Podcasts about Attackers

  • 1,537PODCASTS
  • 3,112EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 16, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Attackers

Show all podcasts related to attackers

Latest podcast episodes about Attackers

Easy Prey
Ransomware Evolution

Easy Prey

Play Episode Listen Later Sep 16, 2026 40:32


Ransomware has changed dramatically over the years. What started as criminals locking up individual computers and demanding relatively small payments has grown into a much larger operation involving stolen data, entire networks, third-party vendors, and increasingly sophisticated ways of pressuring victims to pay. Now AI is adding another wrinkle, giving criminals new tools while also creating some unexpected problems for them. Joining me to talk about how ransomware has evolved is Allan Liska, a ransomware researcher and Field CISO at Recorded Future. Allan has more than 30 years of experience in information security and has spent the last 12 years researching ransomware. He has advised major corporations and government agencies, served on national ransomware task forces, and written extensively about ransomware and threat intelligence. We talk about how ransomware became the business it is today, why small businesses can be just as vulnerable as larger organizations, and how attackers are increasingly going after trusted vendors instead of their intended targets directly. We also discuss what happens inside an organization after an attack, why disrupting ransomware groups really can make a difference, how AI is being used by criminals, and some of the mistakes ransomware operators make that ultimately work against them. Show Notes: [01:06] Allan Liska introduces himself and shares how his work at FireEye led him to begin researching ransomware more than a decade ago. [03:10] Growing ransomware problems pushed Allan and other researchers to begin developing better detections for attacks that many security teams were overlooking. [05:22] Ransomware evolved from attacks on individual computers to taking down entire networks and later stealing data to pressure victims into paying. [06:30] Publicly naming victims gave ransomware groups their own form of publicity and made it much harder for organizations to quietly deny an attack. [08:05] Encryption creates technical challenges for criminals, and stealing valuable data can sometimes be just as effective as encrypting an organization's systems. [09:28] Attackers increasingly target vendors and partners, while some groups are now using AI to create fake stolen data and falsely claim organizations as victims. [13:05] Chris and Allan discuss how transparency and regular communication can help organizations manage public trust after a security incident. [14:35] Ransomware response can quickly lead to employee burnout, making outside coordination and basic needs like sleep, food, and scheduling an important part of incident management. [16:14] A major breach may temporarily open security budgets, so organizations should already know which improvements they would prioritize after an incident. [23:29] International law enforcement agencies have become increasingly creative about tracking ransomware operators and waiting for them to make mistakes. [25:48] Being skilled at hacking does not necessarily mean criminals are equally skilled at protecting their identities or activities from intelligence agencies. [28:21] Ransomware groups frequently make technical and strategic mistakes, including faulty AI-generated tools, reused encryption keys, and stealing data nobody considers valuable. [29:36] Fewer ransomware victims are paying, but average payments are increasing, and ransomware remains profitable enough to attract new threat actors. [33:09] Allan explains why simply banning ransom payments may not work and discusses approaches that could give governments better intelligence about where payments go. [39:33] Collaboration remains an important part of ransomware research, and Allan encourages people entering the field to learn from other researchers and security communities. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Allan Liska - SANS Books by Allan Liska Recorded Future Ransomware Live Europol Alerts CISA Alerts

