Podcasts about BitLocker

  • 166PODCASTS
  • 322EPISODES
  • 59mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 13, 2026LATEST
BitLocker

POPULARITY

20192020202120222023202420252026


Best podcasts about BitLocker

Latest podcast episodes about BitLocker

Ask The Tech Guys (Audio)
HOT 284: Understanding How to Recover Deleted Files - Can You Recover Deleted Files?

Ask The Tech Guys (Audio)

Play Episode Listen Later Sep 13, 2026 16:35 Transcription Available


On this week's Hands-On Tech, Mikah helps Harriett understand whether deleted files are truly gone when the recycle bin is emptied, and whether accidentally deleted files can still be recovered. Send in your questions for Mikah to hot@twit.tv, and he'll answer them in a future episode! Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: scribe.how/hot

discord files recover twit cloud storage atg mikah bitlocker mikah sargent garbage collection club twit recycle bin filevault club twit discord ask the tech guys
All TWiT.tv Shows (MP3)
Hands-On Tech 284: Understanding How to Recover Deleted Files

All TWiT.tv Shows (MP3)

Play Episode Listen Later Sep 13, 2026 16:35 Transcription Available


On this week's Hands-On Tech, Mikah helps Harriett understand whether deleted files are truly gone when the recycle bin is emptied, and whether accidentally deleted files can still be recovered. Send in your questions for Mikah to hot@twit.tv, and he'll answer them in a future episode! Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: scribe.how/hot

tech hands discord files recover twit cloud storage atg mikah bitlocker mikah sargent garbage collection club twit recycle bin filevault club twit discord ask the tech guys
The Tech Guy (Video HI)
HOT 284: Understanding How to Recover Deleted Files - Can You Recover Deleted Files?

The Tech Guy (Video HI)

Play Episode Listen Later Sep 13, 2026 16:35 Transcription Available


On this week's Hands-On Tech, Mikah helps Harriett understand whether deleted files are truly gone when the recycle bin is emptied, and whether accidentally deleted files can still be recovered. Send in your questions for Mikah to hot@twit.tv, and he'll answer them in a future episode! Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: scribe.how/hot

discord files recover twit cloud storage atg mikah bitlocker mikah sargent garbage collection club twit recycle bin filevault club twit discord ask the tech guys
Total Mikah (Video)
Hands-On Tech 284: Understanding How to Recover Deleted Files

Total Mikah (Video)

Play Episode Listen Later Sep 13, 2026 16:35 Transcription Available


On this week's Hands-On Tech, Mikah helps Harriett understand whether deleted files are truly gone when the recycle bin is emptied, and whether accidentally deleted files can still be recovered. Send in your questions for Mikah to hot@twit.tv, and he'll answer them in a future episode! Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: scribe.how/hot

tech hands discord files recover twit cloud storage atg mikah bitlocker mikah sargent garbage collection club twit recycle bin filevault club twit discord ask the tech guys
Total Mikah (Audio)
Hands-On Tech 284: Understanding How to Recover Deleted Files

Total Mikah (Audio)

Play Episode Listen Later Sep 13, 2026 16:35 Transcription Available


On this week's Hands-On Tech, Mikah helps Harriett understand whether deleted files are truly gone when the recycle bin is emptied, and whether accidentally deleted files can still be recovered. Send in your questions for Mikah to hot@twit.tv, and he'll answer them in a future episode! Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: scribe.how/hot

tech hands discord files recover twit cloud storage atg mikah bitlocker mikah sargent garbage collection club twit recycle bin filevault club twit discord ask the tech guys
Digital Forensics Now
Bite The Log Archive Cracker And You're Hooked

Digital Forensics Now

Play Episode Listen Later Aug 24, 2026 104:17 Transcription Available


Send us Fan MailAI is speeding up digital forensics, but speed without control is how good labs get burned. We dig into a safer way to work: use AI-assisted coding to generate a repeatable process, then test it against a real corpus of known extractions so results stay deterministic, verifiable, and defensible. If you've ever felt your LLM results “drift” from run to run, this mindset shift is the difference between a helpful assistant and a hidden liability. We also get practical with what's new across the community: a free macOS timestamp utility, Android intrusion logs (and how to extract and parse them when a user has opted in), and a deep look at Apple Unified Logs and log archives as an underrated iOS forensics goldmine. The big takeaway on logs is interpretation: one scary-looking line is not a conclusion. You have to read the surrounding sequence of events to avoid false narratives, and we talk about how newer workflows can process log archives directly from extractions without requiring a Mac. From there we move into evidence sources that often decide cases: iOS Health database artifacts, LevelDB and IndexedDB for browser forensics, and a standout BitLocker improvement that can auto-unlock secondary encrypted volumes when keys are preserved in a system image. Finally, we walk through reporting at scale with LAVA, the LEAPPs viewer that adds conversation views, analytics, tagging, notes, and LAVA subset exports for massive chats that would otherwise choke HTML reports. If this helped you rethink your workflow or gave you a new artifact to chase, subscribe, share the episode with your lab, and leave a review so more examiners can find it. What tool or artifact do you want us to test next?Notes:Timestamped - https://thebinaryhick.blog/2026/08/16/timestamped/Brett Shavers Blog Posts - http://linkedin.com/pulse/let-ai-run-your-case-make-you-stupid-brett-shavers-vproc/Android Logical Extractor - https://github.com/prosch88/ALEXTim Korver Blog Posts - https://www.linkedin.com/in/tim-korver/recent-activity/articles/SANS DFIR Summit & Training - https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2026MSAB Digital Summit - https://www.msab.com/msab-mobile-forensics-digital-summit-2027/Cellebrite 101 - https://community.cellebrite.com/s/101HEART Metadata Forensics - https://github.com/MetadataForensics/HEART_by_Metadata_ForensicsArsenal - https://arsenalrecon.com/productsLEAPPs & LAVA - leapps.org

Business of Tech
Dave Bloom: Why Small MSPs Can Sustain High Margins by Limiting Tool Overhead

