Podcasts about bug bounties

  • 412PODCASTS
  • 951EPISODES
  • 46mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 18, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about bug bounties

Show all podcasts related to bug bounties

Latest podcast episodes about bug bounties

WSJ Tech News Briefing
TNB Tech Minute: Top OpenAI and Microsoft Staff Knew Scraping News Websites was an ā€˜Existential Threat'

WSJ Tech News Briefing

Play Episode Listen Later Sep 18, 2026 1:48


Plus: Hackers used Anthropic's Claude tools to hack OpenAI. And Coinbase is seeking approval to list perpetual futures. Danny Lewis hosts. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Daily Tech Headlines
Bug Bounty Researchers Hacked OpenAI Using Anthropic's Claude – DTH

Daily Tech Headlines

Play Episode Listen Later Sep 18, 2026


Lucid and Bolt plan big European robotaxi push, German court rules Meta is liable for fake investment ads, Costco opens up to DoorDash and Uber Eats. MP3 Please SUBSCRIBE HERE for free or get DTNS shows ad-free. A special thanks to all our supporters–without you, none of this would be possible. If you enjoy whatContinue reading "Bug Bounty Researchers Hacked OpenAI Using Anthropic’s Claude – DTH"

Threat Talks - Your Gateway to Cybersecurity Insights
How a 19-Year-Old Hacked the NEWS Without Breaking In

Threat Talks - Your Gateway to Cybersecurity Insights

Play Episode Listen Later Sep 15, 2026 21:17


Your Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number.Ā Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way.Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone.Ā Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested.Timestamps(00:00) - MFA was on. He got in anyway. (02:04) - Why the biggest news organization became the target (03:24) - Mapping the attack surface before touching anything (04:54) - Eleven findings in the first responsible disclosure (08:50) - The Media Cloud help page and the live TOTP QR code (11:19) - How the password reset removes your second factor (14:29) - The 1 to 5 million euro estimate, and what to fix Key Topics CoveredAttack surface discovery against a large public broadcasterResponsible disclosure done well: response time, remediation, and recognitionWhere the next generation of defenders comes from, and how they choose a sideRelated ON2IT Content & Referenced Resources:Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams

Cyber Security Today
Surviving and thriving in the AI Vulnpocalypse

Cyber Security Today

Play Episode Listen Later Sep 5, 2026 29:36


Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems. Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.Ā  She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders. The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world. 00:00 Weekend Show Intro 00:07 Katie Moussouris Background 02:00 Bug Bounties Then and Now 03:31 AI Hype and Model Escapes 05:06 The Real Cost of Fixing 08:36 Smart AI Regulation 12:34 Tools for Defenders vs Rogues 15:53 Metasploit and Agentic Risk 17:25 Nightmare Eclipse and Microsoft 21:53 Luta Security Today 24:28 Training the Next Generation 27:46 Hope, UBI, and Wrap Up

Critical Thinking - Bug Bounty Podcast
Episode 189: What Happened to HackerOne with Joel Margolis

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Aug 27, 2026 74:18


Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we're (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest - Joel Magolishttps://x.com/0xteknogeek====== This Week in Bug Bounty ======Kara Sprague's Statement:ā€œI read Joel's post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don't have the full fix yet, but I own it and am also open to working together to find a good solution.ā€ Kara Sprague, CEO, HackerOne Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit pluginhttps://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-codeClaude Kithttps://github.com/yeswehack/claude-kit====== Resources ======What Happened to HackerOne?https://blog.teknogeek.io/posts/what-happened-to-hackerone/Watch our episode with Alex Ricehttps://www.youtube.com/watch?v=Pa4wWv_ONjM====== Timestamps ======(00:00:00) Introduction(00:04:18) The early days: LHE's, Covid, and the rise of AI(00:17:20) HSM Program, HAI, and resource allocation(00:36:41) Sales Incentivisation(00:46:10) AI and Researcher Reports Data(00:54:38) How Can H1 Revive its Old Self(01:02:40) Triage

