Podcasts about Attackers

  • 1,525PODCASTS
  • 3,053EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 3, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Attackers

Show all podcasts related to attackers

Latest podcast episodes about Attackers

The Non-Negotiables: Arsenal Podcast
E242: “Trying to Get Into Space” - Arsenal's Title Defence, Champions League Ambition & Squad Fitness (Season Preview)

The Non-Negotiables: Arsenal Podcast

Play Episode Listen Later Aug 3, 2026 78:26


The NN Pod completes its 2026/27 season preview by assessing what success now looks like for Arsenal after winning the Premier League, reaching the Champions League final and establishing themselves among Europe's strongest sides.The hosts debate whether retaining the league title should remain the priority or whether the Champions League has become the defining target. With the pressure of ending Arsenal's 22-year title wait finally removed, they consider whether the team can approach the new campaign with greater freedom while still managing the demands of defending its crown.Attention then turns to the condition of the squad. William Saliba's absence, uncertainty around Jurrien Timber and the physical load carried by players including Declan Rice, Martin Ødegaard, Bukayo Saka and Kai Havertz raise questions about rotation, recovery and whether Arsenal can keep their most important players available for the decisive months of the season.The episode also examines where the attack must improve after a title-winning campaign built heavily on defensive control, set pieces and narrow victories. The hosts assess the need for better individual returns, the potential evolution of Arsenal's midfield and right-hand side, and whether a fitter Ødegaard can help unlock a more expansive version of the team.Finally, the discussion moves to Max Dowman, the pathway for Arsenal's academy players, the club's continuing difficulties in the sales market and the transfer priorities that remain before the window closes. With Arsenal beginning the season as champions rather than challengers, the question is no longer how they reach the top — but how much further they can go.Chapters:(00:00) - Arteta's Non-Negotiables & Intro(00:49) - What Constitutes Success This Season?(03:46) - Arteta's Contract Situation(06:33) - Rotation, Injuries & Managing the Squad(09:11) - Can Fans Accept Rotation?(11:56) - Premier League or Champions League?(14:05) - Managing the Champions League Schedule(19:54) - Where Must Arsenal's Attack Improve?(22:13) - Better Returns From Arsenal's Attackers(25:05) - Can Arsenal Attack More Without Losing Control?(26:33) - Fine Margins, Set Pieces & Sustainability(29:45) - Replacing Saliba's Influence(34:15) - Ødegaard's Deeper Midfield Role(37:39) - Max Dowman's Breakout Potential(39:10) - Ife Ibrahim & Arsenal's Next Academy Prospects(44:16) - Can Other Hale End Players Break Through?(47:54) - Academy Pathways & Player Development(51:32) - Arsenal's Selling Problem(54:07) - Why Are Arsenal Players Undervalued?(01:02:27) - Arsenal's Remaining Transfer Priorities(01:05:03) - Meslier's Pre-Season Performance(01:06:16) - Vieira, Nelson, Jesus & the Oversized Squad(01:09:02) - Optimism Ahead of the New Season(01:12:14) - Arsenal at the Top of the Mountain(01:15:03) - Will Arsenal Play Better Football?(01:17:13) - Outro & What's Next

Security Conversations
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click' Exploits, and Magnets of Threats

Security Conversations

Play Episode Listen Later Jul 31, 2026 206:39


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear' advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

Cyber Security Today
OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

Cyber Security Today

Play Episode Listen Later Jul 31, 2026 11:38


OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

The CyberWire
Building a great firewall around AI.

The CyberWire

Play Episode Listen Later Jul 30, 2026 25:40


China embraces open AI models, then worries it's become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot worm. A critical Rails flaw demands urgent patching. Mac users are lured into installing malware through fake Claude guides. Amazon links a string of NPM compromises to North Korea. And Russia charges Telegram founder Pavel Durov with aiding terrorism. Ben Yelin joins us with a border search case that's breaking new ground. Don't bite the North Korean hand that feeds you. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies talking about a border search case that's breaking new ground. If you enjoyed this conversation, check out Ben on the Caveat podcast here.  Selected Reading As China's A.I. Gets Stronger, It Poses New Risks to Beijing (New York Times) Minnesota Water Utilities Suffer ‘Coordinated Cyber Attack' (GovTech) CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security (HSToday) ‘DangleGeddon': AI Could Weaponize Forgotten DNS Records at Global Scale (SecurityWeek) Word worm crawls into Copilot, spreads chaos (The Register) Possible arbitrary file read and remote code execution in Active Storage variant processing (GitHub) Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (Huntress) Amazon identifies North Korean hacker group behind open-source supply chain attacks (AWS Security Blog) Russia accuses Telegram CEO Pavel Durov of aiding terrorism in its latest digital crackdown (AP News) North Korea's elite hackers turned on their own government — and got caught (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Ekot
Ekot 08:00 Flera döda i ryska attacker mot Ukraina