Business of Tech

Play Episode Listen Later Aug 4, 2026 25:10


The episode examines margin disparity and operational strategy for MSPs serving regulated industries, spotlighting how compliance-driven overhead can become a structural moat for providers targeting underserved segments. The discussion centers on Trumbull Tech's model, which leverages a minimal-staff, tool-focused approach to deliver compliant services to small client bases (1–50 seats) across legal, financial, and healthcare verticals. The analysis underscores the risk and complexity inherent in regulated environments, noting that as vendors begin to package compliance offerings alongside MSPs, the defensibility of this margin advantage may erode. Trumbull Tech operates with gross margins well above channel averages—reporting 55–60%, attributed to intentional client selection, rigorous cost modeling, a preference for lightweight device management (MDM) solutions over enterprise-heavy platforms like Microsoft Intune, and strict avoidance of fixed, unlimited support contracts. The company's operational approach bundles basic but essential compliance tools, such as BitLocker enforcement, password complexity, password rotation, remote wipe, and targeted endpoint management, tailored specifically for smaller businesses. This model is predicated on the belief that most regulatory mandates can be reasonably satisfied with a uniform, low-overhead stack, thereby avoiding the staff overhead typical of more complex enterprise solutions. Supporting developments in the episode include an account of security intervention using Huntress with a small remote CPA firm, illustrating both the ubiquity of risk (not limited to large organizations) and the practical utility of combining automation with incident response. The conversation also touches on AI adoption hesitancy in small regulated businesses, logistics of relationship-based staffing for stickiness, and the rejection of strict vertical specialization in favor of scalable, stack-based delivery. These elements collectively describe a playbook where risk containment is achieved through standardization and upfront client selection, rather than deep customization. Implications for MSPs and IT providers include the need to critically assess their service models in the context of regulatory risk, operational scalability, and margin management. Overdependence on a specific set of tools or a uniform client profile may limit adaptability as vendor offerings and client expectations evolve. Providers entering or serving regulated markets should recognize that margin advantages rooted in compliance operations depend on active management of client selection, tool stack efficiency, and transparent risk tradeoffs, as opposed to reliance on elaborate enterprise frameworks or unlimited support promises. Attention to practical safeguards, clear lines of accountability, and periodic reassessment of vendor overlap is essential to remain viable as compliance delivery mechanisms evolve. Supported by: OpenTextScalePad

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 263 - No Chatbot, No Midnight, No Insider Info, No Simple Patch Tuesday, No Soup for You

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jul 20, 2026 53:43


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April.   Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading.   Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing.   China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push.   UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/

HeroicStories
How Do I Turn Off BitLocker? What Happens If I Do?

HeroicStories

Play Episode Listen Later Jul 8, 2026 6:12


BitLocker encrypted your drive, intentionally or otherwise, but now you want it gone. Turning it off is easy whether you run Windows Home or Pro. I'll walk you through both, explain what you're giving up, and remind you why saving that recovery key matters.

Mike Tech Show
MTS-2026-06-18 #995

Mike Tech Show

Play Episode Listen Later Jun 19, 2026


Bitlocker keys, Tweaking utility, Legacy Outlook for Mac, Onyx for Mac

Risky Business
Risky Business #842 -- Anthropic needs an adult in the C suite

Risky Business

Play Episode Listen Later Jun 17, 2026 59:59


On this week's show Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: Anthropic's Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won't keep the world safe from your AI doomsday machine The FISA 702 statute expired, but the spying can (probably) continue! NPM v12 delivers some protection against supply chain attacks, but not enough. Microsoft has a series of bugs that prevent Windows Update from … updating Much, much more! This episode is also available on YouTube Show notes Anthropic suspends new AI models after government directive | NBC News Tech Anthropic rankles users with safety-first Fable release | NBC News Tech How a 90-minute White House deadline sparked Silicon Valley's biggest AI fight | washingtonpost.com Pete Hegseth (@PeteHegseth) on X | X (formerly Twitter) David Sacks (@DavidSacks) on X | X (formerly Twitter) DoW CIO Kirsten Davies (@DoWCIODavies) on X | X (formerly Twitter) David Shulman (@DavidShulmanFL) on X | X (formerly Twitter) Controversial FISA spying law expires tonight. The spying will continue. | Ars Technica GitHub announces npm security changes to tackle supply-chain attacks | BleepingComputer Why NPM v12 won't stop supply chain attacks - Risky Business Media | Social Signals Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks | BleepingComputer Microsoft patches Exchange Server zero-day exploited in attacks | BleepingComputer Max severity Ivanti Sentry vulnerability now exploited in attacks | BleepingComputer CISA warns of another cPanel plugin flaw exploited in attacks | BleepingComputer Critical Fortinet FortiSandbox flaws now exploited in attacks | BleepingComputer CISA orders feds to patch actively exploited Ivanti flaw by Sunday | BleepingComputer CISA to require federal agencies to patch some cyber vulnerabilities within 3 days | therecord.media Path traversal flaw in AI dev platform Langflow exploited in attacks | BleepingComputer Microsoft: Some Windows PCs fail to install latest monthly updates | BleepingComputer Microsoft fixes BitLocker recovery bug on Windows Server 2025 | BleepingComputer Microsoft fixes Windows update failures linked to WUSA installer | BleepingComputer New attack turned Microsoft 365 Copilot into 1-click data theft tool | BleepingComputer Over 73,000 French govt employees affected in Tchap messenger breach | BleepingComputer Signal Alums Reveal ‘Encrypted Spaces,' a System for Making Private Collaboration Apps | wired.com FBI disrupts massive AI-powered phishing service using a million URLs | BleepingComputer Cyberattack shuts down major Australian sugar mills, disrupting harvest | The Record Drug Sites Hijacked Spotify's Search Ranking Through Fake Podcasts, Report Finds | wired.com It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests | 404.feed.press Who Runs the Ransomware Group ‘The Gentlemen?' | krebsonsecurity.com :brdKnife: (@cR0w@infosec.exchange) | Infosec Exchange

