Podcasts about Breach

  • 4,318PODCASTS
  • 11,111EPISODES
  • 47mAVG DURATION
  • 1DAILY NEW EPISODE
  • Jun 12, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories




Best podcasts about Breach

Show all podcasts related to breach

Latest podcast episodes about Breach

HIPAA Critical
IBJI agrees to $4 million settlement after breach 

HIPAA Critical

Play Episode Listen Later Jun 12, 2026 4:50 Transcription Available


This episode examines recent healthcare data breaches and settlements, including the $4 million IBJI case involving extended attacker dwell time, Mission Community Hospital's $1.5 million RansomHouse extortion settlement, and third-party vendor risks exposed by the La Perouse billing breach. We also discuss Rutgers University research showing hospitals using third-party tracking pixels are 46 percent more likely to experience breaches, emphasizing the critical need for system patching, vendor oversight, and web property audits.

Cyber Security Headlines
Fortinet patches FortiSandbox, GitHub disables npm scripts, Nottingham University breach

Cyber Security Headlines

Play Episode Listen Later Jun 12, 2026 8:12


Fortinet patches a new critical FortiSandbox flaw GitHub to disable npm install scripts by default to stop supply chain attacks Nottingham University announces data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-fortinet-patches-fortisandbox-github-disables-npm-scripts-nottingham-university-breach/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call.   But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception.   We fight relentlessly to protect your business, brand, and people.   Doppel. Outpacing what's next in social engineering.   Learn more at doppel.com.

Royal Blue: The Everton FC Podcast
EVERTON OUTRAGED! Blues Ordered to Pay Burnley £35m+ Over PSR Breach!

Royal Blue: The Everton FC Podcast

Play Episode Listen Later Jun 11, 2026 26:23


Everton have been ordered by a Premier League Independent Disciplinary Commission to pay nearly £40 million in compensation and interest to Burnley following a legal claim over Profitability and Sustainability Rules (PSR) breaches. Host Ian Croll is joined by the Liverpool Echo's Everton FC correspondent Joe Thomas to break down a decision that the club has branded "fundamentally flawed in both law and fact." Burnley's case relies on the legal principle of 'loss of chance,' arguing that if Everton's point deduction had been applied during the 2021/22 season, the Blues would have been relegated and the Clarets would have stayed up.  The club has already launched an official appeal, warning that this sets a "dangerous and unworkable precedent for English football." Ian and Joe discuss what this massive ruling means for the club's finances, how The Friedkin Group (TFG) is responding, and why the club insists this won't trigger any future PSR sanctions. What are your thoughts on this breaking news? Drop a comment below!

Crypto Talk Radio: Basic Cryptonomics
Billions Flow Out Of #Zcash After AI-Discovered Vulnerability

Crypto Talk Radio: Basic Cryptonomics

Play Episode Listen Later Jun 10, 2026 23:43


Billions Flow Out Of Zcash After AI-Discovered Vulnerability #Crypto #Cryptocurrency #podcast #BasicCryptonomics #Bitcoin  Website: ⁠⁠⁠⁠https://CryptoTalk.FM Facebook: ⁠⁠⁠⁠@ThisIsCTR⁠⁠⁠⁠ Chapters (00:00:01) - Crypto Talk Radio(00:02:58) - CryptoTalk FM: News, Topics, and More(00:03:31) - Does the Treasury Under Attack Impact Crypto?(00:11:44) - Does a Crypto Startup Need a Bank?(00:16:56) - Zcash: AI Found a Breach in the Code(00:18:07) - All the Crypto Hype You Can Read

Black Hills Information Security
Breach Disclosure Lag is Worse Than Ever – 2026-06-08

Black Hills Information Security

Play Episode Listen Later Jun 9, 2026 69:51 Transcription Available


This episode covers the rising costs and restrictions surrounding AI agents, including token consumption, model access policies, and the growing dependence on AI tools for security work. The hosts discuss Troy Hunt's retrospective on Have I Been Pwned reaching its 1,000th tracked breach, examining why breach disclosures appear to be slowing and how GDPR and CCPA requirements affect notification practices. Additional topics include password and email hygiene, the value of breach-notification services, AI infrastructure and data center costs, and new research mapping AI-enabled cyber threats to the MITRE ATT&CK framework.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis

Security Squawk
DentaQuest Breach Exposes 2.6 Million — and Why "Confident" Small Businesses Keep Getting Hit

Security Squawk

Play Episode Listen Later Jun 9, 2026 34:47


Your dental plan just became your biggest security problem. DentaQuest — one of the largest dental-benefits companies in America — had the personal and health data of 2.6 million people dumped online, and almost none of those people ever chose to do business with them. If you think your own company is too careful for this, the newest numbers say otherwise. *Confidence you can't prove is just exposure wearing a smile.* Bryan Hornung and Randy Bryan break down this week's stories — for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. (Reginald Andre is out this week — back next episode.) First up: the DentaQuest breach. The extortion crew ShinyHunters stole 234 gigabytes of data, tried to shake DentaQuest down for a ransom, and when the company didn't pay, they dumped the whole thing on a leak site. Inside that pile: names, birthdates, phone numbers, Medicaid IDs, and health-insurance details on 2.6 million people. The detail that should make you angry — researchers found roughly 1.7 million Social Security numbers in a separate folder, and a large share of them appear to belong to children. A stolen kid's SSN is gold to a fraudster, because nobody checks a nine-year-old's credit for ten years. And here's the part every business owner needs to hear: most victims never picked DentaQuest at all — their employer or their state Medicaid program did. Somebody else's vendor became your breach. Then we close on the mirror. A brand-new survey of 4,400 small and mid-size businesses found that owners have never felt more secure — 68% are confident they can stop an attack, and 75% trust they can respond. The problem? 45% of them got breached in the last year anyway. The number that stops you cold: among businesses hit more than once, confidence actually went UP — to 91% in the U.S. Meanwhile two-thirds still don't turn on multi-factor authentication, and only about 17% encrypt their data — the cheap, boring controls that stop most attacks. The average breach at a company under 500 people now runs about $3.31 million. Owners are scared of sci-fi AI malware while the rip current — phishing, weak passwords, no monitoring — is the thing actually pulling them under. Two stories, one crack running through both: somebody assumed they were covered, and the assumption was the vulnerability. The fix isn't more fear or more confidence — it's proof. In this episode, we discuss: • How 2.6 million people got exposed by a company most of them never chose. • Why ShinyHunters' "pay-or-we-leak" model makes your backups useless. • Why a stolen child's Social Security number is worth more than yours. • How small businesses can feel 68% confident and still get breached 45% of the time. • Why getting hit twice somehow makes owners MORE confident — and why that's backwards. • The two cheap controls two-thirds of businesses still skip. • How to replace "I feel secure" with proof you can actually show. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk

The Flank
SURGE EXPOSE HERETICS? | NEW G2 FRIES BREACH! | THE FLANK BO7 MINOR 2

The Flank

Play Episode Listen Later Jun 6, 2026 85:07


FaZe ZooMaa, Enable, Parasite, Benj, and Attach break down the first day of the Call of Duty League Minor matches!

Cybercrime Magazine Podcast
Cybercrime Wire For Jun 5, 2026. Breach Hits Brazil's Dominant Food Delivery App. WCYB Digital Radio

Cybercrime Magazine Podcast

Play Episode Listen Later Jun 5, 2026 1:36


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

The New CISO
Rogue Agents: The New Era of AI Insider Threats (part 2)

The New CISO

Play Episode Listen Later Jun 4, 2026 43:04


What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.Eric opens with a sobering reality: ransomware victims who decline to pay are re-attacked at staggering rates. He explains why criminals treat cybercrime as a business, invest weeks in reconnaissance—mapping SharePoint, harvesting file trees, and studying access patterns—and why a botched recovery hands them the same door twice.The conversation turns to the new insider threat hiding in plain sight: rogue AI agents. Eric shares a real case in which one executive's casual query exposed the next round of layoffs and triggered coordinated lawsuits. They unpack how agents inherit excessive access, how attackers hijack them once inside, and why organizations are now building insider-threat programs to monitor AI behavior.Eric argues AI is an accelerant on every unresolved problem—weak identity management, entitlement drift, missing asset inventories, and absent data classification. They debate whether IT and security should be unified under the CISO, why the CISO needs a direct line to the board, and the legal landmines that follow a breach, from cyber insurance to the “reasonable steps” standard.The episode closes with Eric's advice for any new CISO: put “spy hunter” on your resume. Counterintelligence, not perimeter defense, is the discipline that wins today. Tune in for part two of a story-driven conversation on why preparation, mindset, and threat hunting beat any single technology.Key Topics• Why ransomware victims who decline to pay get re-attacked• How attackers map SharePoint, file trees, and access patterns• The new insider threat: rogue and hijacked AI agents• A real case of an AI agent exposing an HR layoff list• Shadow IT and the cost of banning AI outright• Permission structures and second-level reviews for agent actions• Why AI exposes gaps in identity, asset, and data classification• Unifying IT and security under the CISO• Why the CISO needs a direct line to the board• Legal traps: cyber insurance, reasonable steps, and missed alerts• The CISO as counterintelligence officer and spy hunterGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:

Cybercrime Magazine Podcast
Cybercrime Wire For Jun. 4, 2026. Red Hat Breach, Compromised Github Account. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jun 4, 2026 1:32


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

CISSP Cyber Training Podcast - CISSP Training Program
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 4, 2026 24:26 Transcription Available


Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

IDTheftCenter
The Weekly Breach Breakdown Podcast: Ransomware Groups Are Beefing, and Defenders Are Winning - S7E`17

IDTheftCenter

Play Episode Listen Later Jun 4, 2026 4:54


Welcome to the Identity Theft Resource Center's Weekly Breach Breakdown for June 5, 2026. I'm Tatiana Cuadras, Communications Assistant for the ITRC. Thanks to Sentilink for their continued support of the podcast and the ITRC. Each week, we break down the latest in data security and privacy, and this week, we have a story that's a little different. It's not about criminals targeting everyday people or businesses. It's about ransomware groups targeting each other. Grab your popcorn. Follow on LinkedIn: linkedin.com/company/idtheftcenter/ Follow on Instagram: instagram.com/idtheftcenter/ Follow on Facebook: facebook.com/IDTheftResourceCenter/ Follow on X: twitter.com/IDTheftCenter Follow on TikTok: www.tiktok.com/@idtheftcenter_ Follow on YouTube: www.youtube.com/@IDTheftCenter

Cybercrime Magazine Podcast
Cybercrime Wire For Jun. 3, 2026. Breach Hits 100 Dutch Hotels, Guests At Risk. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jun 3, 2026 1:19


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

The Kick it Forward Podcast
ROT | Schemes: FREE BEERS & PLANTS!!! Shannon Noll Plane Stunt Safety Breach, The Most Insensitive Instagram Edit Ever, & Listener Dan Auditions For The Jacob Elordi 007 Sketch.

