POPULARITY
Categories
Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here. Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
A police National Security Group senior staff member has faced a grilling today over what efforts were made to divert LynnMall attacker Ahamed Samsudeen from the path of violent extremism. Samsudeen was shot dead by police in a West Auckland Woolworths supermarket after stabbing shoppers in September 2021. The coronial inquest into his death is examining his path to extremism and the time leading up to the attack. Finn Blackwell reports.
Can you still trust an incoming phone call when AI can imitate a familiar voice, personalize the conversation and target information specifically to you? In this episode, I speak with Alex Quilici, CEO of YouMail, about how artificial intelligence is changing phone fraud and why the personal devices carried by employees are becoming part of the corporate attack surface. Alex explains how YouMail uses data from its consumer call-protection service to identify scam behavior, understand the type of fraud taking place and connect those patterns with the phone numbers involved. Advances in large language models have improved this analysis, but the same technology is also helping criminals build far more convincing campaigns. Generic robocalls are being replaced by personalized conversations designed to extract information, impersonate trusted people and manipulate victims. Fraudsters can use AI throughout the attack chain, from identifying targets and analyzing stolen data to generating dialogue and adapting an approach during the call. Alex argues that attackers have adopted these capabilities faster than many defenders expected because successful fraud produces an immediate financial return. The conversation also examines why voice biometrics can no longer be treated as sufficient proof of identity. As voice-cloning tools improve, companies may need to combine multiple forms of authentication and move sensitive communications into trusted applications. A call received through a banking app, for example, could give the customer greater confidence that the caller really represents their bank. For businesses, the risk extends beyond company-managed technology. Attackers can identify where someone works, learn about their role and contact them through a personal phone that may sit outside corporate monitoring. An employee's private number can therefore provide another route into the business through impersonation and social engineering. Alex also makes a persuasive case for collecting less personal data. Personalization can improve a service, but every additional piece of information becomes something an attacker might obtain during a breach. His advice is to identify the minimum information needed to deliver the intended experience rather than gathering data simply because it may prove useful later. Despite the seriousness of the threat, Alex offers evidence that coordinated action can produce results. He has seen brand-impersonation campaigns reduced from tens of millions of calls each month to around 100,000 through monitoring, disruption and cooperation between businesses and telecommunications providers. If AI is making fraudulent calls harder to recognize, should businesses stop treating the telephone network as a trusted communication channel by default? Listen to the episode and share your thoughts with me.
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs
The former flatmate of a man who attacked customers at an Auckland supermarket, says he would talk about ISIS as if it was a sports team. Finn Blackwell reports.
MFA and password resets aren't always enough.That's terrifying for security teams today. In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing/BEC-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. This turns a simple phishing click into a long-term breach.It's time to rethink your defenses. Join us as Cisco Talos Threat Researcher Michael Kelley breaks down how this new breed of automated attack works and, more importantly, how you can spot it. From hunting for suspicious device authorization grants to securing your cloud infrastructure, don't miss this critical look at the new frontier of business email compromise. Blog: https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/
A coroner's inquest has heard that LynnMall attacker Ahamed Samsudeen became fixated with his lawyer and ended up stalking her in the lead up to his stabbing spree at a West Auckland supermarket. Samsudeen was shot dead by police after his attack at a Woolworths in 2021. Part of the inquiry is looking at whether Samsudeen's attitude towards women could have raised red flags about his risk to others. Finn Blackwell reports.
See omnystudio.com/listener for privacy information.
The former mentor of the man who went on a frenzied stabbing attack at an Auckland supermarket has spoken about his radical ideas of Islam. Ahamed Samsudeen was shot twelve times by police, ending the attack that saw six people stabbed and another injured. A coronial inquest into his death is underway, looking at the time leading up to the attack and his path to violent extremism. Finn Blackwell reports.
A man who was hiding in the bushes at a popular park in Melbourne's south-east grabbed a woman before approaching a second woman and attempting to lure her into a nearby tunnel.See omnystudio.com/listener for privacy information.