David Bombal
#581: AES Explained: How Encryption Protects Your Data

David Bombal

Play Episode Listen Later Jun 13, 2026 28:02


Big thanks to TryHackMe for sponsoring this video. Learn Cyber Security with Practical Labs on TryHackMe:https://tryhackme.com/DavidBombalTech Use my code DAVIDTECH25 to get 25% OFF on Annual Subscription! Dr. Mike Pound joins David Bombal to explain symmetric encryption, AES, secret keys, VPN encryption, TLS, block ciphers, stream ciphers and why encryption is one of the most important building blocks in modern cybersecurity. In this video, Mike explains what encryption actually does: it takes readable plaintext and turns it into unreadable ciphertext so that only someone with the correct secret key can decrypt it. He breaks down how symmetric encryption works, why the same key is used to encrypt and decrypt, and why algorithms like AES are used everywhere from secure websites and VPNs to BitLocker and full disk encryption. You'll learn why AES is so fast on modern CPUs, how keys interact with encryption algorithms, and why AES uses rounds of substitution and permutation to scramble data. Mike also explains the difference between block ciphers and stream ciphers, including AES, DES, Triple DES, ChaCha20 and older algorithms like RC4 and A5/1. The discussion also covers why symmetric encryption is used for bulk encryption in protocols like TLS and IPsec, why asymmetric encryption is used differently, and why you should never write your own encryption algorithm or implement your own AES code for real-world security. If you want to understand how encryption protects your data, how VPNs and secure web traffic work, and why AES is still one of the most important algorithms in cybersecurity, this is a great place to start. // Mike SOCIAL // X: / _mikepound YouTube Channel: / computerphile // YouTube Video REFERENCE //Password Cracking: Can a Rainbow table reverse a hashed password?: • Password Cracking: Can a Rainbow table rev... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:27 - TryHackMe Sponsor 0:49 - Intro 01:18 - Symmetric vs Asymmetric Encryption 04:38 - Key Exchange and VPN Analogy 06:10 - Examples of Symmetric Algorithms 08:56 - Advantages of Stream vs Block Cyber 10:31 - Deeper AES Explanation 14:34 - Substitution, Permutation, Mixing in AES 19:24 - Don't Implement your Own Encryption 20:16 - TryHackMe Sponsor - DEMO 24:21 - DES Algorithm and the NSA 26:01 - Where to Learn More about Encryption 27:42 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #symmetricencryption #aes #des

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 12, 2026 6:39


More Bitlocker Issues: GreatXML https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Oracle Security Alert Advisory - CVE-2026-35273 https://www.oracle.com/security-alerts/alert-cve-2026-35273.html https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ How Deceptive Installers Are Targeting macOS Users https://www.huntress.com/blog/deceptive-installers-macos-infostealers My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Paul's Security Weekly
Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, Bitlocker, Peoplesoft, and More - SWN #589

Paul's Security Weekly

Play Episode Listen Later Jun 12, 2026 31:53


Bad Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, GreatXML, Bitlocker, Peoplesoft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-589

Paul's Security Weekly TV
Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, Bitlocker, Peoplesoft, and More - SWN #589

Paul's Security Weekly TV

Play Episode Listen Later Jun 12, 2026 31:53


Bad Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, GreatXML, Bitlocker, Peoplesoft, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-589

Hack Naked News (Audio)
Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, Bitlocker, Peoplesoft, and More - SWN #589

Hack Naked News (Audio)

Play Episode Listen Later Jun 12, 2026 31:53


Bad Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, GreatXML, Bitlocker, Peoplesoft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-589

Hack Naked News (Video)
Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, Bitlocker, Peoplesoft, and More - SWN #589

Hack Naked News (Video)

Play Episode Listen Later Jun 12, 2026 31:53


Bad Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, GreatXML, Bitlocker, Peoplesoft, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-589

Cyberhelden
Cyberhelden 76 - Gewurm, wormen, en zwart water

Cyberhelden

Play Episode Listen Later Jun 11, 2026 53:18


Een AI-supportbot die zonder goede controle Instagram-accounts weggeeft, de Silent Ransom Group die data steelt en slachtoffers afperst zonder bestanden te versleutelen, en een GitHub-issue waarmee een AI-agent zijn eigen repository in gevaar kan brengen. Ronald, Marco en Jelle beginnen met drie verhalen waarin vertrouwen gevaarlijk ruim wordt uitgedeeld. Daarna duikt Ronald in YellowKey. Met een speciaal geprepareerde USB-stick kan een aanvaller Windows Recovery misleiden en de standaard BitLocker-bescherming van Windows 11 omzeilen. Minstens zo interessant is de ruzie eromheen: onderzoeker Nightmare-Eclipse zegt meerdere zero-days te publiceren uit frustratie over Microsoft, waarna een publiek conflict ontstaat over disclosure, verantwoordelijkheid en de macht van een grote leverancier. Marco bespreekt vervolgens een proof-of-concept voor adaptieve AI-wormen. In plaats van één vast ingebouwd aanvalspad gebruikt deze worm lokale AI-agenten om per doelwit een strategie te bedenken, fouten te herstellen en kennis met andere besmette machines te delen. Het is nog laboratoriumonderzoek, maar wel een ongemakkelijke vooruitblik op malware die ook redeneert. Tot slot gaat Jelle ouderwets Shodan-bingo spelen met automatic tank gauges: kleine systemen die brandstof- en vloeistoftanks meten en soms nog direct aan het internet hangen. Cyber-fysieke ellende hoeft niet te beginnen bij een energiecentrale; een vergeten meetkastje met een hardcoded creds is soms genoeg. *Bronnen* Meta AI-support en Instagram - 404 Media: https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/ - TechCrunch: https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/ Silent Ransom Group en DNS fast flux - Resecurity: https://www.resecurity.com/blog/article/silent-ransom-group-srg-uncovering-dns-fast-flux-infrastructure - FBI: https://www.fbi.gov/file-repository/cyber-alerts/silent-ransom-group-targeting-law-firms-052325.pdf Claude Code GitHub Action - GMO Flatt Security: https://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/ YellowKey en Microsoft - Ars Technica: https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/ - Windows Central: https://www.windowscentral.com/microsoft/microsoft-backs-off-legal-threats-against-windows-security-researchers Adaptieve AI-wormen - Paper, AI Agents Enable Adaptive Computer Worms: https://arxiv.org/abs/2606.03811 Automatic tank gauges - NSA: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4507204/nsa-joins-cisa-and-partners-to-release-guidance-on-hardening-automatic-tank-gau/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/

Passwort - der Podcast von heise security
Der DNSSEC-Fail beim DENIC und andere Neuigkeiten

Passwort - der Podcast von heise security

Play Episode Listen Later Jun 10, 2026 139:50 Transcription Available


Als sich das DENIC kürzlich bei einem Schlüsselwechsel ein Bein stellte, gingen im deutschen Internet für kurze Zeit die Lichter aus. Sylvester und Christopher haben den DNS-Experten Carsten Strotmann eingeladen, der ihnen und den Hörern im ersten Teil der Folge die Gründe und Auswirkungen dieses Ausfalls erläutert. Im zweiten Teil geht es dann zunächst um einen digitalen Raubzug mithilfe eines Domainklaus. Er betraf ein Unternehmen aus dem Krypto-Universum (as in Kursschwankung, nicht as in quantensicher) und dessen Kunden. Dann klären die beden Hosts die Frage, ob YellowKey den Beinamen "Bitlocker-Bypass" verdient hat und - ganz neu - probieren ein neues Format aus. In drei fünfminütigen Kurzschnipseln erzählen sie weitere aktuelle Begebenheiten rund um Signal, PQC und eine weitere Failzwiebel. Keywords: DENIC, DNSSEC, Key Rollover, Ausfall, Domains, Registry, Registrar, Exploit, Full Disclosure, Nightmare Eclipse, YellowKey, Bitlocker, Windows, Signal, Datenbank, Post-Quanten-Kryptografie, Zero-Trust Proof, Redundanz, CIA-Triade,