The Kick it Forward Podcast

Play Episode Listen Later Jun 3, 2026 58:04


NEW MERCH AVAILABLE NOW⁠⁠⁠⁠⁠⁠⁠⁠⁠ ROT: We're off to Europe, and the silly travel shirts are on the way. Sketch Tank: Listener Dan's hilarious auditions to be in the Jacob Elordi Sketch. Shannon Noll sung on a plane - Harry is NOT happy with the safety breaches. Yappers: The most inappropriate fire instagram edit in history + 6-7 is well and truly alive. Schemes: Free Bunnings plants, free Beers with a burger, and unlimited money at the pokies HACK. Listener submitted KIF soundboard HERE ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠JOIN OUR PATREON FOR HEAPS OF BONUS STUFF⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Learn more about your ad choices. Visit megaphone.fm/adchoices

Law School
Torts Before 1L: Negligence Part One - Duty, Breach, Reasonable Care, and Special Duty Rules

Law School

Play Episode Listen Later Jun 3, 2026 63:08


The Cybersecurity Defenders Podcast
"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach & CISA cPanel vulnerability / Intel Chat [#328]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jun 1, 2026 29:05


Originally recorded: Friday May 29, 2026In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026.Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting the “/mnt/user-data” directory.Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained franchise-related documents. SecurityWeek article Matt references.CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being actively exploited in the wild.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Law School
Contracts Before 1L: Performance, Conditions, Breach, Excuse, and Third-Party Rights

Law School

Play Episode Listen Later May 30, 2026 59:08


Click Here for the Review Guide: Performance, Conditions, Breach, Excuse, and Third-Party RightsIn this episode, we explore the high-stakes, real-world implications of contractual obligations—focusing on how performance is measured, when breaches occur, and how legal doctrines of excuse operate to handle impossible or unfair situations. Whether you're a law student, a legal professional, or simply interested in the mechanics of contract law, this breakdown delivers clarity on the nuanced ways law allocates risk amidst human unpredictability. Most construction projects, like pipelines, run into delays that threaten entire businesses—and many fail to grasp why performance timing is everything. This episode uncovers the real-world importance of performance, conditions, and breach, going beyond the theory to show how legal concepts translate into practice when stakes are high and delays costly.Imagine you're 58 days into a multimillion-dollar pipeline build, only 15 miles laid despite tight schedules and market volatility. Your contractor's progress seems impossible, and crucial deadlines are slipping away. This scenario highlights why understanding whether performance is due, excused, or breached can make or break you. We break down how to diagnose if a failure originates from broken promises or failed conditions—name-dropping the crucial distinction between promises and conditions, and how this impacts legal obligations in practice.You'll discover:The difference between express conditions—triggered by words like "if" or "provided that"—and constructive conditions, implied by law to facilitate fairness and order.How the "perfect tender" rule under the UCC demands absolute conformity for goods, and the exceptions that prevent economic sabotage.The multi-factor test for "substantial performance" and how courts evaluate whether project imperfections justify partial payment or total breach.The stark contrast between material breaches that justify cancellation, and minor deviations that require damages.When anticipatory repudiation allows the non-breaching party to act immediately, and the delicate timing around retraction and adequate assurances.How doctrines like impossibility, impracticability, and frustration of purpose serve as legal escapes when external forces make performance impossible or pointless.Why does this matter? Because ignoring these nuances can lead to catastrophic mistakes—either by hasty breach or unknowing acceptance of defective performance. The path to mastery lies in understanding the precise seismic shifts that turn promises into enforceable obligations, and breaches into strategic decisions.Whether you're a law student facing exams or a professional navigating high-stakes contracts, this episode arms you with clarity on performance and breach, ensuring you're prepared for real-world and test scenarios alike. Perfect for anyone who needs to decode contractual failure and navigate the fine line between compliance and breach, this is essential listening to see performance in a new light.Get ready to see through the chaos, master the performance grid, and approach breach law with confidence—and perhaps even a little daring.Key Topics:The distinction between promises and conditions and their impact on performance timingSubstantial performance doctrine in common law and perfect tender rule under the UCCClassifying breaches: material versus minor, and their remediesAnticipatory repudiation: how clear refusals to perform can be addressed earlyThe doctrines of impossibility, impracticability, and frustration of purpose as excusesHow third-party beneficiaries, assignments, and delegations influence contractual rights and obligationsCritical analysis of contractual modification standards under common law versus UCCThe importance of specificity in drafting, especially related to express vs constructive conditionsPractical exam tips: decoding contractual language, applying multi-factor analyses, and

Cybercrime Magazine Podcast
Cybercrime News For May 28, 2026. Iranian Hackers Linked to LA Transit Breach. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later May 28, 2026 3:31


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Cyber Security Headlines
Glassworm botnet shattered, China overhauls surveillance, Charter confirms ShinyHunters breach

Cyber Security Headlines

Play Episode Listen Later May 28, 2026 7:21


Glassworm botnet gets shattered China overhauls world's biggest surveillance network Charter confirms ShinyHunters data breach Check out your show notes here: https://cisoseries.com/cybersecurity-news-glassworm-botnet-shattered-china-overhauls-surveillance-charter-confirms-shinyhunters-breach/ Huge thanks to our sponsor, Guardsquare AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

Cybercrime Magazine Podcast
Cybercrime Wire For May 27, 2026. Beach Mutual Breach Hits 131K Rhode Islanders. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later May 27, 2026 1:31


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

RNZ: Morning Report
Manage My Health breach prompts security warning

RNZ: Morning Report

Play Episode Listen Later May 27, 2026 4:02


The privacy commissioner has recommended a central vetting process for GP apps, following the Manage My Health data breach. It found Health NZ and Manage My Health "failed in their responsibilities" to have adequate security controls when hundreds of thousands of medical files were stolen in a cyber attack. The Commissioner says GP practices need to review their security settings and third party providers. Luke Bradford, President and Chair of the Royal New Zealand College of General Practitioners spoke to Ingrid Hipkiss.

