Podcasts about botnets

  • 395PODCASTS
  • 1,002EPISODES
  • 38mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 25, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about botnets

Show all podcasts related to botnets

Latest podcast episodes about botnets

Breach FM - der Infosec Podcast
Flurfunk - Berlin-Update, Trumps Cyber-Memorandum, Keycloak-Lücke & KI-Agenten gegen Taiwan

Breach FM - der Infosec Podcast

Play Episode Listen Later Aug 25, 2026 70:14


Eine sehr politische Folge – und eine, in der ich mich für Max Monolog-Lastigkeit der letzten Wochen revanchiere.Zum Berliner Landesnetz: Die Systeme sind wieder online, Bürgerservices erreichbar. Digitalstaatssekretär Florian Hauer sagt, es gebe aktuell keinen Hinweis auf eine Infiltrierung, aber nur als Momentaufnahme. Abgeflossen seien nur ohnehin öffentlich verfügbare Daten. Wir diskutieren, ob diese Art halbgarer Kommunikation hilft – und ob man es in so einer Lage überhaupt richtig machen kann.Das Hauptthema: Am 12. August hat Trump ein National Security Presidential Memorandum unterzeichnet, das geprüften US-Unternehmen offensive Cyberoperationen gegen ausländische cyberkriminelle Organisationen erlaubt – unter staatlicher Kontrolle, mit Verträgen bei DOJ oder DHS und schriftlicher Freigabe pro Operation. Ich bin überrascht, wie durchdacht das Papier formuliert ist, gerade bei den Definitionen. Nur ist damit noch nicht mal die halbe Miete gemacht: Die eigentlichen Verfahren, also Mindeststandards, Targeting, Deconfliction und Rules of Engagement, müssen erst in den nächsten 60 Tagen definiert werden, und bis dahin darf keine einzige Operation genehmigt werden. Offen bleiben bis dahin Attribution, Third-Party-Infrastruktur, Haftung bei Kollateralschäden und ein dünnes Oversight-Modell ohne Berichtspflicht an den Kongress. Meine Vermutung zu den Teilnehmern: Die Großen übernehmen risikoarme Botnet- und Scam-Compound-Takedowns, für alles Heiklere entstehen Startups.Max bringt eine Keycloak-Schwachstelle: CVE-2026-18963, CVSS 9.1, unauthentifizierte Account-Übernahme über einen schwachen Password-Reset-Mechanismus. Alle Versionen bis 26.7.2 betroffen.Zum Abschluss zwei Meldungen mit möglichem Staatsbezug: Ein kleiner britischer Stromerzeuger war im Juli vier Tage offline, Medienberichte deuten auf iranische Akteure, offiziell attribuiert ist nichts. Und Taiwan: Die israelische Firma Dream hat ein 160-MB-Archiv analysiert, das eine viertägige Kampagne mit bis zu acht parallelen Subagenten auf Basis von OpenClaw und Hermes dokumentiert. 21 Regierungssysteme kartiert, 85 Accounts geknackt, betroffen auch die Nuklearsicherheitsbehörde. Der Initial Access war banal: drei vergessene Debug-API-Endpunkte. Faszinierend ist die Orchestrierung – Findings wurden mit Wahrscheinlichkeiten bewertet, bei Sackgassen recherchierten die Agenten selbstständig neue Techniken.NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" (Weißes Haus) https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/Juristische Einordnung des Memorandums (Mayer Brown) https://www.mayerbrown.com/en/insights/publications/2026/08/presidential-memorandum-authorizes-vetted-private-companies-to-conduct-offensive-cyber-operations-against-foreign-criminal-organizationsOffene Fragen zu Haftung und Oversight (Crowell & Moring) https://www.crowell.com/en/insights/client-alerts/license-to-hack-the-white-house-greenlights-private-sector-offensive-cyber-operationsKeycloak CVE-2026-18963 (Red Hat) https://access.redhat.com/security/cve/CVE-2026-18963Dream: "Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia" https://www.dream.security/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asiaTaiwan Ministry of Digital Affairs: Monatsbericht Cybersicherheit https://moda.gov.tw/en/press/monthly-report/Einordnung des Taiwan-Angriffs (The Register) https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/Berliner Landesnetz: Update der Senatskanzlei https://www.berlin.de/rbmskzl/aktuelles/pressemitteilungen/2026/pressemitteilung.1703898.phpOpenAI: "Pacing model development in an era of cyber-critical capabilities"https://openai.com/index/pacing-model-development-cyber-capabilities/

The CyberWire
The botnet that scouts before it strikes. [Research Saturday]

The CyberWire

Play Episode Listen Later Aug 15, 2026 27:13


Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

Research Saturday
The botnet that scouts before it strikes.