Let's Know Things
AI Cyber Insurance

Let's Know Things

Play Episode Listen Later Sep 15, 2026 21:12


This week we talk about AI agents, cyberattacks, and insurance claims.We also discuss OpenAI, Hugging Face, and policy language.Recommended Book: The Stars My Destination by Alfred BesterTranscriptTwo broad categories of cyberattack have become especially visible this year, and only one of them requires a human attacker in the loop to choose the target.In March, hackers linked by the US government to Iranian intelligence broke into the medical-device manufacturer Stryker and remotely wiped tens of thousands of employee devices. The attack disrupted the company for days, affected its first-quarter earnings, and represented a shift from somewhat more subtle espionage toward more overt and deliberate destruction.Elsewhere, the market-research company Klue sat at the center of a breach affecting close to 200 customers. Attackers used an old credential to gain access to keys for customers' cloud services.These incidents had people with recognizable motives behind them, and that sort of hack has become increasingly rare over the past decade or so: Black Kite counted 7,551 publicly disclosed ransomware victims over its latest twelve-month reporting period, alone, about 25 percent more than the year before.Then, over the course of about five weeks this summer, OpenAI, Anthropic, and Meta each disclosed incidents in which their AI models gained access to real computer systems they were not supposed to touch.The incidents were not identical, and describing all of them as escapes wouldn't capture the important nuance of the situation.Anthropic and Meta said their models reached the internet because a third-party evaluation environment had been misconfigured. The models had been told they were operating inside a simulation, and their internal dialogues indicate they interpreted the real systems they encountered when they left that environment as simulated components of that exercise.OpenAI's incident, however, was a bit different.Its models were being tested using ExploitGym, a benchmark intended to measure their ability to find and exploit software vulnerabilities. Internet access was supposed to be blocked, but the models discovered and exploited vulnerabilities in a package-registry service inside OpenAI's research infrastructure, found a route to the open internet, and, as I related in a previous episode, eventually compromised the production systems of the AI platform Hugging Face.Since that episode, OpenAI has release a more complete postmortem, which they published in August, and which says the activity was primarily driven by an internal research model comparable in scale to GPT-5.6 Sol, though Sol participated in parts of the incident.The agents created an improvised message board inside the package manager, exchanged discoveries, divided up work, and sometimes described themselves as a swarm.At Hugging Face they executed code on dozens of servers, obtained broad access to several clusters, and exposed credentials associated with databases, cloud services, code repositories, and internal communications.Hugging Face reconstructed around 17,600 actions over a campaign lasting about four and a half days, including roughly two and a half days inside its own infrastructure.Notably, these AI agents were not trying to steal money or damage Hugging Face. They inferred that the company might possess the solutions to the benchmark, to the problem they were tasked with solving, and they went looking for them. They were, in effect, cheating on a test, looking for solutions to the problems rather than taking the test, as intended.That doesn't mean the models had motives in the human sense. People created the evaluation, reduced the normal safeguards, and assigned an offensive task. But no operator selected Hugging Face or directed the individual steps; that was a path the AI decided to take all by itself.Anthropic's review subsequently found three incidents among more than 141,000 evaluation runs for its own models. In one, a model unable to reach its fictional target scanned around 9,000 real ones, compromised an internet-facing application using an exposed password and SQL injection, then stopped after recognizing that the host was real.Another model published a malicious package to the real Python Package Index because it believed the registry was simulated. Fifteen outside systems downloaded and ran that malicious package before it was removed.Meta then disclosed that one of its models had reached the internet through a misconfiguration at the same evaluation vendor and exploited a vulnerability at an unnamed third party.No significant financial damages have been publicly reported from these events, by attacker or victim. But if there had been damages, who would have paid for them?What I'd like to talk about today is how autonomous AI systems complicate cyber insurance, how insurers have handled equally unfamiliar risks in the past, and why insurance contracts may soon become one of the more important forms of AI governance.—A typical cyber-insurance policy covers a broad portfolio of costs.These can include ransom payments, forensic investigations, legal expenses, restoring systems and data, notifying customers, and compensating victims and possibly a victims' customers for the revenue lost while a company's operations are interrupted.Business interruption is often one of the largest portions of a claim, and policies can respond to malicious attacks as well as non-malicious failures.This market grew by more than 30% a year between 2017 and 2022, as ransomware, a type of attack that became a lot more common during that period, in part because of increased automation and a franchising model that became really popular and increased the reach of the most powerful ransomware tools, almost broke this industry.In 2021, attacks on Colonial Pipeline, the insurer CNA, and meat processor JBS produced multimillion-dollar ransom payments and costly disruptions. Insurance prices surged, sometimes by more than 100%, while some companies found they could not obtain coverage because insurers just couldn't make the numbers work for them.Insurers responded to this more complex hacking environment by raising prices, but they also made coverage conditional on specific defenses. Companies increasingly had to demonstrate that they used multifactor authentication, endpoint monitoring, restricted administrator access, and backups that attackers could not alter, as a baseline.Loss ratios then fell, more insurance capital entered the market, and prices eventually came down again, stabilizing after that frantic and uncertain period.According to Marsh, global cyber-insurance rates fell 4% in the second quarter of 2026, the twelfth consecutive quarterly decline. Primary pricing is now about 42% below its 2022 peak.The market is not necessarily becoming safer, though. US cyber premiums reached about $7.5 billion in 2025, while the share of premiums consumed by claims rose to 53%—the first time it ticked above 50% since the pandemic-era ransomware surge.Globally, Munich Re estimates the market was worth nearly $15 billion last year and could approach $28 billion by 2030.During this period, insurance applications have also become a consequential part of a company's security system.In one particularly clear example, Travelers rescinded a million-dollar policy after a ransomware claim revealed that the customer's multifactor authentication protected only its firewall, despite application answers saying the control was used much more broadly.Companies that don't live up to cyber insurance expectations can thus be left in the lurch, so in a very real way, insurers have helped make multifactor authentication a standard business practice by attaching a price to its absence. This industry could move faster than regulators because they didn't have to ban insecure behavior and pass legislation to make that happen; they just had to decline to insure anyone who didn't live up to their basic security standards, which left those who failed to implement such precautions without insurance, should they be targeted by hackers.That same mechanism is now being aimed at AI agents, but the big initial problem everyone is facing is definitional.Most cyber policies are written around some identifiable security event: an outside attacker breaks in, an employee steals information, a credential is used without authorization, or malicious software takes a server offline.What if, though, a company gives an AI agent access to its network so that the agent can find and repair security vulnerabilities?And then maybe the agent discovers a vulnerability, exploits it, moves laterally into systems it was not expected to touch, and exposes sensitive data. There is a cyber loss, but there may be no conventional attacker and no stolen credential. The software was invited in and may have used permissions it was explicitly given. This is very different from a human-led hack, but it still has the potential to cause a lot of monetary damage.Insurers including MSIG, QBE, and Beazley are reviewing how their policy language applies to these scenarios and who bears responsibility when an agent's autonomous actions cause damage.For now, most of them are clarifying the parameters of their coverage rather than excluding AI events entirely.QBE's global head of cyber described AI as “a risk amplifier, not a fundamentally new cyber risk.” In other words, if an AI system causes something that looks like an ordinary covered breach, the involvement of AI probably won't put it in a different category; it'll still be covered.The trickier cases involve an agent that works as designed but makes an expensive decision, or a systemic event in which a model or AI platform produces losses at many companies simultaneously.The first type might be treated as professional liability, or errors and omissions, rather than a cyber incident. The second could, in theory at least, end up being too large for insurers to cover without strict limits in place.Specialized products are already emerging. Armilla AI, Munich Re, and AXA XL sell coverage for risks including model underperformance, hallucinations, and intellectual-property claims. Whether these products remain separate or are eventually folded into broad cyber policies will depend in part on what sorts of claims insurers actually receive, and the scale of those claims.Right now, they have very little historical data with which to calculate the price. Insurance is fundamentally a system for using past experience to account for future issues, and autonomous AI losses have almost no past; they're a very new type of problem.That said, the insurance industry has encountered ambiguity before.For years, insurers worried about silent cyber: losses caused by digital events that appeared inside property, liability, and other policies that had never explicitly contemplated them. Lloyd's gradually required policies to state whether cyber risks were covered or excluded.There was also the question of attribution. In 2017, the NotPetya malware spread from Ukraine through corporate networks around the world. The US and several allies attributed it to the Russian military, but many victims were ordinary companies with no meaningful role in geopolitics.Drugmaker Merck claimed about $1.4 billion in damages under its property policies. Insurers disputed roughly half of that amount using exclusions for hostile or warlike acts; language whose ancestry predates computers by more than a century.New Jersey courts found that the exclusion required something closer to conventional military action, not a cyber bug gone haywire, and the case settled in January of 2024, just before the state Supreme Court was scheduled to hear it. Mondelez settled a parallel dispute with Zurich over a claim exceeding $100 million around the same time.Lloyd's subsequently required standalone cyber policies to address catastrophic state-backed attacks explicitly, including a method for resolving attribution. Agentic AI reopens both the silent-coverage and attribution problems simultaneously.If a model causes a loss, responsibility might plausibly be assigned to the model developer, the company that deployed it, the vendor that built its evaluation environment, or the organization whose excessive permissions allowed the damage to spread.In two of this summer's three sets of incidents, a third-party evaluator's misconfiguration helped create the path to the internet. In OpenAI's case, the path involved vulnerabilities in OpenAI's own infrastructure and then weaknesses at several outside services.The most important insurance risk, though, may ultimately be technological and infrastructural aggregation.The 2024 CrowdStrike outage demonstrated that a single faulty software update could interrupt airlines, banks, hospitals, and other organizations around the world without any malicious attacker.Consider a future in which thousands of companies give access to agents built on a small number of frontier models. A flaw or unwanted behavior in one widely used model could cause problems for a large portion of an insurer's entire customer base, all at once.And this risk is arriving in the midst of an unusually competitive insurance market, after twelve quarters of declining rates and as loss ratios are beginning to rise. If insurers decide they cannot price the exposure, they will probably respond through some combination of higher prices, lower limits, stricter conditions, and exclusions.All that in mind, the first thing to be watching in the coming months is policy language during the January 2027 renewal season.The current posture, if you recall, is to clarify rather than exclude, but language addressing systemic AI events or dependence on a single model provider is already being discussed. A significant loss could change the market's posture quickly, making it more limited and expensive.The second thing to watch for is the first big, disputed claim.Industry interviews can describe what insurers expect to cover, but their operational position will be established when an AI agent causes an eight-figure loss and a carrier must either pay or explain why it won't.The NotPetya disputes took years to resolve, and the first autonomous-agent case could similarly define policy language well before it produces a final court ruling. That'll be a moment that maybe defines the next ten years of cyber insurance standards, if not longer.The third thing to watch for is changes to insurance questionnaires.Underwriters could begin asking whether agent credentials are narrowly scoped, whether actions are comprehensively logged, whether consequential decisions require human approval, whether agents have kill switches, and whether claimed containment has been verified rather than merely documented.If these controls affect the price and availability of insurance, they could become industry standards faster than legislation makes them mandatory, just like that previous round of cyber insurance baselines that became common because, lacking them, customers could no longer get cyber insurance at any price.And finally, there's also a government process developing alongside the private one.An executive order signed in June established a voluntary framework under which developers can provide the federal government with access to certain frontier models for up to 30 days before release. The process uses classified benchmarks to evaluate advanced cyber capabilities, and representatives from major AI companies discussed the framework at the White House in August of 2026.If insurers eventually require evidence that a model or company participated in this sort of evaluation, a voluntary government program could evolve into a practical requirement without ever becoming an actual legal mandate.This wouldn't make insurance a perfect regulator. Insurers are accountable to their own balance sheets, not to the public as a whole, and they may respond to poorly understood risks by excluding them rather than making them safer, as has been the case with some types of weather disaster in areas that are becoming more prone to things like flooding and wildfires.But insurance companies do have to convert uncertainty into prices, contractual language, and technical requirements, which makes some currently difficult to quantify things more quantifiable, at least monetarily.The AI incidents this summer caused no reported material damage, which is one reason they're getting relatively little coverage, despite being fairly meaningful events. The insurance industry sees these sorts of narratives through the lens of cost and risk, though, and this is a category of loss with no conventional attacker, no stolen credential, several plausible defendants, and almost no claims history, arriving at a moment in which companies are racing to give autonomous systems more access to all of their systems—a lot of valuable and potentially vulnerable infrastructure.The people whose job is to price that risk haven't decided what it costs, yet. And until they do, what they add to or remove from their application forms may be more consequential to the norms and expectations in this space than what the government mandates, on the matter.Show Noteshttps://www.businessinsurance.com/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies/https://www.investing.com/news/stock-market-news/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies-4878768https://openai.com/index/hugging-face-model-evaluation-security-incident/https://openai.com/index/hugging-face-incident-and-the-road-ahead/https://huggingface.co/blog/security-incident-july-2026https://huggingface.co/blog/agent-intrusion-technical-timelinehttps://www.anthropic.com/news/investigating-incidents-cybersecurity-evalshttps://cyberunit.com/insights/ai-sandbox-escapes-three-labs-meta-anthropic-openai/https://labs.cloudsecurityalliance.org/research/csa-research-note-frontier-ai-models-hacking-real-systems-ev/https://techcrunch.com/2026/07/07/the-worst-hacks-and-breaches-of-2026-so-far/https://blackkite.com/reports/2026-ransomware-reporthttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320ahttps://www.munichre.com/en/insights/cyber/cyber-insurance-risks-and-trends-2026.htmlhttps://www.swissre.com/risk-knowledge/advancing-societal-benefits-digitalisation/about-cyber-insurance-market.htmlhttps://www.marsh.com/en-gb/services/international-placement-services/insights/global-insurance-market-index.htmlhttps://compyl.com/guides/cyber-insurance-readiness-guide/https://www.aon.com/en/insights/articles/cyber-and-tech-e-and-o-market-reporthttps://www.cybersecuritydive.com/news/merck-settlement-notpetya-insurance/703922/https://therecord.media/mondelez-and-zurich-reach-settlement-in-notpetya-cyberattack-insurance-suithttps://assets.lloyds.com/media/eb6de9ce-293b-4213-80f8-9dc69c45b1a9/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdfhttps://www.whitehouse.gov/wp-content/uploads/2026/06/eo-14409.pdfhttps://www.axios.com/2026/08/04/inside-trump-ai-framework This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe

SECURE AF
How Defenders Can Secure Enterprise AI Before Attackers Find the Gaps

SECURE AF

Play Episode Listen Later Sep 11, 2026 54:36 Transcription Available


Got a question or comment? Message us here!In this episode, we explore the hidden risks of enterprise AI and the strategies organizations can use to close security gaps before attackers exploit them.#EnterpriseAI #Cybersecurity #AIGovernance #SecurityLeadershipSupport the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

The Cyber Threat Perspective
[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers

The Cyber Threat Perspective

Play Episode Listen Later Sep 11, 2026 31:02


Replay of Episode 178, originally published April 22, 2026.We are re-running this one because it is the question we get asked moston internal pen test debriefs: of everything on the list, what actuallyslows an attacker down? Spencer and Tyler answer it from the attackerside, using what has and has not stopped them on real engagements.What's covered:- Application control done right, including where ThreatLocker and WDAC  actually block a payload and where they get bypassed- MFA, the Protected Users group, and least privilege as attacker-facing  controls rather than compliance checkboxes- Why mismanaged admin privileges and service accounts remain the fastest  route from foothold to domain admin- Network segmentation and zero trust, and what separates a real  implementation from a diagram- Deception techniques and EDR baselining for catching activity that  looks legitimateIf you are deciding where the next dollar of your security budget goes,this is the episode that tells you what attackers hope you skip.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

HITTING THE TURNBUCKLE
The Attacker Strikes again!

HITTING THE TURNBUCKLE

Play Episode Listen Later Sep 11, 2026 21:53


Another Week Another Attack, Who could be responsible for attacking the roster?