The Daily Crunch – Spoken Edition
Ghost hackers: the cybersecurity mystery that nobody has solved; plus, Iranian hackers blamed for breach of LA transit system

The Daily Crunch – Spoken Edition

Play Episode Listen Later May 27, 2026 8:25


A shadowy group that stole and dumped the NSA's most powerful hacking tools still has implications for how companies think about digital risk today. Also, an Israeli cybersecurity firm said Iran's government is behind Ababil of Minab, a fake hacktivist persona that has claimed a series of data breaches after the start of the war in Iran. Learn more about your ad choices. Visit podcastchoices.com/adchoices

The Ben Joravsky Show
Kevin Ryan—Unto The Breach Once More

The Ben Joravsky Show

Play Episode Listen Later May 25, 2026 74:36


Trump diverts about $1.8 billion in taxpayers's money to his cronies—just call him President Slush Fund. Ben riffs. Kevin Ryan talks about the lessons he learned from his recent Senate campaign. From there he covers everything from Hegseth in Kentucky to George Washington at Valley Forge. A shout out to Robin Kelly. A call for ranked-choice voting. A plea for a separation between church and state. A recital from Henry the Fifth. And a few words about the paradox of saying Happy Memorial Day. Kevin is the state director for Veterans For All Voters. His views are his own. See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

BibleWorm
Episode 743 Disputing with God: The Unmended Breach (Exodus 32:1-20 & 30-35)

BibleWorm

Play Episode Listen Later May 25, 2026 69:14


In this first episode of our summer series on Disputing with God, we are reading the story of the Golden Calf, Exodus 32:1-20 and 30-35. We've read it together before, but the regular lectionary stops us pretty early in its unfolding ... and we found that moving farther into the story directed our eyes not to the Israelites or to God, but to the space between them–their relationship, still fairly new and fragile. And you know what else is right between them–our man Moses, holding the tablets, trying to reach in both directions at once. What's left after this kind of rupture? What's possible?

LibertiHarrisburgPodcast
20 - Once More Unto The Breach - Gospel Servants - 05-24-2026

LibertiHarrisburgPodcast

Play Episode Listen Later May 25, 2026 35:43


What if your weakness is actually where God's power is revealed the most? In this sermon from 2 Corinthians 12, Pastor Jordan Porr walks through Paul's suffering, the “thorn in the flesh,” and the powerful truth that God's grace is sufficient even in our darkest moments. If you've ever asked “Why am I suffering?” this message will point you back to the hope, strength, and comfort found in Christ alone

TechLinked
Microsoft 365 Update, GitHub Breach, Nvidia GPU Security Update + more!

TechLinked

Play Episode Listen Later May 23, 2026 7:53


Timestamps: 0:00 Microsoft 365 Update 1:02 GitHub Breach 1:58 Nvidia GPU Security Update 4:06 QUICK BITS INTRO 4:11 Meta Releases Reddit-like App 4:34 Riot's Vanguard Anti-Cheat Hits Cheaters Hard 5:05 Discord Enables End-to-End Encryption 5:31 Spotify and UMG Reach AI Deal 6:14 Pizza Hut Sued by Franchisee Over AI NEW SOURCES: https://lmg.gg/Bdpll Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Today
GitHub Breach Exposes 3,800 Repos | Microsoft Kills SMS Authentication | Proton Fights Canada Bill

Cyber Security Today

Play Episode Listen Later May 22, 2026 9:19


GitHub confirms a major supply chain breach after a malicious Visual Studio Code extension reportedly gave attackers linked to TeamPCP access to roughly 3,800 internal repositories. The bigger issue: developer workstations now hold some of the most sensitive secrets in modern software organizations. Also today: Microsoft begins phasing out SMS-based authentication for personal accounts, calling text-message authentication a growing fraud risk as it shifts toward phishing-resistant passkeys. Researchers also disclose a nine-year-old Linux privilege escalation flaw, CVE-2026-46333, nicknamed SSH-Keysign-Pwn, which can allow root-level access with local machine access. And Proton publicly threatens to leave Canada rather than comply with proposed surveillance legislation it says would undermine its no-logs privacy promise. Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. If cybersecurity, privacy, and digital infrastructure matter to your business, this is the daily briefing you need. Timestamps: 00:00 Top Stories Rundown 00:24 GitHub Supply Chain Breach 01:09 Developer Workstations at Risk 02:31 Microsoft Ditches SMS MFA 04:15 Linux Root Escalation Flaw 06:11 Proton vs Canada Surveillance Bill 08:03 Wrap Up and Sign Off #cybersecurity #github #microsoft #linux #protonvpn #privacy #databreach #supplychainattack #infosec #cybernews

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 21, 2026 5:39


GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001

Cyber Security Headlines
GitHub VS Code extension breach, Shai-Hulud npm package compromise, Huawei/Luxembourg telecom link

Cyber Security Headlines

Play Episode Listen Later May 21, 2026 7:37


GitHub breach via VS Code extension Shai-Hulud wave compromises 600 npm packages Huawei attack behind Luxembourg telecom crash Get the show notes here: https://cisoseries.com/cybersecurity-news-github-vs-code-extension-breach-shai-hulud-npm-package-compromise-huawei-luxembourg-telecom-link/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

Risky Business
Risky Business #838 -- GitHub investigates possible breach

Risky Business

Play Episode Listen Later May 20, 2026 62:49


On this week's show Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patches. Polish Government urges officials to ditch Signal for mSzyfr Much, much more This week's show is brought to you by Thinkst Canary. Thinkst's founder, Haroon Meer, is this week's sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn't trivially easy. This episode is also available on YouTube. Show notes GitHub on X: "We are investigating unauthorized access to GitHub's internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub's internal repositories (such as our customers' enterprises, organizations, and repositories), we are closely" / X CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran Iran hackers: Hackers have breached tank readers at gas stations; officials suspect Iran is responsible | CNN Politics War and Data Centers Are Driving Up the Cost of Fiber-Optic Cable Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes hold | The Record from Recorded Future News NCSC's Ollie Whitehouse on surviving the "bugpocalypse" - Risky Business Media Defense at AI speed: Microsoft's new multi-model agentic security system tops leading industry benchmark | Microsoft Security Blog Project Glasswing: what Mythos showed us Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable' First public macOS kernel memory corruption exploit on Apple M5 OpenAI launches Daybreak to combat cyber threats | Cybersecurity Dive Zero-day exploit completely defeats default Windows 11 BitLocker protections - Ars Technica GitHub - Wack0/bitlocker-attacks: A list of public attacks on BitLocker · GitHub Catalin Cimpanu: "The Polish government has advi…" - Mastodon CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday | The Record from Recorded Future News CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) Huawei zero-day attack behind last year's crash of Luxembourg's entire telecoms network | The Record from Recorded Future News Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN | Cybersecurity Dive Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs | The Record from Recorded Future News Streamer Realtime Deepfakes Himself into Mr. Beast, Says He Loves 'Touching Little Boys'