Research Saturday

Play Episode Listen Later Aug 15, 2026 27:13


Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 5, 2026 6:30


Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing A Deep Dive Into the Latest XCSSET Version https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 31, 2026 5:50


Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198 Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh Inconsistent Group Chats https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cyber Security Today
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens

Cyber Security Today

Play Episode Listen Later Jul 29, 2026 12:56


Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began. Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps. Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance. Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft. 00:00 Introduction and Headlines 00:30 South Carolina Hospital Ransomware Attack 02:07 Healthcare Ransomware Crisis 03:25 IoT Botnet Uses Blockchain 05:40 Shared AI Chats Exposed 08:00 AI Agent Infiltrates Thailand Ministry 10:45 Swiss Train Maker Refuses Ransom 12:31 Closing Remarks

Talking Heads - Craft Computing
Ep. 440 - LLMs become botnets by reading websites; Playstation users protest Sony

Talking Heads - Craft Computing

Play Episode Listen Later Jul 9, 2026 125:20


LLMs become botnets by reading websites; Playstation users protest Sony

Cybercrime Magazine Podcast
Cybercrime News For Jul. 6, 2026. Google Ties Residential Proxy to TV Botnet. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 6, 2026 2:58


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Inside Darknet
124; Mirai Botnet

Inside Darknet

Play Episode Listen Later Jul 6, 2026 19:45


Im Jahr 2016 hat ein 20-jähriger Minecraft-Spieler namens Paras Jha mit Mirai eines der größten DDoS-Botnetze der Geschichte losgelassen. Seine Malware kompromittierte Millionen unsicherer IoT-Geräte und brachte damit Twitter, Netflix, Reddit und weitere Plattformen zum Absturz.

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 260 - Phish Fails, Canada Botnet Busts, Keystroke Confessions, Prime Day Hauls

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jun 29, 2026 48:37


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   A Canadian health authority apologizes after using a fake "bonus day off" as bait in a phishing simulation that backfired badly https://nlhealthservices.ca/news/nl-health-services-apologizes-for-the-recent-cybersecurity-awareness-exercise/   Canada's spy agency CSIS used a first-ever court-authorized warrant to remotely disinfect botnet-hijacked routers and IoT devices on Canadian soil https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html   Meta paused its internal AI training program after a tool quietly logging employee keystrokes, clicks, and screen content leaked the data across the entire company https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/     Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Ben - https://www.linkedin.com/in/benjamincorll/ Ben - https://www.linkedin.com/in/ben-k-b7196831/

Cyber Security Today
Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking

Cyber Security Today

Play Episode Listen Later Jun 22, 2026 10:03


A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies.  Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off

The CyberWire
The botnet browser blues.

The CyberWire

Play Episode Listen Later Jun 18, 2026 25:15


International law enforcement disrupts the SocGholish botnet. The UK's cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU's cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies, and coh-host of Caveat, as he discusses the failure of FISA section 702 to reauthorize. Selected Reading Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp (Bleeping Computer) Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns (Infosecurity Magazine) Cyberspace Locked in a Nation-State Contest, Says NCSC CEO (BankInfo Security) EU grants Ukraine access to cybersecurity reserve for major attacks (The Record) Killing me gently: Inside Gentlemen's EDR killer framework (ESET) ShapedPlugin update flow hacked to infect WordPress sites (Bleeping Computer) F5 issues out-of-band patches for critical NGINX vulnerabilities (Bleeping Computer) Atlassian, Splunk Patch Critical Vulnerabilities (SecurityWeek) Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents (HackRead) Kodak Admits Data Breach After ShinyHunters Hack Claims (SecurityWeek) Cybercriminals Are Worried About AI Taking Their Jobs Too (Infosecurity Magazine) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Hacker And The Fed
Your Smart TV Might Be Part of a Botnet

Hacker And The Fed

Play Episode Listen Later Jun 11, 2026 44:50


Chris and Hector break down a shocking discovery involving smart TVs being used as residential proxy nodes, a major Meta AI support failure that enabled widespread Instagram account takeovers, and new AI systems uncovering decades-old software vulnerabilities. They also discuss AI security guardrails, consumer privacy, and the growing risks of convenience-driven technology. Join our Patreon for weekly bonus episodes: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

Risky Business
Risky Business #840 -- Microsoft walks back researcher threats

Risky Business

Play Episode Listen Later Jun 3, 2026 66:03


On this week's show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution. They cover: Adversaries are tracking US troop locations with commercially available location data A new Signal phishing campaign is going after message backups 404 Media is suing ICE to get its spyware contract with REDLattice (lol) Microsoft's tone-deaf response to ‘never justifiable' zero-day disclosures Mini Shai-Hulud pops up again just as Glassworm gets shattered Much, much more This week's episode is sponsored by Authentik, an open source identity platform that you can host yourself. In this week's sponsor interview Authentik's CEO Fletcher Heisler joins Patrick Gray to talk about how they're keeping up with the bugpocalypse, and also the work they're doing to support identities for AI agents. This episode is also available on YouTube. Show notes The Pentagon Knew Enemies Could Track Troops' Phones for Years. Now They Are | wired.com U.S. says troops were targeted with location data, as senator warns ad industry is a ‘national security threat' | TechCrunch Security DOD location data attachment (Wyden) | Risky Business #830 -- LiteLLM and security scanner supply chains compromised | Risky Business Media US has seized nearly $1 billion in crypto from Iran, Bessent says | Russia claims foreign spy agencies hacked officials' phones | therecord.media Hackers are trying to steal Signal users' backups in new wave of phishing attacks | TechCrunch Security We Sued ICE to Get Its Spyware Contract. The Agency Is Redacting Essentially Everything | Social Signals Microsoft calls zero-day releases ‘never justifiable' as researcher threatens to drop more | therecord.media A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure | Social Signals Microsoft says it will not pursue security researchers after zero-day backlash | therecord.media IBM's new $5B initiative will help enterprises rapidly patch open-source vulnerabilities | Social Signals Federal audit reveals NIST's NVD is plagued by poor planning and duplication | cyberscoop.com Hackers Used Meta's AI Support Bot to Seize Instagram Accounts | krebsonsecurity.com Critical Windows Netlogon RCE flaw now exploited in attacks | BleepingComputer CISA adds exploited Palo Alto Networks GlobalProtect flaw to KEV | Cybersecurity Dive Password manager Dashlane says hackers stole some customers' password vaults | TechCrunch Security CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain | cyberscoop.com Botnet of more than 17 million devices dismantled | arstechnica.com Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans | therecord.media ACCC investigating Olympics ticket scam | ABC Dozens of Red Hat packages backdoored through its offical NPM channel | arstechnica.com Solo podcast: A deep dive on TeamPCP - Risky Business Media | Trump administration releases scaled-back AI executive order | cyberscoop.com Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket | cyberscoop.com