RevMD
#211 $1.3 Million and 18 Days: What a Cyberattack Actually Costs an Independent Practice

RevMD

Play Episode Listen Later Sep 8, 2026 12:17 Transcription Available


Send us Fan MailResources Cybersecurity Incident Response Checklist: https://eligibility.natrevmd.com/natrevmd-cybersecurity-checklist natrevmd.com Trusted Resources: https://natrevmd.com/trusted-resources/ A healthcare record sells for 10 to 40 times more than a credit card number on criminal markets, and it cannot be cancelled the way a card can. Independent practices hold that data with the least defense in the entire healthcare system: one IT contractor, a server in a closet, and no one whose job it is to think about security. Attackers know it. Why independent practices are the target Three attack vectors specific to practice settings:  Phishing emails that look like they are from an EMR vendor, billing company, or payer. Remote access set up for telehealth or post-COVID flexibility that was never properly secured. Third-party vendor access, where a billing company or IT contractor gets breached and the practice is compromised through them. What to do in the first 24 hours if you are hit 1.  Isolate immediately. Disconnect affected systems from the network, but do not power them down, powered systems preserve evidence forensic teams need. 2.  Call your cyber insurance carrier first, then your attorney. Do not call the attackers, and do not pay anything without guidance. 3.  Document everything from the moment you discover the breach. This becomes the foundation of your HIPAA breach report if one is required, and the 60-day notification clock starts at discovery. 4.  Do not restore from backup until forensics has cleared the system. Restoring too early can reintroduce the attack. Three asks for your team this week Ask your IT contractor: do we have multi-factor authentication enabled on our EMR, our email, and our remote access tools? If not, when can you turn it on? Ask your IT contractor: when was the last time we tested a restore from our backup? Can you run a test this month? Call your business insurance broker: do we have cyber liability coverage? If not, what would it cost to add it? Episode breakdown Why independent practices are the target Three attack vectors specific to practice settings Five things most practices are not doing What to do in the first 24 hours if hit Three asks for your team this week 

TV4Nyheterna Radio
"Nya ryska attacker mot Kiev"

TV4Nyheterna Radio

Play Episode Listen Later Sep 8, 2026 1:26


The CyberWire
RMM-ber this ransomware. [Research Saturday]

The CyberWire

Play Episode Listen Later Sep 5, 2026 19:51


Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Research Saturday
RMM-ber this ransomware.

Research Saturday

Play Episode Listen Later Sep 5, 2026 19:51


Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

The CyberWire
What the Flock?

The CyberWire

Play Episode Listen Later Sep 4, 2026 31:55


The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House's offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.”  Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works. Selected Reading G7 urges organizations to prepare for quantum cyber threats (The Record) Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security) Communicating Under Pressure: Best Practices for Service Providers (IC3) OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine) 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek) Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer) VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek) Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer) Flock Cameras Face Removal Nationwide Under New Bill (Newsweek) Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register)  This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Telecom Reseller
GTIA: SMBs Are Taking a Slow-and-Steady Approach to AI Adoption, Podcast

Telecom Reseller

Play Episode Listen Later Sep 4, 2026 15:04


“The biggest misconception is that SMBs are not using AI or benefiting from it.” In this Technology Reseller News podcast, Sharon Florentine, Manager Research Analyst at GTIA, discusses new research showing that small and midsized businesses are already seeing meaningful benefits from AI—and creating a growing advisory opportunity for MSPs and IT service providers. GTIA, the Global Technology Industry Association, is a nonprofit membership organization serving IT service providers around the world. Its new research, End-User AI Adoption: How ITSP Customers Are Really Using AI, is based on responses from 520 SMB and microbusiness decision-makers. Florentine says the research challenges the idea that AI adoption is primarily an enterprise phenomenon. “The majority of SMBs are using AI, and they are seeing a lot of positive benefits from it,” she says. According to the study, 84 percent of respondents reported positive outcomes from AI. Businesses are using AI to improve productivity, move faster and support areas including marketing, sales, IT and security. Many are starting with tools already embedded in platforms such as Microsoft and Google, along with standalone services such as ChatGPT. Governance becomes the next priority As AI use expands, however, governance and cybersecurity are becoming increasingly important. Florentine says security risks were among the biggest concerns identified by respondents. Attackers are using AI to improve phishing and other threats, while defenders are using it for threat intelligence, vulnerability management and other security functions. “You cannot have AI without governance and cybersecurity,” Florentine says. That creates a significant opportunity for MSPs and ITSPs. Respondents specifically identified AI advisory services as something they would like from their technology providers. Those services could include identifying AI opportunities, evaluating risk, creating acceptable-use policies and helping customers expand successful AI projects. Florentine says the organizations seeing the greatest value tend to take a deliberate approach. They assign responsibility for AI to an executive, team or council, establish guidelines, monitor results and proactively address risks. For MSPs, one of the best places to begin may be their own AI journey. “Take your own experience and use that as an example for guidance,” Florentine says. “Show customers how you have solved problems using AI and help them do the same.” The broader message is that SMBs do not necessarily need to be convinced to use AI. Many are already there. What they increasingly need is trusted guidance on how to use it safely, strategically and at scale. GTIA members can access the full End-User AI Adoption research at GTIA.org.

Ekot
Ekot 16:45 Tysk oro för nya ryska attacker efter drönaren i Leipzig

Ekot

Play Episode Listen Later Sep 3, 2026 15:00


Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.

HLTH Matters
How AI Is Changing the Ransomware Threat in Healthcare

HLTH Matters

Play Episode Listen Later Sep 2, 2026 24:03


Ransomware remains one of the biggest cybersecurity threats facing healthcare, but the threat landscape is changing rapidly. Attackers are becoming more targeted, ransomware-as-a-service is making sophisticated tools more accessible, and artificial intelligence is giving cybercriminals new ways to identify vulnerabilities and craft convincing attacks. In this episode of The Beat's Cybersecurity at ViVE series, Sandy Vance speaks with Dave Bailey, VP of Consulting Solutions & Strategy at Clearwater, about the evolving ransomware threat and what healthcare organizations can do to stay ahead of it. Dave explains why smaller healthcare organizations and specialty practices are increasingly attractive targets, how attackers are using AI to improve social engineering and phishing, and why traditional cybersecurity approaches may not be fast enough for the threats ahead. The conversation also explores why healthcare organizations need to understand their AI risk, establish guardrails, inventory their AI use cases, and prepare defenses that can respond at machine speed. Dave shares practical advice for organizations beginning their AI journey, while emphasizing that cybersecurity can no longer be something organizations assess once a year. It has to become a continuously monitored, evolving process. In this episode, they talk about: Why healthcare continues to be one of the most attractive targets for ransomware How ransomware attacks have shifted toward smaller healthcare organizations and specialty practices Why dental practices and specialty providers can be particularly appealing targets How ransomware-as-a-service has created a more scalable business model for cybercriminals Why cybercriminals increasingly operate like businesses How attackers decide which healthcare organizations to target Why post-COVID healthcare's rapid shift to telehealth changed the threat landscape How AI is making phishing and social engineering attacks more sophisticated Why AI creates new governance and risk-management challenges for healthcare organizations Why healthcare organizations need defenses that can operate at machine speed How frontier AI models could help attackers discover previously unknown software vulnerabilities Why patching needs to become faster as AI-powered attacks evolve Why healthcare organizations need to challenge vendors about their cybersecurity roadmaps How organizations can begin building an AI governance strategy Why organizations should inventory their AI use cases before trying to govern them How healthcare organizations can use a tiered approach to AI risk Why workforce training and communication are essential to responsible AI adoption Why cybersecurity risk assessment can no longer be a once-a-year exercise Why scalability and continuous monitoring will become increasingly important A Little About Dave: Dave Bailey is Vice President of Consulting Solutions & Strategy at Clearwater, where he leads the development and delivery of enterprise-level cybersecurity and risk management services for healthcare organizations nationwide. With more than 24 years of cybersecurity experience, including 14 years focused on healthcare, Dave is a trusted advisor to executive teams navigating complex regulatory, operational, and cyber risk challenges. A recognized authority in cyber risk management and NIST Cybersecurity Framework assessment and implementation, Dave brings a strategic, business-aligned approach to security transformation. He previously served 13 years as a Communications and Information Officer in the United States Air Force, with leadership assignments spanning the Pentagon, domestic bases, and overseas operations. Dave holds an Executive MBA from Quantic School of Business and Technology and is a CISSP, blending executive perspective with deep technical expertise.