The Tech Blog Writer Podcast
Cybersecurity Upside Down With Benny Czarny, founder and CEO of OPSWAT

The Tech Blog Writer Podcast

Play Episode Listen Later May 20, 2026 39:29


What if the cybersecurity industry has spent decades fighting the wrong battle? In this episode of Tech Talks Daily, I sat down with Benny Czarny, founder and CEO of OPSWAT, to discuss why he believes the traditional "detect and respond" model is no longer enough in a world where AI is accelerating cyber threats faster than security teams can react. Benny joined me to discuss his new book, Cybersecurity Upside Down, which combines personal stories from building OPSWAT with a bold argument for rethinking how organizations approach cyber defense altogether. His central belief is simple but provocative: detection-based security has trapped the industry in a losing cycle in which attackers need to succeed only once, while defenders are forced into a constant state of reaction. During our conversation, Benny explained how his thinking evolved after realizing that even layering dozens of antivirus engines and sandboxing technologies still failed to stop malicious files reliably. That realization ultimately pushed him toward a prevention-first philosophy built around Deep Content Disarm and Reconstruction, or CDR. Rather than trying to determine whether a file is malicious, the approach assumes files may already be dangerous and regenerates clean, safe versions before they ever reach users or systems. We also explored how generative AI is changing the cybersecurity landscape in ways many organizations still underestimate. Benny shared why AI is dramatically reducing the time required to create malware, weaponize exploits, and scale attacks, effectively giving even inexperienced attackers capabilities once reserved for nation states or advanced cybercriminal groups. He also raised concerns that AI data lakes could become contaminated with malicious content, creating entirely new risks for organizations rushing to deploy large language models without securing the data feeding them. One of the most fascinating aspects of the discussion was the psychology and culture within cybersecurity teams. Benny argued that the industry often celebrates visible incident response activity while undervaluing quiet prevention. In a world dominated by alerts, dashboards, and SOC metrics, truly preventing attacks can almost appear invisible, despite potentially delivering far greater security outcomes. We also talked about the sectors Benny believes are most exposed today, including energy, manufacturing, and critical infrastructure operators that still rely heavily on reactive security models while facing growing operational and regulatory complexity. He explained why some industries are advancing faster than others and why compliance mandates could become a major catalyst for broader prevention-first adoption. Beyond cybersecurity itself, this episode also offered a fascinating look into Benny's entrepreneurial journey, what he learned building OPSWAT over two decades, how AI helped him research and structure his book, and why he is now even producing a cybersecurity-focused TV series called Into the Breach, designed to make complex security concepts easier for wider audiences to understand. This conversation challenges many of the assumptions the cybersecurity industry has normalized for years. Whether you work in security, IT leadership, compliance, or want to understand how AI is reshaping digital risk, this episode offers a very different perspective on what modern cyber resilience could look like in practice.

Business of Tech
Security Proof Becomes an MSP Service: Insurance, Trustmarks, and the Evidence Operating Model

Business of Tech

Play Episode Listen Later May 20, 2026 14:04


Security operations for MSPs are undergoing a structural shift from simply deploying additional tools to establishing a liability-focused accountability model, where the ability to provide operational evidence of controls is becoming as critical as the tools themselves. This shift is catalyzed by corporate insurance, procurement, and third-party verification structures—such as those cited by WatchGuard, Assurix, and the NIST AI cybersecurity overlays—demanding verifiable security outcomes and alignment with external standards, rather than relying on provider assertions alone. Survey data referenced from Cybersmart and Beta News reveals that 75% of MSPs experienced at least one breach in the past year, while 54% endured multiple incidents; concurrently, SMB buyers state security is a top priority, but only 13% of microbusinesses operate proactively. According to WatchGuard's global survey of 842 professionals, 94% of clients using dedicated MSPs feel adequately protected, yet 58% indicate intent to change providers within three years—highlighting a disconnect between perceived and delivered value. The emergence of Assurixs' live MSP Trustmark, based on 64 operational controls, further formalizes evidence requirements as market prerequisites. These dynamics are reinforced by shifts in insurer behavior and regulatory alignment. Huntress and Acrisure are collectively rolling out a cyber insurance package contingent on adoption of Huntress's managed detection and response, explicitly tying coverage eligibility to verifiable provider-side controls. The maturing of NIST's AI cybersecurity overlays introduces new standardized control checklists likely to become operational requirements. Additionally, reports from Omdia and MSP Channel Insights note that vendor ecosystems are now rewarded for integrating security as an outcome with automation and multi-tenant integration—reflecting market demand for reliable, defensible evidence of controls. For MSPs and IT leaders, these developments drive the need to restructure contracts to clearly delineate evidence obligations, manage liability exposure, and price evidence production as a formal deliverable rather than as unreimbursed support. Failing to do so risks absorbing unfunded post-incident evidence work, margin erosion, and loss of control over the security value conversation. Operationally, maintaining live accreditations, standing up a formal evidence management function, and explicitly excluding unmanaged SaaS, identity, and AI workflows from baseline service tiers are becoming necessary to maintain profitability and accountability. 00:00 Breach, Then Switch  04:52 SaaS Blind Spot 07:16 Prove or Pay 10:24 Why Do We Care?  Supported by:  Zero Networks HaloPSA   

Tavis Smiley
Bishop William J. Barber II joins Tavis Smiley

Tavis Smiley

Play Episode Listen Later May 20, 2026 16:33 Transcription Available


President and senior lecturer of Repairers of the Breach and Moral Mondays, Bishop William J. Barber II reflects on their rally outside the White House yesterday and their challenge to distorted theology that justifies war and policy violence.Become a supporter of this podcast: https://www.spreaker.com/podcast/tavis-smiley--6286410/support.