Black Hills Information Security
Anti-Tech Extremism - 2026-06-01

Black Hills Information Security

Play Episode Listen Later Jun 3, 2026 73:40 Transcription Available


This episode covers a Wired report on the rise of “anti-tech extremism” and growing public opposition to AI infrastructure projects, including debates over data centers, resource consumption, local communities, and government responses. The hosts also discuss AI coding assistants, model safety restrictions, and the evolving capabilities of large language models. Additional topics include Anthropic's reported IPO plans and valuation, AI's impact on the tech industry, and a conversation with David Bianco about AI-generated threat-hunting datasets and cybersecurity training.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis

Cyber Security Headlines
Meta AI hands over Instagram access, Dutch police dismantle botnet, RedHat packages backdoored

Cyber Security Headlines

Play Episode Listen Later Jun 2, 2026 7:07


Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot.   The good news: The Vanta  [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you.   Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk.   Get started at vanta.com/headlines. 

Breach FM - der Infosec Podcast
Flurfunk - KimWolf-Botnet, Portraitbox-Breach, GitHub-Supply-Chain & Anbieterkonzentration

Breach FM - der Infosec Podcast

Play Episode Listen Later Jun 2, 2026 69:15


Jacob Butler, 23, online bekannt als "Dort", wurde in Ottawa verhaftet. Ihm wird vorgeworfen, das DDoS-for-Hire-Botnet KimWolf mit über einer Million kompromittierten Geräten betrieben zu haben. Angriffe bis 30 Terabit/s dokumentiert, darunter auf das US Department of Defense Information Network. Brian Krebs hatte ihn im Februar öffentlich identifiziert, woraufhin Butler ihn mit DDoS, Doxing und Swatting anging. Ich nutze das als Aufhänger für eine Diskussion mit Max über IoT-Botnet-Verantwortung und wo die Grenze zwischen Provider-Pflicht und Konsumentenverantwortung liegt.Dann der Portraitbox-Breach – von dem ich selbst betroffen war. Angreifer erlangten am 16./17. Mai Zugriff auf den Paderborner Fotodienstleister, luden Daten herunter und löschten sie. Betroffen: Fotos, Namen, E-Mail-Adressen, Bestellhistorien – darunter massenhaft Kita- und Schulfotos von Kindern. Zahlungsdaten nicht betroffen. Die Benachrichtigungspflicht liegt strukturell bei den Fotografen. Die ZAC NRW ermittelt.GitHub hat einen Breach gemeldet: Ein Mitarbeiter installierte eine kompromittierte Version der NX-Konsole VS Code Extension – Teil der TeamPCP-Kampagne, über die wir in den letzten Wochen mehrfach berichtet haben. Betroffen: rund 3.800 interne GitHub-Repositories. Keine Kunden-Repos kompromittiert, aber wer Zugriff auf interne Engineering-Repos hat, hat deutlich mehr als nur Code. Das führt Max und mich zu einer längeren Debatte über Anbieterkonzentration: Es ist nicht gesund, Produktivität, Entwicklung und Security beim gleichen Anbieter zu konsolidieren – und das sage ich mit vollem Bewusstsein meiner eigenen Befangenheit.Zum Abschluss: CISA hat eine externe Nominierungsmöglichkeit für den KEV-Katalog eingeführt. Meine These: Das "Known Exploited"-Flag wird für Patch-Priorisierung zunehmend irrelevant – wenn die Zeit von Vulnerability zu Exploit bei unter 30 Minuten liegt, muss man ohnehin von sofortiger Ausnutzung ausgehen.KimWolf-Botnet-Festnahme (KrebsOnSecurity)https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/KimWolf-Botnet-Festnahme (DOJ)https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddosPortraitbox-Breach (heise online)https://www.heise.de/news/Sicherheitsvorfall-bei-Fotoanbieter-Wird-Portraitbox-erpresst-11304453.htmlGitHub Breach / NX-Konsole Supply Chain (TeamPCP)https://github.blog/security/supply-chain-security/security-incident-nx-console-extension/CISA KEV Nomination Processhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog

Risky Business News
Risky Bulletin: Dutch police take down 17m device botnet

Risky Business News

Play Episode Listen Later May 29, 2026 8:45


Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched. Show notes Risky Bulletin: Dutch police take down giant botnet of 17 million devices

Cyber Security Headlines
Glassworm botnet shattered, China overhauls surveillance, Charter confirms ShinyHunters breach

Cyber Security Headlines

Play Episode Listen Later May 28, 2026 7:21


Glassworm botnet gets shattered China overhauls world's biggest surveillance network Charter confirms ShinyHunters data breach Check out your show notes here: https://cisoseries.com/cybersecurity-news-glassworm-botnet-shattered-china-overhauls-surveillance-charter-confirms-shinyhunters-breach/ Huge thanks to our sponsor, Guardsquare AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

Cyber Security Today
AI Vulnerability Explosion, Kim Wolf Botnet Arrest, Ghost CMS Hack, Iran Cyber Espionage