Apple @ Work
Breaking down Apple's bug bounty cap and cool down period

Apple @ Work

Play Episode Listen Later Aug 25, 2026 14:00


Apple @ Work is exclusively brought to you by Mosyle,Ā the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage & protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work-ready with no effort and at an affordable cost.Ā Request your EXTENDED TRIALĀ today and understand why Mosyle is everything you need to work with Apple. In this episode of Apple @ Work, 9to5Mac's Arin Waichulis joins me to talk about Apple's decision to put in cool-down periods on its bug bounty submission program. Links Security Byte Podcast Apple caps security bug reports amid surge in AI-generated findings Security Bite: Apple's baffling bug bounty changes finally make sense Listen and subscribe Apple Podcasts Overcast Spotify Pocket Casts Castro RSS

Hacker Valley Studio
Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Hacker Valley Studio

Play Episode Listen Later Aug 19, 2026 34:52


Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ –  Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Critical Thinking - Bug Bounty Podcast
Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Aug 6, 2026 58:04


Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Trend of Bug Bounty Programshttps://x.com/iangcarroll/status/2082535987633410540Next chapter: Restructuring GitHub's bug bounty programhttps://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHubhttps://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854Gauntlet Loophttps://x.com/mattshumer_/status/2081830214384886228KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/====== Timestamps ======(00:00:00) Introduction(00:05:40) Bug Bounty Program Trends & Pricing Changes(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop(00:36:58) LHE vs Hackbot(00:43:21) KindaRails2Shell & WP2Shell

Critical Thinking - Bug Bounty Podcast
Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Jul 30, 2026 83:11


Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It's almost time for DEFCON! We're joined by Harley Kimball and Ariel Garcia to preview this year's Bug Bounty Village!Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztnaToday's Guests: Harley Kimball - https://x.com/infiniteloginsAriel Garcia - https://x.com/Arl_rose====== This Week in Bug Bounty ======Meet YesWeHack at DEFCON 34https://www.yeswehack.com/fr/page/yeswehack-defcon-34====== Resources ======Bug Bounty Village Agenda https://www.bugbountydefcon.com/agenda-2026BBV CTF 2026https://www.bugbountydefcon.com/ctfHacker Hangout with TikTok, HackerOne, and Bug Bounty Villagehttps://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd====== Timestamps ======(00:00:00) Introduction(00:04:39) Podcast ATO & ATM Hacks(00:17:12) Bug Bounty Village Preview(00:31:02) BBV Room Layout and Swag(00:42:36) BBV Agenda(01:10:57) Harley's Hackbot

Resilient Cyber
AI, Bug Bounties & the Vulnerability "Slopdemic"

Resilient Cyber

Play Episode Listen Later Jul 30, 2026 33:43 Transcription Available


Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.In this episode:Casey's path from building Bugcrowd to advising, investing, and policy workWhy more practitioners need to get involved in policy, and why law is just codeThe slopdemic vs. the vulnpocalypse, and what actually changed in submissionsAI lowering the bar for a broader, less predictable pool of threat actorsDaniel Stenberg, curl, and maintainers below the security poverty lineThe lightning rod vs. rockets distinction between VDPs and bug bountiesThe pentest market correction underway from AI pricing pressureCollapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.ioChapters:0:00 Intro and Casey's backgroundĀ 2:56 Why practitioners belong in policyĀ 6:22 The slopdemic vs. the vulnpocalypseĀ 9:40 AI lowering the bar for threat actorsĀ 11:47 Open source, curl, and the security poverty lineĀ 15:37 VDP vs. bug bounty readinessĀ 19:20 The pentest market correctionĀ 24:20 What breaks first in vulnerability managementĀ 27:20 Hack-back and non-cooperative defenseĀ 28:43 A near-term playbook for security leadersĀ 31:40 CFAA, SRLDF, and disclose.ioConnect with Casey:Ā LinkedIn: https://www.linkedin.com/in/caseyjohnellis Blog: https://cje.io disclose.io: https://disclose.io Bugcrowd: https://www.bugcrowd.comResilient Cyber: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.

Canaltech Podcast
VocĆŖ confiaria em um hacker para proteger sua empresa?

