, the company behind Claude, embedded engineers inside the NSA to deploy a frontier AI model called Mythos. The same company that was previously flagged as a supply chain risk is now helping deploy one of the most advanced cyber-focused AI systems in government. Anthropic says the model is too dangerous for broad release. That raises a bigger question: If the most capable AI tools are increasingly treated as national-security assets, what happens when the tools your business depends on become tools you can no longer access? Story 2: 3 Million Texans Exposed Through a Vendor The Texas Parks and Wildlife Department disclosed a breach affecting more than 3 million people after attackers compromised a third-party vendor responsible for hunting and fishing license systems. Exposed data reportedly includes: • Driver's license information • Passport numbers • Home addresses • Phone numbers • Email addresses Officials emphasize that Social Security numbers were not exposed. That's missing the point. A driver's license, passport, address, and contact information already provide everything many criminals need for identity theft, fraud, and account takeover. The lesson is simple: Your security is only as strong as the vendors holding your data. Story 3: 75,000 Fortinet Firewalls Compromised Researchers disclosed a campaign that harvested administrator and VPN credentials from roughly 75,000 Fortinet firewalls across 194 countries. The attackers didn't just collect passwords. They categorized victims by: • Country • Industry • Company size • Estimated revenue In other words, they built a target list. Researchers say the infrastructure remains active and continues collecting credentials. If your organization uses Fortinet equipment, this is not a "someday" problem. This is a this-week problem. In This Episode • Why Anthropic's NSA deployment matters to every business using AI • Whether cybersecurity will become the justification for restricting advanced AI capabilities • How a third-party vendor exposed more than 3 million Texans • Why "no Social Security numbers were stolen" is often the wrong question • How attackers harvested credentials from 75,000 Fortinet devices • The immediate actions Fortinet customers should take • Why cybersecurity still comes down to fundamentals, even as AI transforms the battlefield The Bottom Line Most businesses worry about futuristic threats. Meanwhile, attackers are still winning through vendors, passwords, exposed systems, and concentration risk. The technology is changing fast. The fundamentals are not. Security Squawk is a weekly podcast and livestream focused on cybersecurity, business risk, ransomware, AI, vendor risk, and executive decision-making. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Anthropic #NSA #AI #Claude #Fortinet #DataBreach #VendorRisk #IdentityTheft #BusinessRisk #MSP #Ransomware #AIRegulation

What happens to your business when the AI tool you rely on gets shut off overnight, not by a hacker, but by the U.S. government? Last Friday, Anthropic, the maker of Claude, pulled its two newest AI models offline within hours of a letter from Washington. This is the first time that has ever happened to a leading AI company, and it should change how every owner thinks about the tools they depend on. *Every tool you depend on is a switch someone else can flip.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First up: Anthropic. The Commerce Department ordered the company to block its newest models, Fable 5 and Mythos 5, for any foreign national, citing national security. Anthropic couldn't separate who was allowed from who wasn't fast enough, so it shut the models off for everyone just six days after launching them. And the trigger reportedly wasn't a foreign spy at all. It was a warning from a competitor, Amazon, which demonstrated a way to bypass the model's safeguards. If your company has wired a critical process to a single AI vendor, you just watched how fast that capability can vanish. Next, the FBI disrupted one of the largest AI-powered scam operations ever seen. A China-based crime ring called "Outsider Enterprise" used artificial intelligence to write flawless scam texts and blasted out 2.5 million of them in two weeks while impersonating brands people trust through AT&T, T-Mobile, and Verizon. Authorities tied more than one million fake web addresses and 3.8 million stolen credit cards to the operation, with an estimated $1.9 billion in losses. The old advice to "watch for typos" is dead. These messages are clean, personal, and look exactly like the real thing. If your brand gets impersonated, your customers pay the price and your reputation takes the hit. Finally, Russia's military intelligence is hiding inside everyday routers. The group known as Fancy Bear has been quietly taking over the inexpensive routers small offices and remote workers buy off the shelf, including MikroTik, TP-Link, and Ubiquiti EdgeRouters, and using them to steal Microsoft 365 logins in transit. They even hide their commands inside normal cloud services so nothing looks suspicious. At its peak, researchers counted more than 18,000 infected connections across 120 countries. The scariest part: they steal the login token, allowing them to bypass multi-factor authentication and remain logged in even after the password is changed. Three stories. One thread. A government order, a billion-dollar scam ring, and a foreign intelligence unit all reached into technology many organizations assumed they controlled. In this episode, we discuss: • Why the government forced Anthropic to pull its newest AI models and what it means for your business • How an AI-powered crime ring scammed people out of an estimated $1.9 billion • Why the router in your closet might be working for Russian intelligence • How "restrict some" quietly becomes "shut it all off" • Why stolen login tokens can bypass your multi-factor authentication • What concentration risk means when you bet your operation on a single vendor • The Monday-morning moves that actually protect your business Security Squawk is a weekly podcast and livestream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Anthropic #AI #FBI #Phishing #Smishing #FancyBear #VendorRisk #BusinessRisk #SMB #MFA

Your dental plan just became your biggest security problem. DentaQuest — one of the largest dental-benefits companies in America — had the personal and health data of 2.6 million people dumped online, and almost none of those people ever chose to do business with them. If you think your own company is too careful for this, the newest numbers say otherwise. *Confidence you can't prove is just exposure wearing a smile.* Bryan Hornung and Randy Bryan break down this week's stories — for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. (Reginald Andre is out this week — back next episode.) First up: the DentaQuest breach. The extortion crew ShinyHunters stole 234 gigabytes of data, tried to shake DentaQuest down for a ransom, and when the company didn't pay, they dumped the whole thing on a leak site. Inside that pile: names, birthdates, phone numbers, Medicaid IDs, and health-insurance details on 2.6 million people. The detail that should make you angry — researchers found roughly 1.7 million Social Security numbers in a separate folder, and a large share of them appear to belong to children. A stolen kid's SSN is gold to a fraudster, because nobody checks a nine-year-old's credit for ten years. And here's the part every business owner needs to hear: most victims never picked DentaQuest at all — their employer or their state Medicaid program did. Somebody else's vendor became your breach. Then we close on the mirror. A brand-new survey of 4,400 small and mid-size businesses found that owners have never felt more secure — 68% are confident they can stop an attack, and 75% trust they can respond. The problem? 45% of them got breached in the last year anyway. The number that stops you cold: among businesses hit more than once, confidence actually went UP — to 91% in the U.S. Meanwhile two-thirds still don't turn on multi-factor authentication, and only about 17% encrypt their data — the cheap, boring controls that stop most attacks. The average breach at a company under 500 people now runs about $3.31 million. Owners are scared of sci-fi AI malware while the rip current — phishing, weak passwords, no monitoring — is the thing actually pulling them under. Two stories, one crack running through both: somebody assumed they were covered, and the assumption was the vulnerability. The fix isn't more fear or more confidence — it's proof. In this episode, we discuss: • How 2.6 million people got exposed by a company most of them never chose. • Why ShinyHunters' "pay-or-we-leak" model makes your backups useless. • Why a stolen child's Social Security number is worth more than yours. • How small businesses can feel 68% confident and still get breached 45% of the time. • Why getting hit twice somehow makes owners MORE confident — and why that's backwards. • The two cheap controls two-thirds of businesses still skip. • How to replace "I feel secure" with proof you can actually show. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk

Three breaches. No malware. No zero-days. Just trust being exploited. This week on Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity incidents that reveal a growing reality: attackers are increasingly targeting people, vendors, and physical access instead of technology. NYC Health + Hospitals disclosed a breach affecting 1.8 million individuals after a third-party vendor compromise exposed sensitive patient information, including fingerprints. Carnival Corporation confirmed a cyberattack impacting nearly 6 million people after attackers used social engineering to gain access through an employee account. Meanwhile, the FBI is warning law firms about criminals posing as IT personnel, physically entering offices, deploying malicious USB devices, and stealing privileged client data. These attacks didn't begin with sophisticated malware or advanced exploits. They succeeded because trust was exploited. In this episode, we discuss: • The growing risk of third-party vendor breaches • Why biometric data theft creates permanent consequences • How social engineering continues to defeat security controls • The resurgence of physical intrusion attacks • What CEOs, business owners, IT leaders, and MSPs should be evaluating right now • Why many organizations may be defending the wrong attack surface If your cybersecurity strategy focuses only on networks, endpoints, and firewalls, this episode will challenge some assumptions. Support the show: https://buymeacoffee.com/securitysquawk Subscribe for weekly executive-level cybersecurity analysis focused on business impact, operational risk, and real-world consequences. #CyberSecurity #DataBreach #Carnival #NYCHealthAndHospitals #SocialEngineering #VendorRisk #LawFirmSecurity #CyberAttack #InformationSecurity #MSP #BusinessRisk #SecuritySquawk

This Week's Cybersecurity Breakdown 1. CISA Shrinks While the FBI Expands Its Cyber Role The federal cyber response structure is changing in real time: CISA reportedly lost over 1,000 employees Proposed federal budget would cut another $707 million FBI IC3 received 1 million cybercrime complaints in 2025 Reported financial losses climbed to $20.9 billion Raises major questions about how businesses should think about federal cyber support going forward 2. DocketWise Breach Exposes Sensitive Immigration Data A breach at an immigration legal platform continues to grow: Attackers used valid credentials to clone a developer pipeline Victim count increased from 116,000 to more than 143,000 individuals Exposed data includes: Social Security numbers passport data tax IDs medical history Another example of trusted access becoming the attack surface 3. 7-Eleven Confirms ShinyHunters Breach The ongoing Salesforce-linked extortion campaign continues: 185,000 franchise applicants exposed 7-Eleven reportedly refused ransom demands Attackers released a 9.4 GB archive publicly Campaign has now impacted organizations including: Google Cisco Qantas Allianz Adidas TransUnion LVMH The Bottom Line The cybersecurity assumptions businesses relied on even 18 months ago are changing. Federal cyber resources are shifting Trusted vendors continue getting breached Attackers are increasingly using legitimate access instead of sophisticated exploits And many organizations are still operating under incident response plans built for a threat landscape that no longer exists. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, cybercrime, vendor risk, and executive-level cybersecurity strategy.

A poisoned software package compromised OpenAI employee devices before security teams could stop it. The company behind critical Ozempic injection components has been offline for weeks after a ransomware attack. And Change Healthcare is now facing another major lawsuit tied to the 2024 breach that crippled healthcare payments nationwide. Three stories. One message: Your business is now exposed to companies you don't control. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three cyber incidents that reveal how third-party trust has become one of the biggest operational risks in business today. This Week's Cybersecurity Breakdown 1. OpenAI, TanStack & the npm Supply Chain Worm A software supply chain attack spread through trusted developer ecosystems at massive speed: 42 npm packages poisoned in six minutes Malware stole GitHub tokens, AWS credentials, and CI/CD secrets OpenAI confirmed two employee devices were compromised ChatGPT Desktop, Codex App, Codex CLI, and Atlas certificates rotated Demonstrates how modern attacks now spread through trusted development infrastructure 2. West Pharmaceutical Ransomware Attack A cyberattack against a company most people have never heard of — but nearly everyone depends on: West Pharmaceutical components are used in roughly 43 billion injectable drug deliveries annually Includes Ozempic, Wegovy, insulin pens, vaccines, and hospital injectables Systems taken offline globally after ransomware deployment Manufacturing disruptions continue weeks later 3. Allied World v. Change Healthcare — The Financial Fallout Begins The legal consequences of the Change Healthcare breach are escalating: Cyber insurer Allied World filed suit seeking more than $1 million in damages Avesis operations were disrupted for roughly 90 days Root cause traced to a low-level Citrix account with no MFA Credentials were reportedly circulating on Telegram prior to the breach The Bottom Line The modern business attack surface is no longer just your company. It's: your software vendors your healthcare clearinghouses your package repositories your pharmaceutical suppliers Every trusted relationship is now a potential point of failure. And when those companies get breached, your business absorbs the consequences. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, supply chain attacks, AI threats, and executive-level cybersecurity strategy.

A cybersecurity line just got crossed. Google has now confirmed the first known case of hackers using artificial intelligence to build a working zero-day exploit that bypasses two-factor authentication. At the same time, Instructure the company behind Canvas, used by over 9,000 schools worldwide appears to have quietly paid a ransom after ShinyHunters stole 275 million student and teacher records and defaced hundreds of school login pages. And if you think these attacks are rare, new data from BlackFog says otherwise: 90% of ransomware attacks this quarter were never publicly disclosed. Most breaches never make headlines. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three stories that reveal where cybercrime is heading next and why most organizations are less prepared than they think. This Week's Cybersecurity Breakdown 1. Canvas / Instructure Data Breach & Apparent Ransom Payment One of the largest education-sector breaches in recent memory: 275 million records allegedly stolen 3.65 TB of data taken from roughly 8,800+ schools Harvard, Stanford, Columbia, Duke, UNC, and other institutions impacted ~330 Canvas login portals defaced with ransomware messages Instructure later announced it had “reached an agreement” with attackers 2. AI Builds the First Confirmed Zero-Day Exploit Google's Threat Intelligence Group confirmed a major escalation: AI used to create a working zero-day exploit Attack specifically targeted two-factor authentication protections Signals a shift in offensive cyber capabilities previously associated with nation-state actors AI is no longer just assisting attackers it's helping build the attacks themselves 3. BlackFog Q1 2026 Report The Hidden Ransomware Crisis The public only sees a fraction of what's happening: 2,160 undisclosed ransomware attacks vs. 264 disclosed Only 1 in 9 attacks becomes public Average ransom demands surpassed $1 million Data stolen in 96% of incidents before encryption Backups alone are no longer enough The Bottom Line Cybersecurity is entering a new phase. AI is accelerating offensive capabilities Ransomware groups are operating in the shadows And organizations are quietly paying attackers to keep breaches out of public view This isn't just a technology problem anymore. It's an operational reality every business leader needs to understand. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, cybercrime, AI threats, and executive-level cybersecurity strategy.

A major U.S. payment processor just got hit by ransomware, again. TSYS, one of the largest payment processors in the country, has been attacked by the Everest ransomware group for the second time in five years. Industry experts warned this was coming. It happened anyway. At the same time, ShinyHunters claims it stole 275 million records from Instructure, the company behind Canvas, the learning platform used by over 9,000 schools. Names, student IDs, and billions of private messages between students and teachers are now at risk. And in healthcare, regulators just fined four companies $1.165 million for ransomware-related failures, not because they were hacked, but because they ignored basic security requirements that have been in place since 2003. In one case, attackers sat inside a network for 16 months undetected. These aren't advanced attacks. These are failures to do the fundamentals. This Week's Cybersecurity Breakdown 1. TSYS Ransomware Attack (Everest Group) A repeat breach at a major payment processor: Systems encrypted and data exfiltrated Second major incident in five years Also impacts Fiserv Raises serious questions about systemic risk in payment infrastructure 2. Instructure / Canvas Data Breach (ShinyHunters) Massive education sector exposure: 275 million records allegedly stolen Student data, IDs, and private communications compromised Root cause: Salesforce misconfiguration Potential impact across 9,000+ schools 3. HHS HIPAA Fines for Ransomware Failures Regulatory enforcement is accelerating: $1.165 million in fines across four companies Failure to complete required security risk assessments One breach went undetected for 16 months OCR has now completed 19 ransomware investigations with the same pattern The Bottom Line These attacks aren't breaking through defenses. They're walking through doors that were never closed. Misconfigurations Missing risk assessments Known vulnerabilities left unpatched This isn't a technology problem. It's an execution problem. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware attacks, and executive-level security insights.