Cyber Security Today

Play Episode Listen Later May 25, 2026 13:14


Is AI about to trigger a cybersecurity vulnerability explosion? In this episode of Cybersecurity Today, David Shipley examines what some researchers are calling the early signs of a "vulnerability apocalypse" as Anthropic's Claude-powered Project Glasswing identifies thousands of potential software flaws at machine speed. The episode breaks down the real numbers behind the hype: over 10,000 candidate vulnerabilities flagged, 1,726 confirmed high or critical findings, 97 patched issues, and the growing concern that AI-driven bug hunting could overwhelm already stretched security teams. One example: a critical WolfSSL certificate forgery vulnerability (CVE-2026-5194, CVSS 9.1). Also in this episode: Canadian authorities arrest Ottawa suspect Jacob Butler, also known as "Dort," allegedly linked to the Kim Wolf botnet operation blamed for nearly 30 terabits-per-second distributed denial-of-service (DDoS) attacks and more than 25,000 incidents. We also cover active exploitation of a Ghost CMS SQL injection vulnerability (CVE-2026-26980), with attackers reportedly compromising hundreds of websites using ClickFix malware lures, including high-profile targets. And finally, an Iran-linked cyber espionage campaign dubbed "Screening Serpents" uses highly personalised fake recruitment approaches to target aerospace, defence, and telecom professionals with new remote access malware. If you work in cybersecurity, infrastructure, or IT leadership, this is one to watch. 00:00 Vunpocalypse Headlines 00:28 AI Finds Vulnerabilities 01:32 False Positives and Costs 02:39 WolfSSL Critical CVE 03:51 Patch Volume Pressure 04:28 Kim Wolf Botnet Arrest 05:13 Botnet Scale and Swatting 06:48 International Takedowns 07:41 Ghost CMS Mass Exploits 09:07 ClickFix Infection Chain 10:25 How to Remediate Ghost 10:39 Iran Spear Phishing Ops 12:51 Closing and Sign Off #Cybersecurity #CyberSecurityToday #AIsecurity #GhostCMS #DDoS #CyberEspionage #Anthropic #ClaudeAI #IranCyberThreat #InfoSec

Objetivo Oposiciones
[PODCAST] ¿Qué es el malware y cómo afecta a tu oposición? (ep. extra)

Objetivo Oposiciones

Play Episode Listen Later May 18, 2026 10:07


¿Sabrías diferenciar un Gusano de un Troyano en tu examen? No dejes que la informática te quite la plaza. Muchos opositores subestiman la seguridad informática, pero el tribunal sabe que es el lugar perfecto para poner "preguntas trampa". En este episodio, Fran te explica de forma sencilla y directa todos los conceptos (Malware, Phishing, Ransomware...) que suelen aparecen en los temarios oficiales. No pierdas puntos por una pregunta de informática. ¡Aprende a distinguir cada amenaza! Temas del episodio Virus vs. Gusano vs. Troyano Ransomware y el Spyware: cómo funcionan los secuestros de datos Qué es la Ingeniería Social y el Phishing Conceptos avanzados: Botnets, ataques DDoS y vulnerabilidades de día cero Qué es lo que realmente te va a preguntar el Tribunal en el examen Enlaces de interés Descarga un esquema gratis sobre peligros y amenazas de la red

Kim Komando Today
Botnet takeover

Kim Komando Today

Play Episode Listen Later Apr 28, 2026 11:07


Your smart devices could be someone else's weapon. A global crackdown wiped out four massive botnets linked to 300,000 attacks. Intelligence Analyst Allan Liska explains who's behind it and what it means for you. Learn more about your ad choices. Visit megaphone.fm/adchoices

Marketplace Tech
How botnets infiltrate the internet of things

Marketplace Tech

Play Episode Listen Later Apr 15, 2026 6:58


Routers, computers, web cameras — they all connect to the internet. And they can be infected with malicious software that lets someone else take over. The device becomes a bot, essentially.A group of these devices networked together then becomes a botnet. And these botnets can then be used for nefarious purposes, like distributed denial of service attacks, without the device owners even knowing about it.Cybersecurity journalist Brian Krebs recently wrote about several large botnets including one called Kimwolf that compromised more than three million devices.

Marketplace All-in-One
How botnets infiltrate the internet of things

Marketplace All-in-One

Play Episode Listen Later Apr 15, 2026 6:58


Routers, computers, web cameras — they all connect to the internet. And they can be infected with malicious software that lets someone else take over. The device becomes a bot, essentially.A group of these devices networked together then becomes a botnet. And these botnets can then be used for nefarious purposes, like distributed denial of service attacks, without the device owners even knowing about it.Cybersecurity journalist Brian Krebs recently wrote about several large botnets including one called Kimwolf that compromised more than three million devices.

La French Connection
Épisode 0x290 - Strava trahit un porte-avions, TELUS perd 1 pétaoctet

La French Connection

Play Episode Listen Later Mar 29, 2026 57:51


Synopsis Dans l'épisode 0x290, Patrick, Steve et Francis reviennent sur une semaine chargée en cybersécurité. Un marin français a révélé la position du porte-avions Charles de Gaulle en Méditerranée via Strava — un problème d'OPSEC récurrent qui rappelle le cas du capitaine de sous-marin russe traqué et exécuté grâce à ses données de course à pied. L'équipe en profite pour discuter de l'utilisation des téléphones personnels par les policiers et militaires canadiens. L'équipe décortique ensuite ce qui pourrait être une des plus grosses brèches au Canada : TELUS Digital compromis par le groupe Shiny Hunters, avec un pétaoctet de données exfiltrées. Le tout via des outils de base comme TruffleHog, en scannant des mots de passe en clair dans les données internes. L'ampleur touche TELUS Santé, la domotique (ADT) et bien plus. Parmi les autres sujets : Google qui finalise l'acquisition de Wiz, Microsoft Copilot qui contourne les règles d'accès pour lire des courriels restreints, la Commission d'accès à l'information du Québec sous enquête, le démantèlement de quatre botnets majeurs avec la participation de la SQ et de la GRC, la vente de son visage et sa voix à l'IA, les pannes informatiques récurrentes dans les hôpitaux québécois, et les menaces cyber liées au conflit au Moyen-Orient qui touchent directement le Canada — incluant l'attaque destructrice contre le conglomérat biomédical Stryker via Microsoft Intune. L'épisode se termine avec un hommage humoristique au décès de Chuck Norris et une réflexion sur la vulnérabilité des infrastructures essentielles canadiennes, d'Hydro-Québec aux stations radar du Grand Nord. Crew Patrick Mathieu Steve Waterhouse Francis Coats Liens et ressources Steve StravaLeaks : le porte-avions Charles-de-Gaulle localisé en temps réel grâce à l'application de sport TELUS Digital confirms breach after hacker claims 1 petabyte data theft US seizes domains and infrastructure used in sprawling botnet campaigns Justice Department disrupts botnet networks that hijacked 3 million devices La Commission d'accès à l'information visée par des enquêtes Canada should ‘absolutely' match Poland's Chinese EV ban at military bases: expert Stryker attack wiped tens of thousands of devices, no malware needed Seriez-vous prêt à vendre votre voix ou à louer votre visage pour entraîner une IA? Switzerland built a secure alternative to BGP ‘Source of data': are electric cars vulnerable to cyber spies and hackers? Max severity Ubiquiti UniFi flaw may allow account takeover The US bans all new foreign-made network routers Patrick Crunchyroll data breach Wiz acquisition finalisée par Google Anthropic finds 22 Firefox vulnerabilities using Claude Disnat serre la vis - MFA enfin activé L'hôpital Maisonneuve-Rosemont affecté par une panne informatique Google Chrome - 26 CVE patchés Microsoft error sees confidential emails exposed to AI tool Copilot Francis ITSEC 2026 : j'y serai! Shamelessplug Join Discord — channel

Cyber Security Headlines
Department of Know: SaaS apps enable breaches, real-time cyber protection, IoT botnet takedown

Cyber Security Headlines

Play Episode Listen Later Mar 23, 2026 32:27


Link to episode page This week's Department of Know is hosted by Rich Stroffolino with guests Bil Harmer, CISO, Supabase, and Chris Ray, Field CTO, GigaOm Thanks to our show sponsor, ThreatLocker Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occurs. Learn more at ThreatLocker.com All links and the video of this episode can be found on CISO Series.com  

Cyber Security Headlines
International botnet takedown, California city ransomed, Azure Monitor phishing

Cyber Security Headlines

Play Episode Listen Later Mar 23, 2026 8:08


Law enforcement seizes botnet infrastructure California city and LA transit agency report cybersecurity issues Microsoft Azure Monitor alerts used for callback phishing attacks  Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-cybersecurity-news-international-botnet-takedown-california-city-ransomed-azure-monitor-phishing/ Huge thanks to our sponsor, ThreatLocker Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what software should be allowed to execute and blocking everything else by default. Fewer unknowns means fewer opportunities for attackers. Learn more at ThreatLocker.com

Sub FM Archives
Buster presents Basspaths feat Botnet - 12 Mar 2026

Sub FM Archives

Play Episode Listen Later Mar 15, 2026 118:00


Buster presents Basspaths feat Botnet on Sub FM 12th March 2026 - https://www.sub.fm

Passwort - der Podcast von heise security
Von kugelsicheren Netzen, kaputten Appliances und kreativen IP-Zertifikaten

Passwort - der Podcast von heise security

Play Episode Listen Later Mar 4, 2026 137:01 Transcription Available


Sylvester ist im Urlaub, daher springt kurzerhand Jan Mahn von der c't ein. Und der hat eine brisante Geschichte mitgebracht, in der es um "Bulletproof Hoster" geht. Also um Anbieter, die auf die guten Sitten im Internet pfeifen - manchmal gar auf Recht und Gesetz - solange ihre oft zwielichtige Kundschaft ihnen monatlich Geld überweist. Doch vorher gibt es einen längeren Rant über einen Security-Appliance-Hersteller, den Christopher sich nicht selber ausgedacht hat, sondern den der Finanz-Nachrichtendienst Bloomberg veröffentlichte. Und es gibt einige PKI-Neuigkeiten, die fast alle etwas mit IP-Adressen zu tun haben.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Feb 13, 2026 5:43


Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary] https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708 OpenSSH Update on MacOS https://www.openssh.org/releasenotes.html Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations

Tech and Science Daily | Evening Standard
PlayStation's hour-long State of Play, UK universities warned on foreign interference, and the botnet lurking in your living room

Tech and Science Daily | Evening Standard

Play Episode Listen Later Feb 10, 2026 5:52


Today on Tech and Science Daily from The Standard: the UK sets out new measures aimed at protecting universities from foreign interference, as concerns grow about pressure on researchers and sensitive collaboration. Plus, a record-setting DDoS attack is linked to the AISURU/Kimwolf botnet — a reminder that insecure everyday devices can end up powering serious cyber disruption. And in gaming, Sony confirms a 60+ minute State of Play landing this week, with major updates expected for the PS5 slate. We also look to science, with new research pointing to an empty lava tube beneath Venus, and a fresh method for measuring energy loss in nanoscale systems that could help shape future electronics. Hosted on Acast. See acast.com/privacy for more information.