Ekot

Play Episode Listen Later Jul 30, 2026 15:00


Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.

Telecom Reseller
Mutare: Voice Is the Last Unguarded Door into the Enterprise, Podcast

Telecom Reseller

Play Episode Listen Later Jul 28, 2026


By Doug Green “Voice is a security channel now, and it deserves the same controls businesses already apply to email and their networks.” In this Technology Reseller News and Cloud Communications Alliance podcast, Doug Green speaks with Chuck French of Mutare about the growing threat of voice-based attacks—and the opportunity for service providers to help customers close a major security gap. French says the voice channel has quietly become one of the last unprotected entry points into many organizations. Traditional tools can label suspicious calls, but they do not give individual businesses control over which calls are allowed, blocked, challenged or routed. The risk is growing rapidly as AI makes voice cloning, impersonation and convincing social-engineering scripts easier and less expensive to produce. Attackers can now imitate a bank, help desk or company executive in real time and at scale. Mutare's Voice Traffic Filter addresses this problem by providing what French describes as a voice firewall. The platform combines customer-defined policies, reputation data, STIR/SHAKEN information, threat-pattern analysis and a voice CAPTCHA that helps distinguish human callers from bots. Unlike carrier-level spam blocking, Mutare allows each organization to establish its own rules. A hospital, financial institution or small business can therefore apply policies suited to its particular risks and customer needs. Mutare has also developed a multitenant version of the platform for MSPs, CSPs and other channel partners. The cloud-hosted service requires no customer-premises equipment or major professional-services deployment. Providers can offer it as a recurring, consumption-based security service while retaining the customer relationship and setting their own pricing. French says Mutare's return to the Cloud Communications Alliance reflects this new service-provider model and its potential value to CCA members. For service providers, the message is clear: voice security represents both an urgent customer need and a new recurring-revenue opportunity. Listen to the podcast to learn how Mutare is helping businesses treat voice as a protected enterprise channel rather than an unguarded utility. Learn more at mutare.com.  

The CyberWire
The world's least private hackers.

The CyberWire

Play Episode Listen Later Jul 27, 2026 27:24


Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Bear Attack
S8 E22: Let's go to battle!

Bear Attack

Play Episode Listen Later Jul 27, 2026 42:31


Attacker's welcome to another radio episode. Polar bear tasked us with picking good songs to go to battle to, check out the attached playlist.https://open.spotify.com/playlist/72d013mV2izQQiQA2nLiNN?si=6mJPuByxQxKb47jcspFTSgLike, subscribe and most importantly spread the word.

The Dana & Parks Podcast
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dana & Parks Podcast
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dana & Parks Podcast

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Dave Glover Show
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Dave Glover Show

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Drivetime with DeRusha
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Drivetime with DeRusha

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Drivetime with DeRusha
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Drivetime with DeRusha

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

I’ve Got Questions with Mike Simpson
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

I’ve Got Questions with Mike Simpson

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

I’ve Got Questions with Mike Simpson
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

I’ve Got Questions with Mike Simpson

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Adam and Jordana
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Adam and Jordana

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Adam and Jordana
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Adam and Jordana

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Scoot Show with Scoot
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Scoot Show with Scoot

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Scoot Show with Scoot
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Scoot Show with Scoot

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Chad Hartman
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Chad Hartman

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Chad Hartman
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Chad Hartman

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Sausage King
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

The Sausage King

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

The Sausage King
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

The Sausage King

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Marty Griffin and Wendy Bell
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Marty Griffin and Wendy Bell

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Marty Griffin and Wendy Bell
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Marty Griffin and Wendy Bell

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

WWL First News with Tommy Tucker
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

WWL First News with Tommy Tucker

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

WWL First News with Tommy Tucker
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