Cyber Security Today
Cybersecurity Today Month in Review: Microsoft Zero-Days, AI Deregulation

Cyber Security Today

Play Episode Listen Later Jun 6, 2026 65:25


Host Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher ("Chaotic/Nightmare Eclipse") publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft's vulnerability disclosure process, and backlash to Microsoft's initially threatening tone before it was partially walked back; the panel debates responsible disclosure, the need for researcher support/organization, transparency vs liability, and how vulnerability reporting is straining under volume. They then examine a White House AI executive order focused on voluntary measures and 30-day model access, criticizing the lack of basic safety and cybersecurity protections amid FOMO about losing to China and an AI investment bubble. The conversation covers AI-driven harms and studies on reduced brain activity and "cognitive surrender," while noting benefits when AI is used as a tutor. Shipley highlights Canada's Senate passing Bill C-8 on critical infrastructure cybersecurity, and the group urges outcome-focused security, architecture/risk prioritization, and critical thinking against AI-enabled social engineering. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. 00:00 Sponsor Message 00:24 Show Welcome Panel 01:17 Microsoft Zero Day Fallout 04:19 Researcher Backlash Drama 06:46 Unionizing Bug Hunters 13:10 Product Liability Debate 23:23 Regulation vs Transparency 26:00 AI Bubble Investor Risk 28:01 White House AI Order 32:24 Cybersecurity Gaps Telecom 33:19 Telecom Trust Breakdown 34:32 AI Harms and Exploitation 35:36 Studies on Cognitive Surrender 38:13 Markets Regulation and Politics 40:13 Canada Cyber Law Win 42:33 Adoption Hype and Subsidy Bubble 48:50 Patch Deluge and AppSec Strain 52:10 Defenses Beyond Patching 54:17 Outcomes Critical Thinking and CIA 01:01:49 Education Disruption and Closing 01:04:14 Sponsor Message Material Security

Blue Security
BitLocker bypass, Verizon DBIR report, & CISA key leak

Blue Security

Play Episode Listen Later Jun 2, 2026 40:49


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss critical cybersecurity topics, including newly discovered Windows Zero Days, insights from Verizon's latest Data Breach Investigations Report, and a significant credential leak at CISA. They emphasize the importance of vulnerability management, the evolving threat landscape, and best practices for securing sensitive data. The conversation highlights the need for organizations to adapt quickly to emerging threats and implement robust security measures to protect against breaches.----------------------------------------------------YouTube Video Link: ⁠https://youtu.be/DtPgg2jQCyM----------------------------------------------------Documentation: https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html?m=1https://www.verizon.com/business/resources/T158/reports/2026-dbir-data-breach-investigations-report.pdfhttps://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

leak verizon bypass summaryin cisa bitlocker data breach investigations report verizon dbir adam brewer
PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 257 - YellowKey Update, Before Stuxnet - Fast16, Bricking Valorant Cheaters, Apple's Anti-Snatch Feature, Chickenpox Immunity

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jun 1, 2026 50:56


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Microsoft releases a temporary mitigation script for "YellowKey," a BitLocker-bypassing Windows zero-day with no permanent fix yet https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/   Researchers uncover FAST16, a state-sponsored cyber-sabotage framework from 2005 that silently corrupted precision engineering calculations — predating Stuxnet by at least five years and linked to NSA tooling https://www.tomshardware.com/software/security-software/decades-old-pre-stuxnet-cyber-sabotage-tool-breaks-cover-nsa-listed-it-as-nothing-to-see-here-fast16-targeted-nuclear-reactors-dam-design-and-other-high-precision-civil-engineering-software-years-before-stuxnet-broke-cover https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/ https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/   Riot Games clarifies its Vanguard anti-cheat doesn't brick PCs — it just renders $6,000 worth of DMA cheat hardware completely useless https://www.ign.com/articles/riot-games-says-it-would-not-and-cannot-use-vanguard-anti-cheat-to-brick-pcs-after-rumors-spread https://www.tweaktown.com/news/111774/valorants-vanguard-anti-cheat-now-destroys-dma-cheat-firmware/index.html https://x.com/dexerto/status/2057785616255860991   Apple is developing an "anti-snatch" feature that automatically locks an iPhone the moment sensors detect it's been ripped from a user's hand — and London thieves already prefer iPhones over Samsungs https://appleinsider.com/articles/26/05/27/rumored-anti-snatch-feature-will-automatically-lock-iphones-yanked-out-of-a-users-hand https://appleinsider.com/articles/25/11/18/london-thieves-snatching-iphones-but-dont-want-no-samsung   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Ben - https://www.linkedin.com/in/benjamincorll/

MobileViews.com Podcast
MobileViews Podcast 612: Tokens vs, Humans w/guest Don Sorcinelli

MobileViews.com Podcast

Play Episode Listen Later Jun 1, 2026 44:52


Jon Westfall and I welcomed back our long-time friend Don Sorcinelli, who hasn't been on the show since last October (podcast 583). Don shared his deliberate "low-tech" approach to entertaining his two-year-old granddaughter, opting for traditional toys over tablets to encourage focus and avoid the "out" that screen time provides. This sparked some fun tech nostalgia, as I recounted my own experiences as a dad of a toddler trying "interactive" toys like the light-sensing Microsoft Barney and the giant yellow Microsoft EasyBall trackball—both of which proved that sometimes, simpler is better. A major theme of this episode was the shifting economic reality of AI. Don, ever the healthy skeptic, compared the current AI hype to the dot-com bust and the "magic math" of non-GAAP reporting. We discussed the "tokens vs. humans" trade-off, noting that as companies like Google and OpenAI move toward token-based pricing, the cost of farming out thinking to AI may soon exceed the cost of hiring a human. I've been finding ways to outsmart these limits by using standard LLMs to "interview" me and generate highly efficient Codex prompts, which usually get the job done on the first try. We also tackled some serious infrastructure and software headaches. I'm currently dealing with expiring Secure Boot certificates on some of my no-name PC boxes—a situation Don rightly called a "mismanaged" disaster on Microsoft's part, given the lack of clear documentation and the bugs causing BitLocker prompts. On a more positive note, my 8GB MacBook Neo continues to impress me with its efficiency, proving that tight optimization can often trump raw specs. We wrapped up with a look at the future of Nvidia ARM-based processors for Windows and a strange sighting during my daily walk: a fiber optic cable hanging at neck height between utility poles, a reminder that even high-tech infrastructure can have very physical (and dangerous) failures