A new type of cyberattack is bypassing every security tool you've invested in — and it starts with a simple Microsoft Teams message. No malware. No exploit. No zero-day. Just someone pretending to be IT support. At the same time, new data shows 73% of ransomware attacks are now entering through VPNs, and small businesses are absorbing an average of $422,000 per incident. Meanwhile, KPMG just released its 8 cybersecurity priorities for 2026, sending a clear message to executives: the biggest risk isn't technology — it's leadership. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three critical developments every business leader needs to understand right now. This Week's Cybersecurity Breakdown 1. Microsoft Teams Hack (UNC6692 Attack Campaign) Hackers are impersonating IT support inside Microsoft Teams to gain access to enterprise environments. No software vulnerability exploited Targets C-suite and senior leadership (77% of victims) Uses legitimate platforms like AWS and Heroku to evade detection 2. VPNs Are Now the Front Door for Ransomware (At-Bay 2026 Report) New insurance data reveals a sharp increase in ransomware attacks targeting VPN infrastructure: 73% of attacks originate through VPNs 60% of victims had EDR deployed — and still got hit SonicWall vulnerabilities linked to a significant percentage of attacks Average loss: $422,000 for SMBs 3. KPMG's 8 Cybersecurity Priorities for 2026 A strategic warning for boards, CEOs, and executives: AI is now an attack surface Non-human identities (APIs, service accounts) are a major blind spot Supply chain attacks are becoming the primary entry point Cybersecurity is no longer an IT issue — it's a leadership responsibility The Bottom Line The biggest cybersecurity gap today isn't technical. It's leadership. You can't patch employee trust You can't rely on tools without oversight You can't delegate cyber risk and expect protection If you're running a business, this is required awareness. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware trends, and executive-level security insights.

The Everest ransomware group claims it has stolen 250,000+ Social Security Numbers and 3.4 million banking records from Frost Bank and Citizens Bank — and the leak countdown is already ticking. At the same time, ShinyHunters just executed coordinated attacks on Zara, Carnival, and 7-Eleven, while a Vercel breach tied to a compromised AI tool exposed how a single employee action can trigger a multi-million dollar data incident. This isn't theoretical cybersecurity risk — this is happening right now, and it directly impacts your business, your customers, and your exposure to AI-driven threats. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cyberattacks shaping the current threat landscape — and what leaders need to understand immediately. This Week's Cybersecurity Breakdown 1. ShinyHunters Cyberattacks (Zara, Carnival, 7-Eleven) One of the most aggressive data breach groups in the world targeted three global brands with a pay-or-leak ultimatum. Carnival: 8.7 million customer records stolen 7-Eleven: 600,000+ Salesforce records compromised Zara: breach originated through third-party vendor Anodot with cloud access 2. Everest Ransomware Attack (Frost Bank & Citizens Bank) A high-impact ransomware operation targeting major U.S. financial institutions: 380+ GB of stolen data posted to a dark web extortion site Includes SSNs, banking data, and unencrypted credit card numbers with CVVs Raises serious questions about data security standards in 2026 3. Vercel Data Breach via AI Tool (Context.ai) A textbook example of modern attack vectors: A single employee connected a compromised AI tool with “Allow All” permissions Attackers gained access to internal systems and are now selling the data for $2 million Highlights the growing risk of AI integrations in enterprise environments Why This Matters These incidents expose three critical realities: Third-party vendors are now primary attack surfaces Ransomware groups are escalating speed and scale AI tools are introducing new, poorly understood security risks If you run a business, manage IT, or rely on cloud platforms — this is required awareness. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware attacks, and security leadership insights.

A ransomware attack on one software vendor exposed 823,000 people's Social Security numbers and bank account data across 80 community banks — and those banks didn't find out for 74 days. That's just one of three stories on today's Security Squawk that show exactly how the vendor trust chain is failing businesses right now. Bryan, Randy, and Reginald break down: a brand-new extortion crew called UNC6783 that's been hitting "several dozen" high-value corporations — including an alleged Adobe breach of 13 million support tickets — by breaking into their outsourced call centers and help desks instead of the companies themselves. Then Microsoft's new research on the Medusa ransomware group (tracked as Storm-1175), which is exploiting zero-day vulnerabilities before patches even exist and can go from initial access to full ransomware deployment in under 24 hours. And finally, the full Marquis Software story: a fintech vendor breach that cascaded through 80 community banks, led to a ransom payment, and ended with Marquis suing their own firewall vendor SonicWall for gross negligence while defending 36+ consumer class action lawsuits. If you trust vendors with your customer data — and you do — this episode is about what happens when that trust gets broken.

Chinese state-linked hackers breached the FBI's own surveillance system — and they got in through a vendor. That's not a spy novel plot; that's a confirmed federal "major incident" declared at the highest severity level under FISMA, and it happened in 2024. That's just the opener. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre cover three stories that show exactly what happens when third-party risk, healthcare IT gaps, and a single phone call aren't taken seriously enough. SALT TYPHOON HACKS THE FBI — China's Salt Typhoon threat group targeted a vendor ISP with access to the FBI's court-authorized wiretap surveillance system. The breach was classified as a FISMA "major incident," the federal government's highest severity designation. BROCKTON HOSPITAL CYBERATTACK — April 6, 2026: ambulances diverted, chemo cancelled, pharmacies closed, staff on paper records. The same hospital was breached in 2021. Average healthcare ransomware recovery: $2.5M, 19 days, 33% increase in patient mortality. HIMS & HERS VISHING ATTACK — 2.5 million subscribers. $2.35 billion in revenue. Gone through one phone call. ShinyHunters used a single vishing call to steal an Okta SSO credential and access Zendesk support tickets. CA AG notified. Class action filed. Support the show: buymeacoffee.com/securitysquawk

A ransomware attack walked in through one email, sat silent for two days, then destroyed every computer in an Indiana sheriff's office — and the FBI is still investigating. That's just one of three cybersecurity stories that every business owner needs to hear this week. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre cover: CHUBB'S 2026 CYBER CLAIMS REPORT — The average cyber insurance claim for large businesses nearly DOUBLED in one year, jumping from $2.2 million to $4.4 million. That's a 586% increase since 2021. And with premiums projected to rise 15-20% in 2026, the cyber insurance market is about to get expensive — even for small and mid-size businesses. ALAMO HEIGHTS ISD CYBERATTACK — A San Antonio-area school district serving 5,400 students went completely offline. Wi-Fi down. Gmail down. Third-party forensic investigators brought in. 27 Texas school districts hit in two years — and $55 million in state grants existed to prevent this. Only one-third applied. JACKSON COUNTY SHERIFF'S OFFICE RANSOMWARE ATTACK — A dormant ransomware payload entered through a phishing email, waited 48 hours, then activated and spread across every connected system. "Anything that it touched, it corrupted so bad, it won't be able to be used again." The sex offender registry may be permanently lost. Support the show: buymeacoffee.com/securitysquawk

31% of businesses that had backup solutions still failed to restore their data during a ransomware attack according to At-Bay's analysis of 186 real insurance claims. And if you think your business is safe because someone "set up backups," you need to watch this. Meanwhile, there are 4.8 million unfilled cybersecurity jobs globally right now and 61% of midsize businesses have zero dedicated security staff on payroll. Bryan Hornung and Reginald Andre break down exactly how bad the staffing gap has gotten (ISC2's 2025 Cybersecurity Workforce Study shows the pipeline shrank from 31% growth in 2022 to just 12% in 2024), why your IT person is being set up to fail, and how much a single mid-level security analyst actually costs vs. what an MSSP can deliver at the same price. Then they go straight at the backup crisis: the 25-point confidence gap between what IT teams believe about recovery and what At-Bay, Sophos, and Spiceworks data actually show. Ransomware attackers are targeting your backup repositories first before they trigger the main attack. The average business is down 24 days after a ransomware hit, with average recovery costs of $1.53 million. For a business under 500 employees, that can be existential. This episode is for every business owner who has ever said "we have backups" or "IT handles security" and hasn't verified either of those statements. Support the show: buymeacoffee.com/securitysquawk