AI is changing cybersecurity faster than most businesses realise. In this episode of Channel Chat, Rob Demain, CEO & Founder of e2e-assure joins Marc Sumner to discuss why cyber resilience now matters more than prevention, how attackers are using AI, and why the future of cyber defence will be AI vs AI. They cover: Why speed is everything in cyber defence The biggest mistakes businesses still make How AI is transforming both attackers and defenders What MSPs and IT leaders need to do next Why Rob believes "15 minutes is too long" when responding to threats A fascinating conversation for MSPs, IT leaders and business owners preparing for the next era of cybersecurity.
Attackers, the time has come for Blitz's bear's finally episode! Please enjoy responsibly.Email us ideas for future episodes at bearattackpodcast@gmail.comAnd share the shit out of this dumpster fire.Love you byeeee!!!!
The radicalisation of a man who stabbed six people at an Auckland mall will be a key question considered by a coroner over the coming weeks. The next two phases of an inquiry into the death of LynnMall attacker Ahamed Samsudeen began in Auckland today. Samsudeen's attack on shoppers inside a supermarket within the mall ended when he was shot dead by police. Finn Blackwell reports from the inquest.
JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk
This episode examines three emerging cybersecurity threats affecting healthcare organizations: Microsoft 365 Groups being exploited for calendar-based phishing attacks, newly discovered vulnerabilities in the widely used DICOM Toolkit that could impact medical imaging systems, and a data breach that originated through social engineering targeting third-party applications. The hosts provide actionable guidance on tightening platform configurations, vetting vendors, and strengthening staff training to address these preventable security gaps.
The Dadley Boyz review last night's episode of NXT and discuss...Who left as NXT Women's Champion?Tatum Paxley's attacker REVEALED!New #1 contenders crowned!Tank Ledger vs. Keanu Carver!Spearsy's REVENGE?!ENJOY!Follow us on Twitter:@AdamWilbourn@MichaelHamflett@MSidgwick@WhatCultureWWEFor more awesome content, check out: whatculture.com/wwe Hosted on Acast. See acast.com/privacy for more information.
The Dadley Boyz preview tonight's NXT and discuss...Will Nattie become NXT Women's CHAMPION?How will Tony D'Angelo react to Naraku's attack?Who will be the #1 contenders?Niko Vance vs. Shiloh Hill!A mystery attacker with no name?!ENJOY!Follow us on Twitter:@AdamWilbourn@MSidgwick@MichaelHamflett@WhatCultureWWEFor more awesome content, check out: whatculture.com/wwe Hosted on Acast. See acast.com/privacy for more information.
Inside BONK's $20M attack. An attacker spent $4.4 million buying BONK tokens, passed a malicious governance proposal with just 7 wallets voting, and walked away with $20 million from the treasury — without hacking anything. CoinDesk's Jennifer Sanasie hosts "CoinDesk Daily." - This episode is brought to you by RealFi, a smarter stablecoin, backed by real-world assets. Find out more at realfi.co. - Ledn provides a secure and transparent way to access liquidity while maintaining your bitcoin holdings. Perfect 8 year track record of keeping clients assets safe. Don't sell your bitcoin. Get a bitcoin-backed loan. Check out your rate by using their loan calculator at ledn.io - JPEG Trading is a global proprietary trading firm specializing in cryptocurrency and decentralized finance markets. From market structure and liquidity provision to quantitative trading strategies, JPEG Trading operates across the full spectrum of blockchain-based assets. Follow @jpegtrading on X to stay ahead of the latest developments in digital asset markets: https://x.com/jpegtrading - This episode was hosted by Uyen Truong “CoinDesk Daily” is produced by Jennifer Sanasie and edited by Victor Chen.