Decipher Security Podcast
Dumping Edge Security Devices, the SystemBC Botnet, and the Joy of Joybubbles

Decipher Security Podcast

Play Episode Listen Later Feb 6, 2026 16:56


This week we talk about the new CISA Binding Operational Directive that sets a deadline for removing end of support edge security devices from federal government networks (1:15), then we discuss the new research from Silent Push on the new variant of the SystemBC botnet (6:45), and finally we have a movie recommendation for you: Joybubbles, the fascinating new documentary about phone phreaker Joe Engressia Jr.Support the show

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jan 16, 2026 7:29


Battling Cryptojacking, Botnets, and IABs Cryptojacking often comes with less obvious addons, like SSH backdoors https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632 Microsoft Copilot Reprompt Attacks Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow. https://www.varonis.com/blog/reprompt Hijacking Bluetooth Accessories Using Google Fast Pair Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories https://whisperpair.eu/#about

Packet Pushers - Full Podcast Feed
PP092: News Roundup–Old Gear Faces New Attacks, Cyber Trust Mark's Trust Issues, Alarms Howl for Kimwolf Botnet

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jan 13, 2026 51:52


Everything old is new again in this Packet Protector news roundup, from end-of-life D-Link routers facing active exploits (and no patch coming) to a five-year-old Fortinet vulnerability being freshly targeted by threat actors (despite a patch having been available for five years). We also dig into a clever, multi-stage attack against hotel operators that could... Read more »

Packet Pushers - Fat Pipe
PP092: News Roundup–Old Gear Faces New Attacks, Cyber Trust Mark's Trust Issues, Alarms Howl for Kimwolf Botnet

Packet Pushers - Fat Pipe

Play Episode Listen Later Jan 13, 2026 51:52


Everything old is new again in this Packet Protector news roundup, from end-of-life D-Link routers facing active exploits (and no patch coming) to a five-year-old Fortinet vulnerability being freshly targeted by threat actors (despite a patch having been available for five years). We also dig into a clever, multi-stage attack against hotel operators that could... Read more »

Hacker And The Fed
When Your Smart Fridge Joins a Botnet

Hacker And The Fed

Play Episode Listen Later Dec 11, 2025 50:36


Chris and Hector break down North Korea's covert push to infiltrate Western companies through fake IT recruiting, the leaked Predator spyware network targeting journalists and activists, and a record shattering DDoS attack driven by millions of compromised IoT devices. Along the way they unpack lazy opsec, hardware backdoors, and why everyday consumer tech keeps ending up in global cyber warfare. Join our new Patreon! ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

Hacker And The Fed
When Your Smart Fridge Joins a Botnet

Hacker And The Fed

Play Episode Listen Later Dec 11, 2025 50:36


Chris and Hector break down North Korea's covert push to infiltrate Western companies through fake IT recruiting, the leaked Predator spyware network targeting journalists and activists, and a record shattering DDoS attack driven by millions of compromised IoT devices. Along the way they unpack lazy opsec, hardware backdoors, and why everyday consumer tech keeps ending up in global cyber warfare. Join our new Patreon! ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

KFI Featured Segments
@WakeUpCall – ‘Wired Wednesday' with Rich DeMuro

KFI Featured Segments

Play Episode Listen Later Dec 3, 2025 5:02 Transcription Available


KFI Tech Reporter Rich DeMuro joins Wake Up Call for ‘Wired Wednesday’! Rich talks about Samsung’s NEW tri-folding phone, a free website to see if your home is part of a botnet, and the best places to go for online shopping promo codes.See omnystudio.com/listener for privacy information.

Cyber Security Headlines
AWS outage botnet smacks 28 countries, LLMs help malware authors evade detection, Anthropic pressed over Claude espionage

Cyber Security Headlines

Play Episode Listen Later Nov 27, 2025 7:02


AWS outage botnet smacks 28 countries LLMs help malware authors evade detection Anthropic questioned over Claude espionage Huge thanks to our episode sponsor, KnowBe4 Cybersecurity isn't just a tech problem—it's a human one.   That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization.   With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.

Cyber Security Today
Cybersecurity Today: October Recap - Addressing AI, DNS Failures, and Security Vulnerabilities

Cyber Security Today

Play Episode Listen Later Nov 1, 2025 74:17


In this episode of 'Cybersecurity Today,' the panel, including Laura Payne from White TOK and David Shipley from Boer on Securities, reviews the major cybersecurity events of October. Key topics include DNS failures at AWS and Microsoft, the rise of AI and its associated security concerns, and several severe cloud and on-premises vulnerabilities in platforms like SharePoint and WSUS. The discussion highlights a surge in sophisticated phishing threats, the integration of AI in cyber attacks, and the critical importance of multifactor authentication. The panel also examines the implications of recent security breaches affecting critical infrastructure and the broader impact of cybersecurity on financial sectors. Ethical concerns about AI's use in creating inappropriate content and the urgent need for better regulatory frameworks for tech and cloud providers are underscored. The episode concludes with a humorous moment as Jim dons a gifted white TOK, bringing a smile to the discussion. 00:00 Introduction and Sponsor Message 00:18 Panel Introduction and AI Discussion 01:02 Cloud Outages and Their Impact 02:52 DNS and Internet Fragility 07:07 Botnets and Cybersecurity Threats 14:09 Industrial Control Systems Vulnerabilities 26:29 AI in Cybersecurity 35:37 Voice Deepfakes and Authentication Risks 38:32 Creative Scams and Real-Time Voice Translators 39:22 The Importance of Safe Words and Persistent Surveillance Issues 40:17 Hybrid Scams and Financial Crimes in Canada 41:44 Corporate Reputation and Financial Crimes Agency 42:41 Challenges with Digital Banking and Security 44:49 The Role of AI and Security in Financial Transactions 45:55 The Impact of Open Banking and Real-Time Payments 50:57 Email Filters and Cybersecurity Awareness 58:03 Microsoft's Security Challenges and Vulnerabilities 01:03:39 Legal Consequences for Cybercriminals 01:12:17 Final Thoughts and Acknowledgements

SECURE AF
RondoDox Botnet Expansion: The Shotgun Approach to IoT Exploitation

SECURE AF

Play Episode Listen Later Oct 22, 2025 7:19


Got a question or comment? Message us here!This week on the #SOCBrief, Andrew breaks down RondoDox, a rapidly growing botnet campaign taking aim at routers, DVRs, and IoT devices worldwide. With over 50 vulnerabilities across 30+ vendors, this “shotgun” exploitation strategy is fueling massive DDoS and crypto-mining attacks.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Security Now (MP3)
SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

Security Now (MP3)

Play Episode Listen Later Oct 15, 2025 165:35


Texas is on the brink of forcing Apple and Google to overhaul app downloads with strict age verification laws—are tech giants ready, or is your privacy about to get caught in the crossfire? The EU aborted their Chat Control vote knowing it would fail. Salesforce says it's not going to pay; customer data is released. Hackers claim Discord breach netted 70,000 government IDs. Microsoft to move Github to Azure. What could possibly go wrong. New California law allows universal data sharing opt-out. OpenAI reports that it's blocking foreign abuse. Who cares. IE Mode refuses to die, so Microsoft is burying it deeper. The massive mess created by Texas legislation SB2420. The BreachForums website gets a makeover. 100,000 strong global botnet attacking U.S. RDP services. UI experts weigh in on Apple's iOS 26 user-interface. 330,000 publicly exposed REDIS servers are RCE-vulnerable Show Notes - https://www.grc.com/sn/SN-1047-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security expressvpn.com/securitynow vanta.com/SECURITYNOW canary.tools/twit - use code: TWIT bigid.com/securitynow

Security Now (Video HD)
SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

Security Now (Video HD)

Play Episode Listen Later Oct 15, 2025 152:07


Texas is on the brink of forcing Apple and Google to overhaul app downloads with strict age verification laws—are tech giants ready, or is your privacy about to get caught in the crossfire? The EU aborted their Chat Control vote knowing it would fail. Salesforce says it's not going to pay; customer data is released. Hackers claim Discord breach netted 70,000 government IDs. Microsoft to move Github to Azure. What could possibly go wrong. New California law allows universal data sharing opt-out. OpenAI reports that it's blocking foreign abuse. Who cares. IE Mode refuses to die, so Microsoft is burying it deeper. The massive mess created by Texas legislation SB2420. The BreachForums website gets a makeover. 100,000 strong global botnet attacking U.S. RDP services. UI experts weigh in on Apple's iOS 26 user-interface. 330,000 publicly exposed REDIS servers are RCE-vulnerable Show Notes - https://www.grc.com/sn/SN-1047-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security expressvpn.com/securitynow vanta.com/SECURITYNOW canary.tools/twit - use code: TWIT bigid.com/securitynow

Security Now (Video HI)
SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

Security Now (Video HI)

Play Episode Listen Later Oct 15, 2025 152:07


Texas is on the brink of forcing Apple and Google to overhaul app downloads with strict age verification laws—are tech giants ready, or is your privacy about to get caught in the crossfire? The EU aborted their Chat Control vote knowing it would fail. Salesforce says it's not going to pay; customer data is released. Hackers claim Discord breach netted 70,000 government IDs. Microsoft to move Github to Azure. What could possibly go wrong. New California law allows universal data sharing opt-out. OpenAI reports that it's blocking foreign abuse. Who cares. IE Mode refuses to die, so Microsoft is burying it deeper. The massive mess created by Texas legislation SB2420. The BreachForums website gets a makeover. 100,000 strong global botnet attacking U.S. RDP services. UI experts weigh in on Apple's iOS 26 user-interface. 330,000 publicly exposed REDIS servers are RCE-vulnerable Show Notes - https://www.grc.com/sn/SN-1047-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security expressvpn.com/securitynow vanta.com/SECURITYNOW canary.tools/twit - use code: TWIT bigid.com/securitynow

Security Now (Video LO)
SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

Security Now (Video LO)

Play Episode Listen Later Oct 15, 2025 152:07


Texas is on the brink of forcing Apple and Google to overhaul app downloads with strict age verification laws—are tech giants ready, or is your privacy about to get caught in the crossfire? The EU aborted their Chat Control vote knowing it would fail. Salesforce says it's not going to pay; customer data is released. Hackers claim Discord breach netted 70,000 government IDs. Microsoft to move Github to Azure. What could possibly go wrong. New California law allows universal data sharing opt-out. OpenAI reports that it's blocking foreign abuse. Who cares. IE Mode refuses to die, so Microsoft is burying it deeper. The massive mess created by Texas legislation SB2420. The BreachForums website gets a makeover. 100,000 strong global botnet attacking U.S. RDP services. UI experts weigh in on Apple's iOS 26 user-interface. 330,000 publicly exposed REDIS servers are RCE-vulnerable Show Notes - https://www.grc.com/sn/SN-1047-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security expressvpn.com/securitynow vanta.com/SECURITYNOW canary.tools/twit - use code: TWIT bigid.com/securitynow

The CyberWire
FBI botnet cleanup backfires.

The CyberWire

Play Episode Listen Later Sep 15, 2025 29:11


FBI botnet disruption leaves cybercriminals scrambling to pick up the pieces. Notorious ransomware gangs announce their retirement, but don't hold your breath. Hacktivists leak data tied to China's Great Firewall. A new report says DHS mishandled a key program designed to retain cyber talent at CISA. GPUGate malware cleverly evades analysis. WhiteCobra targets developers with malicious extensions. North Korea's Kimsuky group uses AI to generate fake South Korean military IDs. My guest is Tim Starks from CyberScoop, discussing offensive cyber operations. A cyberattack leaves students hung out to dry. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined once again by Tim Starks from CyberScoop discussing offensive cyber operations. You can read Tim's article Google previews cyber ‘disruption unit' as U.S. government, industry weigh going heavier on offense for more background. Selected Reading The FBI Destroyed an Internet Weapon, but Criminals Picked Up the Pieces (Wall Street Journal) 15 ransomware gangs ‘go dark' to enjoy 'golden parachutes' (The Register) 600 GB of Alleged Great Firewall of China Data Published in Largest Leak Yet (HackRead) China Enforces 1-Hour Cybersecurity Incident Reporting (The Cyber Express) ​​DHS watchdog finds mismanagement in critical cyber talent program (FedScoop) GPUGate Malware: Malicious GitHub Desktop Implants Use Hardware-Specific Decryption, Abuse Google Ads to Target Western Europe (Arctic Wolf) 'WhiteCobra' floods VSCode market with crypto-stealing extensions (Bleeping Computer) AI-Forged Military IDs Used in North Korean Phishing Attack (Infosecurity Magazine) Mitsubishi to acquire Nozomi Networks for nearly $1 billion. (N2K CyberWire Business Briefing)  Dutch students denied access to jailbroken laundry machines (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Random but Memorable
How to build a career in cybersecurity with Heath Adams | JOB HUNT BOT FATIGUE

Random but Memorable

Play Episode Listen Later Sep 2, 2025 68:29


Want to work in cybersecurity but don't know where to begin? Or just curious what it takes to break into the field? This week, we're joined by the internet's very own Heath Adams, better known as The Cyber Mentor. He demystifies the application process and what it takes to build a career in cybersecurity – no matter your background.

Cyber Security Headlines
Malicious Go module, new Mirai botnet, Silk Typhoon exploits cloud

Cyber Security Headlines

Play Episode Listen Later Aug 25, 2025 9:26


Malicious Go module steals credentials via Telegram Mirai-based botnet resurfaces targeting systems globally Silk Typhoon hackers exploit cloud trust to hack downstream customers Huge thanks to our sponsor, Prophet Security Ever feel like your security team is stuck in a loop of alert fatigue and manual investigations? Meet Prophet Security. Their Agentic AI SOC Platform automates the tedious stuff: triaging, investigating, and responding to alerts - so your analysts can focus on real threats. Think 10x faster response times and a smarter way to secure your business. Learn more at prophetsecurity.ai. Find the stories behind the headlines at CISOseries.com.

The CyberWire
Botnet's back, tell a friend. [Research Saturday]

The CyberWire

Play Episode Listen Later Jul 5, 2025 22:47


Please enjoy this encore of Research Saturday. This week we are joined by ⁠⁠Silas Cutler⁠⁠, Principal Security Researcher at ⁠⁠Censys⁠⁠, asking the important question of "Will the Real Volt Typhoon Please Stand Up?" The FBI's disruption of the KV Botnet in December 2023, attributed to the Chinese threat group Volt Typhoon, targeted infected systems but did not affect the botnet's control infrastructure. Despite law enforcement efforts and technical exposure, the botnet's infrastructure has remained largely stable, with only changes in hosting providers, raising questions about whether another party operates the botnet. Censys scanning data from 2024 shows a shift in the botnet's control servers, indicating a response to disruption attempts, while the botnet's operators have shown limited efforts to obscure their infrastructure. The research can be found here: ⁠⁠Will the Real Volt Typhoon Please Stand Up? Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
A tale of two botnets. [Research Saturday]

The CyberWire

Play Episode Listen Later Jun 28, 2025 24:55


This week we are joined by Kyle Lefton, Security Researcher from Akamai, who is diving into their work on "Two Botnets, One Flaw - Mirai Spreads Through Wazuh Vulnerability." Akamai researchers have observed active exploitation of CVE-2025-24016, a critical RCE vulnerability in Wazuh, by two Mirai-based botnets. The campaigns highlight how quickly attackers are adapting proof-of-concept exploits to spread malware, underscoring the urgency of patching vulnerable systems. One botnet appears to target Italian-speaking users, suggesting regionally tailored operations. The research can be found here: ⁠Two Botnets, One Flaw: Mirai Spreads Through Wazuh Vulnerability Learn more about your ad choices. Visit megaphone.fm/adchoices