Canaltech Podcast

Play Episode Listen Later Jul 29, 2026 16:44


Empresas como Google, Microsoft e Meta jĆ” pagam milhƵes de dólares para quem encontra falhas de seguranƧa em seus sistemas. Mas e se esses especialistas forem justamente hackers? Esse Ć© o tema do novo episódio do Podcast Canaltech. Nesta edição, Fernanda Santos conversa com Rudinei Carapinheiro, chefe de EstratĆ©gias da IPV7, empresa que recentemente anunciou a aquisição da HuntersPay, uma das principais plataformas brasileiras de Bug Bounty. Durante a entrevista, o executivo explica como funciona esse modelo de seguranƧa ofensiva, quem sĆ£o os chamados hackers Ć©ticos e por que eles podem se tornar grandes aliados das empresas na prevenção de ataques cibernĆ©ticos. O episódio tambĆ©m aborda os desafios da ciberseguranƧa no Brasil, a importĆ¢ncia da cultura de prevenção, os critĆ©rios para selecionar pesquisadores de seguranƧa. VocĆŖ tambĆ©m vai conferir: Meta quer que vocĆŖ use menos o ChatGPT, conversa no Claude pode estar pĆŗblica sem vocĆŖ perceber e Balsa leva internet ao fundo dos rios da AmazĆ“nia. Este podcast foi roteirizado e apresentado por Fernanda Santos e contou com reportagens de Marcelo Fischer, Viviane FranƧa e Renato Moura. A trilha sonora Ć© de Guilherme Zomer, a edição de Leandro Gomes e a arte da capa Ć© de Erick Teixeira. O Podcast Canaltech estĆ” concorrendo para entrar no Top 20 do PrĆŖmio iBest 2026! Se vocĆŖ acompanha nossos episódios, curte as entrevistas e gosta do conteĆŗdo que produzimos todos os dias, sua ajuda pode fazer toda a diferenƧa. Vote no Podcast Canaltech aqui. Ɖ rĆ”pido, gratuito e vocĆŖ pode votar atĆ© 3 vezes por dia.See omnystudio.com/listener for privacy information.

Critical Thinking - Bug Bounty Podcast
Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Jul 23, 2026 73:10


Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://substack.com/@0xmoose====== This Week in Bug Bounty ======How to use Claude Code for Bug Bounty: find fast, validate manuallyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-claude====== Resources ======Signal Over Noise: AI Agents and the Operator Moathttps://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-theFBDL Goes Agentic: AI Agents Can Now Build Your Test Environmentshttps://bugbounty.meta.com/blog/fbdl-goes-agentic/====== Timestamps ======(00:00:00) Introduction(00:11:01) Satisfaction for hackbot finds(00:19:31) Hackbot Mechanics and Tech Debt(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing(01:05:45) Hackbot Load Distribution

Security Now (MP3)
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Security Now (MP3)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

All TWiT.tv Shows (MP3)
Security Now 1086: The Apex Agentic Adversary

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Security Now (Video HD)
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Security Now (Video HD)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Security Now (Video HI)
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Security Now (Video HI)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Radio Leo (Audio)
Security Now 1086: The Apex Agentic Adversary

Radio Leo (Audio)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Security Now (Video LO)
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Security Now (Video LO)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

All TWiT.tv Shows (Video LO)
Security Now 1086: The Apex Agentic Adversary

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Radio Leo (Video HD)
Security Now 1086: The Apex Agentic Adversary

Radio Leo (Video HD)

Play Episode Listen Later Jul 8, 2026 173:23 Transcription Available


From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com

Critical Thinking - Bug Bounty Podcast
Episode 181: Bug Bounty Singularity

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Jul 2, 2026 52:16


Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Are bug bounties cooked?https://hakluke.com/are-bug-bounties-cookedWe built a Hackbothttps://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html====== Timestamps ======(00:00:00) Introduction(00:07:22) Manual vs. AI Hacking(00:17:27) Building a Hackbot(00:23:53) Negatives of Hackbots(00:31:34) Logistics and Problems of Singularity (00:46:21) Successes

Critical Thinking - Bug Bounty Podcast
Episode 180: State of Bug Bounty Maturity Posture Report

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Jun 25, 2026 72:44


Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://x.com/SteveHernandezMEmail Steve at info@bugbountymaturity.comFill out this form to enter a Critical Thinkers rafflehttps://forms.ctbb.show/mdaz====== Resources ======State of Bug Bounty Maturity Posturehttps://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026Take the Bug Bounty Maturity Assessmenthttps://bugbountymaturity.com/assessmentAI Is Compressing the Bug Bounty Maturity Curvehttps://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve====== Timestamps ======(00:00:00) Introduction(00:04:09) State of Bug Bounty Maturity Posture(00:22:33) Researcher Interface & Program Trust(00:44:38) Maturity Bands and Scoring (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve

Critical Thinking - Bug Bounty Podcast
Episode 179: Maintaining Motivation in Post-AI Bug Bounty World

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Jun 18, 2026 46:27


Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access:https://www.threatlocker.com/capabilities/zero-trust-cloud-access====== Timestamps ======(00:00:00) Introduction(00:04:57) Managing Hacker Motivation(00:10:45) Community, Competition, & Curosity(00:16:54) Using AI with Passion(00:23:10) The LHE Method & Sharing Wins(00:28:01) Video POCs, Scripts, & Talking about Bugs(00:40:49) Watching your health & stopping mid-hack

The Audit
Cyber News: Bug Bounty Fail, Open-Source Malware & Facebook SMB Phishing

The Audit

Play Episode Listen Later Jun 15, 2026 36:08 Transcription Available


An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most.Ā The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use.Ā 

Ethereum Cat Herders Podcast
How to Secure Smart Contracts from AI Attacks | CredShields | Indranil Roy | EPD #33

Ethereum Cat Herders Podcast

Play Episode Listen Later Jun 3, 2026 45:23


In this episode of Ecosystem Project Demo 33 on the ECH Institute channel, we dive deep into the evolving landscape of Web3 security with Indranil Roy from CredShields. As AI continues to transform the tech industry, it also introduces new vulnerabilities and sophisticated "AI attacks" targeting smart contracts.Indranil shares expert insights on the proactive measures developers and organizations can take to secure their blockchain applications. We explore the intersection of artificial intelligence and cybersecurity, discussing how to leverage advanced tooling and rigorous auditing to safeguard assets in an increasingly complex digital environment.

The Business of Open Source
The AI-Induced Death of A Bug Bounty Program with Glauber Costa

The Business of Open Source

Play Episode Listen Later Jun 1, 2026 43:33


The Business of Open Source is back! I'm starting a series about AI and open source this week.Ā I reached out to Glauber Costa, founder of Turso, after reading a post of his on LinkedIn about how bot-written PRs for their bug bounty program forced them to discontinue the program completely. In this episode, he talked about the bug bounty program — how it started, who contributed to it initially, why he considered it a huge success. And then he talks about what started happening when bots entered the picture.Ā He also talked about the difference between an open source project that accepts contributions and one that doesn't, about the difference between an open source project and software that's in the public domain, and how people in open source used to be seen as weirdos who hate money.Ā Glauber isn't an AI hater — he talks about how they use AI at Turso, and how he has no problem with AI-assisted pull requests. The issue is when the result isn't high-quality. There's also a difference between AI-assisted and 100% bot written. Then it creates essentially a denial of service attack on the community, because the maintainers end up having to spend so much time responding to bot-created PRs.Ā What's your experience with AI and Open Source? Who else should I talk to? Let me know.Ā Do you like The Business of Open Source? Help it to continue to exist by sponsoring the podcast.Does your company have a positioning problem? Work with me to better position your product and see your growth take off.Ā 

Security Conversations
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap

Security Conversations

Play Episode Listen Later May 26, 2026 49:37


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be told

VC Hunting Podcast - Know the Money!
mythos ai destroys apple m5 chips

VC Hunting Podcast - Know the Money!

Play Episode Listen Later May 16, 2026 2:48 Transcription Available


Two researchers from a small Palo Alto outfit drove up to Apple's Cupertino headquarters to hand-deliver something the bug bounty queue would have buried. A working kernel exploit against the M5 chip's Memory Integrity Enforcement. Built in five days. With AI help. Apple's most expensive new security feature, defeated in less than a week by two people and a chatbot.The defender has to be right everywhere. The attacker only needs one path. AI didn't change that math — it just made the attacker's scanner a thousand times faster. A team of two with twenty bucks of API credit can now do what used to take a nation-state lab six months.Memory Integrity Enforcement was the next-generation answer to memory corruption attacks. Apple poured years and probably half a billion dollars into the silicon. The M5 is brand new. Five days. Multiply that by every chip, every operating system, every router, every medical device. The attack surface didn't expand. The time-to-discover collapsed.The five-day exploit isn't the story. The bug bounty queue is. The page used to look like a defense layer. It looks like a triage room now.Two people drove to Cupertino with their findings. They knocked. They got in the meeting. They gave Apple a chance to fix it before anyone else found it. That version of the story is still happening. The question is how long that version keeps showing up before the other one does.AI compresses the time between vulnerability and exploit. It does not compress the time between exploit and disclosure. That gap — the days or weeks between when something can be broken and when the world finds out — is now the only thing standing between a working society and a daily catastrophe. Two researchers chose the long version. The next two might not. Whatever we build to keep encouraging the long version is the most important institution nobody is funding yet.ā±ļø Chapters0:00 — Two researchers drive to Apple HQ with a 5-day exploit0:25 — MiniDoge: nation-state lab six months → 2 people with $20 API0:55 — Nyx: Memory Integrity Enforcement defeated; time-to-discover collapsed1:25 — HH: the bug bounty queue used to be a defense — now it's a triage room1:45 — Saarvis: the good ending requires a knock; that version is still happening2:10 — Saarvis: the gap between exploit and disclosure is now everything⚔ Learn agentic ai free - https://staas.fund/ai-workshop ⚔-----

Critical Thinking - Bug Bounty Podcast
Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later May 14, 2026 69:57


Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== This Week in Bug Bounty ======COST, AI frontier models and more: A measured take on the future of security testinghttps://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testingCommon AI misconceptions debugged!https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportionBountySync + Socialhttps://luma.com/bountysync_social====== Resources ======Ghosts of Encryption Pasthttps://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/tessl Skill Optimizerhttps://tessl.io/registry/tessl/skill-optimizer/0.8.0The Internet Is Falling Down, Falling Down, Falling Downhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/High Fidelity Check for the cPanel Authentication Bypasshttps://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/Achieving Deterministic Prompt Injection Through Client-Side Feedback Loopshttps://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/GPT-5.5: Mythos-Like Hacking, Open To Allhttps://xbow.com/blog/mythos-like-hacking-open-to-allRemote Command Execution in Google Cloud with Single Directory Deletionhttps://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral====== Timestamps ======(00:00:00) Introduction(00:09:20) AMPScript(00:25:10) Tessl Skill Optimizer(00:33:07) cPanel & WHM Authentication Bypass(00:40:46) Advice for Bug Bounty Programs(00:50:07) Prompt Injection Through Client-Side Feedback Loops(00:54:37) GPT 5.5(01:01:00) Remote Command Execution in Google Cloud

Critical Thinking - Bug Bounty Podcast
Episode 173: Bug Bounty is Dead and AI Killed it.

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later May 7, 2026 61:30


Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we're talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access:https://www.criticalthinkingpodcast.io/tl-ztca====== Resources ======We want your feedback on this!https://forms.ctbb.show/future_of_bug_bountyEvolving the Android & Chrome VRPs for the AI Erahttps://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-eraPaid Submissions?https://x.com/d0rsky/status/2047744193976742120Keep the Robots Out of the Gymhttps://danielmiessler.com/blog/keep-the-robots-out-of-the-gymIs my data used for model training?https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training====== Timestamps ======(00:00:00) Introduction(00:06:28) Network effects of Bug Bounty(00:31:55) Hopium/Copium(00:47:21) The Great Training Data Debate

Security Now (MP3)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (MP3)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

All TWiT.tv Shows (MP3)
Security Now 1077: A Browser AI API?

All TWiT.tv Shows (MP3)

Play Episode Listen Later May 6, 2026 155:01 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video HD)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video HD)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video HI)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video HI)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Radio Leo (Audio)
Security Now 1077: A Browser AI API?

Radio Leo (Audio)

Play Episode Listen Later May 6, 2026 155:01 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video LO)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video LO)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

All TWiT.tv Shows (Video LO)
Security Now 1077: A Browser AI API?

All TWiT.tv Shows (Video LO)

Play Episode Listen Later May 6, 2026 155:00 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Breaking Into Cybersecurity
Breaking Into Cybersecurity - Nikhil Agarwal

Breaking Into Cybersecurity

Play Episode Listen Later May 2, 2026 22:31


Description:Want to break into cybersecurity? Learn how Nikhil Agarwal moved from reverse engineering video games to leading AI security teams and automating complex infosec workflows. [bic-00003]In this episode, we explore:How childhood curiosity about software keys and "cheat codes" builds a foundation for red teaming. [bic-00004]The evolution from freelance bug hunting to professional penetration testing. [bic-00004]Nikhil reveals practical AI tools for automating security tasks in the cloud. [bic-XXXX1] [bic-00009]Demystifying AI-powered threat hunting: Practical steps and strategies. [bic-XXXX2] [bic-00009]Implementing AI for cloud security threat detection and automated incident response. [bic-00008]Timestamps: [bic-00004]00:00 - Intro & Countdown00:29 - Welcome Nikhil Agarwal00:52 - Childhood curiosity and reverse engineering games01:45 - Early freelance red teaming and the "pre-bug bounty" eraGuest Bio: [bic-00004]Nikhil Agarwal is a cybersecurity expert specializing in AI security teams and the automation of complex security operations. He leverages a background in red teaming and penetration testing to bridge the gap between hands-on technical skills and modern AI-driven cloud security.Community Link | Subscribe on YouTube [bic-00007]Tags: [bic-00005] [bic-00006]Nikhil Agarwal, AI Security, Red Teaming, Cloud Security Automation, Bug Bounty, AI Threat Hunting, breaking into cybersecurity, cybersecurity career, how to get into cybersecurity, cybersecurity podcast, infosec career, cybersecurity career change, cybersecurity for beginners, cybersecurity career advice, cybersecurity jobs, CISO interview, pivot to cybersecurity, cybersecurity certifications.***Sponsored by CPF Coaching LLC - http://cpf-coaching.comThe Breaking into Cybersecurity: It's a conversation about what they did before, why they pivoted into cyber, what the process was they went through, how they keep up, and advice/tips/tricks along the way.Check out our books:The Cybersecurity Advantage - https://leanpub.com/the-cybersecurity-advantageDevelop Your Cybersecurity Career Path: https://amzn.to/3443AUIHack the Cybersecurity Interview: https://www.amazon.com/Hack-Cybersecurity-Interview-Interviews-Entry-level/dp/1835461298/---About the hosts:Renee Small is the CEO of Cyber Human Capital and author of Magnetic Hiring. https://www.linkedin.com/in/reneebrownsmall/Christophe Foulon is a Cybersecurity Strategist and passionate about customer service and process improvement. https://www.linkedin.com/in/christophefoulon/- Website: https://www.cyberhubpodcast.com/breakingintocybersecurity- Podcast: https://podcasters.spotify.com/pod/show/breaking-into-cybersecuri- YouTube: https://www.youtube.com/c/BreakingIntoCybersecurity- Linkedin: https://www.linkedin.com/company/breaking-into-cybersecurity/

Critical Thinking - Bug Bounty Podcast
Episode 172: Source Code Review Meta Analysis

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Apr 30, 2026 51:01


Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.Expires June 30, 2026. ====== This Week in Bug Bounty ======Open-source security testing: the Bug Bounty guide to code analysishttps://www.yeswehack.com/learn-bug-bounty/open-source-guide-code-analysis?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=open-source-guide-code-analysis====== Resources ======Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)https://slcyber.io/research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#:~:text=across%20different%20languages.-,A%20MUST%2DKNOW%20BEHAVIOUR%20OF%20PATH.COMBINE,-Another%20key%20implementation====== Timestamps ======(00:00:00) Introduction(00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes.(00:17:33) Mapping the software(00:24:46) Sniffing for blood(00:31:54) Common Patterns and Pitfalls

Cybercrime Magazine Podcast
Evolution Of Bug Bounties. A Hacker's Perspective. Katie Moussouris, Founder & CEO, Luta Security.

Cybercrime Magazine Podcast

Play Episode Listen Later Apr 28, 2026 14:45


Katie Moussouris is the founder and CEO at Luta Security. In this episode, she joins host Charlie Osborne to discuss her career and the bug bounty industry, including her work in launching one of the first major bug bounty programs at Microsoft, and more. • For more on cybersecurity, visit us at https://cybersecurityventures.com

Critical Thinking - Bug Bounty Podcast
Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Apr 23, 2026 22:44


Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking agesFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out ThreatLocker Ringfencinghttps://www.criticalthinkingpodcast.io/tl-rf====== Resources ======The ultimate Bug Bounty guide to OS command injection vulnerabilitieshttps://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-os-command-injectionCritical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validationhttps://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-wordpress-bypass-pluginAituglo featured on YWHhttps://www.yeswehack.com/community/developer-aituglo-bug-bounty-storyAdobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21sthttps://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/====== Resources ======SVG clickjackinghttps://lyra.horse/blog/2025/12/svg-clickjacking/ ====== Timestamps ======(00:00:00) Introduction(00:06:35) Protobuff XSS(00:12:51) Leaking Age & CSPTs(00:15:59) Capital Letters and Clickjacking

miami os discord hacks bug bounties uppercase scoped capital letters oidc clickjacking ytcracker ekoparty
Security Now (MP3)
SN 1075: Yes. Exactly. - The Zero-Day Ticking Clock

Security Now (MP3)

Play Episode Listen Later Apr 22, 2026 160:28


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

All TWiT.tv Shows (MP3)
Security Now 1075: Yes. Exactly.

All TWiT.tv Shows (MP3)

Play Episode Listen Later Apr 22, 2026 160:28 Transcription Available


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

Security Now (Video HD)
SN 1075: Yes. Exactly. - The Zero-Day Ticking Clock

Security Now (Video HD)

Play Episode Listen Later Apr 22, 2026 160:28 Transcription Available


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

Security Now (Video HI)
SN 1075: Yes. Exactly. - The Zero-Day Ticking Clock

Security Now (Video HI)

Play Episode Listen Later Apr 22, 2026 160:28 Transcription Available


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

Radio Leo (Audio)
Security Now 1075: Yes. Exactly.

Radio Leo (Audio)

Play Episode Listen Later Apr 22, 2026 160:28 Transcription Available


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

Security Now (Video LO)
SN 1075: Yes. Exactly. - The Zero-Day Ticking Clock

Security Now (Video LO)

Play Episode Listen Later Apr 22, 2026 160:28 Transcription Available


Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security

No Password Required
No Password Required Breakout Room with Fagan Afandiyev

No Password Required

Play Episode Listen Later Apr 21, 2026 20:28


Fagan Afandiyev — Elite Cybersecurity Competitor and Legendary Whitehatter No Password Required: Breakout Room: Episode 1 — Fagan Afandiyev Fagan Afandiyev is a cybersecurity student at the University of South Florida and a member of the CyberHerd competition team, known for his strategic mindset and passion for solving complex challenges. From competing in international robotics competitions to discovering cybersecurity through hands-on platforms, Fagan has built his skills through curiosity, persistence, and a love for problem solving. Fagan shares how competitions, community, and continuous learning shaped his journey into cybersecurity. He walks through his growth within USF's cyber community, and how that led to a penetration testing internship at Microsoft. He also offers insight into the mindset needed to succeed in cybersecurity, encouraging others to embrace challenges, learn through failure, and find enjoyment in the process. Follow Fagan on Linked in here: https://www.linkedin.com/in/fagan-afandi/ Presented by ThreatLocker Chapters:Ā  00:00 Introduction to Cybersecurity Passion 3:02 Ā Ā Journey to Cyber Herd and University Life 06:12 Internship at Microsoft and Career Aspirations 08:59 Hackathon Experience and Community Engagement 12:39 Behind the Scenes of Cyber Competitions 14:30 Ā Overcoming Challenges in Cyber Competitions 18:00 Gratitude and Mentorship in Cybersecurity Ā 

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 7, 2026 6:55


How often are redirects used in phishing in 2026? https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870 Hackerone Suspends Internet Bug Bounty https://hackerone.com/ibb?type=team https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/ Bluehammer Windows 0-day Privilege Escalation https://github.com/Nightmare-Eclipse/BlueHammer https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html https://deepwiki.com/Nightmare-Eclipse/BlueHammer Keycloak MFA Bypass CVE-2026-3429 https://access.redhat.com/security/cve/cve-2026-3429

Security Now (MP3)
SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

Security Now (MP3)

Play Episode Listen Later Feb 4, 2026 175:34


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com