The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through malicious websites and SEO poisoning. Researchers trick Claude into remote code execution. AI's strain on the power grid is complicated. Monday business briefing. Our guest is Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. Anime and AI meet adolescent antics. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Gabi Reish, VP Product, Threat Intelligence & Exposure Management at Bitsight, sharing insights on how cybercriminal activity is shifting. You can learn more here. Selected Reading FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network (HackRead) Russian hackers steal government logins (The Telegraph) Lawmaker Probing Pegasus Spyware Infected Using Same Malware (BankInfo Security) PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (Jamf) Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek) Red teamers turned Claude Desktop into a double agent to do their evil bidding (The Register) How Data Centers Grid Instability Threatens Reliability (IEEE Spectrum) Quantifind has secured $200 million in a funding round led by Summit Partners. (N2K Pro Business Briefing) Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts (The Straits Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Attackers! As you know Blitz Bear is going to be M.I.A. for awhile, so we decided a good send off would be to listen to two of his favorite bands. The Amity Affliction and August Burns Red.https://open.spotify.com/playlist/5ZuiU6zfXO4gCaPNKEiN9g?si=qxOsiK08St6th-mh3XMAVwAs always tell everyone, we really appreciate it!
Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from Seoul
Spurs Chat: Discussing all Things Tottenham Hotspur: Hosted by Chris Cowlin: The Daily Tottenham/Spurs Podcast Hosted on Acast. See acast.com/privacy for more information.
Originally Aired July 31, 2019In this episode I review Smackdown Live that aired 7/30/19 discussing some of the highlights of the show including Drew McIntyre's losing streak, Sami Zayn as Aleister Black's next opponent, the fans slowly turning on Bayley and Trish's solid night on the mic.Go AD-FREE at patreon.com/wwepodcastBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-wwe-podcast--2187791/support.
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.htmlChapters:0:00 Intro & catching up1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)9:18 CISA advisory: billboard & highway sign controllers13:46 Cursor "DuneSlide" prompt-injection sandbox escape20:34 Claude Fable 5 export controls lifted28:17 Data centers, nuclear déjà vu & the AI race33:39 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #promptinjection
Ekots dagliga, längre sändningar med nyheter och fördjupning. Lyssna på alla avsnitt i Sveriges Radios app.
Alyssa Thomas was suspended for one game by the WNBA...after she viciously attacked Caitlin Clark. Now that Alyssa Thomas is returning from suspension...Alyssa Thomas is pleading for sympathy and turning herself into the victim. We reveal and react to Alyssa Thomas...demanding the WNBA police fan behavior. We compare the WNBA to communism...and discuss the rampant entitlement throughout the league. We explain why Alyssa Thomas is proving that the WNBA isn't ready for primetime...and why the WNBA should return to being a niche product. USE PROMO CODE BTL25 TO SAVE 25% WITH SUGAR MOUNTAIN TRADING: https://sugarmountaintrading.com
For review:1. Talks between Cuba and the U.S. are at a standstill, despite the island recently approving a series of free-market reforms, Cuban Foreign Minister Bruno Rodríguez announced Tuesday.2. Attackers shot dead two members of Iran's Islamic Revolutionary Guard Corps at their home in the western city of Paveh, near the border with Iraq's Kurdistan region, state media reported Tuesday.It was not immediately clear who was behind the shooting. 3. Top US envoys Steve Witkoff and Jared Kushner were in Doha on Tuesday for meetings with Qatari mediators to discuss negotiations with Iran, but Qatar and Iran said there would be no high-level meeting between Washington and Tehran on Tuesday or in the coming days.4. Israeli Prime Minister Benjamin Netanyahu told IDF troops in the southern Lebanon security zone on Tuesday that the military would remain in the area for the foreseeable future, crediting the soldiers' work for the recent agreement between Israel, Lebanon, and the US that demands Hezbollah's disarmament to enable an Israeli withdrawal.5. The Israel Defense Forces' Military Intelligence Directorate and Southern Command submitted a warning last week to Chief of Staff Lt. Gen. Eyal Zamir that Hamas's military wing is preparing for renewed war with Israel, the Kan public broadcaster reported Sunday.6. Russian President Putin has admitted that there was no deal with President Trump to end the war in Ukraine, after Kremlin officials insisted such an agreement was made between the two leaders last August in Alaska.7. China called on Ukraine and Russia to resume peace talks “as soon as possible” and reiterated its support for an immediate ceasefire during a UN Security Council meeting on Monday, June 30.8. Outgoing UK Prime Minister Keir Starmer has announced that British defense spending will reach close to £80 billion ($105 billion) annually by 2029.9. Based in Townsville in northern Queensland, the Australian Army's 3rd Brigade is undergoing a massive transformation, as the heavy armored formation absorbs whole new fleets of vehicles.10. Russia and China conducted joint bomber patrol flights on Saturday for the first time this year, prompting Japan and South Korea to scramble fighter aircraft.
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 103: We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 — Introductory banter, Thinkst Canary sponsorship 2:55 — Why threat intel analysts are built for the AI moment 11:09 — Government takes the wheel: Mythos, Fable & the frontier labs 16:15 — Did the government go too far/not far enough? 25:42 — Anthropic's "best PR campaign in history" 31:52 — Alibaba, distillation & the model-router cartel 40:58 — Costin's stack: Chinese open-weight models & token economics 46:12 — Dumping, evals & the real work of AI engineering 1:04:32 — Soft power: how the world gets pushed toward China 1:14:43 — "The bullshit": over-refusal & the Opus 4.8 regression 1:32:03 — The trillion-dollar IPO endgame 1:35:49 — The Klue OAuth breach and secure-by-default 1:45:32 — Shout-outs: UAP jellyfish, LABScon 2026
In honor of America's 250th, Attacker's we present a Bear Attack Radio that screams Freedom and fun.Enjoy!
The Tim Conway Jr. Show Hour 2 (6.25) This hour goes from hope to havoc. We kick off with a real breast cancer breakthrough — the FDA just greenlit Trodelvy as a first-line treatment for the hardest-to-treat triple-negative breast cancer, the first ADC approved across PD-L1 status, and it's already proving more durable than chemo. Then sports get ugly: the WNBA suspended Phoenix's Alyssa Thomas and slapped her with a flagrant 2 for driving her fist into Caitlin Clark's throat — a hit refs somehow missed live. Next, the House Whisperer himself, Dean Sharp, breaks down home electrical do's and don'ts (electricity isn't magic, it's water in a pipe) and the man-stuff guide to buying power tools. And we close on the stench story gripping LA: 85 million pounds of spoiled meat, seafood, and bread rotting inside a burned-out Boyle Heights warehouse, as crews race to haul it out before it becomes a full-blown biohazard. Breakthroughs, cheap shots, and a biohazard. Hit play. breakthrough, game-changer, greenlit, FDA-approved, cheap shot, flagrant, dropped the hammer, no-call, caught on camera, ugly, stench, biohazard, rotting, race against time, hauled out, do's and don'ts, man stuff, must-know, dangerous, exposed, accountability, fallout, sidelined, suspended, slammed, viral, jaw-dropping, hope vs. havoc, the truth about, what you need to know. See omnystudio.com/listener for privacy information.
In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.
All links and images can be found on CISO Series Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and George Finney, CISO, University of Texas System. Joining is Sean Walls, CISO, Bob's Discount Furniture. In this episode: Asymmetric accounting Sometimes it really is that easy The spirit of the saying The cheapest way in A huge thanks to our sponsor, Native Security Native is the Cloud Security Control Plane. It helps enterprises enforce secure-by-design architecture across multi-cloud environments by translating security intent into the cloud provider's built-in controls, previewing impact before rollout, and keeping enforcement aligned as the environment changes.
In the headlines today, thousands of vacationers are buying medications in Thailand that would usually require a prescription back home, what are the risks, and are there benefits? Then, a dispute between a YouTuber and his cameraman allegedly turns violent, in crime news three women are suspected of stealing 30,000 baht from a Brit snoozing in public, also nine have been arrested in a nationwide data trafficking operation, down in Samui the roosters are apparently out of control, and finally the King and Queen are set to head to France for a state visit.
LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here. Selected Reading Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch) Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch) Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps (Zafran) 23 ClawHub Plugins Squat Official Org Scopes (Manifold Security) Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr) Indian auto giant Bajaj Auto hit by ransomware incident (The Record) U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times) Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek) US adds sanctions against accused Cambodian scammers Prince Group (Reuters) Ushering in the Next Frontier of Quantum Innovation (The White House) Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK. Attackers exploit Gravity SMTP flaw to harvest secrets From WordPress sites. Executive Order accelerates federal shift to post-quantum cryptography. Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts. Keeping tabs on the tab-keepers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts and where more effort needs to be made to get the U.S. and its critical infrastructure quantum-ready. Selected Reading 'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk (Reuters) Intel agencies: Frontier AI models will reshape cybersecurity faster than expected (CyberScoop) Anthropic's Mythos AI broke into almost all NSA classified systems in hours (SecurityAffairs) Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (TechCrunch) FortiBleed campaign used custom FortiGate sniffer to steal credentials (BleepingComputer) Gizmodo readers hit with ClickFix malware prompts after account compromise (The Register) New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones (SecurityWeek) TFL Hackers Admit Carrying Out Cyberattack That Cost £39M (Law360) Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin (Wordfence) Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration (Security Week) Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
AI isn't necessarily creating impossible new attacks, but it is drastically lowering the technical barrier to entry for cybercriminals. In this episode, Ashish Rajan speaks with Simon Biggs, Cyber Incident Response Specialist at Varonis, about how AI is accelerating the attack lifecycle. Simon explains how attackers are using AI kits to instantly set up ephemeral phishing portals, query SQL databases in minutes, and bypass AI guardrails to compile Remote Access Trojans (RATs). We also discuss the shift in ransomware tactics from "encryption-first" to "data-theft-first," and how AI empowers attackers to post-process terabytes of stolen data to monetize it in novel ways. For defenders, the message is clear: if your S3 access logs and SQL transaction logs aren't turned on before a breach, your forensics team won't be able to tell lawyers or regulators what data was actually lost. Discover why data classification and proactive logging are the ultimate lifelines for IR teams in the AI age. Guest Socials - Simon's Linkedin Podcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction(02:00) Simon Biggs' Background in Law Enforcement and Varonis(03:10) Is There a Huge Volume of Sophisticated AI Attacks?(04:10) How AI Accelerates SQL Queries and Business Email Compromise (BEC)(05:15) Why AI Kits Are the New Metasploit and BloodHound(08:15) Varonis Threat Labs: Copilot Prompt Injection Vulnerability(09:20) The Forensic Challenge: Auditing Prompts vs. Understanding AI Output(10:30) Tricking AI Guardrails to Compile Malware(12:15) Defensive Strategies: Shadow AI, Permissions, and Logging(15:30) Using Defensive AI and BloodHound for Threat Hunting(17:30) Why Ransomware is Now "Data First, No Encryption"(20:50) The Legal Nightmare of Unclassified Stolen Data(23:20) Why Windows Forensics Can't Tell You What Data Was Stolen(31:20) The Crucial Importance of Enabling S3 and Cloud Audit Logs(35:10) How AI Allows Attackers to Post-Process Terabytes of Stolen DataResources spoken about during the episode:Simon's Research at VaronisArticle about SearchLeak Article about RepromptVaronis Threat LabsThank you to Varonis for sponsoring this episode of Cloud Security Podcast
Send us Fan MailA champagne bottle can teach you more about cybersecurity than you'd expect. We start with sabrage, the old French tradition of opening champagne with a saber, and we get hands-on with the real mechanics: finding the bottle seam, aiming at the pressure-focused weak spot under the lip, and using a controlled slide instead of raw strength. When it works, it's clean, safe, and oddly satisfying. When it doesn't, it's a fast lesson in why technique beats confidence. From there, we turn the physics into a security mindset. Attackers rarely “cut through the whole bottle” they hunt for the one weak point that breaks everything open. We talk about what that means for cybersecurity leadership, preparedness, and incident response: practice before you're under pressure, keep your defenses sharp on campaign, and avoid the expensive pattern of procrastinating until an incident forces a rushed buying spree. Readiness is a balance, not a single obsession. Then we nerd out on the blades themselves, from a Napoleonic-era hanger built for this kind of work to a Scottish basket-hilted broadsword and a stunning 1600s katana. We get into why European swords often chase flexibility while Japanese blades lean on differential hardening for a harder edge, plus the cultural story behind foreign steel and expressive fittings. We wrap by cutting fruit and confronting the final lesson: hesitation changes outcomes, so train your form until decisive action feels normal. If you enjoyed the mix of history, hands-on technique, and practical cybersecurity takeaways, subscribe, share this with a friend who'd try sabrage, and leave a review with your favorite “weak spot” lesson from the conversation.
The FBI just foiled an expansive domestic terror plot that targeted the UFC Freedom 250 event on the White House South Lawn — drone bombs, a pre-staged sniper team, and a second wave to storm the gate. But the part legacy media won't tell you is the motive: per the federal affidavit, suspects like 19-year-old Tycen Proper and California's Michael Alan Thomas wanted to target "capitalist elites," billionaires, and AIPAC-funded politicians — rhetoric that sounds word-for-word like AOC, Bernie Sanders, and Graham Platner. For free and unbiased Medicare help, dial 580-308-0975 to speak with my trusted partner, Chapter, or go https://askchapter.org/oconnor *Paid Partnership* SHOP OUR MERCH: https://store.townhallmedia.com/ BUY A LARRY MUG: https://store.townhallmedia.com/products/larry-mug Watch LARRY with Larry O'Connor LIVE — Monday-Thursday at 12PM Eastern on YouTube, Facebook, & Rumble! Find LARRY with Larry O'Connor wherever you get your podcasts! SPOTIFY: https://open.spotify.com/show/7i8F7K4fqIDmqZSIHJNhMh?si=814ce2f8478944c0&nd=1&dlsi=e799ca22e81b456f APPLE: https://podcasts.apple.com/us/podcast/larry/id1730596733 Become a Townhall VIP Member today and use promo code LARRY for 50% off: https://townhall.com/subscribe?tpcc=poddescription https://townhall.com/ https://rumble.com/c/c-5769468 https://www.facebook.com/townhallcom/ https://www.instagram.com/townhallmedia/ https://twitter.com/townhallcom Chapter: Chapter and its affiliates are not connected with or endorsed by any government entity or the federal Medicare program. Chapter Advisory, LLC represents Medicare Advantage HMO, PPO, and PFFS organizations and stand alone prescription drug plans that have a Medicare contract. Enrollment depends on the plan’s contract renewal. While we have a database of every Medicare plan nationwide and can help you to search among all plans, we have contracts with many but not all plans. As a result, we do not offer every plan available in your area. Currently we represent 50 organizations which offer 18,160 products nationwide. We search and recommend all plans, even those we don’t directly offer. You can contact a licensed Chapter agent to find out the number of products available in your specific area. Please contact Medicare.gov, 1-800-Medicare, or your local State Health Insurance Program (SHIP) to get information on all of your options.Become a Townhall VIP member with promo code "LARRY": https://townhall.com/subscribeSee omnystudio.com/listener for privacy information.
We also talk about the World Cup, because that is more fun! This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit redwhitebluesfc.substack.com
The boys from All With Smiling Faces Podcast are back to put Newcastle United's attackers under the microscope!
Origianlly Aired July 2019In this episode I review Smackdown Live that aired 7/30/19 discussing some of the highlights of the show including Drew McIntyre's losing streak, Sami Zayn as Aleister Black's next opponent, the fans slowly turning on Bayley and Trish's solid night on the mic.Go AD-FREE at https://Patreon.com/WWEPodcastBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-wwe-podcast--2187791/support.
Welcome to The Strongest Links, where Gav, Ashley, Kev, and Chris break down the most credible transfer links to Liverpool FC under Andoni Iraola. Each week, we analyze potential targets using performance data, player comparisons, tactical fit, and future potential. For an ad free watch head over to our Patreon channel were all members (free or paid) get our youtube shows ad free! JOIN OUR PATREON - patreon.com/TalkinKopPodcast Subscribe, Like, Hit the bell icon and never miss another show! ** All views on the show are those of the individual and do not represent those of the Talkin' Kop ** lfc fan channel - liverpool fan channel - liverpool fc - lfc - lfc fan reaction - liverpool fan tv - lfc fan tv - lfc fan media - liverpool match reaction - lfc live chat - liverpool live chat - anfield reaction - liverpool live podcast - lfc live podcast - liverpool news - lfc news - liverpool free content - lfc live shows - liverpool analysis - lfc matchday - liverpool matchday - liverpool transfer news - liverpool transfer updates - lfc transfer news - liverpool live - liverpool podcast Training in the Fire by Twin Musicom is licensed under a Creative Commons Attribution 4.0 license. https://creativecommons.org/licenses/by/4.0/ Artist: http://www.twinmusicom.org/ Learn more about your ad choices. Visit podcastchoices.com/adchoices
AP correspondent Charles de Ledesma reports a dozen people have been killed in a Johannesburg suburb.
Have we become so used to data breaches that we no longer stop to think about what they actually mean for the people affected? In this episode of Tech Talks Daily, I speak with Simon Pamplin, CTO at Certes, about why cybercrime remains one of the biggest threats facing businesses and consumers alike. While headlines about ransomware attacks and data breaches appear almost every day, Simon argues that too many organizations are still treating cybersecurity as a technology problem rather than a business risk with real human consequences. Our conversation begins with a simple but powerful question. Why are so many companies still focused on protecting networks when attackers are really after the data itself? Simon explains why traditional perimeter-based security approaches are struggling in a world where information moves between cloud environments, devices, applications, and partners far beyond the boundaries organizations once controlled. We also discuss the personal cost of cybercrime. Behind every breach announcement are real people whose financial records, personal details, healthcare information, and digital identities may have been exposed. Simon shares why the impact often extends far beyond resetting a password, creating financial, emotional, and reputational consequences that can last for years. Another major theme is the growing concern about quantum computing and the rise of harvest-and-decrypt attacks. While fully realized quantum computing may still be in the future, cybercriminals are already collecting encrypted data with the expectation that future technology will eventually unlock it. Simon explains why businesses need to think about protecting sensitive information today rather than waiting for tomorrow's threats to become reality. The conversation also examines the growing pressure from regulations such as GDPR, DORA, and NIS2. With larger penalties and increased regulatory scrutiny, organizations are facing greater accountability for how they handle and protect customer information. Simon argues that trust has become one of the most valuable assets a business can possess and one of the easiest to lose. Of course, no cybersecurity discussion would be complete without addressing AI. We explore how AI is making attacks faster, cheaper, and more accessible while also creating opportunities for defenders. Simon shares his thoughts on why businesses must rethink long-held assumptions and prepare for a future in which cybercriminals can automate many techniques that once required significant expertise. Throughout our discussion, Simon returns to a consistent message. Attackers target data because it has value. Organizations that focus their efforts on protecting that data, wherever it travels, will be in a far stronger position than those relying solely on traditional defenses. If you are responsible for cybersecurity, risk management, compliance, or digital transformation, this episode offers a timely discussion of what businesses should prioritize as threats continue to evolve. Customer trust becomes harder to earn and easier to lose. When the next breach makes headlines, will it simply be another news story, or will it be a reminder that every piece of stolen data belongs to a real person whose life could be affected?
The Athletic writer debriefs the recent press interview with Leeds United chairman Paraag Marathe and weighs up the club's summer transfer strategy. Hosted on Acast. See acast.com/privacy for more information.
A federal watchdog questions NIST over its vulnerability database backlog. Google patches an Android zero-day. Citizen Lab exposes a powerful location-tracking platform. Malware hides commands in Steam comments. Researchers spot AI-assisted malware development. Attackers compromise Red Hat's npm namespace. DriveSurge spreads malware through ClickFix and fake updates. FreePBX patches a critical flaw. And Dashlane responds to a brute-force attack. Our guest is Laure Lydon, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on digital health platforms. Meta's AI support bot proves a bit too eager to help. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Maria Varmazis speaks with Laure Lydon, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on privacy, security, and trust in digital health platforms, especially in sensitive areas like women's health. This interview is part of our partnership with Infosecurity Europe. Selected Reading Inspector general finds NIST mistakes have made vulnerability database ineffective (The Record) Google fixes one actively exploited Android zero-day, 124 flaws (Bleeping Computer) Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech (The Citizen Lab) GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure (Security Affairs) Threat Actor Uses AI to Build EDR Evasion Tools (Infosecurity Magazine) Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets (Infosecurity Magazine) Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks (Bleeping Computer) Critical Hard-Coded Credentials Vulnerability in FreePBX User Control Panel (Beyond Machines) Dashlane password manager users locked out by brute force attacks (Bleeping Computer) Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The FBI warns attackers are abusing Microsoft OAuth authentication. India pushes faster patching as AI speeds up cyberattacks. Iranian hackers blend phishing with SEO poisoning. Anthropic's AI finds thousands of open source flaws, while AI also reshapes bug bounties and fuels supply-chain attacks hitting thousands of GitHub repos. Plus, a new LMS zero-day, bulletproof hosting arrests in the Netherlands, FTC action over bogus “active listening” claims, and another busy week for cyber funding and M&A. Our guest is Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation.” Please disregard all searches for disregard. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation." Selected Reading FBI warns of Kali365 phishing service targeting Microsoft 365 accounts (Bleeping Computer) India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws (Infosecurity Magazine) Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign (Infosecurity Magazine) Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects (SecurityWeek) HackerOne takes an axe to its bug bounty rewards (The Register) Automated 'Megalodon' Campaign Spreads GitHub Repo Backdoors (GovInfo Security) Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment (SecurityWeek) Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands (SecurityWeek) FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (Federal Trade Commission) Socket raises $60 million in Series C funding. (N2K Pro Business Briefing) You can no longer Google the word 'disregard' (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Parliament in Israel passes a law to set up special military trials for Palestinians accused of taking part in the deadly Hamas-led attack in October 2023. The tribunal will be able to sentence those convicted to death. Also in this podcast: the European Union approves new sanctions against Israeli settlers accused of “supporting the extremist and violent colonisation of the West Bank". Ministers start to resign from Keir Starmer's government, as the embattled British prime minister fights to stay in office. The UN says more than 400 civilians have been killed in Afghanistan since a cross-border conflict with Pakistan broke out in October last year. A senator in the Philippines takes refuge inside parliament to avoid arrest over his alleged role in former President Rodrigo Duterte's war on drugs. President Emmanuel Macron co-hosts the "Africa Forward Summit" in Kenya, to try to reset France's relationship with the continent. And new research suggests participating in the arts slows the ageing process. The Global News Podcast brings you the breaking news you need to hear, as it happens. Listen for the latest headlines and current affairs from around the world. Politics, economics, climate, business, technology, health – we cover it all with expert analysis and insight.Get the news that matters, delivered twice a day on weekdays and daily at weekends, plus special bonus episodes reacting to urgent breaking stories. Follow or subscribe now and never miss a moment.Get in touch: globalpodcast@bbc.co.uk