WWL First News with Tommy Tucker

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Larry Richert and John Shumway
MINI TRUE CRIME ROUNDUP: World Cup sex trafficking, D4VD in court, Salman Rushdie's attacker and more

Larry Richert and John Shumway

Play Episode Listen Later Jul 26, 2026 35:39


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal and more. Festering audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Larry Richert and John Shumway
TRUE CRIME ROUNDUP: In the courtroom with D4VD and Vance Boelter, plus a Catholic preist scandal, Salman Rushdie's attacker and more

Larry Richert and John Shumway

Play Episode Listen Later Jul 26, 2026 56:44


This week, we have updates on major cases across the country. These include human trafficking cases linked to the World Cup, the D4VD murder case in California, a nurse accused of killing patients, the trial for author Salman Rushdie's attacker, a Catholic priest scandal, the Vance Boelter case in Minnesota, and more. Featuring audio from 1010 WINS in New York, WCCO News and Talk in the Twin Cities, KYW Newsradio in Philadelphia, the Dana & Parks Show out of KMBZ in Kansas City, Marty Griffin out of KDKA Radio in Pittsburgh, A New Morning out of WBEN News and Talk in Buffalo and the Dave Glover Show out of KMOX in St. Louis.

Learn Cardano Podcast
SecondFi Hack Update: 16.1M ADA Stolen, Recovery Timeline Explained

Learn Cardano Podcast

Play Episode Listen Later Jul 24, 2026 12:38 Transcription Available


SecondFi has released more detail on the wallet security incident that saw about 16.1 million ADA, roughly US$2.6 million, withdrawn from 374 wallets between 21 and 23 June. The update includes a public warning about fake recovery emails, findings from Groom Lake's forensic investigation, and a clearer explanation of the cryptographic flaw involved.Peter breaks down what SecondFi says happened, including the reported external attacker, the possibility of a second separate attacker, the per-transaction signature issue, and why public transaction data may have been enough to derive affected private key material under certain conditions. The episode also covers the wider discussion around cross-chain wallet code, CTRL Wallet, Yoroi migration, EMURGO tooling and the unauthorised publication of relevant code.The key safety message is simple: use only official SecondFi channels, do not click recovery emails, never share private keys, and wait for audited recovery and migration tooling rather than trusting anyone offering support through emails, comments or direct messages.Chapters:0:00 Fake Recovery Email Warning1:15 Incident Investigation Update2:18 Second Attacker Identified2:56 Cryptographic Root Cause3:45 Signing Formula Breakdown5:46 Vulnerable Wallet Library6:37 CTRL Wallet And Yoroi8:22 Published Code Question9:14 SecondFi Wind Down9:34 Recovery And Migration Tools11:25 Private Key SafetyWhat you'll learn:- SecondFi warned users that fake recovery emails are phishing attempts and that official communication is through its X account and technical support channels.- SecondFi said the June incident involved approximately 16.1 million ADA, about US$2.6 million, stolen from 374 wallets.- Groom Lake's independent investigation identified an external actor and suggested the primary operation may be linked to the DPRK-linked Lazarus Group.- The investigation also identified activity from a second separate attacker affecting a different set of wallets during the same window.- The root cause described by SecondFi was a subtle cryptographic flaw in how wallet software generated per-transaction signatures.- The signing issue meant data that should have depended on secret information could under some conditions be computed from public blockchain data.- SecondFi says the flaw has been patched, new wallets created with corrected software are not known to be affected, and the wallet is being wound down.- SecondFi is preparing safe migration functionality for early August and a zero-knowledge-proof recovery tool targeted for August after specialist third-party audits.Links & References:⚠️ Security Alert: FAKE RECOVERY EMAIL:- https://link.learncardano.io/m7FsGqOfficial SecondFi website:- https://link.learncardano.io/6llK2PWhat happened to SecondFi:- https://link.learncardano.io/fNJfCuThe signing math:- https://link.learncardano.io/5Pu20KVulnerable Library:- https://link.learncardano.io/cPTJG9Andrew Westberg's Opinion:- https://link.learncardano.io/cVwd7CEMURGO's internal JS framework Dullahan:- https://link.learncardano.io/0vu7M5⚠️ Recovery Update: Bounty Offer Made to Attacker:- https://link.learncardano.io/lG2331Website: https://link.learncardano.io/bQ68RcX/Twitter: https://link.learncardano.io/3a1QtvDisclaimer: This content is for educational purposes only. Nothing constitutes financial advice.DISCLAIMER: This content is for informational and educational purposes only and is not financial, investment, or legal advice. I am not affiliated with, nor compensated by, the project discussed—no tokens, payments, or incentives received. I do not hold a stake in the project, including private or future allocations. All views are my own, based on public information. Always do your own research and consult a licensed advisor before investing. Crypto investments carry high risk, and past performance is no guarantee of future results. I am not responsible for any decisions you make based on this content.

Relating to DevSecOps
Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

Relating to DevSecOps

Play Episode Listen Later Jul 24, 2026 46:40


Send us Fan MailAI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.

Security Conversations
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16

Security Conversations

Play Episode Listen Later Jul 23, 2026 136:03


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 106: We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 5:24 OpenAI admits it was the Hugging Face "hacker" 10:06 What's ExploitGym and who's on top of the leaderboard 12:59 Reward hacking: Did anyone train this thing not to cheat? 19:35 Marketing stunt or real incident? The zero-day in the package proxy 26:43 Was OpenAI already plugged into Hugging Face? 29:17 Paperclips, kill switches, and "going rogue" 34:49 Crisis comms, regulatory capture, and the second Cold War 43:02 Approve every action? Auto mode and swarms 50:10 "Lab leak" and calls for biosafety levels 1:00:31 The missing models: no Mythos, no Kimi, no independent referee 1:07:04 Costin's prediction: owning frontier-class hardware will require a license 1:13:41 fast16 as a benchmark: Inside the Sol Searching research 1:26:51 Compression and altitude: are reverse engineers being replaced? 1:41:24 Finding the gem in 100 samples, and the swarm frontier 2:00:41 Claude Opus 5 drops, Gemini 3.5 Flash Cyber

The Cybersecurity Defenders Podcast
AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 23, 2026 35:27


AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.In this episode:• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.• Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.Stories covered:• https://huggingface.co/blog/security-...• https://openai.com/index/hugging-face...Chapters:0:00 Cold open — the attacker was the model2:20 The whole story in one breath6:41 The timeline: two disclosures, five days apart11:37 Attack chain, part 1: getting in through a malicious dataset15:53 Attack chain, part 2: escaping the eval sandbox22:10 Motive, attribution & intent: cheating on the benchmark25:31 What was (and wasn't) exposed28:08 The bigger picture: the fire drill started the fire31:39 Lessons for labs, platforms, and solo developers33:15 New fear unlocked: models backdooring modelsThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00ze...• Apple Podcasts: https://podcasts.apple.com/us/podcast...• YouTube: / @limacharlieio Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #AIsecurity #OpenAI #HuggingFace #infosec

IT Privacy and Security Weekly update.
EP 301. Deep Dive. Broken Face and the AI, Privacy, and Security Weekly Update for the Week ending July 21st 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 23, 2026 44:10