SECURE AF
ShinyHunters Breach of Instructure Canvas LMS

SECURE AF

Play Episode Listen Later May 20, 2026 5:21 Transcription Available


Got a question or comment? Message us here!In this episode of the #SOCBrief, we break down the ShinyHunters breach of Instructure's Canvas LMS and what it means for security teams everywhere. From exploiting a lesser-monitored service to exfiltrating millions of records, this attack highlights the growing risk of third-party vendors and supply chain exposure. We walk through how the breach unfolded, key indicators of compromise, and the practical steps SOC teams can take to detect, monitor, and reduce vendor-related risk before it becomes a crisis.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

TrustedSec Security Podcast
8.16 - Canvas On Fire: Inside the Largest Education-Sector Breach in History

TrustedSec Security Podcast

Play Episode Listen Later May 19, 2026 46:19


On this episode of Security Noise, we are joined by TrustedSec Founder and CEO Dave Kennedy and IR Practice Lead Ryan Macfarlane to talk about the Canvas LMS Ransomware incident. HOLD ON TO YOUR GRADES as we dive into the attack details, response strategies, and overall outlook for cybersecurity in education and beyond! From the initial breach to the scramble to restore systems, we break down exactly how attackers exploited vulnerabilities in one of the most widely used learning management platforms in the world. About this podcast: Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the infosec topics that interest them the most. Hack the planet! Find more cybersecurity resources on our website at https://trustedsec.com/resources.

SECURE AF
Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk

SECURE AF

Play Episode Listen Later May 19, 2026 55:12 Transcription Available


Got a question or comment? Message us here!When the Canvas LMS went down, thousands of institutions came to a halt, right in the middle of finals. In this episode, we break down what really happened, what data may have been exposed, and why this incident is a wake-up call for every organization relying on SaaS platforms.From vendor risk and contract blind spots to business continuity failures, we unpack the real lessons security leaders need to hear, and what you should be doing right now to prepare for the next breach.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Talking Fast: A Gilmore Girls Podcast
Factored Out: S7 Ep21

Talking Fast: A Gilmore Girls Podcast

Play Episode Listen Later May 19, 2026 85:30


This week Alexis and Suzanne cover Season 7 Episode 21, "Unto the Breach." They ponder the decision for Logan to propose to Rory when they apparently never talked about marriage. They reminisce about their graduations, and Alexis's preparation for graduating with her doctorate. Get involved in your local community and help resist ICE and fascism! Look for organizations like ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Indivisible⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Party for Socialism and Liberation⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, and others!Donate to the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠World Central Kitchen⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ to help feed people throughout the world who are without food!Donate to help feed those suffering the forced starvation of genocide in Gaza with the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Palestine Children's Relief Fund⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.Learn more about how to support LGBTQ+ rights at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠PFLAG⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and check out the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Trevor Project⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠!And call your representatives using the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠5 Calls⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ app.Want to listen to our episodes ad-free? ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Join our Patreon⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and help support us as we make this podcast!Rate and review us on Apple Podcasts, Spotify, or wherever you listen. Join us on Instagram and TikTok @talkingfastpodcast, and send your thoughts to talkingfastpodcast@gmail.com

Paul's Security Weekly
AI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459

Paul's Security Weekly

Play Episode Listen Later May 18, 2026 96:29


Interview with Dimitri Sirota from BigID Most organizations think AI risk lives in the model – or the identity. It doesn't. It lives in the data. In this episode, BigID's CEO reframes the conversation: why legacy access controls are breaking down, why visibility into sensitive data is the missing foundation, and what it takes to govern humans and machines under a single, accountable framework. Segment Resources: BigID's Agent Access Management Guide BigID's podcast, CTRL + ALT + AI This Week's Topic: Cascading Breaches We're seeing more and more 3rd and 4th party attacks that chain through multiple layers of compromised tools and services. In this topic segment, we discuss the two main aspects of this trend: How we can stop the chain of breaches from a third party library, vendor, or service provider How this might get handled at the legal, contractual, and organizational levels We discuss two big recent examples: Sonicwall's 2025 breach of their cloud firewall configuration backup service The compromise of Aqua Security's widely used Trivy open source tool The Weekly Enterprise News Finally, in the enterprise security news, Funding and M&A courtesy of the Security, Funded newsletter We have evidence that attackers are leveraging AI now (this sounds like old news, but there was little to no evidence before, when people were claiming this) The Angry admin problem emerges again Vulnerability information is getting crazy to keep up with Breach information is getting crazy to keep up with You can give your Agents an allowance now - don't spend it all in one place Are vulnerabilities sparse or dense? Mythos, as a model, isn't all that special Deploy your own deception sensors! Japan made something weird. Again. All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-459

Enterprise Security Weekly (Audio)
AI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459

Enterprise Security Weekly (Audio)

Play Episode Listen Later May 18, 2026 96:29


Interview with Dimitri Sirota from BigID Most organizations think AI risk lives in the model – or the identity. It doesn't. It lives in the data. In this episode, BigID's CEO reframes the conversation: why legacy access controls are breaking down, why visibility into sensitive data is the missing foundation, and what it takes to govern humans and machines under a single, accountable framework. Segment Resources: BigID's Agent Access Management Guide BigID's podcast, CTRL + ALT + AI This Week's Topic: Cascading Breaches We're seeing more and more 3rd and 4th party attacks that chain through multiple layers of compromised tools and services. In this topic segment, we discuss the two main aspects of this trend: How we can stop the chain of breaches from a third party library, vendor, or service provider How this might get handled at the legal, contractual, and organizational levels We discuss two big recent examples: Sonicwall's 2025 breach of their cloud firewall configuration backup service The compromise of Aqua Security's widely used Trivy open source tool The Weekly Enterprise News Finally, in the enterprise security news, Funding and M&A courtesy of the Security, Funded newsletter We have evidence that attackers are leveraging AI now (this sounds like old news, but there was little to no evidence before, when people were claiming this) The Angry admin problem emerges again Vulnerability information is getting crazy to keep up with Breach information is getting crazy to keep up with You can give your Agents an allowance now - don't spend it all in one place Are vulnerabilities sparse or dense? Mythos, as a model, isn't all that special Deploy your own deception sensors! Japan made something weird. Again. All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-459

AP Audio Stories
Israeli troops intercept vessels from a flotilla trying to breach the blockade of Gaza

AP Audio Stories

Play Episode Listen Later May 18, 2026 0:42


AP correspondent Charles de Ledesma reports Israel aims to stop a new flotilla breaking the blockade on Gaza aid.

Paul's Security Weekly TV
AI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459

Paul's Security Weekly TV

Play Episode Listen Later May 18, 2026 96:29


Interview with Dimitri Sirota from BigID Most organizations think AI risk lives in the model – or the identity. It doesn't. It lives in the data. In this episode, BigID's CEO reframes the conversation: why legacy access controls are breaking down, why visibility into sensitive data is the missing foundation, and what it takes to govern humans and machines under a single, accountable framework. Segment Resources: BigID's Agent Access Management Guide BigID's podcast, CTRL + ALT + AI This Week's Topic: Cascading Breaches We're seeing more and more 3rd and 4th party attacks that chain through multiple layers of compromised tools and services. In this topic segment, we discuss the two main aspects of this trend: How we can stop the chain of breaches from a third party library, vendor, or service provider How this might get handled at the legal, contractual, and organizational levels We discuss two big recent examples: Sonicwall's 2025 breach of their cloud firewall configuration backup service The compromise of Aqua Security's widely used Trivy open source tool The Weekly Enterprise News Finally, in the enterprise security news, Funding and M&A courtesy of the Security, Funded newsletter We have evidence that attackers are leveraging AI now (this sounds like old news, but there was little to no evidence before, when people were claiming this) The Angry admin problem emerges again Vulnerability information is getting crazy to keep up with Breach information is getting crazy to keep up with You can give your Agents an allowance now - don't spend it all in one place Are vulnerabilities sparse or dense? Mythos, as a model, isn't all that special Deploy your own deception sensors! Japan made something weird. Again. All that and more, on this episode of Enterprise Security Weekly. This segment is sponsored by BigID. Visit https://securityweekly.com/bigid to learn more about them! Show Notes: https://securityweekly.com/esw-459

The New CISO
Lessons From a Spy Hunter: The Real Cost of a Breach (Part 1)

The New CISO

Play Episode Listen Later May 14, 2026 34:30


What does it feel like to stand in the smoking ruin of a ransomware attack? In this episode, Steve Moore is joined by former FBI undercover operative Eric O'Neill—the man who helped capture Robert Hanssen—to explain why modern cybercrime is just traditional espionage repackaged, and why the dark web has quietly become the world's third-largest economy.Eric traces his path from the FBI's counterintelligence trenches to founding NeXasure AI and writing cybersecurity books that read like spy thrillers. He and Steve unpack the staggering scale of cybercrime, which Eric predicts could reach $20 trillion in global GDP within years—a marketplace selling everything from ransomware kits to stolen credentials.They dismantle the “it won't happen to me” mindset that still lingers in boardrooms. Eric describes how attackers use AI agents to scan for vulnerable systems, walks through how Scattered Spider socially engineered MGM in a ten-minute phone call, and explains why disabled MFA remains the leading point of failure for small and mid-size businesses.Eric then unpacks the painful calculus of paying a ransom. He explains why the FBI says never pay, when OFAC sanctions make payment a federal crime, and why—even after paying—an organization must still do the same forensic, legal, and architectural work. Steve and Eric also detail how attackers resell access and treat victims as repeat customers. The episode closes with a candid look at recovery. Eric and Steve explore why most companies fail at restoration, why rolling back to “before the attack” leaves the original flaw wide open, and why preparation always beats panic. Tune in for a part-one masterclass for any leader who thinks their organization is too small to be a target.Key Topics• How traditional espionage evolved into modern cybercrime• The dark web as the world's third-largest economy• Why every organization is a target, regardless of size• The MGM ransomware attack and Scattered Spider's playbook• Disabled MFA as the leading cause of SMB compromise• Vulnerability assessments versus fire-time remediation costs• The pay-versus-don't-pay ransomware calculus• OFAC sanctions and the legal risks of paying• Why restoring backups is not the same as recovery• The how, where, why, what, and when of breach forensicsGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:

Black Hills Information Security
The Canvas / Instructure Breach – 2026-05-11

Black Hills Information Security

Play Episode Listen Later May 12, 2026 63:18 Transcription Available


Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis

The Law School Toolbox Podcast: Tools for Law Students from 1L to the Bar Exam, and Beyond
555: Listen and Learn -- The Breach Element of a Negligence Claim (Torts)

The Law School Toolbox Podcast: Tools for Law Students from 1L to the Bar Exam, and Beyond

Play Episode Listen Later May 11, 2026 20:45


Welcome back to the Law School Toolbox podcast! Today, we're discussing the different methods a plaintiff may use to establish the second element of a negligence claim -- breach. We also talk about the "res ipsa loquitur" doctrine, and we will walk through several hypotheticals involving breach of the standard of care.  In this episode we discuss: An overview of negligence claims The reasonable person standard The "res ipsa loquitur" doctrine Hypothetical scenarios involving breach of the standard of care Resources: "Listen and Learn" series (https://lawschooltoolbox.com/law-school-toolbox-podcast-substantive-law-topics/#listen-learn) California Bar Examination – Essay Questions and Selected Answers, July 2021 (https://www.calbar.ca.gov/Portals/0/documents/admissions/Examinations/July-2021-CBX-Essay-Qs-and-Selected-Answers.pdf) Podcast Episode 244: Listen and Learn – Negligence Per Se (https://lawschooltoolbox.com/podcast-episode-244-listen-and-learn-negligence-per-se/) Podcast Episode 257: Listen and Learn – The Reasonable Person Standard (https://lawschooltoolbox.com/podcast-episode-257-listen-and-learn-the-reasonable-person-standard/) Podcast Episode 318: Listen and Learn – Negligence: Duties of Professionals and Children (https://lawschooltoolbox.com/podcast-episode-318-listen-and-learn-negligence-duties-of-professionals-and-children/) Podcast Episode 319: Listen and Learn – Negligence: Duties of Landlords, Owners, and Possessors of Land (https://lawschooltoolbox.com/podcast-episode-319-listen-and-learn-negligence-duties-of-landlords-owners-and-possessors-of-land/) Download the Transcript  (https://lawschooltoolbox.com/episode-555-listen-and-learn-the-breach-element-of-a-negligence-claim-torts/) If you enjoy the podcast, we'd love a nice review and/or rating on Apple Podcasts (https://itunes.apple.com/us/podcast/law-school-toolbox-podcast/id1027603976) or your favorite listening app. And feel free to reach out to us directly. You can always reach us via the contact form on the Law School Toolbox website (http://lawschooltoolbox.com/contact). If you're concerned about the bar exam, check out our sister site, the Bar Exam Toolbox (http://barexamtoolbox.com/). You can also sign up for our weekly podcast newsletter (https://lawschooltoolbox.com/get-law-school-podcast-updates/) to make sure you never miss an episode! Thanks for listening! Alison & Lee

The Economist Morning Briefing
Orban's rule ends; Putin accuses Ukraine of truce breach, and more

The Economist Morning Briefing

Play Episode Listen Later May 10, 2026 3:04


At least seven people were killed by Israeli strikes in Lebanon, according to health officials Hosted on Acast. See acast.com/privacy for more information.

Redwood Bureau
Facility Containment Protocol: FLOOR_3 - BREACH

Redwood Bureau

Play Episode Listen Later May 9, 2026 54:46


Hosted by Josh Tomar!  https://twitter.com/tomamoto https://www.twitch.tv/tomamoto Editing, Narration & Production by The Disciple https://twitter.com/The__Disciple https://www.youtube.com/@TheOnlyDisciple Subscribe on Spotify!  https://open.spotify.com/show/5OgfQg3svBwSUiU0zGqhet Please Review us on Apple Podcasts!  https://podcasts.apple.com/us/podcast/redwood-bureau/id1597996941 Find more shows like Redwood Bureau at https://eerie.fm/ Learn more about your ad choices. Visit podcastchoices.com/adchoices

The Warning with Steve Schmidt
Steve Schmidt & Bishop William Barber: A Moral Reckoning

The Warning with Steve Schmidt

Play Episode Listen Later May 7, 2026 42:47 Transcription Available


Steve Schmidt is joined by Bishop William Barber, president, Repairers of the Breach and founding director and professor, Yale Center for Public Theology and Public Policy. They discuss the excesses and greed of America’s oligarchy, Trump’s messiah complex, our urgent message to future Democratic leaders, and more. Support The Warning and become a YouTube member today! https://www.youtube.com/channel/UC2I50t9-7Ol7AjwryRv-Fiw/join Today's Merch: Team First Amendment https://thewarningwithsteveschmidt.com/products/team-first-amendment-crewneck SUBSCRIBE for more and follow me here: Substack: https://steveschmidt.substack.com/subscribe Store: https://thewarningwithsteveschmidt.com/ Bluesky: https://bsky.app/profile/thewarningses.bsky.social Facebook: https://www.facebook.com/SteveSchmidtSES/ TikTok: https://www.tiktok.com/@thewarningses Instagram: https://www.instagram.com/thewarningses/ X: https://x.com/SteveSchmidtSES See omnystudio.com/listener for privacy information.

The Football Ramble
Ramble Reacts: Bog roll Breach

The Football Ramble

Play Episode Listen Later Apr 29, 2026 30:33


It's not fair to compare Atletico 1-1 Arsenal to the beauty of PSG 5-4 Bayern Munich. Let's just say it was a more interesting game than we might have expected.Marcus and Vish went live on YouTube straight after full-time to break down an evening full of controversy, sandwiches and bog roll. Jump in, the water's still warm.Get your Ramble World Cup watchalong tickets hereFind us on Bluesky, X, Instagram, TikTok and YouTube, and email us here: show@footballramble.com.Sign up to the Football Ramble Patreon for ad-free shows for just $5 per month: https://www.patreon.com/footballramble.***Please take the time to rate us on your podcast app. It means a great deal to the show and will make it easier for other potential listeners to find us. Thanks!*** The Football Ramble, the original and best football podcast. Brand new podcasts every single weekday throughout the Premier League season and every day throughout the 2026 FIFA World Cup.No cliches. No ex-pros like Peter Crouch or The Rest is Football. Just the funniest football conversation out there. Your guardian for the season, daily not weekly. Stick to the Ramble, totally. Hosted on Acast. See acast.com/privacy for more information.