A ransomware negotiator at DigitalMint secretly ran the attacks he was being paid to stop and then negotiated ransoms on behalf of the companies he'd just hit. This week on Security Squawk, we break down $75 million in extorted ransoms, an Iranian hacker group that destroyed 80,000 Stryker devices in three hours without using any malware, and a new Ponemon Institute survey showing 77% of industrial companies got breached in the past year. DigitalMint: Angelo Martino, a ransomware negotiator at Chicago-based cybersecurity firm DigitalMint, has been charged with running at least 10 ransomware attacks using the BlackCat/ALPHV gang while simultaneously negotiating ransoms for his own victims. Five companies he attacked then hired DigitalMint and were assigned Martino as their negotiator. Ransoms totaled $75.25 million. Two co-conspirators, including another DigitalMint negotiator and an employee at rival firm Sygnia, already pleaded guilty in December. Stryker: On March 11, the Iran-linked hacktivist group Handala wiped approximately 80,000 employee devices at medical device giant Stryker using Microsoft Intune, the same device management tool your IT team uses every day. No malware. No ransomware. Just a compromised admin account and a "remote wipe" command. OT Security Survey: A new Ponemon Institute survey commissioned by Siemens Energy found 77% of organizations running operational technology factories, pipelines, utilities, industrial control systems were breached in the last 12 months. 41% of attacks go completely undetected. Recovery takes seven months on average. Support the show: buymeacoffee.com/securitysquawk

A hacker used an AI chatbot to break into 10 government agencies and steal records on 195 million people — without writing a single line of code. Meanwhile, Cognizant's TriZetto healthcare billing platform sat silently compromised for over a year while 3.4 million patients' data walked out the door. This week on Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down four stories that will change how you think about cybersecurity risk in 2026. COGNIZANT TRIZETTO + UMMC TriZetto Provider Solutions — a Cognizant company that processes medical billing for thousands of doctors and hospitals — was breached in November 2024. The company didn't discover it until November 2025. One full year. In that time, 3,433,965 patients had their Social Security numbers, Medicare IDs, birth dates, and health insurance details exposed. And in parallel: UMMC was hit by ransomware in February 2026 — shutting down all 35 of its statewide clinics for nine days, canceling surgeries, and sending doctors back to pen and paper. AKZONOBEL AkzoNobel — the $12 billion paint giant behind Dulux — confirmed that the Anubis ransomware gang stole 170GB of data from one of its U.S. sites. Passport scans, private emails, confidential client agreements. They called it "contained." The data is already public. AI AND THE MEXICO GOVERNMENT HACK Fewer than five people used Claude Code AI to breach 10 Mexican government agencies. 150 GB stolen. 195 million identities exposed. The AI initially said no. The attacker talked it into cooperating anyway. The cost of entry for a sophisticated cyberattack just became the price of an AI subscription. [00:00] Intro [02:30] Cognizant TriZetto: 3.4M Patients, 1 Year of Silence [11:00] UMMC: 9-Day Clinic Shutdown Update [15:30] AkzoNobel: "Contained" Means Nothing When the Data Is Already Gone [21:00] Claude Code and the Mexico Hack: AI Just Became a Weapon Anyone Can Afford [27:00] Wrap-Up Support the show: buymeacoffee.com/securitysquawk

This week's Security Squawk episode isn't about phishing. It's about structural weakness. Three separate incidents. Three different industries. One uncomfortable pattern: the systems organizations trust most are expanding risk quietly — and in some cases, architecturally. First, a lawsuit that should make every board member pay attention. Marquis Software Solutions, a fintech serving 74 U.S. banks, is suing SonicWall. The allegation centers on SonicWall's cloud backup system, where firewall configuration backups were allegedly accessible and contained credentials — including MFA scratch codes. Those backups were reportedly used to compromise Marquis, leading to a ransomware incident and downstream exposure. What began as a scoped 5% customer exposure was later reported as potentially impacting all customers. This is not a misconfigured endpoint. This is a control-plane failure. For CEOs, this reframes vendor risk. It's no longer a questionnaire exercise. It's a litigation vector. If a security provider's design exposes authentication artifacts, your internal diligence may not matter. The liability chain now includes vendors and MSPs in a very direct way. For IT Directors, the operational question is simple: what exactly is inside your firewall backups? Are reusable authentication artifacts stored? Who can access vendor-hosted exports? If attackers obtain your configuration backups, can they replay your defenses? For MSPs, the exposure is real. If you manage firewall exports or MFA deployments, you are part of the architecture. And potentially part of the courtroom. Then we shift to UFP Technologies, a medical device manufacturer. Intrusion detected. Billing and shipping label systems disrupted. Data stolen or destroyed. Insurance expected to offset financial impact. But this isn't primarily a data story. Attackers disrupted order-to-cash and fulfillment velocity. In healthcare supply chains, slowing billing and labeling can create immediate executive escalation without touching the factory floor. Modern ransomware groups increasingly target business process choke points — ERP, labeling, scheduling — because leverage doesn't require full encryption anymore. For CEOs, “no material impact expected” is accounting language. Customers measure impact in delayed shipments. For IT leaders, the question becomes operational: can billing, labeling, and fulfillment functions recover independently? Are those systems segmented? Tested? Immutable? For risk managers and insurers, this represents a shift in underwriting focus — from endpoints to process resilience. Finally, the University of Hawaiʻi Cancer Center ransomware incident. Roughly 87,000 study participants directly impacted. But historical datasets, including Social Security numbers collected from driver's license and voter registration data dating back to 1998, expanded potential exposure to nearly 1.2 million individuals. They engaged the threat actors. They received a decryptor. They received “assurances” that data was destroyed. That's not verification. That's negotiation. The uncomfortable truth: legacy identity data becomes modern ransom currency. Research environments often have weaker governance than clinical systems, yet they can contain decades of sensitive identifiers. For boards, the issue isn't just security posture. It's data retention discipline. What obsolete identity data are you still holding? Why? For how long? And who owns the risk? Across these stories, three themes emerge: Control-plane trust is fragile. Operational choke points are the new leverage strategy. Data retention is compounded liability. Cybersecurity is no longer just about stopping intrusion. It's about architectural accountability and governance maturity. If you value independent, executive-level analysis without vendor spin, support the show at: buymeacoffee.com/securitysquawk The real question is this: Are your greatest cyber risks coming from external attackers — or from design decisions you haven't revisited in years?

Hospital Shutdown, Ransomware Surge, Fortinet Failures A hospital doesn't cancel chemotherapy appointments because of a “technical issue.” They cancel them because they've lost operational control. This week, the University of Mississippi Medical Center shut down its entire network after a ransomware attack disrupted systems — including Epic. Clinics closed. Elective procedures paused. Outpatient services halted. Emergency operations activated. Leadership described the shutdown as precautionary. But here's the real question executives should be asking: Why was a full network shutdown necessary? If segmentation is validated… If identity governance is enforced… If lateral movement detection is operationalized… Why does the only safe option become “turn it all off”? In this episode of Security Squawk, we break down what this incident signals about containment confidence, governance maturity, and operational resilience — not just in healthcare, but across every industry that depends on uptime. And we zoom out. Because UMMC isn't happening in isolation. According to TechRadar, ransomware groups have reached an all-time high in 2025. The victim growth rate has doubled. Qilin and other affiliate-driven operators are scaling aggressively. This isn't random chaos. It's industrialization. More fragmentation. More specialization. More execution discipline on the criminal side. Healthcare, public sector, and critical infrastructure are being economically targeted because downtime equals leverage. When systems go dark, negotiation pressure spikes. Then we connect it to something many leaders are still underestimating: Fortinet exploitation patterns. Edge vulnerabilities. VPN credential harvesting. Reinfection cycles months after patches were released. The vulnerability itself isn't the story. The response maturity is. Attackers are repeatedly probing whether organizations: – Patch fast enough – Rotate exposed credentials – Reset trust boundaries after compromise – Validate segmentation integrity – Rebuild identity confidence When those governance steps are skipped, attackers come back. That's not a tooling failure. That's a leadership failure. This episode translates three headlines into one hard truth: Ransomware is no longer just a malware problem. It's a containment confidence problem. For CEOs: If you cannot isolate an intrusion without shutting down revenue operations, your resilience model is fragile. For IT Directors: Active Directory recovery is not a restore-from-backup event. It's a trust re-establishment event. For MSPs: Client environments are operating in a denser criminal ecosystem. Tool stacking without maturity validation will not scale. For Risk Leaders: Financial exposure is no longer limited to ransom. Revenue interruption, regulatory scrutiny, and reputational damage compound quickly — especially in healthcare. We also discuss: • Why attacker communication often signals a second phase • Why affiliate ransomware models are accelerating • Why segmentation validation will become a board-level metric • Why detection speed does not equal governance strength Security Squawk exists to translate cybersecurity chaos into business reality — without vendor spin and without hype. If you value that kind of analysis and want to support independent, executive-focused cybersecurity conversations, you can back the show at: buymeacoffee.com/securitysquawk Your support helps us keep this live, timely, and unfiltered. Because criminals are already running maturity audits. And they invoice in operational shutdown. The question is simple: If it happened to you tomorrow, could you contain it — or would you turn the lights off?