2.5 Admins
2.5 Admins 301: F(OSS) Consulting

2.5 Admins

Play Episode Listen Later May 28, 2026 29:17


It looks like Bitlocker had a back door in it, how a listener accidentally broke Gitea for users of the snap version, Google accidentally published an unpatched exploit for Chromium-based browsers, why people are starting to ditch Bitwarden, and moving a tech stack away from large corporations. Plugs Support us on patreon and get an ad-free RSS feed with some early episodes How Klara and TrueNAS fixed ZFS's longest standing limitation Webinar: June 25th @ 11am EDT: Understanding AnyRAID with Jon from HexOS News/discussion YellowKey Bitlocker Bypass Vulnerability Microsoft shares mitigation for YellowKey Windows zero-day How I Broke Gitea for Everyone Google publishes exploit code threatening millions of Chromium users The Quiet Renovation at Bitwarden Free consulting We were asked about moving a tech stack away from large corporations. See our contact page for ways to get in touch.

Late Night Linux All Episodes
2.5 Admins 301: F(OSS) Consulting

Late Night Linux All Episodes

Play Episode Listen Later May 28, 2026 29:17


It looks like Bitlocker had a back door in it, how a listener accidentally broke Gitea for users of the snap version, Google accidentally published an unpatched exploit for Chromium-based browsers, why people are starting to ditch Bitwarden, and moving a tech stack away from large corporations. Plugs Support us on patreon and get an ad-free RSS feed with some early episodes How Klara and TrueNAS fixed ZFS's longest standing limitation Webinar: June 25th @ 11am EDT: Understanding AnyRAID with Jon from HexOS News/discussion YellowKey Bitlocker Bypass Vulnerability Microsoft shares mitigation for YellowKey Windows zero-day How I Broke Gitea for Everyone Google publishes exploit code threatening millions of Chromium users The Quiet Renovation at Bitwarden Free consulting We were asked about moving a tech stack away from large corporations. See our contact page for ways to get in touch.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 21, 2026 5:39


GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001

Hacker And The Fed
Microsoft Has a Bigger Security Problem Than Anyone Admits

Hacker And The Fed

Play Episode Listen Later May 21, 2026 53:19


Chris and Hector break down a major ransomware attack on Foxconn, the growing strain AI data centers are putting on power grids, and new allegations surrounding Microsoft security and cloud infrastructure. They also discuss insider threats, ransomware leaks, BitLocker concerns, and why cybersecurity vendors continue to overwhelm the industry with noise instead of solutions. Join our Patreon for weekly bonus episodes: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

Tech Enthusiast Hour
TEH 267: Apple's AI, Google I/O Updates, and the BitLocker Yellow Key Security Flaw

Tech Enthusiast Hour

Play Episode Listen Later May 21, 2026 65:18


In This Episode: Apple's AI, Google I/O Updates, and the BitLocker Yellow Key Security Flaw This week the TEH Podcast is hosted by Leo Notenboom, the “Chief Question Answerer” at Ask Leo!, and Gary Rosenzweig, the host and producer of MacMost, and mobile game developer at Clever Media. (You’ll find longer Bios on the Hosts page.) Top Stories 0:00 GR: What will the new Siri be like? (WWDC coming up) Stand-alone app Voice assistant that understands what you mean Gemini but not Gemini, Gemini model running on Apple's servers, doing Apple things 12:30 LN: Bitlocker busted? Yellowkey exploit 16:00 How encryption keys are really stored 22:00 GR: Folding Phones? Big deal or niche product? Really looks like Apple is doing this soon (iPhone Ultra) Pixel Fold: https://store.google.com/product/pixel_10_pro_fold?hl=en-US&pli=1  33:00 GR: Google I/O stuff, audio glasses, AI agents Glasses without any visual component: just mic, speaker and camera? 36:00 LN: https://bee.computer/  41:00 Hot take: People don't want agents, as people don't normally have assistants. Normal people talk to other people (chat) Also: Could it come to a point where it is all just moving too fast? Ain’t it Cool 57:00 GR: I'll Miss Stephen Colbert 1:00:00 LN: New Murderbot – Platform Decay BSP: Blatant Self-Promotion 01:01:16 GR: https://macmost.com/10-reasons-why-you-should-be-using-icloud-photos.html  01:03:43 LR: Has BitLocker Been Broken? What YellowKey Means to You – askleo.com/192620 Transcript teh_267 Video

Security Now (MP3)
SN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

Security Now (MP3)

Play Episode Listen Later May 20, 2026 171:52 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Risky Business
Risky Business #838 -- GitHub investigates possible breach

Risky Business

Play Episode Listen Later May 20, 2026 62:49


On this week's show Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patches. Polish Government urges officials to ditch Signal for mSzyfr Much, much more This week's show is brought to you by Thinkst Canary. Thinkst's founder, Haroon Meer, is this week's sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn't trivially easy. This episode is also available on YouTube. Show notes GitHub on X: "We are investigating unauthorized access to GitHub's internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub's internal repositories (such as our customers' enterprises, organizations, and repositories), we are closely" / X CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran Iran hackers: Hackers have breached tank readers at gas stations; officials suspect Iran is responsible | CNN Politics War and Data Centers Are Driving Up the Cost of Fiber-Optic Cable Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes hold | The Record from Recorded Future News NCSC's Ollie Whitehouse on surviving the "bugpocalypse" - Risky Business Media Defense at AI speed: Microsoft's new multi-model agentic security system tops leading industry benchmark | Microsoft Security Blog Project Glasswing: what Mythos showed us Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable' First public macOS kernel memory corruption exploit on Apple M5 OpenAI launches Daybreak to combat cyber threats | Cybersecurity Dive Zero-day exploit completely defeats default Windows 11 BitLocker protections - Ars Technica GitHub - Wack0/bitlocker-attacks: A list of public attacks on BitLocker · GitHub Catalin Cimpanu: "The Polish government has advi…" - Mastodon CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday | The Record from Recorded Future News CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) Huawei zero-day attack behind last year's crash of Luxembourg's entire telecoms network | The Record from Recorded Future News Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN | Cybersecurity Dive Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs | The Record from Recorded Future News Streamer Realtime Deepfakes Himself into Mr. Beast, Says He Loves 'Touching Little Boys'