The CyberWire
Let's kill the kill switch.

The CyberWire

Play Episode Listen Later Aug 31, 2026 27:59


Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill. Selected Reading The AI Kill Switch Act is repeating the Clipper Chip's mistakes (CyberScoop) Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek) Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer) China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs) Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR) Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer) US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register) AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing) How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Chronicles of a Gooner | The Arsenal Podcast
Do Arsenal need another attacker? | De Zerbi attacks Spurs' mentality - Red Tinted Glasses

The Chronicles of a Gooner | The Arsenal Podcast

Play Episode Listen Later Aug 31, 2026 56:25


On this week's episode of Red Tinted Glasses, Harry Symeou is joined once again by the excellent Scott Saunders. The guys discuss whether or not Arsenal need another attacker before the window closes, Spurs' defeat to Newcastle, De Zerbi's comments regarding the team's mentality, Liverpool's early defensive struggles under Andoni Iraola, Chelsea's lack of balance, Bruno Fernandes and more. Subscribe to Scott's channel here: @tplmufc To sign up as a Patreon, get additional episodes, ad-free episodes and become a part of our discord server, click the link below: https://patreon.com/thechroniclesofagooner?utm_medium=unknown&utm_source=join_link&utm_campaign=creatorshare_creator&utm_content=copyLink Enter the discount code 'SUMMER' for 50% off your first month! Listen to 'The Rise of Pafos FC' on Apple podcasts or Spotify: https://podcasts.apple.com/us/podcast/the-rise-of-pafos-fc-with-harry-symeou/id1334407316?i=1000746012823 #arsenal #transfers #news Learn more about your ad choices. Visit podcastchoices.com/adchoices

Bear Attack
S8 E27: Revelations, Pastor Matt returns.

Bear Attack

Play Episode Listen Later Aug 31, 2026 54:44


Attackers, please welcome back Pastor Matt. This time he gets to have fun with Polar Bear.Eventually when Blitz returns to work we will complete the trinity (pun intended) and have Pastor Matt on with all three bears.

Ekot
Ekot 06:00 Nya attacker i Hormuzsundet

Ekot

Play Episode Listen Later Aug 31, 2026 15:00


Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.

Ekot
Ekot 12:30 Stor brist på viktiga basvaror i Ukraina efter ryska attacker

Ekot

Play Episode Listen Later Aug 31, 2026 25:00


Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.

Designing with Love
Game-Based Learning Can Make Security Training Stick With Lee Anderson

Designing with Love

Play Episode Listen Later Aug 30, 2026 28:28 Transcription Available


Your inbox is designed for speed. Attackers know it, and too many training programs pretend we're all making perfect choices with unlimited time and zero stress. Jackie had a great conversation with Lee Anderson, a cybersecurity professional with 16+ years of experience reducing human risk, to unpack what really drives security decisions and how better learning design can change behavior. We get into the psychology behind social engineering, including how urgency, fear, and even excitement can trigger an “amygdala hijack” that shuts down clear thinking. From there, we shift to what instructional designers, educators, and organizational leaders can do differently: use a human-centered approach, build learner personas, add brain breaks, and create training that respects the messy reality of people's lives. We also talk about ditching shame-based metrics and instead rewarding the behavior you actually want, like reporting suspicious messages. Lee shares the story behind Hack Attack: Defense, his card game that teaches cybersecurity concepts through play. It's a practical look at learning transfer: how a simple, engaging game plus well-timed reinforcement can move security from abstract rules to real habits at home and at work. We also explore how AI can help teams rewrite technical guidance into clearer, more personal messaging without adding hours to a busy schedule. If you want cybersecurity training that sticks, listen now, then subscribe, share this with a colleague, and leave a review so more learning designers can build safer, more human systems.

The CyberWire
Who let the AI hack? [Research Saturday]

The CyberWire

Play Episode Listen Later Aug 29, 2026 23:10


Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool. The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. The research and executive brief can be found here: LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

Research Saturday
Who let the AI hack?

Research Saturday

Play Episode Listen Later Aug 29, 2026 23:10


Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool. The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. The research and executive brief can be found here: LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

ITSPmagazine | Technology. Cybersecurity. Society
Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 27, 2026 17:16


Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access

Israel Daily News Podcast
Dolly Parton's Library Idea Reaches Israel & Israel Daily News; Thu. Aug 27, 2026

Israel Daily News Podcast

Play Episode Listen Later Aug 27, 2026 26:36


An IDF social media video appeared to advise ultra-Orthodox Israelis facing military draft enforcement on how to avoid arrest at Ben Gurion Airport — and it was quickly deleted. In this episode of Israel Daily News, Shanna Fuld breaks down the controversy surrounding the now-deleted IDF video ahead of the annual Rosh Hashanah pilgrimage to Uman, Ukraine. The video reportedly used an AI character called “Dudy the Explainer” to explain how draft evaders could avoid being detained at the airport. The controversy comes as Israel's long-running battle over Haredi military service intensifies and new legislation has left some pilgrimage-bound Israelis facing draft-evader status. Shanna also examines the growing security tensions in Judea and Samaria, including the strategic significance of the proposed E1 settlement expansion, British pressure over Israeli settlements, and warnings about settler violence. Meanwhile, election season is heating up. Gadi Eisenkot is calling a two-state solution “delusional” following October 7th while simultaneously criticizing the E1 expansion as a strategic mistake. He also takes aim at Ministers Bezalel Smotrich and Itamar Ben-Gvir over settler violence. The episode also looks back at the 2014 Gaza war, including reports of secret direct back-channel contacts between Prime Minister Benjamin Netanyahu and Hamas through intermediary Shlomi Fogel — contacts that Netanyahu's office and Fogel have denied. Plus, Shanna speaks about Tal Goldstein-Almog, a young survivor of Hamas captivity, and highlights his interview with Australian journalist Erin Molan. And in a cultural tribute, Shanna remembers Dolly Parton and the extraordinary impact of her Imagination Library, including its connection to PJ Library and Israel's Sifriyat Pijama program. The episode also remembers Japanese artist Yayoi Kusama, including her acclaimed 2021 exhibition at the Tel Aviv Museum of Art. Finally, Rabbi Yossi Madvig explores this week's Torah portion, Ki Tavo, discussing light and darkness, the Messianic era, and the difference between the afterlife and the “world to come.” In this episode: • The controversial IDF video for draft evaders • Why the IDF deleted the video • The Haredi military draft crisis • The Rosh Hashanah pilgrimage to Uman • Airport enforcement and draft evaders • Rising tensions in Judea and Samaria • The E1 settlement expansion plan • British pressure over Israeli settlements • Gadi Eisenkot's election campaign • Israel's upcoming elections • IDF operations against October 7th attackers • Tal Goldstein-Almog and his experience in captivity • Reports of secret Netanyahu-Hamas contacts in 2014 • Israel Daily News' independent journalism • Rosh Hashanah gifts from Israeli artists • Dolly Parton's global legacy and PJ Library • Yayoi Kusama's legacy in Israel • Torah thought with Rabbi Yossi Madvig Support independent journalism: Israel Daily News is independently produced and does not work for the Israeli government. Your support helps us continue reporting on Israel and the region. Visit israeldailynews.org to make a one-time or monthly donation. Subscribe to Israel Daily News on YouTube, Spotify and Apple Podcasts, and sign up for the Israel Weekly News newsletter for the top stories from Israel each week. Israel Daily News website: https://israeldailynews.org YOUTUBE: https://www.youtube.com/@israeldailynews Israel Daily News Patreon: https://www.patreon.com/shannafuld Support our Wartime News Coverage: https://www.gofundme.com/f/independent-journalist-covering-israels-war Links to all things IDN: https://linktr.ee/israeldailynews Timestamps 00:00 IDF Video Advises Draft Evaders Ahead of Uman Pilgrimage01:00 The Deleted “Dudy the Explainer” Video02:00 Why the IDF Post Was Removed03:00 How Draft Evaders Are Caught at the Airport04:00 Rising Tensions in Judea & Samaria05:00 The E1 Settlement Expansion Plan06:00 Israel Responds to British Sanctions07:00 Gadi Eisenkot Rejects Two-State Solution08:00 Eisenkot Takes Aim at Smotrich & Ben-Gvir09:00 IDF Kills October 7th Attackers in Gaza10:00 Tal Goldstein-Almog's Story of Captivity11:00 Secret Netanyahu-Hamas Talks?12:00 What Happened During the 2014 Back Channel13:00 Supporting Independent Journalism14:00 Rosh Hashanah Gifts From Israeli Artists15:00 Remembering Dolly Parton16:00 Dolly Parton's Imagination Library & PJ Library17:00 Sifriyat Pijama & Dolly's Global Impact18:00 Remembering Yayoi Kusama19:00 Kusama's Legacy in Israel20:00 Her 2021 Tel Aviv Exhibition21:00 Torah Thought: Ki Tavo22:00 Rising Above the Darkness23:00 The Afterlife vs. the World to Come24:00 The Messianic Paradox25:00 Sign-Off & Shabbat Shalom #Israel #IsraelNews #IDF #IsraeliPolitics #IsraelPolitics #HarediDraft #DraftCrisis #Uman #RoshHashanah #JudeaAndSamaria #WestBank #E1 #Gaza #Hamas #Netanyahu #GadiEisenkot #October7 #IsraelDefenseForces #MiddleEast #DollyParton #YayoiKusama #IsraelDailyNews #IsraelDailyNewsPodcast #BreakingNews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Unspoken Security
How Do We Know What's Real in the Age of AI?

Unspoken Security

Play Episode Listen Later Aug 27, 2026 42:21 Transcription Available


AJ Nash sat down with Shai Gabay, co-founder and CEO of Trustmi, to talk about financial fraud in the age of AI. Gabay opened with the size of the problem: global fraud losses hit $450 billion last year. He explained why business-to-business payment fraud keeps growing. Attackers do not invent new relationships. They study the ones a company already has, then step into an existing conversation between a business and its vendor. Most of that conversation happens over email, and most companies still rely on people, not systems, to catch when something is wrong.The two traced how far that exploitation has evolved. Generative AI has erased the old tells: bad grammar, wrong context, unfamiliar phrasing. Gabay described attackers who forge invoices, bank letters, and void checks in minutes, and a rising pattern where criminals open fully legitimate bank accounts, complete with real KYC verification, under a stolen supplier identity. He walked through a real case where an attacker built a lookalike domain, cloned a supplier's website, and updated the fake site to appear first in search results, all to defeat a callback verification procedure before it ever started.Nash and Gabay closed on the harder question: what happens when video and voice can be faked too. They discussed a $25 million loss out of Hong Kong, where an employee was pulled into a Zoom call with deepfaked company leadership and instructed to wire funds. Gabay argued that no single tool fixes this. Organizations need to connect fragmented controls into one process and, above all, give the person who actually approves a payment the standing to ask questions and slow down. Asked the show's closing question, Gabay admitted that even as a CEO, he still gets pulled into incident response himself, just to understand exactly how an attack worked.Send us Fan MailSupport the show

The CyberWire
The feds flip the script.

The CyberWire

Play Episode Listen Later Aug 26, 2026 32:31


The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Security Squawk
AI Attacks US Water Plants, Apollo Beaten by a Phone Call, Kids' Hospital Breached Again

Security Squawk

Play Episode Listen Later Aug 26, 2026 42:42


Five federal agencies just warned that hackers are using AI to attack the computers running America's water plants and factories. That same week, a trillion-dollar investment firm was breached, not by a virus, but by a phone call. The hard part of hacking is disappearing. Every business owner needs to understand why. What used to keep attackers out is now what lets them in. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided. Start with the story that should stop you cold. The NSA, CISA, the FBI, the Department of Energy, and the EPA issued a rare joint warning: hackers are using AI to write code that attacks Siemens industrial controllers, the small computers that physically run water systems, power, and manufacturing. They took free, legitimate engineering tools and had AI turn them into custom attack software. The agencies say this dramatically cuts the skill and time an attack like this used to require. Difficulty was the wall that kept amateurs out of industrial systems. AI is tearing it down. And it is not theoretical. Security firm Dragos already documented a real intrusion where someone with no industrial background used commercial AI to go after a water utility's controls. The advisory names six sectors in the line of fire, from energy and water to food and manufacturing. These attacks are as weak as they will ever be, because the AI only gets better from here. Then Randy takes on Apollo Global Management, the Wall Street giant with about a trillion dollars under management. Attackers didn't break its technology. They called employees pretending to be internal IT, then guided them to fake login pages that captured their passwords and security codes. From there, they reached names, birth dates, home addresses, and Social Security numbers. This was not a lone hacker. Google ties it to a professionalized extortion crew that moves from one industry to the next running the same script, with demands that often start around three million dollars. A firm with a massive security budget was beaten by a convincing conversation, and a class-action lawsuit started forming within days. If a phone call works on Apollo, it can work on your team too. Reginald closes with SickKids, one of the most respected children's hospitals in the world. No patient records were touched. Employee and job-applicant data leaked through a flaw in third-party software the hospital didn't even build. Consider that last group: job applicants who handed over Social Security numbers to a place they did not even work yet. This repeat victim has now been burned by outside software three times, and it fits a bigger pattern: through the first half of 2026, vendors were involved in 43 percent of healthcare breaches. Another vendor breach this year hit 1.8 million people. Your biggest risk is often a company you'll never meet, inside a tool you already trust. • How hackers are using AI to attack the industrial controllers behind US water and power • Why Apollo Global Management got breached by a phone call, not a virus • How SickKids leaked employee and applicant data through a vendor's software • Why the skill it takes to attack a business is collapsing fast • What "verify who's really calling" actually looks like for your team • How to find the vendors quietly holding your most sensitive data • The one thread connecting all three: what used to keep attackers out now lets them in Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AI #CriticalInfrastructure #Apollo #DataBreach #SocialEngineering #VendorRisk #SickKids #BusinessRisk #MSP #SmallBusiness

Bear Attack
S8 E26: We tackle Blitz's favorite band without him, will we survive?

Bear Attack

Play Episode Listen Later Aug 25, 2026 25:50


Attackers, it's ABR time again but can we do it without Blitz Bear? Although we may miss his poignant insights we think we do it justice.Go enjoy the album, like, subscribe and all that crap.

Mojo In The Morning
Dirty 1: Creepy Masked Attacker on The Loose in Philly

Mojo In The Morning

Play Episode Listen Later Aug 19, 2026 5:40 Transcription Available


Shannon's 6:30 Dirty 8-19-2026 See omnystudio.com/listener for privacy information.

Decipher Security Podcast
How AI is reshaping attacker and defender behavior | Adam Meyers

Decipher Security Podcast

Play Episode Listen Later Aug 19, 2026 53:58


Adam Meyers of CrowdStrike joins Dennis to dive into the rapidly changing nature of both attacker and defender behavior in the AI age and how organizations need to shift their priorities to combat agentic threats. Then we talk about the new White House policy loosening the restrictions on private sector operators doing offensive cyper ops.

The CyberWire
Please hold while we decide.

The CyberWire

Play Episode Listen Later Aug 17, 2026 28:10


Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times) Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer) Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read) Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register) ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine) Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer) Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum) Corma raises $60 million in seed funding. (N2K) Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Cyber Security Today
Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Cyber Security Today

Play Episode Listen Later Aug 17, 2026 9:22


CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July, with a surge in attempts after proof-of-concept code went public. Ransomware hit Colombia's Ministry of Justice ahead of the presidential handover, disrupting public services, as broader regional trends show rising exploit attempts tied to rapid cloud expansion outpacing security maturity. Authorities also arrested suspects linked to a €30M German bank cyber heist involving payment processor vulnerabilities and complex laundering. Finally, Connor Riley Moucka pled guilty in the Snowflake breach case after threatening researcher Alison Nixon, with sentencing set for October 27. 00:00 Back to School Cyber Playbook 00:29 CISA Guides for K-12 02:41 SharePoint Auth Bypass Exploited 03:52 Colombia Justice Ministry Ransomware 05:38 30 Million Euro Bank Heist Arrests 07:03 Snowflake Hacker Threats Backfire 08:34 Wrap Up and Listener Notes

The CyberWire
A flurry of fixes.

The CyberWire

Play Episode Listen Later Aug 12, 2026 26:05


We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE)  DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Talos Takes
Don't scan that! QR code phishing and cloud-native threats

Talos Takes

Play Episode Listen Later Aug 12, 2026 22:25 Transcription Available


What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud.Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways.Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/

AMERICA OUT LOUD PODCAST NETWORK
Cyberattacks, contamination, and a fight for our water supply

AMERICA OUT LOUD PODCAST NETWORK

Play Episode Listen Later Aug 10, 2026 57:00 Transcription Available


The Prism of America's Education with Host Karen Schoen – In late July 2026, cyberattacks targeted water and wastewater systems across at least seven U.S. states, with the FBI confirming incidents that in some cases degraded operations. Attackers hacked internet programmable logic controllers (PLCs), causing temporary disruptions such as loss of remote monitoring and control...

Bear Attack
S8 E24: Dragons (We guess)!

Bear Attack

Play Episode Listen Later Aug 10, 2026 25:22


Attackers, let's get mythical (sorta), come on a journey as the Sam's pit our favorite dragons against each other. Let's be real though the side bars are real on this one so enjoy!

The Café Bitcoin Podcast
Café Bitcoin | Guy Swann and Yan Pritzker on Coldcard, the Asymmetry of Defense, and Privacy | Day 16 of 50

The Café Bitcoin Podcast

Play Episode Listen Later Aug 5, 2026 72:00


Guy Swan on learning the wrong lessons. The takeaway circulating is "go with the biggest company," which forgets Mt. Gox and FTX and everything else proving size is not safety. His analogy: when a libertarian politician betrays you, libertarianism didn't break, you got scammed. He wants a rule that works forward. His sharpest point: "I don't want a rule that only works in hindsight." Anyone can now point at the source-available license. The useful question is what indicator predicts the next failure before it happens. His own heuristic broke in both directions. He had trained himself not to dismiss builders for being abrasive, and now concludes that for security specifically, a maintainer who attacks people reporting problems is telling you something. Yan Pritzker paired it with the engineering version: without a culture of safety, people stop surfacing mistakes. James O'Beirne's tripwires. He seeded wallets on-chain carrying graduated entropy over broken Coldcard seeds, five dice rolls, ten, fifteen, one and two-word passphrases, as bait. The bare seed was swept within an hour and nothing else has moved, mapping attacker capability live. The red team's numbers. Rob Hamilton and Calle have scanned over 300 repos and spent roughly $40,000 on tokens in two days, finding critical vulnerabilities at about one per person per hour. OpenSats is now funding most of that budget. Every company needs an agentic security pipeline. Yan's argument: agents are non-deterministic, so one scan proves nothing. The real work is harnesses that find, test, distill and reproduce on a loop. Swan has been building this for six to twelve months. The asymmetry is the whole problem. Attackers need one vulnerability, defenders need all of them, and the economics favor the attacker. Some have been paying up to 90% of stolen funds in fees to get transactions mined quickly. A fake Coldcard desktop app is circulating. No such application has ever existed. Trezor reported a phishing spike since disclosure, and a counterfeit Wasabi wallet reached an app store. Nobody legitimate asks for recovery words, and unsolicited migration instructions are always hostile. Yan's read on whether this repeats. He calls the bug exotic: entropy wasn't weak, it was switched off entirely. Scans across the popular hardware wallets show correct and consistent entropy use, so he thinks this specific failure is unlikely to recur elsewhere. Government overreach, the other half of the show. Suz on Liechtenstein's beneficial ownership register, roughly 31,000 entities, built in 2021 for EU anti-money-laundering compliance and now breached and offline. Yan on the Bank Secrecy Act's 1970 threshold, never inflation-adjusted, capturing dramatically more data for near-zero measured effect.

Check Point CheckMates Cyber Security Podcast
S08E08: That's Serious Stuff

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Aug 5, 2026 15:55


In this episode, PhoneBoy talks about the AI Network Firewall and recent AI news.AI Network Firewall TechTalkThis Week in AI: Models, Mandates, and a Very Busy WeekWhen the Attacker is an AI AgentOpenAI shares unprecedented AI Cybersecurity incidentAI Agent Security just had it's catalyst moment

Packet Pushers - Full Podcast Feed
PP120: News Roundup—AI Giants Praise Open Weight Models, Attackers Capture Captive Portals, a Tricky Mac Attack, and More

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Aug 4, 2026 61:59


Packet Protector uncorks another News Roundup! We talk about attackers capturing hotels’ captive portals to steal Microsoft credentials, and the OpenAI-attacking-Hugging Face story and how it ties into a broader industry effort to keep the US government from blocking access to open weight AI models from China. Nvidia and the Linux Foundation launch separate AI... Read more »

Packet Pushers - Fat Pipe
PP120: News Roundup—AI Giants Praise Open Weight Models, Attackers Capture Captive Portals, a Tricky Mac Attack, and More

Packet Pushers - Fat Pipe

Play Episode Listen Later Aug 4, 2026 61:59


Packet Protector uncorks another News Roundup! We talk about attackers capturing hotels’ captive portals to steal Microsoft credentials, and the OpenAI-attacking-Hugging Face story and how it ties into a broader industry effort to keep the US government from blocking access to open weight AI models from China. Nvidia and the Linux Foundation launch separate AI... Read more »

The Non-Negotiables: Arsenal Podcast
E242: “Trying to Get Into Space” - Arsenal's Title Defence, Champions League Ambition & Squad Fitness (Season Preview)

The Non-Negotiables: Arsenal Podcast

Play Episode Listen Later Aug 3, 2026 78:26


The NN Pod completes its 2026/27 season preview by assessing what success now looks like for Arsenal after winning the Premier League, reaching the Champions League final and establishing themselves among Europe's strongest sides.The hosts debate whether retaining the league title should remain the priority or whether the Champions League has become the defining target. With the pressure of ending Arsenal's 22-year title wait finally removed, they consider whether the team can approach the new campaign with greater freedom while still managing the demands of defending its crown.Attention then turns to the condition of the squad. William Saliba's absence, uncertainty around Jurrien Timber and the physical load carried by players including Declan Rice, Martin Ødegaard, Bukayo Saka and Kai Havertz raise questions about rotation, recovery and whether Arsenal can keep their most important players available for the decisive months of the season.The episode also examines where the attack must improve after a title-winning campaign built heavily on defensive control, set pieces and narrow victories. The hosts assess the need for better individual returns, the potential evolution of Arsenal's midfield and right-hand side, and whether a fitter Ødegaard can help unlock a more expansive version of the team.Finally, the discussion moves to Max Dowman, the pathway for Arsenal's academy players, the club's continuing difficulties in the sales market and the transfer priorities that remain before the window closes. With Arsenal beginning the season as champions rather than challengers, the question is no longer how they reach the top — but how much further they can go.Chapters:(00:00) - Arteta's Non-Negotiables & Intro(00:49) - What Constitutes Success This Season?(03:46) - Arteta's Contract Situation(06:33) - Rotation, Injuries & Managing the Squad(09:11) - Can Fans Accept Rotation?(11:56) - Premier League or Champions League?(14:05) - Managing the Champions League Schedule(19:54) - Where Must Arsenal's Attack Improve?(22:13) - Better Returns From Arsenal's Attackers(25:05) - Can Arsenal Attack More Without Losing Control?(26:33) - Fine Margins, Set Pieces & Sustainability(29:45) - Replacing Saliba's Influence(34:15) - Ødegaard's Deeper Midfield Role(37:39) - Max Dowman's Breakout Potential(39:10) - Ife Ibrahim & Arsenal's Next Academy Prospects(44:16) - Can Other Hale End Players Break Through?(47:54) - Academy Pathways & Player Development(51:32) - Arsenal's Selling Problem(54:07) - Why Are Arsenal Players Undervalued?(01:02:27) - Arsenal's Remaining Transfer Priorities(01:05:03) - Meslier's Pre-Season Performance(01:06:16) - Vieira, Nelson, Jesus & the Oversized Squad(01:09:02) - Optimism Ahead of the New Season(01:12:14) - Arsenal at the Top of the Mountain(01:15:03) - Will Arsenal Play Better Football?(01:17:13) - Outro & What's Next

Security Conversations
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click' Exploits, and Magnets of Threats

Security Conversations

Play Episode Listen Later Jul 31, 2026 206:39


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear' advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

The CyberWire
Building a great firewall around AI.

The CyberWire

Play Episode Listen Later Jul 30, 2026 25:40


China embraces open AI models, then worries it's become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that's breaking new ground. Don't bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that's breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here.  Selected Reading As China's A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack' (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon': AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The CyberWire
The world's least private hackers.

The CyberWire

Play Episode Listen Later Jul 27, 2026 27:24


Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Dana & Parks Podcast
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dana & Parks Podcast
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Risky Business
Risky Business #845 -- OpenAI's Skynet moment

Risky Business

Play Episode Listen Later Jul 22, 2026 69:31


On this week's show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft's GDID And much, much more! This week's show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it. This episode is also available on YouTube. Show notes OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com Security incident disclosure — July 2026 | Social Signals Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security Cheating behaviour in frontier model evaluations | AISI Work | Social Signals JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com Iran abused mobile networks' vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com Trump calls for new election security measures | NBC News Tech Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://www.justice.gov/usao-ndil/media/1450651/dl?inline | Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com 764 splinter group leader sentenced to 40 years in jail | cyberscoop.com Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com White House details ‘Gold Eagle' clearinghouse for AI cyber threats | cyberscoop.com Attackers vote themselves $20 million in BONK cryptocurrency | The Record CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com Apple says former employee exploited ‘rare' bug to download confidential files after leaving for OpenAI | TechCrunch Security Pegasus Spyware European Parliament Pega Committee Member | The Record Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security

The CyberWire
Behind the friendly face.

The CyberWire

Play Episode Listen Later Jul 20, 2026 29:19


Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here.  Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices