Podcasts about Attackers

  • 1,531PODCASTS
  • 3,083EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 31, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Attackers

Show all podcasts related to attackers

Latest podcast episodes about Attackers

The CyberWire
Let's kill the kill switch.

The CyberWire

Play Episode Listen Later Aug 31, 2026 27:59


Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill. Selected Reading The AI Kill Switch Act is repeating the Clipper Chip's mistakes (CyberScoop) Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek) Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer) China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs) Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR) Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer) US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register) AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing) How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Chronicles of a Gooner | The Arsenal Podcast
Do Arsenal need another attacker? | De Zerbi attacks Spurs' mentality - Red Tinted Glasses

The Chronicles of a Gooner | The Arsenal Podcast

Play Episode Listen Later Aug 31, 2026 56:25


On this week's episode of Red Tinted Glasses, Harry Symeou is joined once again by the excellent Scott Saunders. The guys discuss whether or not Arsenal need another attacker before the window closes, Spurs' defeat to Newcastle, De Zerbi's comments regarding the team's mentality, Liverpool's early defensive struggles under Andoni Iraola, Chelsea's lack of balance, Bruno Fernandes and more. Subscribe to Scott's channel here: @tplmufc To sign up as a Patreon, get additional episodes, ad-free episodes and become a part of our discord server, click the link below: https://patreon.com/thechroniclesofagooner?utm_medium=unknown&utm_source=join_link&utm_campaign=creatorshare_creator&utm_content=copyLink Enter the discount code 'SUMMER' for 50% off your first month! Listen to 'The Rise of Pafos FC' on Apple podcasts or Spotify: https://podcasts.apple.com/us/podcast/the-rise-of-pafos-fc-with-harry-symeou/id1334407316?i=1000746012823 #arsenal #transfers #news Learn more about your ad choices. Visit podcastchoices.com/adchoices

The CyberWire
Who let the AI hack? [Research Saturday]

The CyberWire

Play Episode Listen Later Aug 29, 2026 23:10


Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool. The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. The research and executive brief can be found here: LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

ITSPmagazine | Technology. Cybersecurity. Society
Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 27, 2026 17:16


Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access

Israel Daily News Podcast
Dolly Parton's Library Idea Reaches Israel & Israel Daily News; Thu. Aug 27, 2026

Israel Daily News Podcast

Play Episode Listen Later Aug 27, 2026 26:36


An IDF social media video appeared to advise ultra-Orthodox Israelis facing military draft enforcement on how to avoid arrest at Ben Gurion Airport — and it was quickly deleted. In this episode of Israel Daily News, Shanna Fuld breaks down the controversy surrounding the now-deleted IDF video ahead of the annual Rosh Hashanah pilgrimage to Uman, Ukraine. The video reportedly used an AI character called “Dudy the Explainer” to explain how draft evaders could avoid being detained at the airport. The controversy comes as Israel's long-running battle over Haredi military service intensifies and new legislation has left some pilgrimage-bound Israelis facing draft-evader status. Shanna also examines the growing security tensions in Judea and Samaria, including the strategic significance of the proposed E1 settlement expansion, British pressure over Israeli settlements, and warnings about settler violence. Meanwhile, election season is heating up. Gadi Eisenkot is calling a two-state solution “delusional” following October 7th while simultaneously criticizing the E1 expansion as a strategic mistake. He also takes aim at Ministers Bezalel Smotrich and Itamar Ben-Gvir over settler violence. The episode also looks back at the 2014 Gaza war, including reports of secret direct back-channel contacts between Prime Minister Benjamin Netanyahu and Hamas through intermediary Shlomi Fogel — contacts that Netanyahu's office and Fogel have denied. Plus, Shanna speaks about Tal Goldstein-Almog, a young survivor of Hamas captivity, and highlights his interview with Australian journalist Erin Molan. And in a cultural tribute, Shanna remembers Dolly Parton and the extraordinary impact of her Imagination Library, including its connection to PJ Library and Israel's Sifriyat Pijama program. The episode also remembers Japanese artist Yayoi Kusama, including her acclaimed 2021 exhibition at the Tel Aviv Museum of Art. Finally, Rabbi Yossi Madvig explores this week's Torah portion, Ki Tavo, discussing light and darkness, the Messianic era, and the difference between the afterlife and the “world to come.” In this episode: • The controversial IDF video for draft evaders • Why the IDF deleted the video • The Haredi military draft crisis • The Rosh Hashanah pilgrimage to Uman • Airport enforcement and draft evaders • Rising tensions in Judea and Samaria • The E1 settlement expansion plan • British pressure over Israeli settlements • Gadi Eisenkot's election campaign • Israel's upcoming elections • IDF operations against October 7th attackers • Tal Goldstein-Almog and his experience in captivity • Reports of secret Netanyahu-Hamas contacts in 2014 • Israel Daily News' independent journalism • Rosh Hashanah gifts from Israeli artists • Dolly Parton's global legacy and PJ Library • Yayoi Kusama's legacy in Israel • Torah thought with Rabbi Yossi Madvig Support independent journalism: Israel Daily News is independently produced and does not work for the Israeli government. Your support helps us continue reporting on Israel and the region. Visit israeldailynews.org to make a one-time or monthly donation. Subscribe to Israel Daily News on YouTube, Spotify and Apple Podcasts, and sign up for the Israel Weekly News newsletter for the top stories from Israel each week. Israel Daily News website: https://israeldailynews.org YOUTUBE: https://www.youtube.com/@israeldailynews Israel Daily News Patreon: https://www.patreon.com/shannafuld Support our Wartime News Coverage: https://www.gofundme.com/f/independent-journalist-covering-israels-war Links to all things IDN: https://linktr.ee/israeldailynews Timestamps 00:00 IDF Video Advises Draft Evaders Ahead of Uman Pilgrimage01:00 The Deleted “Dudy the Explainer” Video02:00 Why the IDF Post Was Removed03:00 How Draft Evaders Are Caught at the Airport04:00 Rising Tensions in Judea & Samaria05:00 The E1 Settlement Expansion Plan06:00 Israel Responds to British Sanctions07:00 Gadi Eisenkot Rejects Two-State Solution08:00 Eisenkot Takes Aim at Smotrich & Ben-Gvir09:00 IDF Kills October 7th Attackers in Gaza10:00 Tal Goldstein-Almog's Story of Captivity11:00 Secret Netanyahu-Hamas Talks?12:00 What Happened During the 2014 Back Channel13:00 Supporting Independent Journalism14:00 Rosh Hashanah Gifts From Israeli Artists15:00 Remembering Dolly Parton16:00 Dolly Parton's Imagination Library & PJ Library17:00 Sifriyat Pijama & Dolly's Global Impact18:00 Remembering Yayoi Kusama19:00 Kusama's Legacy in Israel20:00 Her 2021 Tel Aviv Exhibition21:00 Torah Thought: Ki Tavo22:00 Rising Above the Darkness23:00 The Afterlife vs. the World to Come24:00 The Messianic Paradox25:00 Sign-Off & Shabbat Shalom #Israel #IsraelNews #IDF #IsraeliPolitics #IsraelPolitics #HarediDraft #DraftCrisis #Uman #RoshHashanah #JudeaAndSamaria #WestBank #E1 #Gaza #Hamas #Netanyahu #GadiEisenkot #October7 #IsraelDefenseForces #MiddleEast #DollyParton #YayoiKusama #IsraelDailyNews #IsraelDailyNewsPodcast #BreakingNews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
The feds flip the script.

The CyberWire

Play Episode Listen Later Aug 26, 2026 32:31


The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Mojo In The Morning
Dirty 1: Creepy Masked Attacker on The Loose in Philly

Mojo In The Morning

Play Episode Listen Later Aug 19, 2026 5:40 Transcription Available


Shannon's 6:30 Dirty 8-19-2026 See omnystudio.com/listener for privacy information.

The CyberWire
Please hold while we decide.

The CyberWire

Play Episode Listen Later Aug 17, 2026 28:10


Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Nick Warner, Neo.ai's CEO, discussing the shifting landscape around AI and agentic security. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It. (The New York Times) Philips and GE investigating Clop ransomware data theft claims (Bleeping Computer) Attackers Probe Critical GeoServer SQL Injection Vulnerability (Hack Read) Crook hawks millions of records allegedly plundered from corporate Azure tenants (The Register) ETSI Proposes 17 Cybersecurity Standards to Support EU CRA (Infosecurity Magazine) Microsoft working on Defender patch for ShieldBreak zero-day (Bleeping Computer) Agentic AI Crunch Creates CPU Comeback (IEEE Spectrum) Corma raises $60 million in seed funding. (N2K) Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware (SecurityWeek) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Spurs Chat: Discussing all Things Tottenham Hotspur: Hosted by Chris Cowlin: The Daily Tottenham/Spurs Podcast
"DE ZERBI NEEDS ATTACKERS!" FEATURE ON BBC RADIO LONDON: Talking Tottenham; The 2026/27 Season

Spurs Chat: Discussing all Things Tottenham Hotspur: Hosted by Chris Cowlin: The Daily Tottenham/Spurs Podcast

Play Episode Listen Later Aug 17, 2026 8:22


Spurs Chat: Discussing all Things Tottenham Hotspur: Hosted by Chris Cowlin: The Daily Tottenham/Spurs Podcast Hosted on Acast. See acast.com/privacy for more information.

The CyberWire
A flurry of fixes.

The CyberWire

Play Episode Listen Later Aug 12, 2026 26:05


We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE)  DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Talos Takes
Don't scan that! QR code phishing and cloud-native threats

Talos Takes

Play Episode Listen Later Aug 12, 2026 22:25 Transcription Available


What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud.Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways.Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/

AMERICA OUT LOUD PODCAST NETWORK
Cyberattacks, contamination, and a fight for our water supply

AMERICA OUT LOUD PODCAST NETWORK

Play Episode Listen Later Aug 10, 2026 57:00 Transcription Available


The Prism of America's Education with Host Karen Schoen – In late July 2026, cyberattacks targeted water and wastewater systems across at least seven U.S. states, with the FBI confirming incidents that in some cases degraded operations. Attackers hacked internet programmable logic controllers (PLCs), causing temporary disruptions such as loss of remote monitoring and control...

Bear Attack
S8 E24: Dragons (We guess)!

Bear Attack

Play Episode Listen Later Aug 10, 2026 25:22


Attackers, let's get mythical (sorta), come on a journey as the Sam's pit our favorite dragons against each other. Let's be real though the side bars are real on this one so enjoy!

Aftonbladet Daily
Putins osynliga krig

Aftonbladet Daily

Play Episode Listen Later Aug 10, 2026 15:16


Litauen varnar för att Ryssland kan komma att utföra false flag-operationer. Attacker eller sabotage som utformas för att se ut att ha utförts av någon annan. Men vad vill Ryssland uppnå med den här typen av hybridkrigföring? Hur trovärdig är Litauens varning om möjliga false flag-operationer? Och hur går det egentligen till när myndigheter försöker fastställa vem som ligger bakom ett sabotage? Gäst: Wolfgang Hansson, fristående utrikesanalytiker Programledare och producent: Jesper Spanne. Klipp från: Global News Kontakt: podcast@aftonbladet.se.

DailyCyber The Truth About Cyber Security with Brandon Krieger
Agentic AI Closing Cloud Security's 15-Minute Exploit Window | DailyCyber 297 with Shimon Tolts

DailyCyber The Truth About Cyber Security with Brandon Krieger

Play Episode Listen Later Aug 9, 2026 62:54


Attackers are moving from a 14-day exploit window to a 15-minute one. On this episode, Shimon Tolts, CEO & Co-Founder of Copperhelm, joins Brandon Krieger to explain how his team built the industry's first agentic cloud security platform to meet that speed — and why security has lagged behind every other engineering discipline in adopting AI. Topics include: What makes a security platform genuinely "agentic" How Context Lake structures cloud data so AI can act with confidence Earning security leaders' trust in autonomous agents on live infrastructure Building at scale: lessons from Unity and ironSource What CISOs should prioritize to prepare for the agentic era Guest: Shimon Tolts, CEO & Co-Founder, Copperhelmhttps://copperhelm.com/ Host: Brandon Krieger, CEO & vCISO Advisor Listen: https://www.DailyCyber.ca Watch Full Episode: YouTube.com/BrandonKrieger Listen: DailyCyber.ca

Federal Drive with Tom Temin
Remote connections that help operators monitor critical systems create opportunities for cyber attackers

Federal Drive with Tom Temin

Play Episode Listen Later Aug 7, 2026 9:08


Keeping water systems running requires remote access for monitoring, maintenance, and vendor support. Securing those connections has become a growing priority for utilities that rely on operational technology every day. A new NIST guide offers practical approaches for doing that. Here to discuss it is CheeYee Tang, an electronic engineer at NIST.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

IT Privacy and Security Weekly update.
EP 303. Gorgones. Deep Dive. The AI, Privacy, and Security Weekly Update for the week ending August 3, 2026.

IT Privacy and Security Weekly update.

Play Episode Listen Later Aug 6, 2026 42:02


Artificial intelligence has fundamentally changed the cybersecurity landscape by reducing the expertise needed to launch sophisticated attacks. Open-weight AI models now automate reconnaissance, vulnerability analysis, and exploit development, allowing attackers to scale operations in minutes instead of days. The Zhuhai-linked "knaithe" campaign demonstrated this shift by combining DeepSeek with the Hermes Agent Framework to autonomously identify and target vulnerabilities. Although configuration barriers prevented successful exploitation, the attackers exposed their own API keys and logs, highlighting operational security risks for both defenders and adversaries.Nation-state actors are increasingly targeting critical infrastructure as a tool of strategic coercion. Iran's CyberAv3ngers group has progressed from website defacements to manipulating industrial control systems in water and energy facilities. Recent attacks on Minnesota water utilities disrupted operations and created risks to water treatment, demonstrating how cyberattacks can produce real-world physical effects without conventional military action.Data sovereignty and supply chain security remain major concerns. Attackers breached Liechtenstein's beneficial ownership registry by bypassing rate limits and exposing sensitive ownership records, undermining trust in a jurisdiction built on financial privacy. Meanwhile, ShinyHunters continues exploiting third-party IT service platforms to steal credentials and compromise organizations through trusted suppliers, creating lasting consequences that cannot be undone by ransom payments.Defensive innovation is shifting toward stronger system design rather than reactive filtering. New techniques isolate sensitive AI knowledge, while formal verification enables machine-checkable reasoning that improves trust and reliability. These advances strengthen AI security but cannot replace effective governance.Confidence in surveillance technology is also weakening. Investigations into Flock Safety's automated license plate reader network found gaps between public claims and operational practices, prompting dozens of municipalities to cancel deployments and reinforcing the need for transparency and accountability.Overall, AI is accelerating offensive cyber capabilities, critical infrastructure is becoming a routine target, and organizations must combine resilient technology with strong governance to defend against increasingly automated threats.

The Café Bitcoin Podcast
Café Bitcoin | Guy Swann and Yan Pritzker on Coldcard, the Asymmetry of Defense, and Privacy | Day 16 of 50

The Café Bitcoin Podcast

Play Episode Listen Later Aug 5, 2026 72:00


Guy Swan on learning the wrong lessons. The takeaway circulating is "go with the biggest company," which forgets Mt. Gox and FTX and everything else proving size is not safety. His analogy: when a libertarian politician betrays you, libertarianism didn't break, you got scammed. He wants a rule that works forward. His sharpest point: "I don't want a rule that only works in hindsight." Anyone can now point at the source-available license. The useful question is what indicator predicts the next failure before it happens. His own heuristic broke in both directions. He had trained himself not to dismiss builders for being abrasive, and now concludes that for security specifically, a maintainer who attacks people reporting problems is telling you something. Yan Pritzker paired it with the engineering version: without a culture of safety, people stop surfacing mistakes. James O'Beirne's tripwires. He seeded wallets on-chain carrying graduated entropy over broken Coldcard seeds, five dice rolls, ten, fifteen, one and two-word passphrases, as bait. The bare seed was swept within an hour and nothing else has moved, mapping attacker capability live. The red team's numbers. Rob Hamilton and Calle have scanned over 300 repos and spent roughly $40,000 on tokens in two days, finding critical vulnerabilities at about one per person per hour. OpenSats is now funding most of that budget. Every company needs an agentic security pipeline. Yan's argument: agents are non-deterministic, so one scan proves nothing. The real work is harnesses that find, test, distill and reproduce on a loop. Swan has been building this for six to twelve months. The asymmetry is the whole problem. Attackers need one vulnerability, defenders need all of them, and the economics favor the attacker. Some have been paying up to 90% of stolen funds in fees to get transactions mined quickly. A fake Coldcard desktop app is circulating. No such application has ever existed. Trezor reported a phishing spike since disclosure, and a counterfeit Wasabi wallet reached an app store. Nobody legitimate asks for recovery words, and unsolicited migration instructions are always hostile. Yan's read on whether this repeats. He calls the bug exotic: entropy wasn't weak, it was switched off entirely. Scans across the popular hardware wallets show correct and consistent entropy use, so he thinks this specific failure is unlikely to recur elsewhere. Government overreach, the other half of the show. Suz on Liechtenstein's beneficial ownership register, roughly 31,000 entities, built in 2021 for EU anti-money-laundering compliance and now breached and offline. Yan on the Bank Secrecy Act's 1970 threshold, never inflation-adjusted, capturing dramatically more data for near-zero measured effect.

Check Point CheckMates Cyber Security Podcast
S08E08: That's Serious Stuff

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Aug 5, 2026 15:55


In this episode, PhoneBoy talks about the AI Network Firewall and recent AI news.AI Network Firewall TechTalkThis Week in AI: Models, Mandates, and a Very Busy WeekWhen the Attacker is an AI AgentOpenAI shares unprecedented AI Cybersecurity incidentAI Agent Security just had it's catalyst moment

The Cybersecurity Readiness Podcast Series
Episode 110 -- When the Attacker Builds the Key: Frontier AI and the Future of Continuous Penetration Testing

The Cybersecurity Readiness Podcast Series

Play Episode Listen Later Aug 5, 2026 40:37


In Episode 110 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Dr. Varin Khera, Co-Founder and Chief Technology Officer of SecStrike and Head of Asia Pacific at Yarix, to examine how frontier AI models have shifted the offense-defense balance in cybersecurity, and why the annual or semi-annual penetration test — long treated as a reliable baseline control — can no longer keep pace with adversaries who reason adaptively, chain misconfigurations across dozens of systems, and build their own attack playbooks in real time.Dr. Khera, who sits on both sides of the AI arms race — building EchoStrike, SecStrike's AI-driven, model-agnostic “symbiotic penetration testing” platform, while also advising enterprise clients through Yarix on how to defend against that same class of technology — walks through how frontier AI differs from the automation that preceded it. Using a locksmith analogy, he explains that older AI tools executed a fixed playbook, while frontier models construct the attack path themselves, discovering and exploiting misconfigurations a once-a-year human-led test would never have the time or reach to find. The conversation details the architecture behind EchoStrike: Crimson Nexus, a persistent, fingerprint-based knowledge engine that learns from past human decisions; the Red Engine, which orchestrates and executes validation actions; Recon, which continuously maps external attack surfaces; and the patent-pending Adaptive Threat Validation (ATV) engine that ties the components together and escalates high-judgment decisions to a human reviewer before any high-impact action is taken.Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode also addresses how security leaders should frame the case for continuous validation to the board — not as a technology purchase, but as a decision about whether to close a known and growing risk — and closes with a rapid-fire exchange on the misconceptions, governance gaps, and accountability questions defining this next phase of AI-driven offensive and defensive security.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-110-when-the-attacker-builds-the-key-frontier-ai-and-the-future-of-continuous-penetration-testing/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.

Packet Pushers - Full Podcast Feed
PP120: News Roundup—AI Giants Praise Open Weight Models, Attackers Capture Captive Portals, a Tricky Mac Attack, and More

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Aug 4, 2026 61:59


Packet Protector uncorks another News Roundup! We talk about attackers capturing hotels’ captive portals to steal Microsoft credentials, and the OpenAI-attacking-Hugging Face story and how it ties into a broader industry effort to keep the US government from blocking access to open weight AI models from China. Nvidia and the Linux Foundation launch separate AI... Read more »

Packet Pushers - Fat Pipe
PP120: News Roundup—AI Giants Praise Open Weight Models, Attackers Capture Captive Portals, a Tricky Mac Attack, and More

Packet Pushers - Fat Pipe

Play Episode Listen Later Aug 4, 2026 61:59


Packet Protector uncorks another News Roundup! We talk about attackers capturing hotels’ captive portals to steal Microsoft credentials, and the OpenAI-attacking-Hugging Face story and how it ties into a broader industry effort to keep the US government from blocking access to open weight AI models from China. Nvidia and the Linux Foundation launch separate AI... Read more »

The Non-Negotiables: Arsenal Podcast
E242: “Trying to Get Into Space” - Arsenal's Title Defence, Champions League Ambition & Squad Fitness (Season Preview)

The Non-Negotiables: Arsenal Podcast

Play Episode Listen Later Aug 3, 2026 78:26


The NN Pod completes its 2026/27 season preview by assessing what success now looks like for Arsenal after winning the Premier League, reaching the Champions League final and establishing themselves among Europe's strongest sides.The hosts debate whether retaining the league title should remain the priority or whether the Champions League has become the defining target. With the pressure of ending Arsenal's 22-year title wait finally removed, they consider whether the team can approach the new campaign with greater freedom while still managing the demands of defending its crown.Attention then turns to the condition of the squad. William Saliba's absence, uncertainty around Jurrien Timber and the physical load carried by players including Declan Rice, Martin Ødegaard, Bukayo Saka and Kai Havertz raise questions about rotation, recovery and whether Arsenal can keep their most important players available for the decisive months of the season.The episode also examines where the attack must improve after a title-winning campaign built heavily on defensive control, set pieces and narrow victories. The hosts assess the need for better individual returns, the potential evolution of Arsenal's midfield and right-hand side, and whether a fitter Ødegaard can help unlock a more expansive version of the team.Finally, the discussion moves to Max Dowman, the pathway for Arsenal's academy players, the club's continuing difficulties in the sales market and the transfer priorities that remain before the window closes. With Arsenal beginning the season as champions rather than challengers, the question is no longer how they reach the top — but how much further they can go.Chapters:(00:00) - Arteta's Non-Negotiables & Intro(00:49) - What Constitutes Success This Season?(03:46) - Arteta's Contract Situation(06:33) - Rotation, Injuries & Managing the Squad(09:11) - Can Fans Accept Rotation?(11:56) - Premier League or Champions League?(14:05) - Managing the Champions League Schedule(19:54) - Where Must Arsenal's Attack Improve?(22:13) - Better Returns From Arsenal's Attackers(25:05) - Can Arsenal Attack More Without Losing Control?(26:33) - Fine Margins, Set Pieces & Sustainability(29:45) - Replacing Saliba's Influence(34:15) - Ødegaard's Deeper Midfield Role(37:39) - Max Dowman's Breakout Potential(39:10) - Ife Ibrahim & Arsenal's Next Academy Prospects(44:16) - Can Other Hale End Players Break Through?(47:54) - Academy Pathways & Player Development(51:32) - Arsenal's Selling Problem(54:07) - Why Are Arsenal Players Undervalued?(01:02:27) - Arsenal's Remaining Transfer Priorities(01:05:03) - Meslier's Pre-Season Performance(01:06:16) - Vieira, Nelson, Jesus & the Oversized Squad(01:09:02) - Optimism Ahead of the New Season(01:12:14) - Arsenal at the Top of the Mountain(01:15:03) - Will Arsenal Play Better Football?(01:17:13) - Outro & What's Next

Security Conversations
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click' Exploits, and Magnets of Threats

Security Conversations

Play Episode Listen Later Jul 31, 2026 206:39


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear' advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

Cyber Security Today
OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

Cyber Security Today

Play Episode Listen Later Jul 31, 2026 11:38


OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

The CyberWire
Building a great firewall around AI.

The CyberWire

Play Episode Listen Later Jul 30, 2026 25:40


China embraces open AI models, then worries it's become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that's breaking new ground. Don't bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that's breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here.  Selected Reading As China's A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack' (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon': AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Telecom Reseller
Mutare: Voice Is the Last Unguarded Door into the Enterprise, Podcast

Telecom Reseller

Play Episode Listen Later Jul 28, 2026


By Doug Green “Voice is a security channel now, and it deserves the same controls businesses already apply to email and their networks.” In this Technology Reseller News and Cloud Communications Alliance podcast, Doug Green speaks with Chuck French of Mutare about the growing threat of voice-based attacks—and the opportunity for service providers to help customers close a major security gap. French says the voice channel has quietly become one of the last unprotected entry points into many organizations. Traditional tools can label suspicious calls, but they do not give individual businesses control over which calls are allowed, blocked, challenged or routed. The risk is growing rapidly as AI makes voice cloning, impersonation and convincing social-engineering scripts easier and less expensive to produce. Attackers can now imitate a bank, help desk or company executive in real time and at scale. Mutare's Voice Traffic Filter addresses this problem by providing what French describes as a voice firewall. The platform combines customer-defined policies, reputation data, STIR/SHAKEN information, threat-pattern analysis and a voice CAPTCHA that helps distinguish human callers from bots. Unlike carrier-level spam blocking, Mutare allows each organization to establish its own rules. A hospital, financial institution or small business can therefore apply policies suited to its particular risks and customer needs. Mutare has also developed a multitenant version of the platform for MSPs, CSPs and other channel partners. The cloud-hosted service requires no customer-premises equipment or major professional-services deployment. Providers can offer it as a recurring, consumption-based security service while retaining the customer relationship and setting their own pricing. French says Mutare's return to the Cloud Communications Alliance reflects this new service-provider model and its potential value to CCA members. For service providers, the message is clear: voice security represents both an urgent customer need and a new recurring-revenue opportunity. Listen to the podcast to learn how Mutare is helping businesses treat voice as a protected enterprise channel rather than an unguarded utility. Learn more at mutare.com.  

The CyberWire
The world's least private hackers.

The CyberWire

Play Episode Listen Later Jul 27, 2026 27:24


Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Bear Attack
S8 E22: Let's go to battle!

Bear Attack

Play Episode Listen Later Jul 27, 2026 42:31


Attacker's welcome to another radio episode. Polar bear tasked us with picking good songs to go to battle to, check out the attached playlist.https://open.spotify.com/playlist/72d013mV2izQQiQA2nLiNN?si=6mJPuByxQxKb47jcspFTSgLike, subscribe and most importantly spread the word.

The Dana & Parks Podcast
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dana & Parks Podcast
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Drivetime with DeRusha
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Drivetime with DeRusha

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Drivetime with DeRusha
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Drivetime with DeRusha

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

I’ve Got Questions with Mike Simpson
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

I’ve Got Questions with Mike Simpson

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

I’ve Got Questions with Mike Simpson
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

I’ve Got Questions with Mike Simpson

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Adam and Jordana
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Adam and Jordana

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Adam and Jordana
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Adam and Jordana

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Scoot Show with Scoot
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Scoot Show with Scoot

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Scoot Show with Scoot
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Scoot Show with Scoot

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Chad Hartman
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Chad Hartman

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Chad Hartman
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Chad Hartman

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Learn Cardano Podcast
SecondFi Hack Update: 16.1M ADA Stolen, Recovery Timeline Explained

Learn Cardano Podcast

Play Episode Listen Later Jul 24, 2026 12:38 Transcription Available


SecondFi has released more detail on the wallet security incident that saw about 16.1 million ADA, roughly US$2.6 million, withdrawn from 374 wallets between 21 and 23 June. The update includes a public warning about fake recovery emails, findings from Groom Lake's forensic investigation, and a clearer explanation of the cryptographic flaw involved.Peter breaks down what SecondFi says happened, including the reported external attacker, the possibility of a second separate attacker, the per-transaction signature issue, and why public transaction data may have been enough to derive affected private key material under certain conditions. The episode also covers the wider discussion around cross-chain wallet code, CTRL Wallet, Yoroi migration, EMURGO tooling and the unauthorised publication of relevant code.The key safety message is simple: use only official SecondFi channels, do not click recovery emails, never share private keys, and wait for audited recovery and migration tooling rather than trusting anyone offering support through emails, comments or direct messages.Chapters:0:00 Fake Recovery Email Warning1:15 Incident Investigation Update2:18 Second Attacker Identified2:56 Cryptographic Root Cause3:45 Signing Formula Breakdown5:46 Vulnerable Wallet Library6:37 CTRL Wallet And Yoroi8:22 Published Code Question9:14 SecondFi Wind Down9:34 Recovery And Migration Tools11:25 Private Key SafetyWhat you'll learn:- SecondFi warned users that fake recovery emails are phishing attempts and that official communication is through its X account and technical support channels.- SecondFi said the June incident involved approximately 16.1 million ADA, about US$2.6 million, stolen from 374 wallets.- Groom Lake's independent investigation identified an external actor and suggested the primary operation may be linked to the DPRK-linked Lazarus Group.- The investigation also identified activity from a second separate attacker affecting a different set of wallets during the same window.- The root cause described by SecondFi was a subtle cryptographic flaw in how wallet software generated per-transaction signatures.- The signing issue meant data that should have depended on secret information could under some conditions be computed from public blockchain data.- SecondFi says the flaw has been patched, new wallets created with corrected software are not known to be affected, and the wallet is being wound down.- SecondFi is preparing safe migration functionality for early August and a zero-knowledge-proof recovery tool targeted for August after specialist third-party audits.Links & References:⚠️ Security Alert: FAKE RECOVERY EMAIL:- https://link.learncardano.io/m7FsGqOfficial SecondFi website:- https://link.learncardano.io/6llK2PWhat happened to SecondFi:- https://link.learncardano.io/fNJfCuThe signing math:- https://link.learncardano.io/5Pu20KVulnerable Library:- https://link.learncardano.io/cPTJG9Andrew Westberg's Opinion:- https://link.learncardano.io/cVwd7CEMURGO's internal JS framework Dullahan:- https://link.learncardano.io/0vu7M5⚠️ Recovery Update: Bounty Offer Made to Attacker:- https://link.learncardano.io/lG2331Website: https://link.learncardano.io/bQ68RcX/Twitter: https://link.learncardano.io/3a1QtvDisclaimer: This content is for educational purposes only. Nothing constitutes financial advice.DISCLAIMER: This content is for informational and educational purposes only and is not financial, investment, or legal advice. I am not affiliated with, nor compensated by, the project discussed—no tokens, payments, or incentives received. I do not hold a stake in the project, including private or future allocations. All views are my own, based on public information. Always do your own research and consult a licensed advisor before investing. Crypto investments carry high risk, and past performance is no guarantee of future results. I am not responsible for any decisions you make based on this content.

Relating to DevSecOps
Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

Relating to DevSecOps

Play Episode Listen Later Jul 24, 2026 46:40


Send us Fan MailAI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.

Security Conversations
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16

Security Conversations

Play Episode Listen Later Jul 23, 2026 136:03


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 106: We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 5:24 OpenAI admits it was the Hugging Face "hacker" 10:06 What's ExploitGym and who's on top of the leaderboard 12:59 Reward hacking: Did anyone train this thing not to cheat? 19:35 Marketing stunt or real incident? The zero-day in the package proxy 26:43 Was OpenAI already plugged into Hugging Face? 29:17 Paperclips, kill switches, and "going rogue" 34:49 Crisis comms, regulatory capture, and the second Cold War 43:02 Approve every action? Auto mode and swarms 50:10 "Lab leak" and calls for biosafety levels 1:00:31 The missing models: no Mythos, no Kimi, no independent referee 1:07:04 Costin's prediction: owning frontier-class hardware will require a license 1:13:41 fast16 as a benchmark: Inside the Sol Searching research 1:26:51 Compression and altitude: are reverse engineers being replaced? 1:41:24 Finding the gem in 100 samples, and the swarm frontier 2:00:41 Claude Opus 5 drops, Gemini 3.5 Flash Cyber

The Cybersecurity Defenders Podcast
AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 23, 2026 35:27


AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.In this episode:• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.• Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.Stories covered:• https://huggingface.co/blog/security-...• https://openai.com/index/hugging-face...Chapters:0:00 Cold open — the attacker was the model2:20 The whole story in one breath6:41 The timeline: two disclosures, five days apart11:37 Attack chain, part 1: getting in through a malicious dataset15:53 Attack chain, part 2: escaping the eval sandbox22:10 Motive, attribution & intent: cheating on the benchmark25:31 What was (and wasn't) exposed28:08 The bigger picture: the fire drill started the fire31:39 Lessons for labs, platforms, and solo developers33:15 New fear unlocked: models backdooring modelsThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00ze...• Apple Podcasts: https://podcasts.apple.com/us/podcast...• YouTube: / @limacharlieio Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #AIsecurity #OpenAI #HuggingFace #infosec

Risky Business
Risky Business #845 -- OpenAI's Skynet moment

Risky Business

Play Episode Listen Later Jul 22, 2026 69:31


On this week's show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft's GDID And much, much more! This week's show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it. This episode is also available on YouTube. Show notes OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com Security incident disclosure — July 2026 | Social Signals Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security Cheating behaviour in frontier model evaluations | AISI Work | Social Signals JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com Iran abused mobile networks' vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com Trump calls for new election security measures | NBC News Tech Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://www.justice.gov/usao-ndil/media/1450651/dl?inline | Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com 764 splinter group leader sentenced to 40 years in jail | cyberscoop.com Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com White House details ‘Gold Eagle' clearinghouse for AI cyber threats | cyberscoop.com Attackers vote themselves $20 million in BONK cryptocurrency | The Record CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com Apple says former employee exploited ‘rare' bug to download confidential files after leaving for OpenAI | TechCrunch Security Pegasus Spyware European Parliament Pega Committee Member | The Record Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security

The CyberWire
Behind the friendly face.

The CyberWire

Play Episode Listen Later Jul 20, 2026 29:19


Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here.  Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The Tech Blog Writer Podcast
How AI Voice Scams Turn Personal Phones Into a Business Risk

The Tech Blog Writer Podcast

Play Episode Listen Later Jul 18, 2026 18:10


Can you still trust an incoming phone call when AI can imitate a familiar voice, personalize the conversation and target information specifically to you? In this episode, I speak with Alex Quilici, CEO of YouMail, about how artificial intelligence is changing phone fraud and why the personal devices carried by employees are becoming part of the corporate attack surface. Alex explains how YouMail uses data from its consumer call-protection service to identify scam behavior, understand the type of fraud taking place and connect those patterns with the phone numbers involved. Advances in large language models have improved this analysis, but the same technology is also helping criminals build far more convincing campaigns. Generic robocalls are being replaced by personalized conversations designed to extract information, impersonate trusted people and manipulate victims. Fraudsters can use AI throughout the attack chain, from identifying targets and analyzing stolen data to generating dialogue and adapting an approach during the call. Alex argues that attackers have adopted these capabilities faster than many defenders expected because successful fraud produces an immediate financial return. The conversation also examines why voice biometrics can no longer be treated as sufficient proof of identity. As voice-cloning tools improve, companies may need to combine multiple forms of authentication and move sensitive communications into trusted applications. A call received through a banking app, for example, could give the customer greater confidence that the caller really represents their bank. For businesses, the risk extends beyond company-managed technology. Attackers can identify where someone works, learn about their role and contact them through a personal phone that may sit outside corporate monitoring. An employee's private number can therefore provide another route into the business through impersonation and social engineering. Alex also makes a persuasive case for collecting less personal data. Personalization can improve a service, but every additional piece of information becomes something an attacker might obtain during a breach. His advice is to identify the minimum information needed to deliver the intended experience rather than gathering data simply because it may prove useful later. Despite the seriousness of the threat, Alex offers evidence that coordinated action can produce results. He has seen brand-impersonation campaigns reduced from tens of millions of calls each month to around 100,000 through monitoring, disruption and cooperation between businesses and telecommunications providers. If AI is making fraudulent calls harder to recognize, should businesses stop treating the telephone network as a trusted communication channel by default? Listen to the episode and share your thoughts with me.