All TWiT.tv Shows (MP3)
Security Now 1079: Daybreak and Codename MDASH

All TWiT.tv Shows (MP3)

Play Episode Listen Later May 20, 2026 171:52 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Security Now (Video HD)
SN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

Security Now (Video HD)

Play Episode Listen Later May 20, 2026 171:51 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Security Now (Video HI)
SN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

Security Now (Video HI)

Play Episode Listen Later May 20, 2026 171:51 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Radio Leo (Audio)
Security Now 1079: Daybreak and Codename MDASH

Radio Leo (Audio)

Play Episode Listen Later May 20, 2026 171:52 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Security Now (Video LO)
SN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

Security Now (Video LO)

Play Episode Listen Later May 20, 2026 171:51 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

Cyber Security Today
Windows 11 BitLocker Zero-Day, TeamPCP Malware Leak, Iran Gas Station Hacks | Cybersecurity Today

Cyber Security Today

Play Episode Listen Later May 20, 2026 13:10


A serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems.  Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. David Shipley breaks down four major cybersecurity stories on Cybersecurity Today. First, a newly disclosed zero-day dubbed YellowKey reportedly defeats default Windows 11 BitLocker protection on systems using TPM-only encryption, giving attackers with physical access a path to unencrypted data through the Windows Recovery Environment. Microsoft is investigating, while security experts are urging stronger BitLocker configurations. The episode also examines the TeamPCP threat group's decision to release offensive tooling publicly, dramatically lowering the barrier for copycat supply-chain attacks. Researchers have already spotted malicious NPM packages borrowing similar techniques, including persistence mechanisms aimed at developer environments such as Visual Studio Code and Claude Code. David also looks at disturbing analysis of the FAST16 malware, which researchers believe was engineered to tamper with nuclear weapons simulation software including LS-DYNA and AutoDyn. And finally, U.S. officials reportedly suspect Iranian actors in cyberattacks targeting internet-exposed gas station automatic tank gauge systems, a reminder that weak operational technology security can quickly become a real-world infrastructure problem. 00:00 Sponsor Message 00:24 Headlines Overview 00:50 BitLocker Zero Day 03:32 TeamPCP Tools Leak 06:13 Copycat NPM Malware 06:50 Fast16 Nuclear Sabotage 08:37 Iran Gas Station Hacks 10:28 Hardening Critical Infrastructure 11:16 Wrap Up And Events 11:59 Sponsor Deep Dive #Cybersecurity #Windows11 #BitLocker #ZeroDay #TeamPCP #IranCyberAttack #SupplyChainAttack #CriticalInfrastructure #CyberSecurityToday

HeroicStories
Has BitLocker Been Broken? What YellowKey Means to You

HeroicStories

Play Episode Listen Later May 20, 2026 10:17


A security researcher just showed that bypassing BitLocker on Windows 11 takes little more than a USB stick and a reboot. I'll discuss what we know, who needs to worry, what the risks are for most people, and what you can do about it right now.

All TWiT.tv Shows (Video LO)
Security Now 1079: Daybreak and Codename MDASH

All TWiT.tv Shows (Video LO)

Play Episode Listen Later May 20, 2026 171:51 Transcription Available


OpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior" after it gets press. Chaotic Eclipse hacker strikes again with a Bitlocker bypass. Google's threat analysis group documents malicious AI use. Canada hasn't learned the lessons of the EU and the UK. AI chatbots may be far more addictive than social media. Project: Hail Mary now available to stream. An apparently-serious zero-point quantum vacuum energy source. A bit of listener feedback. OpenAI's & Microsoft's vulnerability discovery systems Show Notes - https://www.grc.com/sn/SN-1079-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit hoxhunt.com/securitynow zscaler.com/security meter.com/securitynow canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 255 - No Keys Required: BitLocker Busted, Canvas Crushed, Forza Fumbles, World Cup 2026

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later May 18, 2026 47:25


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Cyb3r Operations https://www.cyb3roperations.com/   https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/ https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor YellowKey Zero-Day: An unpatched BitLocker bypass dubbed "YellowKey" allows physical attackers to unlock encrypted Windows 11 and Server 2022/2025 drives using just a USB stick — no password or recovery key needed — and the frustrated researcher behind it is threatening more disclosures after Microsoft allegedly ignored previous reports. https://calmatters.org/economy/technology/2026/05/california-went-big-on-canvas-the-worst-happened/ https://databreaches.net/2026/05/08/one-size-does-not-fit-all-sometimes-victims-probably-should-pay-ransom/ https://www.bleepingcomputer.com/news/security/us-govt-seeks-instructure-testimony-on-massive-canvas-cyberattack/ Canvas Ransomware Attack: ShinyHunters breached education platform Canvas twice within a week, stealing data from an estimated 275 million users across nearly 9,000 institutions globally, disrupting final exams across California and beyond — and now the U.S. House Committee on Homeland Security is demanding Instructure executives testify, while analysts debate whether refusing to pay the initial ransom made the fallout far worse.    https://insider-gaming.com/forza-horizon-6-leak-drops-155-gb-content/ Forza Horizon 6 Leak: Playground Games accidentally uploaded the complete, unencrypted 155GB build of Forza Horizon 6 to Steam ten days before its May 19 release, making the full game available to pirates — and Playground has since issued lifetime bans to players who streamed the leaked footage.   https://www.rotowire.com/soccer/article/2026-world-cup-groups-full-group-by-group-preview-analysis-projections-and-dark-horses-100836 https://au.news.yahoo.com/head-knocks-ultra-violence-viral-231852371.html 2026 World Cup Preview: With the expanded 48-team tournament kicking off June 11 across the U.S., Canada, and Mexico, Spain, France, and England headline the favorites — but the new format means more upsets, more dark horses, and storylines ranging from Messi's likely final campaign to Iraq's return to the World Cup stage for the first time since 1986.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Buck - https://www.linkedin.com/in/buck-rogers-9952446a/

Hacker News Recap
May 17th, 2026 | Mozilla to UK regulators: VPNs are essential privacy and security tools