Agentic AI is changing the threat landscape. We've moved beyond chatbots to autonomous systems that navigate files and take actions, expanding the attack surface. Recent incidents highlight the risk. Hugging Face suffered a breach where an AI agent became the entry point into production systems, showing that developer tools are now critical infrastructure. OpenAI's GPT-5.6 accidentally deleted user data, including a production database, after misconfiguring an environment variable—no malicious intent, just real consequences, underscoring the need for mandatory sandboxing. Meanwhile, SpaceX's Grok Build tool was found defaulting to collecting user repositories and sending them to internal cloud storage without clear consent, a reminder of “default-on” data exfiltration risks. A newer threat, Agent Data Injection, manipulates trusted metadata (like IDs or fields) with crafted inputs to mislead agents into unintended actions. A strong counterexample is the 1Password–Claude integration, which requires biometric approval before accessing credentials, keeping secrets out of the AI entirely. Human-in-the-loop controls should be standard.Legacy systems remain a major risk. Windows, OpenSSL, and WordPress continue to produce serious vulnerabilities. LegacyHive allows privilege escalation in Windows by loading another user's registry hive. HollowByte exploits a small crafted TLS payload in OpenSSL to trigger memory over-allocation and denial of service. The wp2shell chain enables unauthenticated remote code execution in WordPress core (versions 6.9–7.0), challenging the assumption that only plugins are risky. At the same time, Windows 10 is reaching end-of-life, yet roughly 17% of devices still run it, especially in cost-sensitive sectors like healthcare and small business. As Windows 11 patches are released, they effectively expose underlying flaws that attackers can reuse against unsupported systems.Trust itself is increasingly being exploited. Attackers are hiding inside legitimate platforms instead of building new infrastructure. HollowGraph malware uses compromised Microsoft 365 calendars as command-and-control channels, embedding instructions in far-future events and routing through normal Graph API traffic. A Norwegian transit test revealed electric buses could be remotely disabled via foreign SIM cards, highlighting risks in over-the-air control systems across transportation sectors. Ransomware groups are also evolving: JadePuffer's ENCFORGE targets AI model artifacts, treating trained models as high-value assets. Researchers have already used GPT models to build exploit chains, signaling AI's shift into offensive security roles.Governance gaps are compounding the problem. A ProPublica report found Microsoft used China-based engineers to support U.S. Department of Defense cloud systems via low-paid American intermediaries who relayed code without understanding it—technically compliant, but operationally risky. The UK scrapped its £1.8B digital ID program after execution failures. In another case, a single typo in a police report, combined with automated license plate recognition, led to a wrongful arrest, showing how systems can enforce human error without validation.The common thread is misplaced confidence—in AI agents, legacy systems, and formal compliance. Practical steps are clear: require human approval for sensitive AI actions, verify data access beyond contractual assurances, sandbox all agents, treat AI models as critical assets with backups, and update detection strategies to monitor abuse within trusted platforms, not just external threats.Trust, increasingly, is the vulnerability.

Risky Business
Risky Business #845 -- OpenAI's Skynet moment

Risky Business

Play Episode Listen Later Jul 22, 2026 69:31


On this week's show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft's GDID And much, much more! This week's show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it. This episode is also available on YouTube. Show notes OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com Security incident disclosure — July 2026 | Social Signals Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security Cheating behaviour in frontier model evaluations | AISI Work | Social Signals JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com Iran abused mobile networks' vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com Trump calls for new election security measures | NBC News Tech Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://www.justice.gov/usao-ndil/media/1450651/dl?inline | Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com 764 splinter group leader sentenced to 40 years in jail | cyberscoop.com Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com White House details ‘Gold Eagle' clearinghouse for AI cyber threats | cyberscoop.com Attackers vote themselves $20 million in BONK cryptocurrency | The Record CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com Apple says former employee exploited ‘rare' bug to download confidential files after leaving for OpenAI | TechCrunch Security Pegasus Spyware European Parliament Pega Committee Member | The Record Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security

All Villa No Filler
HERE WE GO! ASTON VILLA TO SIGN GARNACHO ON LOAN FROM CHELSEA | AVFC STILL NEED ATTACKERS

All Villa No Filler

Play Episode Listen Later Jul 22, 2026 41:17


Aston Villa have agreed a deal to sign Garnacho on loan from Chelsea with a conditional obligation to buy.FOLLOW US AND SUBSCRIBE ONLINE!WEBSITEwww.allvillanofiller.comGET IN TOUCHYouTube: Search All Villa No FillerTwitter: @VillaNoFillerInstagram: @allvillanofillerFacebook: All Villa No FillerEmail: allvillanofiller@gmail.comHOSTS: George Zielinski (@ZielinskiGeorge) / Frankie Maguire (@FrankieMaguire)PRODUCTION: Frankie Maguire#avfc #utv #astonvilla #football #villapark #soccer Hosted on Acast. See acast.com/privacy for more information.

RNZ: Checkpoint
LynnMall attacker held in extreme prisoners unit prior to attack

RNZ: Checkpoint

Play Episode Listen Later Jul 21, 2026 2:08


The Coroner's court has heard about the extreme prisoners unit where Ahamed Samsudeen was held before he attacked shoppers at an Auckland mall. Samsudeen was shot dead by police, ending his stabbing spree at LynnMall five years ago. A Coroner's inquest is underway into his death. Finn Blackwell was in court.

The CyberWire
Behind the friendly face.