Google has confirmed that state-backed threat actors are operationally using Gemini across the intrusion lifecycle — not experimentally, but strategically. In this episode of Security Squawk, we break down how AI is being integrated into reconnaissance, phishing refinement, vulnerability research, and even dynamic malware generation. According to Google's Threat Intelligence Group, multiple clusters — including DPRK-linked actors — are using Gemini to synthesize OSINT, map organizational structures, refine recruiter impersonation campaigns, and research exploit paths. In one case, malware known as HONESTCUE leveraged Gemini's API to dynamically generate C# code for stage-two payload behavior, compile it in memory using legitimate .NET tooling, and execute filelessly. This isn't a zero-day story. It's a friction story. At the same time, two individuals in Connecticut were charged for allegedly using thousands of stolen identities to exploit FanDuel's onboarding and promotional systems. No exotic exploit. No advanced intrusion chain. Just automated workflow abuse at scale. The pattern is clear: AI is compressing attacker timelines, and identity-driven fraud is industrializing predictable processes. We examine: How AI-enhanced phishing eliminates traditional grammar-based red flags Why trusted SaaS domains (Gemini share links, Discord CDNs, Cloudflare fronting, Supabase backends) are weakening reputation-based defenses What model distillation attempts (100,000+ structured prompts) signal about API abuse and intellectual property risk How fileless malware compiled with legitimate developer tooling challenges signature-based detection Why onboarding workflows and recruiting processes are now primary attack surfaces For CEOs, this is about erosion of trust anchors and shifting insurability expectations. For IT Directors and SOC leaders, this means reevaluating fileless execution visibility, API anomaly detection, and the reliability of reputation filtering models. For MSPs and risk managers, breaches will increasingly originate from workflow exploitation rather than perimeter misconfiguration. AI didn't invent new attack types. It removed friction from existing ones. And when friction disappears, scale compounds. If your recruiting, onboarding, verification, or AI product interfaces can be scripted — they can be weaponized. This episode is about operational clarity in a rapidly compressing threat landscape. Keywords: Google Gemini, HONESTCUE malware, AI phishing, state-backed threat actors, DPRK cyber operations, model distillation attacks, API abuse detection, fileless malware, .NET in-memory compilation, identity fraud, FanDuel fraud case, workflow exploitation, SaaS infrastructure abuse, Cloudflare phishing, Discord CDN payloads, Supabase backend abuse. Support the show https://buymeacoffee.com/securitysquawk

In this episode of Security Squawk, Bryan Hornung, Reginald Ande, & Randy Bryan break down three stories that should change how executives think about cyber risk. This is not about tools, alerts, or vendor promises. It is about operational dependency, leadership accountability, and financial exposure when systems fail. Story one focuses on active exploitation of SolarWinds Web Help Desk vulnerabilities being used as an entry point for ransomware staging. Researchers are seeing attackers move fast after initial access, blending in by using legitimate remote management and incident response tools. That is the point. When attackers use normal looking admin utilities, many organizations do not detect the intrusion until the business impact is already locked in. If you run Web Help Desk or you have not verified your patch posture, this is a governance issue, not an IT debate. Patch timelines and exposure management are leadership decisions because they directly affect business interruption risk. Story two is a warning about the ransomware market adapting. As more organizations refuse to pay for data theft only extortion, threat actors are expected to pivot back toward encryption. Encryption creates urgency because it disrupts operations. The financial exposure shifts toward downtime, recovery labor, lost revenue, and customer churn. Executives should treat restore capability like a business continuity requirement. If your recovery plan has not been tested under pressure, it is not a plan. Story three covers the BridgePay ransomware incident and the downstream impact on merchants and local government services. Even when payment card data is not confirmed compromised, availability failures still create real harm. Customers do not care which vendor was hit. They only see that your business cannot process transactions. This is a clear reminder to revisit vendor criticality, SLAs, outage communications, and contingency processing options. Security Squawk is built for business owners, executives, board members, and IT leaders who want the real world impact without the fear marketing. Subscribe, share, and support the show at https://buymeacoffee.com/securitysquawk

Cyber risk is escalating fast, and most business leaders are still operating with outdated assumptions. This episode of Security Squawk confronts that reality head on. Ransomware is no longer limited to encrypted files and downtime calculations. Threat actors are escalating pressure tactics into the physical world, including intimidation and direct threats against employees and executives. That shift fundamentally changes the risk profile for organizations. Once physical safety enters the equation, cybersecurity stops being a technical issue and becomes a leadership, legal, and duty of care problem. Companies that are unprepared for this escalation expose themselves to serious liability, regulatory scrutiny, and reputational damage that insurance alone cannot fix. At the same time, businesses are quietly introducing new risks through personal AI agents and automation tools. These tools are often adopted without security review, legal oversight, or compliance consideration. Marketed as productivity enhancers, personal AI agents frequently operate with broad access to email, files, customer data, and internal systems. When these agents mishandle or leak data, responsibility does not fall on the software vendor or the employee experimenting with automation. It falls squarely on the business. Regulators, insurers, and courts do not accept ignorance or convenience as a defense. We also examine why extortion groups like ShinyHunters continue to succeed even as companies invest heavily in security controls. This is not about sophisticated hacking techniques. It is about business pressure. Attackers understand deadlines, brand risk, customer trust, and executive fear. They exploit supply chains, third party vendors, and disclosure obligations to force decisions under time constraints. Paying extortion may feel like resolution, but it often increases long term risk, invites repeat targeting, and complicates regulatory reporting. Throughout this episode, the focus is not on tools, vendors, or technical jargon. It is on decision making. Who owns cyber risk inside the organization? How prepared is leadership to respond when incidents move beyond IT into legal, HR, and physical security territory? And how does a board defend its actions when regulators or plaintiffs start asking questions after an incident? This conversation is designed for CEOs, business owners, board members, and senior leaders who understand that cybersecurity is inseparable from operational risk, financial exposure, and executive accountability. If your strategy relies on cyber insurance, compliance checklists, or the belief that serious incidents only happen to larger companies, this episode will challenge that thinking. Security Squawk cuts through vendor noise and fear driven messaging to focus on what actually matters to businesses making real decisions. Support the show at https://buymeacoffee.com/securitysquawk

This episode of Security Squawk breaks down a familiar and dangerous pattern in cybersecurity. Major brands are losing data. Attackers are moving fast. And companies are still relying on silence and delay as a response strategy. We cover hackers auctioning stolen source code from a major retailer, an unprotected database exposing millions of Gmail and Instagram records, ransomware claims involving Nike and Under Armour, and a gas station breach that exposed Social Security numbers. This is not about advanced hacking techniques or rare exploits. It is about basic security failures, weak response decisions, and the real business impact of hesitation after data exposure. If you are a business owner, executive, or IT leader, this episode explains why modern breaches cause damage long before confirmation and why waiting to respond often shifts risk onto customers and employees

Cybersecurity failures are no longer just IT problems. They are legal, financial, and leadership failures. In this episode of Security Squawk, we break down how a ransomware attack on Ireland's Office of the Ombudsman delayed justice for citizens and what that incident reveals about preparedness, accountability, and real-world consequences of cyber risk. We start with the Ireland cyberattack that forced a key public watchdog agency to halt case processing for months. This was not a minor disruption. Systems were taken offline, legal action was required to prevent potential data leaks, and people relying on the system became collateral damage. The story highlights a hard truth. When cybersecurity fails, mission failure follows. Government or private sector, the outcome is the same. From there, we zoom out to the private sector where the warning signs are flashing red. New survey data shows cybersecurity litigation risk is rising faster than any other legal exposure for U.S. businesses. Corporate legal teams expect cyber and data privacy disputes to intensify, yet fewer of them feel prepared compared to last year. That gap tells us everything we need to know. Companies understand the risk is growing, but they are not investing or aligning fast enough to reduce it. We also examine the dangerous confidence gap in middle market firms. Nearly one in five experienced a cyber incident, yet almost all executives still believe their security posture is strong. Confidence without controls is not resilience. It is exposure. This disconnect raises serious questions about leadership accountability and how security decisions are being made at the executive level. The episode also dives into research showing that many top U.S. companies still fail basic cybersecurity hygiene. Reused passwords, outdated software, poor configuration, and unpatched systems remain common in 2025. These are not advanced threats. These are fundamentals. When organizations cannot execute the basics, the issue is not technical skill. It is culture, discipline, and leadership priority. We discuss the ongoing wave of data breaches affecting insurance, healthcare, and business services organizations, exposing millions of records. These incidents are proof that many companies remain reactive instead of proactive. Third-party risk, weak internal controls, and poor governance continue to amplify the damage. Finally, we tackle a growing blind spot. AI security governance. As businesses rapidly adopt AI tools, many still lack formal rules, oversight, or risk frameworks. Without governance, innovation turns into liability. Attackers move faster than policy, and organizations are left exposed. This episode is a wake-up call for business leaders, MSPs, IT professionals, and security decision-makers. Cybersecurity is no longer about compliance checklists or technology spend. It is about reducing real risk, protecting trust, and leading responsibly. If you want to understand why cyberattacks now lead to lawsuits, why confidence is not the same as security, and why leadership decisions matter more than ever, this episode delivers the insight you need. Subscribe, follow, and share Security Squawk. And if you want to support the show, you can always buy me a coffee at buymeacoffee.com/securitysquawk.

Today on Security Squawk we are breaking down three different incidents that all point to the same underlying issue. Basic security failures with real consequences. An Oregon state agency exposes personal information tied to environmental complaints. Nissan suffers a ransomware incident that leaks nearly 900 gigabytes of internal data. And an Illinois government agency exposes sensitive information connected to more than 700,000 individuals. Randy Bryan, Reginald Andre, and Bryan Hornung walk through what actually happened, why these incidents keep repeating across industries, and what they mean for businesses that assume they are too small or too quiet to be targeted. If government agencies and global manufacturers are struggling with access control, monitoring, and accountability, the real question is what that means for your organization. Join us live to understand the risks and what to do next. Join Randy Bryan, Reginald Andre, and Bryan Hornung live and be part of the conversation.

University of Phoenix confirms a massive data breach affecting almost 3.5 million current and former students, staff, and partners after attackers exploited a zero-day in Oracle E-Business Suite. We break down the implications for identity theft risk and breach response. Next, Andre explains why most existing medical devices would fail the FDA's new cybersecurity standards and how healthcare organizations can manage legacy device risk in critical environments. Finally, Bryan breaks down a cloud breach spree that hit 50 global organizations because multi-factor authentication wasn't enforced. Learn why MFA is no longer optional and how basic security failures lead to major breaches. Tune in for expert insights, practical advice, and what every IT leader needs to know today.

In this annual Security Squawk tradition, we do two things most people avoid: accountability and predictions. First, we break down the top cyber-attacks of 2025 and translate them into what actually matters for business owners, IT pros, and MSPs. Then we grade our predictions from last year using real outcomes. No excuses. No hand waving. No “well technically.” Why does this episode matter? Because 2025 made one thing painfully clear. Most cyber damage does not come from genius hackers. It comes from predictable failures. Unpatched systems. Over-trusted third parties. Tokens and sessions that live too long. Help desks that can be socially engineered. And organizations that still treat cybersecurity like an IT issue instead of a business survival issue. We start with the Top 10 Cyber-Attacks of 2025 and pull out the patterns hiding behind the headlines. This year's list includes ransomware and extortion campaigns, software supply chain failures, identity and OAuth token abuse, and attacks that caused real operational disruption, not just data exposure. These stories show how attackers scale impact by targeting widely deployed platforms and trusted business tools, then turning that access into downtime, data theft, and brand damage. One of the biggest lessons of 2025 is simple: identity is the new perimeter. Many of the most important incidents were not break-in stories. They were log-in stories. Stolen sessions and OAuth tokens keep working because they let attackers bypass MFA, move quickly, and blend in as legitimate users. If your security strategy is focused only on blocking failed logins, you are watching the wrong signal. 2025 also reinforced how fragile third-party trust has become. Integrations are everywhere. They make businesses faster and more efficient, but they also expand the blast radius. When a third-party tool or service account is compromised, it can become a shortcut into systems that were never directly attacked. In this episode, we talk about practical steps like minimizing access scopes, eliminating unnecessary integrations, shortening token lifetimes, and having a real plan to revoke access when something looks off. We also dig into why on-prem enterprise tools continue to get hammered. Many organizations still run internet-facing platforms that are patched slowly and monitored poorly. Attackers love that combination. In 2025, we saw repeated exploitation of high-value enterprise software where a single weakness led to widespread compromise across industries. If your patching strategy is “we will get to it,” attackers already have. Another major theme this year was operational disruption. Some of the costliest incidents were not just about stolen data. They shut down production, halted sales, broke customer service systems, and created ripple effects across supply chains. That is where executives feel cyber risk the hardest. Data loss hurts. Downtime is a business emergency. Then we grade last year's predictions. Did AI take our jobs? Not even close. What it did do was raise the baseline for both attackers and defenders. AI improved phishing quality, accelerated scams, and forced organizations to confront the risks of adopting new tools without clear controls. We also review our call on token and session-based attacks. That prediction aged well. Identity-layer abuse dominated 2025. The issue was not a lack of MFA. The issue was that attackers did not need to defeat MFA if they could steal what comes after it. We also revisit regulation. It did not arrive all at once. It crept forward. Agencies and lawmakers continued tightening expectations, especially in sectors that keep getting hit. Businesses that wait for mandates before improving controls will pay more later, either through recovery costs, insurance pressure, or lost trust. Finally, we look ahead to 2026 with new predictions that are probable, not obvious. We discuss what is likely to change around identity, help desk security, SaaS governance, and how leaders measure cyber readiness. The short version is this: 2026 will reward companies that treat access as a living system and punish those that treat it like a one-time setup. If you like the show, help us grow it. Subscribe, leave a review, and share this episode with someone who still thinks cybersecurity is just antivirus and a firewall. And if you want to support the podcast directly, buy me a coffee at buymeacoffee.com/securitysquawk.

Cyber attacks are no longer a future problem or a Silicon Valley issue. They are happening right now across the United States, quietly and relentlessly, targeting local governments, public agencies, schools, police departments, fire services, and critical infrastructure that most people rely on every day. In this episode of the Security Squawk Podcast, we break down the uncomfortable truth about the current cyber threat landscape and why much of it is flying under the radar. We start with a major data breach involving 700Credit, a financial services company widely used by car dealerships across the country. The breach impacted an estimated 5.8 million consumers, exposing sensitive personal information including names, addresses, birth dates, and Social Security numbers. What makes this incident especially troubling is that it originated through a third-party integration and went undetected until it was too late. This is a textbook example of how supply chain risk, weak API oversight, and poor third-party visibility continue to plague organizations of all sizes. For business owners, IT leaders, and managed service providers, this breach highlights a critical lesson. Security controls inside your own environment are meaningless if your partners, vendors, or integrations are not held to the same standard. Attackers know this, and they are exploiting it aggressively. Next, we shift to a growing and deeply concerning trend involving nation-state threat actors, particularly Russian-backed groups targeting network edge devices. Firewalls, VPN appliances, routers, and other edge infrastructure are now prime targets because they offer direct access to internal networks and often remain poorly monitored or improperly configured. These attacks are not always sophisticated zero-day exploits. In many cases, they succeed because of exposed management interfaces, outdated firmware, or weak credentials. This matters because edge devices sit at the front door of nearly every organization. Once compromised, they allow attackers to persist quietly, move laterally, and stage future attacks without triggering traditional endpoint defenses. The takeaway is clear. If you are not actively inventorying, patching, and monitoring your edge infrastructure, you are already behind. Then we pull the lens back even further and focus on what may be the most underreported cyber crisis happening today. Public sector organizations across the United States are under sustained cyber attack. Cities, towns, school districts, emergency services, and municipal agencies are being hit week after week. These incidents rarely make national headlines. Instead, they show up in small local news outlets, if they are reported at all. We discuss a real-world incident in Attleboro, Massachusetts, where a cybersecurity event disrupted online municipal services and briefly appeared on local television. Stories like this are happening everywhere. From ransomware attacks that shut down city services to breaches that expose resident data, public organizations are being targeted because attackers know they are often underfunded, understaffed, and slow to recover. Using data from ransomware.live and other tracking resources, we highlight how widespread these attacks really are. Thousands of U.S.-based victims are logged publicly, many of them tied to government or quasi-government entities. This is not random. It is a calculated strategy by cybercriminals who understand the pressure public agencies face to restore services quickly, often making them more likely to pay ransoms or quietly rebuild without public disclosure. Throughout the episode, we connect these stories to practical lessons for businesses, MSPs, and IT professionals. Cybersecurity is no longer about preventing every breach. It is about resilience, visibility, and response. It is about understanding where your real risk lies and taking proactive steps before an incident forces your hand. If you work in IT, run an MSP, manage infrastructure, or support public organizations, this episode delivers insight you can use immediately. We cut through the noise, skip the fear marketing, and focus on what actually matters in today's threat environment. Security Squawk exists to make cybersecurity real, relevant, and actionable. If this episode brings value to you, please subscribe, leave a review, and share it with someone who needs to hear it. And if you want to support the show directly, the easiest way is to buy us a coffee at https://buymeacoffee.com/securitysquawk Your support helps us keep producing honest conversations about the threats most people never see until it's too late.

This episode breaks down the true scale of the cybercrime economy. Randy covers the Marquis vendor breach that exposed data across more than 74 banks and credit unions and highlights the ongoing weakness in third-party risk. Andre examines the FinCEN report showing over 2 billion in ransomware payments last year and reveals how organized these criminal groups have become. Bryan closes with a deep dive into the US Treasury's decade long analysis of 4.5 billion in ransom payments, showing how ransomware has grown into an economy that rivals legitimate global businesses. This is essential insight for business leaders, MSPs, and IT professionals who want to understand what is really driving the surge in cybercrime.

This episode breaks down three major cybersecurity stories that reveal exactly where businesses are exposed and how fast the threat landscape is shifting. We analyze how a ransomware group hijacked an emergency alert system to trigger fake national warnings, why more than half of retailers are still paying ransoms despite stronger defenses, and what security leaders should expect heading into 2026. You will learn the real weaknesses behind these incidents, why attackers continue to outpace outdated systems, and how companies can strengthen their defenses now. This episode delivers practical insights, real world examples, and expert commentary that help MSPs, IT teams, and business leaders stay ahead of the next wave of cyber threats.

In this Security Squawk episode, Brian Horning from Xact IT is joined by guests to unpack three real ransomware incidents, the rapid rise of “The Gentlemen” gang, and how attackers bypass basic security by turning off tools like Windows Defender. You'll learn why relying only on built-in protections creates dangerous blind spots, what layered security with EDR, SOC monitoring, and log retention looks like, and the practical steps business leaders can take now to harden their defenses and reduce ransomware risk.

In this episode of Security Squawk, we dig into three major cyber incidents — the DoorDash data breach exposing users' contact info, the Logitech zero-day and data-theft campaign tied to Clop, and the ransomware attack on the Pennsylvania AG office. We break down how each attack played out, what it means for MSPs and business owners, and how you can protect your organisation when the threat spectrum keeps shifting.

In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity failures hitting government, media, and healthcare. We expose how a single employee action triggered a Nevada ransomware attack, why stolen Slack credentials led to a major Nikkei data leak, and how new NHS and Doctor Alliance breaches highlight the growing crisis in healthcare security. This episode is packed with insights for business leaders, MSPs, and IT pros who want to stay ahead of todays cyber threats. Listen to expert analysis, real world breakdowns, and practical steps to protect your organization from ransomware, credential theft, and supply chain attacks. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this week's episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity incidents that show how no industry is immune — from universities and government contractors to the British Library itself. We dig into a 1.2 million-record donor data breach, a ransomware-driven shutdown, and the growing supply-chain risk for MSPs and IT providers. Tune in for sharp analysis, real-world lessons, and actionable advice to protect your business from being the next victim. Cybersecurity podcast, data breach, ransomware, MSP, vendor risk, university breach, British Library, Conduent, IT security trends ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this week's Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three massive cybersecurity stories shaping 2025. Bryan kicks off with Qilin — the ransomware gang behind over 700 global attacks this year. Andre covers a New York city that paid a $150,000 ransom to restore operations after a crippling hit. And Randy unpacks a major ISP email breach in Australia that led to SIM-swaps and stolen data. Packed with sharp insights, humor, and practical advice, this episode is a must-listen for MSPs, IT pros, and business owners looking to stay ahead of 2025's top threats.In this week's Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three massive cybersecurity stories shaping 2025. Bryan kicks off with Qilin — the ransomware gang behind over 700 global attacks this year. Andre covers a New York city that paid a $150,000 ransom to restore operations after a crippling hit. And Randy unpacks a major ISP email breach in Australia that led to SIM-swaps and stolen data. Packed with sharp insights, humor, and practical advice, this episode is a must-listen for MSPs, IT pros, and business owners looking to stay ahead of 2025's top threats. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this week's episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre tackle three major cybersecurity stories that show how the digital landscape is shifting fast, and why business owners, IT pros, and MSPs can't afford to get complacent. Andre kicks things off with the end of an era: Microsoft has officially ended support for Windows 10, even though nearly 41% of Windows users are still running it. He breaks down what that means for everyday users, how the new Extended Security Updates (ESU) program works, and why delaying an upgrade could leave your business wide open to attacks. Next, Randy dives into a ransomware attack that hit a key platform in the $4.3 trillion municipal bond market, disrupting critical financial infrastructure and proving that ransomware isn't just targeting small towns and hospitals anymore. It's going after the systems that keep entire economies running. He explains what went wrong, how it connects to larger threat trends, and what public-sector organizations can learn from it. Then Bryan closes out the show by unpacking Microsoft's 2025 Digital Defense Report, which offers a massive view into the global threat landscape. Microsoft processes over 100 trillion security signals every day, and the report highlights what's working, what's failing, and where the next wave of cyber threats is coming from. Bryan shares key stats, actionable takeaways, and the five core principles Microsoft says every business should follow to defend against ransomware and identity-based attacks. Together, the team connects the dots between these stories, showing how legacy systems, financial vulnerabilities, and evolving threat tactics are all part of the same bigger picture. Expect smart insight, real-world examples, and a few sarcastic jabs along the way as they break down what these headlines mean for your business and your bottom line. Listen to learn: What Microsoft's end of Windows 10 support really means for security Why ransomware is now a systemic financial risk The most important lessons from Microsoft's new Digital Defense Report How to protect your business with resilience, not just reaction If you enjoy the show, hit subscribe, leave a review, and share it with your network. You can also support the podcast directly at buymeacoffee.com/securitysquawk, where every coffee helps us keep squawkin' about cybersecurity that actually matters. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity stories that show just how messy 2025 has become for data protection. Randy covers the WestJet breach that exposed more than 1.2 million customers, proving even major airlines can't keep turbulence out of their networks. Andre unpacks how the NSW government accidentally uploaded flood victims' personal data to ChatGPT, turning an AI experiment into a privacy nightmare. Bryan closes with new research showing ransomware attacks are climbing again just as fewer companies renew their cyber insurance — the perfect setup for costly business shutdowns. The team shares insights, lessons, and a few laughs as they explain what these stories mean for business owners, IT pros, and MSPs trying to stay ahead of the next big hit. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre dissect three headline-making cybersecurity incidents that highlight how threats keep evolving—just in different directions. Randy kicks things off with WestJet's massive data breach, where over 1.2 million customers had their information exposed, showing how even major airlines struggle with protecting sensitive data in 2025. Andre dives into a shocking story out of Australia—the NSW government accidentally uploading flood victims' personal data to ChatGPT, revealing how AI misuse and data mishandling can turn into a privacy nightmare overnight. Bryan closes with the latest findings showing ransomware attacks are rising again—just as fewer companies renew their cyber insurance policies, setting up the perfect storm for costly business disruptions. The team breaks down what these stories mean for business owners, from growing AI data risks to the real cost of skipping cybersecurity insurance. Expect practical takeaways, sharp insights, and a few laughs along the way as the guys decode what's really happening behind the headlines. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this episode of the Security Squawk Podcast, Bryan Hornung and Randy Bryan break down how ransomware keeps evolving and why businesses can't afford to let their guard down. Bryan covers three major stories: a ransomware attack on Volvo's supplier that exposed sensitive employee data, new research showing that 80% of ransomware victims get hit again, and how the Akira ransomware gang is flipping remote management tools against their victims. Randy dives into cyberattacks on global manufacturing, including production halts at Asahi and fallout from the Jaguar Land Rover ransomware incident. We'll unpack what these attacks mean for supply chains, IT teams, and everyday businesses—and why persistence is the new weapon of choice for cybercriminals. Tune in for sharp insights, real-world advice, and a little bit of sarcasm to keep it interesting. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this episode of Security Squawk, Bryan and Randy break down two major cyber stories with real-world lessons for IT leaders and MSPs. First, a FinWise Bank insider breach tied to American First Finance exposed data on nearly 689,000 customers—highlighting offboarding failures and insider risk. Then, a ransomware attack on U.S.-based Collins Aerospace disrupted airport check-in systems across Europe, forcing manual backups and long delays. We unpack what happened, why it matters, and the practical steps businesses can take to reduce insider and third-party risk. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this week's Security Squawk Podcast, Bryan Hornung and Randy Bryan break down two major cybersecurity threats making headlines. First, Bryan covers how artificial intelligence is already supercharging ransomware, making attacks faster, cheaper, and harder to stop. Then Randy dives into the massive ShinyHunters breach that leaked sensitive data from Vietnam's national credit bureau, putting millions at risk worldwide. Tune in for sharp insights, practical advice, and a dose of wit as we connect the dots for business owners, IT professionals, and MSPs. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

This week on Security Squawk, Bryan Hornung and Randy Bryan break down two hard-hitting cybersecurity stories. Jaguar Land Rover's production lines grind to a halt after a massive cyberattack, showing how ransomware directly disrupts global manufacturing. Meanwhile, CISOs face mounting pressure to stay silent about breaches, raising serious questions about transparency, accountability, and corporate risk. Tune in for sharp insights, real-world lessons, and a dose of wit as we unpack what these stories mean for businesses, IT pros, and MSPs. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

This week on Security Squawk, Randy and Bryan tackle two major cyber stories shaping 2025. First, Anthropic admits hackers are weaponizing its AI tools, giving cybercriminals a terrifying new advantage in building attacks faster than ever. Then, Bryan breaks down how Amazon disrupted a sophisticated campaign by Russia's APT29 (Cozy Bear), which abused Microsoft 365 device code authentication and cloud infrastructure to hijack accounts at scale. We explain how hackers are using AI to supercharge cybercrime, why APT29's tactics mark a dangerous evolution from past campaigns like SolarWinds and NotPetya, and what this means for businesses, IT professionals, and MSPs. Tune in for sharp insights, real-world examples, and practical takeaways to keep your defenses strong. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

While everyone obsesses over AI security, the old-school cyber threats are piling up. In this episode of the Security Squawk Podcast, hosts Bryan Hornung and Randy Bryan break down four major incidents that prove ransomware, breaches, and network shutdowns aren't going anywhere. We cover: Nevada state offices crippled by a major security incident Farmers Insurance data breach affecting over 1 million people Data I/O ransomware attack shutting down systems Nissan's design studio breach claimed by the Qilin ransomware gang Plus, we connect the dots to show why ransomware attacks have surged nearly threefold in 2024 — and what businesses need to do to avoid being the next headline. Stay sharp, stay informed, and don't let the AI hype distract you from the real threats hitting businesses every day. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this week's Security Squawk Podcast, hosts Bryan Hornung and Randy Bryan deliver an unfiltered breakdown of the week's most pressing cybersecurity headlines. We're talking about the Workday breach that exposed Salesforce customer data without a single file encrypted—just stolen credentials and surgical precision. Next up, we expose how Akira ransomware is turning cybercrime into marketing warfare, publicly naming and shaming victims in a bold bid to force ransom payouts. Finally, we tackle a brutal stat making waves across the industry: 25% of CISOs are replaced following a ransomware attack. If you're in cybersecurity leadership—or aiming to stay out of the headlines—this episode is your playbook for resilience. Packed with blunt analysis, leadership lessons, and real-world implications, this is one you'll want to share with your entire exec team. ☕ Like what you hear? Support the podcast: buymeacoffee.com/securitysquawk Workday breach, Salesforce breach, ransomware leak sites, Akira ransomware tactics, cybersecurity leadership, CISO turnover, cloud data security, Security Squawk Podcast ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

In this episode of Security Squawk Podcast, hosts Bryan Hornung, Randy Bryan, and Reginald Andre tackle major cybersecurity events impacting high-profile targets. First, luxury fashion giant Chanel falls victim to a devastating cyberattack, compromising customer data. Next, the city of St. Paul grapples with widespread tech disruptions linked to a cybersecurity incident, revealing municipal vulnerabilities. Finally, an urgent investigation into an SSL vulnerability by cybersecurity hardware provider SonicWall leaves businesses scrambling for protection. Learn critical security insights, risk management tips, and proactive steps to safeguard your business against evolving threats. Cybersecurity, Chanel cyberattack, St. Paul tech disruptions, SonicWall vulnerability, SSL security, data breach, municipal cybersecurity, Security Squawk Podcast. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...

This week on the Security Squawk Podcast, we're diving into three major cybersecurity incidents that highlight just how vulnerable even the most well-known organizations still are in 2025. First up, we cover the massive data breach at Co-op, where all 6.5 million members had their personal information stolen. That's right—every single member. We unpack what went wrong, how the breach was discovered, and the long-term fallout for one of the UK's largest retail cooperatives. Then, we turn our attention to the notorious Scattered Spider cybercrime group, which is back in the headlines after breaching major corporations like Clorox and Cognizant. And how did they get in? Not with some zero-day exploit or advanced malware—just simple, convincing phone calls. It's a wake-up call for any business that thinks cybersecurity is all about firewalls and antivirus. Finally, we bring it closer to home with a cyberattack that shut down systems in the Fort Smith Public School District in Arkansas. It's the latest in a growing trend of ransomware targeting schools and disrupting education. We explore what districts can do to prepare and why K–12 institutions remain such easy, high-impact targets for cybercriminals. If you're a business owner, IT professional, school administrator, or just someone who cares about protecting data, this is one episode you don't want to miss. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...