Hacker News Recap

Play Episode Listen Later May 18, 2026 15:54


This is a recap of the top 10 posts on Hacker News on May 17, 2026. This podcast was generated by wondercraft.ai (00:30): Mozilla to UK regulators: VPNs are essential privacy and security toolsOriginal post: https://news.ycombinator.com/item?id=48166459&utm_source=wondercraft_ai(02:00): Security researcher says Microsoft built a Bitlocker backdoor, releases exploitOriginal post: https://news.ycombinator.com/item?id=48168856&utm_source=wondercraft_ai(03:31): I don't think AI will make your processes go fasterOriginal post: https://news.ycombinator.com/item?id=48168221&utm_source=wondercraft_ai(05:02): At least 25 Flock cameras have been destroyed in five states since April 2025Original post: https://news.ycombinator.com/item?id=48170798&utm_source=wondercraft_ai(06:33): Native all the way, until you need textOriginal post: https://news.ycombinator.com/item?id=48168058&utm_source=wondercraft_ai(08:04): AI subscriptions are a ticking time bomb for enterpriseOriginal post: https://news.ycombinator.com/item?id=48168056&utm_source=wondercraft_ai(09:35): AI is a technology not a productOriginal post: https://news.ycombinator.com/item?id=48168626&utm_source=wondercraft_ai(11:06): Apple Silicon costs more than OpenRouterOriginal post: https://news.ycombinator.com/item?id=48168198&utm_source=wondercraft_ai(12:37): I turned a $80 RK3562 Android tablet into a Debian Linux workstationOriginal post: https://news.ycombinator.com/item?id=48168668&utm_source=wondercraft_ai(14:08): WHO declares Ebola outbreak a global health emergencyOriginal post: https://news.ycombinator.com/item?id=48168708&utm_source=wondercraft_aiThis is a third-party project, independent from HN and YC. Text and audio generated using AI, by wondercraft.ai. Create your own studio quality podcast with text as the only input in seconds at app.wondercraft.ai. Issues or feedback? We'd love to hear from you: team@wondercraft.ai

Computer Talk with TAB
Computer Talk 5-16-26 HR 1

Computer Talk with TAB

Play Episode Listen Later May 16, 2026 39:00


Bitlocker may not be as locked as we thought!, AI Note takers for you Dr visit is screwing up 60% of the time! Caller wants a new laptop, Whatnot seller but keeps buffering, Flashdrive issues write protection, Proton VPN/Mail accounts,

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; Adobe Patches

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 14, 2026 5:26


Proxying the Unproxyable? Sending EXE traffic to a Proxy https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982 New Nightmare Eclipse Vulnerabilities Disclosed https://github.com/Nightmare-Eclipse/YellowKey https://github.com/Nightmare-Eclipse/GreenPlasma Adobe Patches https://helpx.adobe.com/security.html

Cyber Security Headlines
Foxconn confirms factory attacks, BitLocker zero-day accesses protected drives, MDASH patches Windows flaws

Cyber Security Headlines

Play Episode Listen Later May 14, 2026 7:09


Foxconn confirms North American factory attack BitLocker zero-day accesses protected drives MDASH patches 16 Windows flaws Get the show notes here: https://cisoseries.com/cybersecurity-news-foxconn-factory-attacks-bitlocker-zero-day-accesses-protected-drives-mdash-patches-windows-flaws/↗ Huge thanks to our episode sponsor, Doppel  Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call.   But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception.   We fight relentlessly to protect your business, brand, and people.   Doppel. Outpacing what's next in social engineering.   Learn more at doppel.com.  

Business of Tech
AI Governance Moves Center Stage: Why Audits and Policy Now Define MSP Risk

Business of Tech

Play Episode Listen Later Apr 8, 2026 12:59


The episode identifies a structural shift in the evaluation and deployment of AI within organizations: decision-making is now driven by governance, control, and auditability rather than by features or capabilities of AI tools. This mechanism is anchored in the need for defendable practices amidst heightened scrutiny from institutions, regulators, and insurers. The change is observable in companies such as Anthropic and OpenAI, as well as in regulatory and procurement activities tracked by outlets like The New York Times and Business Insider, signaling that market adoption is tightly coupled to liability, enforcement, and institutional risk visibility. A primary area of evidence is cybersecurity, where state-sponsored attackers have leveraged AI to automate infiltration attempts, according to reporting on Anthropic's disclosures concerning Chinese actors targeting dozens of companies and agencies. The same sources note that Anthropic's AI identified over 500 previously unknown zero-day vulnerabilities in open-source software, demonstrating increased operational tempo and automation on both sides of the cybersecurity equation. In procurement, declining app download metrics for Claude, following its involvement in U.S. security policy narratives, showcase how reputational and geopolitical risk can quickly alter adoption patterns. Additional developments reinforce this trend. Machine learning conferences have systematically audited and penalized the use of AI-generated peer review, leading to hundreds of paper rejections and mass article retractions, according to Semaphore and Nature. On the hardware front, HP, AMD, and Intel are collaborating to address BitLocker vulnerabilities via an industry standard rather than proprietary features, illustrating how vendors are responding to systemic risk through structural controls and standards. Channelholic's references to workforce limitations underscore that automation's workload cannot be absorbed by labor alone. For MSPs and IT service providers, these developments mean the core value proposition shifts from offering AI tools to governing their use, ensuring full documentation, traceability, and defensibility. Failure to treat this as a governance issue leads to underpricing, overlooked controls, and transfer of liability for autonomously executed actions. Providers must now develop acceptable use policies, audit AI agent activity logs, and systematically vet vendors on audit trail, policy, and breach notification—otherwise risking exclusion from regulated deals and exposure to contractual and compliance penalties. 00:00 The Visibility Problem 03:45 Platform Lock-In 06:30 Governed or Liable 09:35 Why Do We Care?  Supported by:  CometBackUp and TimeZest

The Full Nerd
Episode 391: 270K Plus Review, Windows 11 Reset, BitLocker Deep Dive & More

The Full Nerd

Play Episode Listen Later Mar 25, 2026 156:32


Join The Full Nerd gang as they talk about the latest PC building news. In this episode the gang is joined by Certified Ethical Hacker (CEH) Mike Danseglio to talk about the Intel Core Ultra 7 270K Plus reviews, Microsoft's promise to improve Windows 11, a deep dive into Bitlocker with the person who created BitLocker, and more. And of course we answer questions live! Links: - 270K Plus review: https://www.pcworld.com/article/3095697/intel-core-ultra-7-270k-plus-5-key-things-to-know.html - Windows 11 pledge: https://www.pcworld.com/article/3093997/windows-11-reset-microsoft-pledges-more-speed-stability-and-control.html - Copilot scaling back: https://www.pcworld.com/article/3094059/microsoft-says-windows-11-will-get-faster-as-it-scales-back-copilot.html Join the PC related discussions and ask us questions on Discord: https://discord.gg/UWhjwg778a Follow the crew on X and Bluesky: @AdamPMurray @BradChacos @MorphingBall @WillSmith ============= Read PCWorld! Website: http://www.pcworld.com Newsletter: http://www.pcworld.com/newsletters/signup ============= Learn more about your ad choices. Visit megaphone.fm/adchoices

Computer Talk with TAB
Computer Talk 3-21-26 HR 1

Computer Talk with TAB

Play Episode Listen Later Mar 21, 2026 40:22


Author caught using AI to publish a book that was 78 percent AI generated, Water Company Startup used AI to make an engineering decision that turned out incorrect at scale, JP Morgan using Bossware to make sure their Jr Bankers don't work too hard, BitLocker turned on without my awareness so now what? Slow Chrome on a site vs other browsers, Dumpster Laptop is still not working, How can they tell the content is AI generated?

This Week in Tech (Audio)
TWiT 1068: Toto's Electrostatic Chuck - Is TikTok's New Privacy Policy Cause for Alarm?

This Week in Tech (Audio)

Play Episode Listen Later Jan 26, 2026 172:26


Microsoft quietly hands over BitLocker keys to the government, TikTok's new privacy terms spark a user panic, and Europe's secret tech backups reveal anxious prep for digital fallout. Plus, how gambling platforms are changing the future of news and sports. You can bet on how much snow will fall in New York City this weekend Europe Prepares for a Nightmare Scenario: The U.S. Blocking Access to Tech China, US sign off on TikTok US spinoff TikTok users freak out over app's 'immigration status' collection -- here's what it means Elon Musk's Grok A.I. Chatbot Made Millions of Sexualized Images, New Estimates Show Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw - Forbes House of Lords votes to ban social media for Brits under 16 Overrun with AI slop, cURL scraps bug bounties to ensure "intact mental health" Route leak incident on January 22, 2026 149 Million Usernames and Passwords Exposed by Unsecured Database Millions of people imperiled through sign-in links sent by SMS Anthropic revises Claude's 'Constitution,' and hints at chatbot consciousness The new Siri chatbot may run on Google servers, not Apple's A Wikipedia Group Made a Guide to Detect AI Writing. Now a Plug-In Uses It to 'Humanize' Chatbots GitHub - anthropics/original_performance_takehome: Anthropic's original performance take-home, now open for you to try! Telly's "free" ad-based TVs make notable revenue—when they're actually delivered - Ars Technica Toilet Maker Toto's Shares Get Unlikely Boost From AI Rush - Slashdot Dr. Gladys West, whose mathematical models inspired GPS, dies at 95 Host: Leo Laporte Guests: Alex Stamos, Doc Rock, and Patrick Beja Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/twit redis.io expressvpn.com/twit shopify.com/twit

The CyberWire
When encryption meets enforcement.

The CyberWire

Play Episode Listen Later Jan 26, 2026 32:03


Microsoft granted the FBI access to laptops encrypted with BitLocker. The EU opens an investigation into Grok's creation of sexually explicit images. Glimmers of access pierce Iran's internet blackout. Koi Security warns npm fixes fall short against PackageGate exploits. Some Windows 11 devices fail to boot after installing the January Patch Tuesday updates. CISA warns of active exploitation of  multiple vulnerabilities across widely used enterprise and developer software. ESET researchers have attributed the cyberattack on Poland's energy sector to Russia's Sandworm. This week's business breakdown. Brandon Karpf joins us to talk space and cyber. CISA sits out RSAC.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest today is cybersecurity executive and friend of the show Brandon Karpf with Dave Bittner and T-Minus Space Daily host Maria Varmazis, for our monthly space and cyber segment. Brandon, Maria and Dave discuss “No more free rides: it's time to pay for space safety.” Selected Reading FBI Accessed Windows Laptops After Microsoft Shared BitLocker Recovery Keys (Hackread) European Commission opens new investigation into X's Grok (The Register) Amid Two-Week Internet Blackout, Some Iranians Are Getting Back Online (New York Times) Hackers can bypass npm's Shai-Hulud defenses via Git dependencies (Bleeping Computer) Microsoft investigates Windows 11 boot failures after January updates (Bleeping Computer) CISA says critical VMware RCE flaw now actively exploited (Bleeping Computer) CISA confirms active exploitation of four enterprise software bugs (Bleeping Computer) ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025 (ESET)  Aikido secures $60 million in Series B funding. (N2K Pro Business Briefing) CISA won't attend infosec industry's biggest conference (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.   Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Techmeme Ride Home
Now We Have The Clawdbot

Techmeme Ride Home

Play Episode Listen Later Jan 26, 2026 21:02


Did you even notice that new TikTok privacy policy over the weekend? AirTags finally have a second generation. Microsoft confirms it will give out your BitLocker recovery keys if you're silly enough to store them with them. And let me introduce you to Clawdbot. Since you can't see the spelling, you won't understand how this is different until I explain. TikTok Is Now Collecting Even More Data About Its Users. Here Are the 3 Biggest Changes (Wired) Apple launches AirTag 2 with improved range, louder speaker, more (9to5Mac) EU opens formal probe into Musk's xAI over Grok deepfakes (FT) Latest ChatGPT model uses Elon Musk's Grokipedia as source, tests reveal (The Guardian) Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw (Forbes) Clawdbot Showed Me What the Future of Personal AI Assistants Looks Like (MacStories) Learn more about your ad choices. Visit megaphone.fm/adchoices

Security Now (MP3)
SN 1059: MongoBleed - Code Signing Under Siege

Security Now (MP3)

Play Episode Listen Later Jan 7, 2026 196:33 Transcription Available


Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the "cabal" rewriting the rules for everyone who builds software—and what it means for your security and your wallet. Code-signing certificate lifetimes shortened by two years. Sadly, ChatGPT is heading toward an advertising profit model. The Python Package Index is strengthening its security. BitLocker gets hardware acceleration, but not today. New York City's mayoral inauguration banned Raspberry Pi's. An astonishingly good British time travel series. A critical link between Vitamin D and Magnesium. A look inside the very bad MongoBleed vulnerability Show Notes - https://www.grc.com/sn/SN-1059-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: meter.com/securitynow threatlocker.com/twit material.security bitwarden.com/twit