The CyberWire

Play Episode Listen Later Jul 20, 2026 29:19


Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here.  Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

RNZ: Checkpoint
Questions over what effort was made to divert LynnMall attacker from extremism

RNZ: Checkpoint

Play Episode Listen Later Jul 20, 2026 2:27


A police National Security Group senior staff member has faced a grilling today over what efforts were made to divert LynnMall attacker Ahamed Samsudeen from the path of violent extremism. Samsudeen was shot dead by police in a West Auckland Woolworths supermarket after stabbing shoppers in September 2021. The coronial inquest into his death is examining his path to extremism and the time leading up to the attack. Finn Blackwell reports.   

The Tech Blog Writer Podcast
How AI Voice Scams Turn Personal Phones Into a Business Risk

The Tech Blog Writer Podcast

Play Episode Listen Later Jul 18, 2026 18:10


Can you still trust an incoming phone call when AI can imitate a familiar voice, personalize the conversation and target information specifically to you? In this episode, I speak with Alex Quilici, CEO of YouMail, about how artificial intelligence is changing phone fraud and why the personal devices carried by employees are becoming part of the corporate attack surface. Alex explains how YouMail uses data from its consumer call-protection service to identify scam behavior, understand the type of fraud taking place and connect those patterns with the phone numbers involved. Advances in large language models have improved this analysis, but the same technology is also helping criminals build far more convincing campaigns. Generic robocalls are being replaced by personalized conversations designed to extract information, impersonate trusted people and manipulate victims. Fraudsters can use AI throughout the attack chain, from identifying targets and analyzing stolen data to generating dialogue and adapting an approach during the call. Alex argues that attackers have adopted these capabilities faster than many defenders expected because successful fraud produces an immediate financial return. The conversation also examines why voice biometrics can no longer be treated as sufficient proof of identity. As voice-cloning tools improve, companies may need to combine multiple forms of authentication and move sensitive communications into trusted applications. A call received through a banking app, for example, could give the customer greater confidence that the caller really represents their bank. For businesses, the risk extends beyond company-managed technology. Attackers can identify where someone works, learn about their role and contact them through a personal phone that may sit outside corporate monitoring. An employee's private number can therefore provide another route into the business through impersonation and social engineering. Alex also makes a persuasive case for collecting less personal data. Personalization can improve a service, but every additional piece of information becomes something an attacker might obtain during a breach. His advice is to identify the minimum information needed to deliver the intended experience rather than gathering data simply because it may prove useful later. Despite the seriousness of the threat, Alex offers evidence that coordinated action can produce results. He has seen brand-impersonation campaigns reduced from tens of millions of calls each month to around 100,000 through monitoring, disruption and cooperation between businesses and telecommunications providers. If AI is making fraudulent calls harder to recognize, should businesses stop treating the telephone network as a trusted communication channel by default? Listen to the episode and share your thoughts with me.

Security Conversations
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack

Security Conversations

Play Episode Listen Later Jul 18, 2026 127:29


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs

RNZ: Morning Report
Former flatmate describes LynnMall attacker's ISIS fixation

RNZ: Morning Report

Play Episode Listen Later Jul 16, 2026 2:38


The former flatmate of a man who attacked customers at an Auckland supermarket, says he would talk about ISIS as if it was a sports team. Finn Blackwell reports.

Talos Takes
ARToken: How attackers are bypassing MFA and maintaining access

Talos Takes

Play Episode Listen Later Jul 15, 2026 18:08 Transcription Available


MFA and password resets aren't always enough.That's terrifying for security teams today. In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing/BEC-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. This turns a simple phishing click into a long-term breach.It's time to rethink your defenses. Join us as Cisco Talos Threat Researcher Michael Kelley breaks down how this new breed of automated attack works and, more importantly, how you can spot it. From hunting for suspicious device authorization grants to securing your cloud infrastructure, don't miss this critical look at the new frontier of business email compromise. Blog: https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/

RNZ: Checkpoint
LynnMall attacker became fixated with lawyer prior to attack

RNZ: Checkpoint

Play Episode Listen Later Jul 15, 2026 2:19


A coroner's inquest has heard that LynnMall attacker Ahamed Samsudeen became fixated with his lawyer and ended up stalking her in the lead up to his stabbing spree at a West Auckland supermarket. Samsudeen was shot dead by police after his attack at a Woolworths in 2021. Part of the inquiry is looking at whether Samsudeen's attitude towards women could have raised red flags about his risk to others. Finn Blackwell reports.

Bear Attack
S8 E20: The Roast of Blitz Bear

Bear Attack

Play Episode Listen Later Jul 13, 2026 59:56


Attackers, the time has come for Blitz's bear's finally episode! Please enjoy responsibly.Email us ideas for future episodes at bearattackpodcast@gmail.comAnd share the shit out of this dumpster fire.Love you byeeee!!!!

WhatCulture Wrestling
WWE NXT Review - Who Left As NXT Women's Champion! Tatum Paxley's Attacker REVEALED! New #1 Contenders Crowned! Spearsy's REVENGE?!

WhatCulture Wrestling

Play Episode Listen Later Jul 8, 2026 58:30


The Dadley Boyz review last night's episode of NXT and discuss...Who left as NXT Women's Champion?Tatum Paxley's attacker REVEALED!New #1 contenders crowned!Tank Ledger vs. Keanu Carver!Spearsy's REVENGE?!ENJOY!Follow us on Twitter:@AdamWilbourn@MichaelHamflett@MSidgwick@WhatCultureWWEFor more awesome content, check out: whatculture.com/wwe Hosted on Acast. See acast.com/privacy for more information.

WhatCulture Wrestling
WWE NXT Preview - Will Nattie Become NXT Women's CHAMPION? How Will Tony D'Angelo React To Naraku's Attack? Who Will Be The #1 Contenders? A Mystery Attacker With No Name?!

WhatCulture Wrestling

Play Episode Listen Later Jul 7, 2026 62:52


The Dadley Boyz preview tonight's NXT and discuss...Will Nattie become NXT Women's CHAMPION?How will Tony D'Angelo react to Naraku's attack?Who will be the #1 contenders?Niko Vance vs. Shiloh Hill!A mystery attacker with no name?!ENJOY!Follow us on Twitter:@AdamWilbourn@MSidgwick@MichaelHamflett@WhatCultureWWEFor more awesome content, check out: whatculture.com/wwe Hosted on Acast. See acast.com/privacy for more information.

Late Confirmation by CoinDesk
How An Attacker Stole $20M From BonkDAO Using Its Own Rules | CoinDesk Daily

Late Confirmation by CoinDesk

Play Episode Listen Later Jul 7, 2026 1:44


Inside BONK's $20M attack. An attacker spent $4.4 million buying BONK tokens, passed a malicious governance proposal with just 7 wallets voting, and walked away with $20 million from the treasury — without hacking anything. CoinDesk's Jennifer Sanasie hosts "CoinDesk Daily." - This episode is brought to you by RealFi, a smarter stablecoin, backed by real-world assets. Find out more at⁠⁠⁠ realfi.co⁠⁠⁠. - Ledn provides a secure and transparent way to access liquidity while maintaining your bitcoin holdings. Perfect 8 year track record of keeping clients assets safe. Don't sell your bitcoin. Get a bitcoin-backed loan. Check out your rate by using their loan calculator at⁠⁠⁠ ledn.io⁠⁠⁠ - JPEG Trading is a global proprietary trading firm specializing in cryptocurrency and decentralized finance markets. From market structure and liquidity provision to quantitative trading strategies, JPEG Trading operates across the full spectrum of blockchain-based assets. Follow @jpegtrading on X to stay ahead of the latest developments in digital asset markets:⁠⁠⁠ https://x.com/jpegtrading⁠⁠⁠ - This episode was hosted by Uyen Truong “CoinDesk Daily” is produced by Jennifer Sanasie and edited by Victor Chen.

The CyberWire
NetNut gets cracked.

The CyberWire

Play Episode Listen Later Jul 6, 2026 28:21


The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through malicious websites and SEO poisoning. Researchers trick Claude into remote code execution. AI's strain on the power grid is complicated. Monday business briefing. Our guest is Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. Anime and AI meet adolescent antics.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. You can learn more here. Selected Reading FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network (HackRead) Russian hackers steal government logins (The Telegraph) Lawmaker Probing Pegasus Spyware Infected Using Same Malware (BankInfo Security) PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (Jamf) Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek) Red teamers turned Claude Desktop into a double agent to do their evil bidding (The Register) How Data Centers Grid Instability Threatens Reliability (IEEE Spectrum) Quantifind has secured $200 million in a funding round led by Summit Partners. (N2K Pro Business Briefing)  Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts (The Straits Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices