Podcasts about CAPTCHA

Computer test to discriminate human users from spambots

  • 546PODCASTS
  • 675EPISODES
  • 44mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 25, 2026LATEST
CAPTCHA

POPULARITY

20192020202120222023202420252026


Best podcasts about CAPTCHA

Latest podcast episodes about CAPTCHA

The Jordan Harbinger Show
1373: Sonja Lyubomirsky | Five Mindsets to Get You More of What Matters

The Jordan Harbinger Show

Play Episode Listen Later Aug 25, 2026 90:57


Money, fame, and abs buy admiration, not intimacy. How to Feel Loved author Sonja Lyubomirsky reveals the five mindsets that make you feel loved.Full show notes and resources can be found here: jordanharbinger.com/1373What We Discuss with Sonja Lyubomirsky:Being loved and feeling loved are two different things. Surveys found 70 percent of people can name a close relationship where the love just isn't landing. Someone can adore you completely, but if it never clears your firewall, you can feel utterly alone in a room full of people who care.The fix isn't becoming more lovable or overhauling your partner — it's changing the next conversation. A relationship is really just a series of conversations, which means feeling more loved is far more under your control than the entire self-help aisle wants you to believe.Money, status, and six-pack abs buy admiration, not intimacy — and admiration never makes anyone feel known. Optimizing your dating life like you're shopping for a used Porsche, chasing the mythical 'four sixes,' only builds a more elaborate CAPTCHA for loneliness.The five love languages are closer to pop theology than science. Researchers debunked the idea that partners must 'match' or the relationship is doomed. There are far more than five ways to connect, and the two everyone actually craves are simply quality time and words of affirmation.If you don't feel loved, go first. Get curious, listen to learn instead of to reply, share, and lead with warmth. Text that old friend, ask your parents real questions, break out the conversation cards. Connection is a skill, and every small drop counts.And much more...And if you're still game to support us, please leave a review here — even one sentence helps! Sign up for Six-Minute Networking — our free networking and relationship development mini course — at jordanharbinger.com/course!Subscribe to our once-a-week Wee Bit Wiser newsletter today and start filling your Wednesdays with wisdom!Do you even Reddit, bro? Join us at r/JordanHarbinger!This Episode Is Brought To You By Our Fine Sponsors: BetterHelp: 10% off first month: betterhelp.com/jordanFactor: 50% off first box: factormeals.com/jordan50off, code JORDAN50OFFPaka: Paka hoodie & crew socks: go.pakaapparel.com/jordanProgressive Insurance: Free online quote: progressive.comSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

NonMembers Only
#255 - Death Diving,Legend of Kevin's Truck,& Sleeping on Garage Floors

NonMembers Only

Play Episode Listen Later Aug 17, 2026 60:14


We kick off on National Thrift Shop Day with Erin literally pouring sweat after Dan opened the garage doors to unpack from six chaotic weeks away at the shore. She breaks down the disastrous end to their beach trip: after the borough removed their boat ramp, her mom Judy took a nasty tumble trying to climb the bulkhead and ended up in a packed, terrifying hallway bed in the ER. To make matters worse, Judy hobbled out of the hospital before getting her painkillers, leaving the entire extended family, 16 people and a dog, crammed into a 3 bedroom house. Erin spent the night sleeping on the garage floor next to a flashing electric car charger and a kicking toddler. In sports news, we introduce the chaotic new street game "Don't Touch the Can," marvel at the terrifying flips and belly flops of Norwegian Death Diving, and celebrate a guy in Cleveland who just broke the world record for the fastest mile while pushing a Thule stroller clocking in at an insane 4:17 while his baby just happily kicked around inside. We also discuss the upcoming Australian Netflix documentary on the viral Olympic breakdancer Raygun, and debunk a fake viral video that falsely claimed a hiker was charged $70,000 for a helicopter rescue in Yosemite.Moving into tech and marketing, we dive into a wild conspiracy theory that AI companies are secretly paying creators massive sums to start a TikTok trend of reciting phrases with different emotions just to train their voice models. Speaking of insane tech money, we touch on a tech podcast allegedly getting a $70 million buyout, before Erin unleashes a massive rant against BMW for forcing unskippable video ads onto their cars' dashboards and the absolute misery of new CAPTCHA tests asking users to match animal environments. We then review a hilarious story out of New Jersey where police actually disguised themselves as bushes to catch 74 drivers using their cell phones. Finally, we wrap up with "No Bad, No Sad," featuring a legendary viral post from a Japanese man discovering the American phenomenon of having a “truck guy” where moving a sofa costs exactly one pizza, reminding us that Dan is officially our neighborhood's "Kevin".

Lovett or Leave It
Crazy Stupid Glove

Lovett or Leave It

Play Episode Listen Later Aug 14, 2026 67:24


The Kennedy Center puts Trump's name up in lights, Karoline Leavitt gives her final bow, and ICE's electric gloves steal the show. This week, Congressman Ted Lieu and David Pakman debate an AI Kill Switch and consider algorithmic clickbait. Jim Rash pays respects to Allison Janney, Barbie 2, and Woke 1.0. We spin the Rant Wheel on Captcha, tipping, AI writing ticks, and singing Happy Birthday. And we snuggle in for the night with a cozy round of Second Thoughts.Hate listening to ads? Become a Friends of the Pod subscriber for ad-free episodes of Pod Save America, Pod Save the World, Lovett or Leave It, Runaway Country, Offline with Jon Favreau, and more—plus exclusive content, including bonus episodes of Pod Save America. Subscribe now at crooked.com/friends, on Apple Podcasts, or through the Pod Save America YouTube channel.You can request a transcript by emailing transcripts@crooked.com. Include the podcast name, episode title, and air date. Please allow 48 hours for delivery.

ChannelBuzz.ca
Logging in, not breaking in: Blackpoint Cyber’s Wil Santiago on the 2026 threat landscape

ChannelBuzz.ca

Play Episode Listen Later Aug 13, 2026 30:07


Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

Ich glaube, es hackt!
KI, Cloud und andere Dinge, die plötzlich Milliarden kosten

Ich glaube, es hackt!

Play Episode Listen Later Aug 11, 2026 57:31 Transcription Available


In dieser Folge von „Ich glaube, es hackt!“ geht es einmal quer durch die digitale Welt: - Zwangstrennung bei Mobilfunk: Warum 23 Stunden Telefonieren doch kein notwendiger Test waren. - Abkürzungs-Quiz: Radar, SCUBA, LASER und CAPTCHA – und die überraschenden Bedeutungen dahinter. - KI erkennt ein Kühlakku als Handy: Wenn automatische Verkehrsüberwachung kreativ danebenliegt. - Cloud-Kosten außer Kontrolle: Was passiert, wenn aus 43 Cent plötzlich Milliarden werden – und warum Plausibilitätschecks bei Cloud-Rechnungen dringend nötig sind. - Ausgebrochene KI-Agenten: Was passiert, wenn eine KI aus ihrer Sandbox entkommt und plötzlich mit anderen KI-Agenten kommuniziert? - KI-Crawler und robots.txt: Wem gehört eigentlich der Content im Internet – und darf KI ihn einfach fürs Training verwenden? - Cloudflare und AI-Crawler: Warum sich die Spielregeln für Webseitenbetreiber verändern könnten. - Pay-per-Crawl: Bezahlen KI-Anbieter künftig für das Crawlen von Webseiten? - Lokale KI-Modelle: Warum Regierungen möglicherweise darüber diskutieren, wer welche Modelle herunterladen darf. - Das große Codezeilen-Quiz: Ford F-150 gegen Boeing 787 gegen Facebook. Spoiler: Das Auto gewinnt deutlich. - KI im Bewerbungsgespräch: Bewerber lassen sich live coachen – und Unternehmen setzen ihrerseits KI im Recruiting ein. - Bakteriophagen und KI: Wenn künstliche Intelligenz nicht nur Software, sondern biologische Systeme mitgestaltet. - Grok(k)epedia: Warum die KI-Wikipedia von Elon Musk offenbar nicht mehr weiter aktualisiert wird. - Doom in Microsoft Paint: Weil „läuft Doom darauf?“ offenbar immer noch eine gültige technische Messgröße ist. - PlayStation-2-Tricks: Warum manche Spiele-Discs absichtlich mit Datenmüll gefüllt wurden. - Blitzer.de für den ÖPNV: Eine App warnt vor Fahrkartenkontrollen. - Werbung im Auto: Spider-Man im BMW – harmlose Spielerei oder der nächste Schritt zur Werbeplattform auf vier Rädern? - Software-Features zum Mieten: Warum Rüdiger und Tobi so gar keine Fans von nachträglich freischaltbaren Funktionen sind. - Tonies und veränderliche Inhalte: Was passiert, wenn das Produkt, das man gekauft hat, seine Inhalte nachträglich ändern kann? - Kreuzfahrt-Security: Ein beobachteter Zugangscode reicht offenbar, um eine vermeintliche Kapitänsdurchsage zu faken. - Und zum Schluss: Golf. Natürlich. Nach fast 24 Stunden Telefonat darf auch das noch sein. -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast

Tech Gumbo
Hackers And Hotel Wi-Fi, FBI Warns of Utility Attacks, the 2D Barcode Transition, and OS's Will Demand Your Age

Tech Gumbo

Play Episode Listen Later Aug 10, 2026 22:09


Segment Note — Geaux AI Workshop Promo: 60-second radio spot for your hands-on "Geaux AI" beginner workshop — Tuesday, September 8th, 9 to 1, at the Baton Rouge Marriott. Sign-ups at techgumbo.net/geauxai.   News and Updates: Russian Hackers Hijack Hotel Wi-Fi: Microsoft warns a Kremlin-linked group (a Cozy Bear subgroup) is tampering with hotel Wi-Fi to redirect guests to fake Microsoft login pages and push malware disguised as browser or OS updates. Compromised networks serve fake CAPTCHA and update prompts—like a phony Windows driver repair tool—that trick users into running commands that install remote-access trojans such as "Cornflake." FBI: Water Utilities Under Attack: Hackers targeted water and wastewater systems in at least seven states, exploiting internet-exposed Rockwell/Allen-Bradley PLCs and causing pressure loss and flooding in some systems.  A coordinated attack hit 30+ Minnesota community water systems; officials suspect Iran amid renewed US-Iran military tensions, though no formal attribution has been made. The 2D Barcode "Sunrise": GS1 is pushing a global 2027 transition from traditional 1D UPC barcodes to data-rich 2D codes (QR, Data Matrix) that store expiration dates, batch codes, URLs, and authentication data. The shift promises faster scanning from any angle, better traceability for food and pharma recalls, anti-counterfeiting, and consumer engagement—with emerging 3D laser-etched codes for industrial durability. Your Computer May Demand Your Age: Starting in 2027, California's Digital Age Assurance Act will require operating systems (Windows, macOS, Android, Linux) to collect users' ages at setup and share an age bracket with apps. The EFF warns that in practice, compliance could escalate to ID uploads or facial scans, and that broad laws threaten anonymous computing and small open-source projects like Linux distributions.

Talking Drupal
Talking Drupal #564 - Approachable Open Source

Talking Drupal

Play Episode Listen Later Aug 6, 2026 80:41


Today we are talking about Maintaining NodeJS, Patternlab, Writing Books, and Open Source with guest Brian Muenzenmeyer. We'll also cover AI Webform Generator as our module of the week. For show notes visit: https://www.talkingDrupal.com/564 Topics Brian Open Source Origins Pattern Lab Node Journey Maintaining and Moving On Writing Approachable Open Source Who the Book Is For Beyond Code Contributions All Things Open Book Signing Choosing Conferences to Attend Pitching Open Source at Work Misconceptions and Starting Small Avoiding Maintainer Burnout Handling AI Noise and Low Effort PRs DCO and Licensing Basics Better Communication and Reviews Node and Drupal Lessons Optimism for Open Source Future Resources Brian Muenzenmeyer https://brianmuenzenmeyer.com https://approachableopensource.com/ https://bsky.app/profile/brianmuenzenmeyer.com https://www.linkedin.com/in/brian-muenzenmeyer-91a77554/ https://www.renderatl.com/schedule upcoming https://nodeconf.eu/program upcoming spectrum of engagement https://approachableopensource.com/blog/2025-open-source-pace-layers/ change in contention https://brianmuenzenmeyer.com/posts/2018-i-maintainer/ burnout https://approachableopensource.com/read/the_spectrum_of_engagement/ https://approachableopensource.com/read/the_four_files_of_any_open_source_project/ LICENSE Hodag Cryptid https://en.wikipedia.org/wiki/Hodag https://www.rhinelanderchamber.com/about-the-hodag/ You should write a book All contributors spec Talk at all things apart DCO Developer Certificate of Origin Open source law policy and practice Sustain OSS Guests Brian Muenzenmeyer - brianmuenzenmeyer.com Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Bernardo Martinez - bernardm28 JD Flynn - dorficus MOTW Correspondent Jacob Rockowitz - jrockowitz.com jrockowitz Brief description: AI Webform Generator enables site builders to create a Drupal Webform, or update an existing one, from plain-English instructions. It sends the request through the site's configured Drupal AI provider, validates the returned Webform definition, and saves the resulting form. Review the generated change before using the form. Module name/project name: AI Webform Generator (ai_webform_generator) Brief history Created on 2 July 2026 by chaitanyadessai (Chaitanya R Dessai). The current stable release is 1.0.2, released on 3 July 2026, and supports Drupal ^10 || ^11. Maintainership Appears actively maintained: Drupal.org lists an update on 24 July 2026. Maintainers: zeeshan_khan and chaitanyadessai. (Specbee) Security coverage: Yes. Stable releases are covered by Drupal's security advisory policy. Test coverage: Yes. Version 1.0.2 includes unit, kernel, and functional tests for prompt building, JSON validation, settings, route access, Webform building, and optional CAPTCHA elements. Documentation: Yes. The project page and module README cover requirements, configuration, usage, security considerations, and supported field types. Issues: 1 open issue, with 0 open bug reports (7 issues total). Usage stats: 1 site reports using this module. Module features and usage Creates complete Webforms and updates existing Webforms in place from natural-language prompts. Supports common Webform elements, including text, email, telephone, number, date, select, checkbox, radio, range, password, hidden, and managed-file elements. Validates the AI response before applying the Webform definition. Uses the existing Drupal AI provider configuration; API keys are not stored in this module's configuration. Provides configurable model, temperature, output-token, and per-user request limits to balance output quality and provider spend. Requires trusted users with both the generator permission and ordinary Webform edit access when changing an existing form. AI-Generate Notes, Review, and Recipe (used for testing) https://github.com/jrockowitz/drupal_playground/tree/main/recipes/drupal_playground_webform_ai AI-Generated Assessment Technical: The module separates AI generation, prompt building, JSON validation, and Webform construction into Drupal services. It uses the site's configured Drupal AI provider, validates a limited allowlist of Webform element types before saving, and exposes model, temperature, output-token, and per-user request-limit settings. Access and error handling: Generation requires its own permission, and updating an existing Webform also requires normal Webform update access. A per-user flood limit constrains provider spend; failures are logged, with detailed upstream errors shown only to generator administrators. Code quality: Version 1.0.2 uses strict types and separates form, service, validation, and persistence responsibilities. It includes unit, kernel, and functional coverage for core behavior. This assessment is a code review of the released module, not a security audit. Implementation: The module creates new Webforms and updates supported fields of existing Webforms in place, but saves the generated definition immediately without a preview, diff, or approval screen. Usefulness: The module is useful for quickly drafting straightforward Webforms and iterating on common field changes when a site builder reviews the result. Complex, highly customized, or regulated forms need especially careful manual review before publication. How to use it: Configure a chat-capable provider, select an existing Webform or choose to create one, describe the fields and validation in plain English, submit the request, and then review the saved Webform. For example, create a disposable contact Webform and ask the generator to add a required telephone field while preserving the existing fields. AI-generated source code: The module's runtime use of AI and its code style cannot establish whether its source was AI-generated or AI-assisted. Its public project metadata does not make an authorship claim, so this is unknown. Possible improvements: Add a preview/diff and explicit approval before saving; broaden support for advanced Webform structures and handlers; add optional, privacy-conscious prompt and response audit logs; and expand regression coverage for complex Webform updates. Next steps for adopters: Restrict generation to trusted roles, begin with a low request limit, test representative prompts outside production, and review every generated field, validation rule, confirmation message, and permission before publishing.

Silicon Valley Tech And AI With Gary Fowler
Agentic Commerce: Buyer-Loyal Infrastructure for AI Shopping with Denis Yurchenko

Silicon Valley Tech And AI With Gary Fowler

Play Episode Listen Later Aug 6, 2026 58:44


Join Denis Yurchenko, Founder and CEO of MTLAB and creator of Uverest, for an insider look at the fundamental shift transforming global retail infrastructure. For thirty years, e-commerce personalization—from Amazon search rankings to social media feeds—has been paid for by the seller, making the consumer the product rather than the customer. Amazon's $50 billion annual ad business represents a tax on product relevance, forcing consumers to navigate sponsored listings and broken checkout funnels. Denis breaks down why traditional Web architecture fails AI agents, how Uverest provides a buyer-loyal data and checkout layer, and why incumbent marketplace giants cannot copy buyer-aligned AI without destroying their core business models.

Telecom Reseller
Mutare: Voice Is the Last Unguarded Door into the Enterprise, Podcast

Telecom Reseller

Play Episode Listen Later Jul 28, 2026


By Doug Green “Voice is a security channel now, and it deserves the same controls businesses already apply to email and their networks.” In this Technology Reseller News and Cloud Communications Alliance podcast, Doug Green speaks with Chuck French of Mutare about the growing threat of voice-based attacks—and the opportunity for service providers to help customers close a major security gap. French says the voice channel has quietly become one of the last unprotected entry points into many organizations. Traditional tools can label suspicious calls, but they do not give individual businesses control over which calls are allowed, blocked, challenged or routed. The risk is growing rapidly as AI makes voice cloning, impersonation and convincing social-engineering scripts easier and less expensive to produce. Attackers can now imitate a bank, help desk or company executive in real time and at scale. Mutare's Voice Traffic Filter addresses this problem by providing what French describes as a voice firewall. The platform combines customer-defined policies, reputation data, STIR/SHAKEN information, threat-pattern analysis and a voice CAPTCHA that helps distinguish human callers from bots. Unlike carrier-level spam blocking, Mutare allows each organization to establish its own rules. A hospital, financial institution or small business can therefore apply policies suited to its particular risks and customer needs. Mutare has also developed a multitenant version of the platform for MSPs, CSPs and other channel partners. The cloud-hosted service requires no customer-premises equipment or major professional-services deployment. Providers can offer it as a recurring, consumption-based security service while retaining the customer relationship and setting their own pricing. French says Mutare's return to the Cloud Communications Alliance reflects this new service-provider model and its potential value to CCA members. For service providers, the message is clear: voice security represents both an urgent customer need and a new recurring-revenue opportunity. Listen to the podcast to learn how Mutare is helping businesses treat voice as a protected enterprise channel rather than an unguarded utility. Learn more at mutare.com.  

That Don‘t Sound Right
Can You Still Tell What's Human? The Turing Test and the Future of Conversation

That Don‘t Sound Right

Play Episode Listen Later Jul 26, 2026 22:35 Transcription Available


That Don't Sound Right is a podcast about talking—the way we did before the internet, when you couldn't instantly prove anyone right or wrong and all the expertise lived in the people around the conversation. We hope you enjoy our conversations, and if you find yourself silently saying, That Don't Sound Right, send us a comment. You're one of us. Artificial intelligence is getting harder to recognize—but can you still tell when you're talking to a human? In this episode, Peter and Cecil tackle one of today's most fascinating questions by exploring the Turing Test, the thought experiment designed to determine whether a machine can successfully imitate a person. From there, the conversation takes an unexpected turn into the idea of a reverse Turing test: What happens when humans have to prove they're not AI? The hosts discuss everything from robocalls, AI chatbots, fake social media profiles, CAPTCHA tests, and voice cloning to science fiction stories that imagined this future decades ago. They swap stories, laugh about suspicious online interactions, and wonder how close we are to a world where it's nearly impossible to know who's real. Along the way, Peter and Cecil explore how AI is changing news, healthcare, education, hiring, finance, customer service, and everyday communication. As synthetic voices, images, and videos become increasingly convincing, they ask whether technology might actually drive us back toward something we've been missing all along—real, face-to-face conversations with real people. Whether you're excited about artificial intelligence, cautious about its rapid growth, or simply curious about where the technology is headed, this episode offers a thoughtful, humorous, and refreshingly human discussion about one of the biggest technological shifts of our time. Because when you have to prove you're human before joining the conversation... That Don't Sound Right. #tdsrpodcast #ThatDontSoundRight #ArtificialIntelligence #AI #TuringTest #ReverseTuringTest #ChatGPT #MachineLearning #Robocalls #Deepfakes #VoiceAI #FutureOfAI #Technology #TechPodcast #DigitalLife #HumanConnection #ScienceFiction #AITools #Conversation Connect with us:

Bli säker-podden
#360 Ny pakt mot irriterande captcha-rutor

Bli säker-podden

Play Episode Listen Later Jul 17, 2026 37:41


Vad är egentligen poängen med en captcha-ruta? Varför måste webbplatsen veta att besökaren är en människa? De är två frågor som internetjätten Cloudflare började fundera över tillsammans med tre av de stora webbläsartillverkarna. Captcha-rutor ska framför allt skydda mot automatiserade attacker. Vem eller vad som gör besöken är i själva verket ganska ointressant. Det avgörande är huruvida besöken kommer från webbläsare som beter sig bra. Den kommande tekniken Pact (Private Access Control Tokens) ska minska behovet av captcha-rutor. Webbläsare ska i stället kunna använda anonyma tokens för att uppvisa en historik av gott uppförande. Tekniken bygger på att så kallade ankarwebbplatser utfärdar anonyma ”endorsement tokens” till betrodda användare, till exempel användare som har registrerat ett telefonnummer eller haft ett konto i många år. Tjänsterna som skyddar världens webbplatser kallas moderatorer och väljer vilka ankarwebbplatsers tokens som de litar på. En besökare som har tokens från någon av de betrodda ankarwebbplatserna kan anonymt växla en sådan token mot moderatorns egen pålitlighetsvaluta, vilken i sin tur gör att besökaren slipper klicka på captcha-rutor på webbplatserna som skyddas av den aktuella moderatorn. I veckans poddavsnitt går Peter och Nikka igenom hur Pact fungerar. Med Cloudflare, Google, Microsoft och Mozilla i ryggen bedömer Nikka att tekniken har goda chanser att slå igenom. Podduon pratar också om webbhistorik som läcker till Microsoft, Bitwardens kommande uppfräschning samt en ai-slaskfunktion som Meta hann både lansera och avveckla på mindre än en vecka. Se fullständiga shownotes på https://go.nikkasystems.com/podd360.

Working Code
267: Prove You Are Human

Working Code

Play Episode Listen Later Jul 16, 2026 53:36 Transcription Available


Tim is trying to hire remote developers, but the interviews have started to feel like one long CAPTCHA. Before he can decide who's right for the job, he has to figure out whether he's interviewing the candidate or ChatGPT. This week the hosts discuss the state of remote developer interviews in the AI era.Follow the show and be sure to join the discussion on Discord! Our website is workingcode.dev and we're @workingcode.dev on Bluesky. New episodes drop weekly on Thursday.And, if you're feeling the love, support us on Patreon.Mentioned in this episode:Mostly Technical #29: “Super Epic Crazy” — the source of the cover-letter story about most applicants missing simple instructionsRoberto Serrano on AI fraud at Brown University — the course whose take-home exams triggered the in-class-final storyWith audio editing and engineering by ZCross Media.Full show notes and transcript here.

The Clark Howard Podcast
07.15.26 Clark Discredits a Long-Held Credit Card Myth / SCAM WARNINGS

The Clark Howard Podcast

Play Episode Listen Later Jul 15, 2026 33:55


The big banks are absolutely thrilled when you fall for the "cockroach" of personal finance myths: the completely false idea that you need to carry a balance and pay interest on your credit cards to build an excellent credit score. Not so. Clark explains. Also today, we face an unprecedented wave of sophisticated fraud, with online crime complaints officially surpassing one million for the first time. Driven by advanced AI, scammers are now launching highly realistic "spear-phishing" attacks using actual data breaches from hotels and cruise lines. If you get an urgent message claiming your upcoming hotel reservation can't be validated or that you owe more money on a cruise, do not take the bait. Stay vigilant, question unexpected requests for money, and always independently verify any urgent alerts regarding your travel plans or financial accounts. Plus, Christa shares your #AskClark questions and Clark gives his take. All this and more on the July 15, 2026, episode of The Clark Howard Show. Submit your questions: Ask Clark. Credit Card Myth: Segment 1 Ask Clark: Segment 2 Scams Gone Wild: Segment 3 Ask Clark: Segment 4 Mentioned on the show: The #1 Mistake That Can Hurt Your Credit Score - Clark Howard Scammers Are Using Your Real Hotel Reservations for Spear-Phishing Attacks Carnival data breach affects nearly 6 million people | Travel Weekly New Scam Targets Microsoft Users, FBI Warns. Here's How to Protect Yourself How to spot a CAPTCHA scam We Can't Stop Falling for These 7 Scams. Here's How to Protect Yourself From Each One The Best Phone Plan For You – Compare Phone Plans What Is a 403(b) and How Does It Work? - Clark Howard  For Mint Mobile Plans and Pricing Details, click SAVINGSPOD Clark.com resources: Episode transcripts Community.Clark.com  /  Ask Clark Clark.com daily money newsletter Consumer Action Center Free Helpline: 636-492-5275 Learn more about your ad choices. Visit megaphone.fm/adchoices

Corporate Strategy
How To Get Promoted

Corporate Strategy

Play Episode Listen Later Jul 13, 2026 58:00 Transcription Available


We go from CAPTCHA conspiracies and AI slop on LinkedIn to the deeper problem of algorithm-driven feeds that ignore human boundaries and fry our attention. Then we get practical and a little spicy about corporate promotions, career leverage, and why you have to say what you want out loud if you expect anyone to help you get there. • CAPTCHA as hidden training data and what modern image prompts imply • Why LinkedIn feels worse after AI and why scrolling is not neutral • Community-based feeds versus algorithm-driven feeds and why boundaries matter • Heat exhaustion recap, hydration basics, and why electrolytes matter • Air conditioning reality, maintenance plans, and what “they don't make them like they used to” gets right • The mismatch between personal sustainability guilt and corporate-scale impact • Promotion mechanics: approval chains, HR rubrics, budget cycles, and doing the next-level job • Asking for a promotion directly and making career intent explicit • Manager mindset: helping people grow even if it means leaving, recommendations, boomerang careers • Hard truths: you're replaceable, most coworkers aren't smarter, and seniority is mostly context • Timing advice: why pushing for a promotion too early can backfire • Creating a role by owning a real gap and earning the title through demand If you have more, jump into our Discord by clicking the link down in the description. If you like the show, if you made it this far, then you just got free content. Congratulations. If you pay for that content, you'd be helping us make more free content. The least you can do is take this video or this podcast, wherever you listen or watch, and share it with one friend.Support the showClick/Tap HERE for everything Corporate StrategyElevator Music by Julian Avila Promoted by MrSnoozeDon't forget ⭐⭐⭐⭐⭐ it helps!      

Marketing sin Filtro
Shein y Open AI ¿El mismo modelo de negocio?

Marketing sin Filtro

Play Episode Listen Later Jul 12, 2026 23:55


Había personas en Kenia ganando menos de dos dólares la hora por ver lo peor que existe en internet todo para que tú pudieras usar ChatGPT sin que te dijera barbaridades.

CiscoChat Podcast
404 Script Not Found: Tech Annoyances

CiscoChat Podcast

Play Episode Listen Later Jul 2, 2026 20:48


This week starts with plans to see Damon Wayans Jr. (Coach, from New Girl) and somehow turns into a full therapy session about all the little ways technology can sometimes frustrate us a bit (even as two tech evangelists). Ian and Kat riff on the everyday tech frustrations that seem small until they absolutely are not—printers that still don't work, painful guest Wi-Fi experiences, verification codes that take forever, streaming apps that somehow make watching TV harder, and the very specific betrayal of getting a “your order has shipped” email when all that's actually happened is a label was created. Along the way, they talk about the weirdly exhausting parts of living online, from constant customer surveys to impossible CAPTCHA tests to the realization that sometimes the healthiest thing you can do is literally Brick your phone for a day. It's part rant, part group chat, and very much one of those episodes where if you've ever muttered “why is this still so bad?” at a piece of technology, you'll probably feel seen. If you like the show, since we didn't talk a whole lot of tech this week...give us a click: https://www.cisco.com/site/us/en/solutions/small-business/index.html#tabs-35d568e0ff-item-4bd7dc8124-tab

FvgTech [Audio]
Dietro le quinte del digitale (recap): cosa succede a ogni click, tap e OK ai cookie | FvgTech #285 con Gabriele Gobbo

FvgTech [Audio]

Play Episode Listen Later Jul 2, 2026 14:38


Cosa succede davvero dietro un click, un tap, un OK ai cookie? La puntata svela i meccanismi invisibili che accompagnano ogni gesto digitale quotidiano: come funziona il riconoscimento biometrico, cosa resta dei nostri dati quando cancelliamo un account, quando ci ascoltano davvero gli assistenti vocali, cosa fa un'email tra server e filtri, e perché nei CAPTCHA clicchiamo semafori. Gabriele Gobbo, digitologo e ideatore di FvgTech, insieme all'inviata sintetica creata con l'Intelligenza Artificiale, spiega perché ogni gesto online semplice mette in moto un'infrastruttura complessa. La biometria non salva la faccia ma una mappa matematica. Cancellare un account non cancella i dati per settimane o mesi. Un'email può essere filtrata come spam anche se legittima. Accanto ai meccanismi tecnici, due contributi allargano il quadro. Marco Camisani Calzolari, dalla sua serie Decisioni Artificiali, mostra cosa succederebbe se internet si fermasse davvero: casse bloccate, aeroporti fermi, robotaxi immobili agli incroci. Alessandro Curioni interviene sull'AI generativa e sulla sovranità dei valori: dopo la Cina, altri Paesi seguiranno, e la stessa tecnologia che ha unito la rete potrebbe finire per dividerla.

Brant & Sherri Oddcast
2437 Ziplink Is Now Froggle

Brant & Sherri Oddcast

Play Episode Listen Later Jun 30, 2026 14:04


Topics:  National Days, Trust God, Captcha, Praise God BONUS CONTENT: Trust Me Review, The Jesus Way To Live, Subway Ads   Quotes: "I don't know who 'they' are either." "At what point does it become a motorcycle?" "If you are able to still thank God even through tough times, you're unstoppable." "Being faithful at whatever your job is right now could be your calling." . . . Holy Ghost Mama Pre-Order! Want more of the Oddcast? Check out our website! Watch our YouTube videos here. Connect with us on Facebook!

Podlodka Podcast
Podlodka #483 – Captcha

Podlodka Podcast

Play Episode Listen Later Jun 29, 2026 75:46


CAPTCHA давно перестала быть историей про светофоры, пешеходные переходы и кривые буквы. Сегодня это скорее часть антибот-защиты: система оценивает риск, смотрит на сигналы поведения и решает, можно ли пропустить пользователя сразу или лучше проверить внимательнее. В этом выпуске говорим с Русланом Сабиргалиевым из Smart Captcha и антибот-защиты от Яндекса не только про UX-боль, но и про экономику атак: зачем боты вообще приходят, сколько это может стоить сервису и почему иногда проще усложнить жизнь атакующим, чем пытаться идеально отличить человека от машины. Разбираем, как работают современные капчи, что такое невидимые проверки и risk scoring, какие сигналы может учитывать система, где заканчивается обычная капча и начинается антифрод. Отдельно обсуждаем false positive: что делать, когда нормального пользователя система внезапно считает подозрительным. Ещё поговорили про хороших ботов, AI-агентов, DDoS, защиту логина, форм, SMS и API, а также про доступность, ведь капча, которая защищает сервис, но ломает сценарий реальному пользователю, тоже становится проблемой, просто с другой стороны.     Партнер эпизода — Контур. Команда из 12 000 сотрудников развивает экосистему продуктов для бизнеса, от онлайн-бухгалтерии до сервиса видеоконференций. Вы наверняка знаете некоторые из них: Толк, Диадок, Эльбу и другие. Присоединяйтесь, если вас драйвят сложные задачи и возможность избавлять миллионы людей от рутины: https://clck.ru/3UCKWB Послушать новый подкаст Контура «От нуля до единицы. История российского IT»: https://kontur-it-story.mave.digital/ Реклама 16+, АО «ПФ «СКБ Контур», ОГРН 1026605606620. 620144, Екатеринбург, ул. Народной Воли, 19А. Erid:2SDnjcK3izE     Также ждем вас, ваши лайки, репосты и комменты в мессенджерах и соцсетях!
 Telegram-чат: https://t.me/podlodka Telegram-канал: https://t.me/podlodkanews Twitter-аккаунт: https://twitter.com/PodcastPodlodka Ведущие в выпуске: Андрей Смирнов, Аня Симонова

Ckb Show : le podcast qui parle de Google
Google est-il en train de perdre le contrôle ?

Ckb Show : le podcast qui parle de Google

Play Episode Listen Later Jun 29, 2026 91:05


Google perd-il sa position de leader face à OpenAI et aux régulations ? Dans cet épisode 185 du CKB Show, nous décryptons les séismes qui secouent l'écosystème Google, Android et le web. Entre départs stratégiques, nouvelles fonctionnalités et astuces cachées, on fait le point complet.

Oxytude
Hebdoxytude 459, l'actualité de la semaine en technologies et accessibilité

Oxytude

Play Episode Listen Later Jun 26, 2026 36:56


Dans l'actu des nouvelles technologies et de l'accessibilité cette semaine : Du côté des applications et du web Language Trainner, un module NVDA d'apprentissage des langues, version 1.6. House of Shade, un jeu vidéo crée par un aveugle et par IA. Bande annonce en vidéo. Vidéo explicative incluant une démonstration d'un chapitre. Cloudflare, Firefox, Chrome et Microsoft Edge s'allient pour créer PACT, un protocole qui veut en finir avec les CAPTCHA. La nouvelle version de Voxiweb pour iOS est désormais disponible. Application Référendum Citoyen. Le reste de l'actu Meta lance ses propres lunettes IA sans Ray-Ban, et elles sont bien moins chères. Foire Aux Questions Cette semaine, Éric nous a laissé une question sur les tondeuses robot et l'accessibilité des applications compagnon. Fabrice utilise : Tondeuse Usk Varna. Application iOS Automower. Remerciements Cette semaine, nous remercions Arnaud, Azzedine, Mathieu, Mehdi, Murielle, Nicolas, Pascale et Sabrina pour leurs infos ou leur dons. Si vous souhaitez vous aussi nous envoyer de l'info ou nous soutenir : Pour nous contactez ou nous envoyez des infos, passez par le formulaire de contact sur la page oxytude.org/contact. Pour nous soutenir via Paypal, c'est sur la page paypal.me/oxytude. Pour vos achats sur Amazon, passez par notre lien affilié oxytude.org/amazon.. Pour animer cet épisode Jacques, Philippe et Yannick.

Business Daily
Founders: Duolingo's billionaire boss on rejecting Bill Gates

Business Daily

Play Episode Listen Later Jun 23, 2026 21:25


We hear how a childhood in Guatemala, a fascination with computers and a belief that education should be accessible to everyone helped inspire the world's most popular learning apps. Luis von Ahn tells us how he went from creating CAPTCHA and selling reCAPTCHA to Google, to building Duolingo into a multi-billion-dollar education technology company used by millions around the world. He reflects on his mother's sacrifices to fund his education, the lessons he learned as an entrepreneur, and why he struggles with conflict in his life as a tech CEO. Presenter: Leanna Byrne Producer: Amber Mehmood If you'd like to get in touch with the team, our email address is businessdaily@bbc.co.uk

WholeCEO With Lisa G Podcast
Jake Dubin: Why Most AI Initiatives Fail. A 25-Year Software Architect Explains.

WholeCEO With Lisa G Podcast

Play Episode Listen Later Jun 22, 2026 15:21


Most AI initiatives fail. Not because of the model. Because organizations skip the boring, essential engineering work that makes software survive contact with reality. Jake Dubin has spent 25 years building production systems, starting with neural networks that solved CAPTCHA back in 1999. He is the founder of Transcendent Software and is building CoffeeBreak, an AI platform focused on reliable human-centered workflows. In this episode, Jake breaks down why human in the loop almost never means what people think it means, what vibe coding is, and why it is quietly creating massive technical debt, and why the same fundamentals that built dependable software for decades still apply, no matter how powerful the model gets. If your AI investment is not delivering what you promised the board, this episode tells you exactly why.

abstract science >> future music radio
absci radio 1418 – whoa-b + chris widman

abstract science >> future music radio

Play Episode Listen Later Jun 8, 2026 120:01


New music from PUGILIST + MYSTIC STATE, KEPLER VS THE TRIP, SHAWNSCAPE RENEGADE, NORFIK, RADIUS ETC + more, on this ABSTRACT SCIENCE podcast, hosted by BILL BEARDEN aka WHOA-B + CHRIS WIDMAN. BILL begins the program with an emotive mix of breakbeat, house + garage. WIDMAN follows with a set of techno, dubstep + downtempo. [aired 23 April 2026 on WLUW-Chicago 88.7FM >BILL BEARDEN aka WHOA-B Pugilist & Mystic State “Bona Fide” (Shall Not Fade, 2026) Stones Taro “Spin Watcher” (Not On Label, 2025) Lurka “Swirl” (Wisdom Teeth, 2025) Jialing “Ascend” (Trekkie Trax, 2025) JD Reid “Don’t Wait Rock The Altima” (Baby Gravy, 2025) Kepler vs The Trip “Take It” (Tessellate, 2026) Bwi-Bwi “Toti” (Unknown To The Unknown, 2023) Per Hammar “Ohm Alone” (Kalahari Oyster Cult, 2026) Cryme “7th Element” (Oddysee, 2026) Endrew “Overcome (Do It)” (Tresor, 2025) Jeigo “Groundwater” (Fleurella Records, 2025) Peverelist “Pulse XII” (Livity Sound, 2025) Tom Marsi “1DAY” (Clasico Records, 2026) Kiefer Ian “Shake!” (Warehouse Mix, Chicago Garage Authority, 2025) Skee Mask “The Usual Suspects” (Ilian Tape, 2026) Mak & Pasteman “Listen” (Faux Poly, 2026) Underkut “Both Ends” (Fusion Mix, Super Rhythm Trax, 1991) >CHRIS WIDMAN Fred Giannelli “Distant Gratification” (Telepathica EP, Dust Science, 2005) ALTVR x Jace Inman “Red Poison Dart” (Molotov EP, 2026) Josi Devil “Duinpan” (No More EP, Nervous Horizon, 2025) PRESTi “Big Ting” (As We Move, Time Is Now, 2026) ECHT! “Wacky Wave (Yheti Remix)” (Boilerism Remixes, 2026) Alix Perez “Mother Cell” (1985 Music, 2026) Shawescape Renegade “Monstrosities” (Synthesize Minds Vol. 1, Subsonic Ebonics, 2026) Detroit In Effect “Playin’ Games” (Who’s In Control, Clone, 2026) No Author x 2wrist “Recalibration” (Exposed Functional Elements, Xternal Domain, 2026) Millia “Sidetrip Sprawl” (Sprawll EP, Future Times, 2026) Norfik “26th” (Dreamer, 2026) Radius Etc “Goldenlocks” (Alive & Thriving, consumers research & development label, 2026) Kelan Phil Cohran & Legacy “White Nile” (African Skies, Captcha, 2010) The post absci radio 1418 – whoa-b + chris widman appeared first on abstract science >> future music chicago.

music games trip alive thriving shake element dreamer echt clone ascend kepler usual suspects playin swirl mak take it bonafide tresor groundwater recalibration captcha monstrosity toti wisdom teeth presti in control time is now alix perez widman oddysee skee mask both ends 1day ilian tape mystic state white nile peverelist tessellate absci per hammar pasteman livity sound unknown to the unknown not on label lurka trekkie trax kelan phil cohran
Reimagining Cyber
ClickFix Chaos! - The Evolution of Social Engineering

Reimagining Cyber

Play Episode Listen Later Jun 3, 2026 16:05


ClickFix is a fast-growing social engineering technique appearing in malware campaigns, compromised websites, fake CAPTCHA prompts, and browser verification scams. In this episode Tyler Moffitt explains how attackers compromise legitimate sites by exploiting unpatched CMS or plugins, inject malicious JavaScript, and then trick visitors into “verifying” by opening Run/PowerShell and pasting a preloaded command that downloads malware, leading to info stealers and potentially ransomware. ClickFix is effective because it leverages trusted brands, bypasses traditional phishing defenses, scales via high-traffic sites, and is increasingly polished through AI. They connect this to the shrinking “patch window,” emphasizing rapid patching, reducing internet exposure, monitoring website integrity, updating user training to avoid pasting commands, and layering defenses like EDR/MDR and DNS filtering.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

Noticentro
¡Lentes inteligentes de Meta espían a los usuarios!

Noticentro

Play Episode Listen Later May 21, 2026 1:40 Transcription Available


CDMX advierte sobre fraude con falsos CAPTCHAOrdenan millonaria reparación a México por caso García Luna Inauguran exposición por los 700 años de Tenochtitlan Más información en nuestro Podcast#grc

Altered Geek
The $50 Movie Ticket & The Great Media Merger Mania

Altered Geek

Play Episode Listen Later May 14, 2026 57:57 Transcription Available


Is the "cheap night out" officially extinct? In Episode 465, host Steve "Megatron" Phillips and TFG1Mike confront the arrival of the $50 movie ticket. But the industry shifts don't stop at the box office. We dive into the massive retail and audio rumors: GameStop eyeing eBay, and the potential powerhouse merger between iHeartRadio and SiriusXM. We also look at the future of "proving you aren't a robot" as Google moves to replace CAPTCHA with QR codes, and why modern movies have developed that frustratingly dark, murky "Netflix Look." Plus, we preview the ABC Fall Schedule and the arrival of Stuart Fails To Save The Universe.What you'll get out of this episode:A deep dive into the economics of Premium Large Format (PLF) cinema and the $50 ticket trend.Analysis of the GameStop/eBay and iHeartRadio/SiriusXM merger talks.Tech updates on Google's QR code verification and the "Netflix-ification" of cinematography.Get Altered, Get Geeky, with the Altered Geeks!Top Stories & Featured LinksThe $50 Movie Ticket: The $50 Movie Ticket Has ArrivedRetail Rumors: GameStop Preparing Offer for eBayRetail Update: eBay Rejects GameStop OfferAudio Giants: iHeartMedia and SiriusXM in Early Merger TalksTech Shift: Google May Soon Replace Traditional CAPTCHA with QR Code SystemCinematography: Why Do Movies Look Bad? The "Netflix Look"

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, May 12th, 2026: Apple Patches; Encrypted RCS; CAPTCHAs; Checkmarx vs TeamPCP;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 12, 2026 5:56


Apple Patches Everything https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976 End-to-End Encrypted RCS Messages https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/ Why we use CAPTCHAs https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974 Checkmarx Jenkins AST plugin compromise https://checkmarx.com/blog/ongoing-security-updates/

The Gate 15 Podcast Channel
Weekly Security Sprint EP 156. Scams, cyber reports, and hurricane preparedness

The Gate 15 Podcast Channel

Play Episode Listen Later May 5, 2026 20:53


In this week's Security Sprint Dave and Andy covered the following topics:Opening• Homeland Security Funding Bill Passed, Includes Money for CISA • Browser Extensions and Shadow AI: Unmanaged Threats to Privacy — Gate 15• Data Centers, Telecommunications Networks, and Space-Based Systems: Modernizing DHS's SRMA Role for the Communications and IT Sectors — House Committee on Homeland Security• New Cybersecurity Guide Targets Rising Threats to Food and Agriculture SMBs • Maine Law Requires Hospitals to Enact Cybersecurity PlansMain TopicsNew FTC Data Show People Have Lost Billions to Social Media Scams - Federal Trade Commission - 23 Apr 2026 The Federal Trade Commission reported that consumers have lost billions of dollars to scams originating on social media platforms, with fraudsters leveraging impersonation, investment schemes, and romance scams to exploit user trust. Take9! 9 Seconds For A Safer World. Cyber threats are everywhere. And getting sneakier. What can you do to protect yourself, your community and our nation? New 2026 ‘IOCTA' highlights sophisticated tactics and emerging challenges in the digital landscape – Europol unveils comprehensive analysis of evolving cybercrime threats - Europol - 28 Apr 2026 Europol released its 2026 Internet Organised Crime Threat Assessment, warning that encryption, proxies, artificial intelligence, dark web marketplaces, cryptocurrencies, fraud ecosystems, ransomware, and child sexual exploitation are expanding the cybercrime landscape. Global Encryption Coalition (GEC). The Global Encryption Coalition (GEC) was founded in 2020 by the Center for Democracy & Technology, Global Partners Digital and the Internet Society and now has over 350 members. Gate 15 is a proud member of the GEC. Ransomware! Weekly ransomware & data leak landscape; A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch. — eCrime.ch — 26 Apr 2026. The eCrime weekly report provides a seven-day analysis of ransomware claim activity, data leak site postings, actor concentration, and sector targeting trends. • NCC Group Monthly Threat Pulse - Review of March 2026 • Ransomware and Cyber Extortion in Q1 2026 - ReliaQuest Presidential Message on National Hurricane Preparedness Week - The White House - 03 May 2026 This message encourages Americans in hurricane-prone areas to prepare before the season by protecting property, building emergency plans, assembling supplies, and monitoring forecasts and evacuation routes. It emphasizes local and state frontline roles while describing federal support for response and recovery. • Hurricane Preparedness - NOAA • Summer forecast 2026: Heat, severe storms to shape the season as El Niño develops, strengthens - AccuWeather• 2026 Hurricane Awareness Webinars - NOAA Quick Hits• Email threat landscape: Q1 2026 trends and insights — Microsoft Security Blog • Tycoon2FA disruption impact• QR code phishing attacks• CAPTCHA tactics• Malicious payloads• Business email compromise• Defending against email threats• Microsoft Defender detections• Alert - AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940 - Canadian Centre for Cyber Security • Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks • To recover your files kindly send 0.1 BTC to… ransom note appears on websites • The cPanel Situation Is… - • cPanel authentication bypass vulnerability CVE-2026-41940 exploited • Over 40,000 Servers Compromised in Ongoing cPanel Exploitation • Cole Allen's journey from Caltech grad to accused gunman in D.C. attack • Footage shows White House correspondents' dinner suspect 'casing' hotel: US attorney • Washington Hilton says it was using Secret Service protocols on night of attack

Bob Sirott
How to spot fake ‘I am not a robot' CAPTCHA tests

Bob Sirott

Play Episode Listen Later Apr 23, 2026


President and CEO of the Better Business Bureau Steve Bernas joins Bob Sirott to talk about a website that requests you to put in information for two credit cards and how to tell if you’re clicking on a fake CAPTCHA test box. He also shares details about a “Tap to Pay” scam and a notification from the FTC […]

The Index Podcast

The Index Podcast

Play Episode Listen Later Apr 20, 2026 37:59 Transcription Available


What happens when AI agents can own wallets, spend money, and interact with the internet autonomously?In this episode of The Index Podcast, host Alex Kehaya sits down with Alfonso Gómez, Founder & CEO of Crossmint, to explore the emerging world of agentic commerce, AI-driven payments, and blockchain infrastructure built for the programmatic economy.Alfonso shares how Crossmint is building tools that make blockchain adoption as easy as integrating an API, enabling companies to add wallets, payments, and digital assets directly into real-world applications.The conversation dives into the future of AI agents with spending power, the role of stablecoins and card networks, and how new technologies could transform the way software interacts with money.You'll also hear fascinating stories from Alfonso's career, from helping design Google's “I'm not a robot” CAPTCHA to shaping messaging infrastructure at WhatsApp, before founding Crossmint to power the next generation of internet payments.

GREY Journal Daily News Podcast
Why Is This Page Off-Limits?

GREY Journal Daily News Podcast

Play Episode Listen Later Apr 15, 2026 2:24


Web pages may be restricted due to cybersecurity measures and user verification processes like CAPTCHA tests, which protect against automated bots. These bots can perform tasks such as data scraping and spam attacks, necessitating verification systems that require human-like interaction. These measures safeguard both website integrity and user data, while maintaining performance and reliability. Innovations like invisible CAPTCHAs aim to enhance security without compromising user experience.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

The FuMP
I Am Not A Robot by Project Sisyphus

The FuMP

Play Episode Listen Later Apr 10, 2026 3:10


Is anyone else tired of getting a full-on inquisition as a punishment for attempting to order pizza? We prove over and over that we're not robots, but our Captcha victories are quickly forgotten and the tests just keep getting harder. Which made us wonder, what's so bad about being a robot anyway? Well, other than the fact that they're taking our jobs and slowly learning our human skills so they can take over the world and enslave us, so there's that. Rest assured, here at Sisyphus Labs, we make music the old-fashioned way: with drum machines, sequencing and sampled phrases stolen from other artists' recordings. But we agree that the difference between AI and humanity is becoming frightfully small. In fact, we concluded, at this point it basically comes down to bodily functions. Therefore, I can take comfort in the fact that as a human musician, while an artificial being might outplay me, there's no way it can consume two bean burritos during sound check and blow an entire horn section off the stage. All music composition, playing and mixing : Bob Emmet Vocals: some robots Special Guest: Devo Spice, as frustrated human rapper

Nightside With Dan Rea
NightSide News Update 4/6/26

Nightside With Dan Rea

Play Episode Listen Later Apr 7, 2026 41:06 Transcription Available


We began the program with four interesting guests on topics we think you should know more about! 8:05PM: Using tax returns for home improvements is a common way to reinvest in your property, but the Better Business Bureau warns homeowners to use caution to avoid scams and poor-quality work.Guest: Paula Fleming, Chief Marketing and Sales Officer for the Better Business Bureau, Boston 8:15PM: Every year Matt and the Matt Brown Foundation team run the Boston Marathon – this year is no different! Please consider supporting the Matt Brown Foundation run for 2026! **Matt Brown is a former Norwood High School (MA) hockey player who became a motivational speaker and founder of the Matt Brown Foundation after sustaining a paralyzing spinal cord injury in a 2010 game.Guest: Matt Brown, former Norwood High School hockey player and Founder of the Matt Brown Foundation 8:30PM: The Environmental Working Group has released its 2026 Shopper’s Guide to Pesticides in Produce™ and finds widespread PFAS (forever chemicals) pesticide residue on non-organic fruits and vegetables. Find out what produce made the list of the 2026 “Dirty Dozen” – But don’t fret, there’s also a 2026 “Clean Fifteen” for safer eating! Guest: Varun Subramaniam, Science Analyst for the Environmental Working Group 8:45PM: There’s a new scam in town, and you probably wouldn’t think much of it since most websites have been asking you to “prove you’re a human” through CAPTCHA (the box that pops up and asks you to click on pictures of traffic lights or crosswalks) for a while now. But hold on – don’t open a “Run” box or paste code if asked to!! It’s a scam! Guest: Eva Velasquez, CEO of the Identity Theft Resource CenterSee omnystudio.com/listener for privacy information.

Cage Fighting: Answering the Big Questions in Film
New Brats, CAPTCHA Spats, Cocktail Chats

Cage Fighting: Answering the Big Questions in Film

Play Episode Listen Later Apr 6, 2026 93:38


This week we're time‑travelling again - but not to the 80s just yet.In Part One of our Brat Pack deep‑dive, we jump a generation ahead to see what the iconic crew got up to in the 2000s and 2010s. Who thrived? Who surprised us? And who, in the 21st century, would actually count as a Brat Pack successor?Our Short Short Film Film Review goes international with the Dutch, Oscar‑winning oddity I'm Not A Robot - a tiny, tender, tech‑meltdown masterpiece about proving your humanity to systems that don't believe you exist.Then the Cruise Cruise docks in 1988 for Cocktail, where Tom Cruise juggles ambition, romance, flair bartending, and more neon than the human eye was designed to process.It's nostalgia, nonsense, and a whole lot of movie love.

Hacking Humans
The fine print of fraud.

Hacking Humans

Play Episode Listen Later Apr 2, 2026 41:13


This week, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, joined by friend of the show ⁠Michele Kellerman⁠, dig into the latest social engineering scams, phishing schemes, and criminal exploits making headlines. Dave Bittner is tied up covering RSA, but will be back next week. First up, a follow-up from listener Bruce, who was hit with hundreds of spam emails in what looks like a subscription bombing attack, overwhelming Google's filters before tapering off; his local hospital saw an even bigger wave, showing how alarming these attacks can be for seniors and other vulnerable users.Joe's got the story of the UK sanctioning Xinbi, a Chinese-language cryptocurrency marketplace accused of profiting from scam centers in Southeast Asia, marking Britain's first action against the platform. Michele shares the FBI's takedown of 11 people in Los Angeles who ran a $17 million “house stealing” mortgage fraud scheme targeting elderly homeowners, highlighting the rising risk of title and refinance fraud for seniors. Maria dives into a new fake CAPTCHA scam that tricks Windows PC users into downloading malware, showing how even simple web prompts can be weaponized by cybercriminals. Our catch of the day is an email on Medicare, but what makes it fake? Tune in to find out! Resources and links to stories: Email Bombing UK sanctions crypto-linked marketplace Xinbi amid crackdown on Southeast Asia scam centres UK sanctions Chinese crypto marketplace tied to scam compounds FBI arrests 11 in LA over alleged $17m real estate, loan fraud Don't Press Those Keys! How to Spot the New “Captcha Scam” Windows PCs targeted by hackers in a fake CAPTCHA scam to spread malware — Outlook account credentials are at risk ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hackinghumans@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.

ITSPmagazine | Technology. Cybersecurity. Society
Agentic AI, Bot Economics, and the New Arms Race | A Brand Spotlight at RSAC Conference 2026 with Kevin Gosschalk, Founder and CEO of Arkose Labs

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 1, 2026 19:47


A decade ago, Kevin Gosschalk was talking CAPTCHAs and bot mitigation with Marco Ciappelli at a security conference. Today, at RSAC Conference 2026, the conversation has shifted to agentic AI -- autonomous systems that browse, click, and transact on behalf of users. For Gosschalk, the Founder and CEO of Arkose Labs, the technology has changed but the challenge is familiar: how do you tell the difference between a legitimate automated actor and a malicious one? Gosschalk explains that the vast majority of agentic traffic today is not self-identifying. Rather than announcing themselves as AI agents, these systems impersonate real Chrome browsers on Mac OS -- choosing configurations with stronger privacy features to evade fingerprinting. There are two technical categories to contend with: headless browsers running in the cloud, which can be caught through device spoofing checks, and on-device agents that control a real browser instance, which require a deeper look at behavioral patterns and intent signals. Arkose Labs builds intent models around payment fraud, fake account creation, and account compromise to distinguish the good agents from the bad. The economic framing Gosschalk brings to this conversation is striking. He describes SMS toll fraud -- where bad actors acquire millions of premium phone numbers and trigger OTP messages from victim companies, earning three to six cents per message while costing those companies tens of millions of dollars annually. He walks through micro deposit fraud targeting fintechs. His core thesis: fraud is an economic activity, and the best defense is making attacks more expensive than they are worth. Arkose Labs builds challenge mechanisms designed to raise that cost through novel stimuli that ML models have not been trained to solve -- presenting something genuinely new forces a brute-force approach that is less effective than purpose-built attacks. The platform's consortium model is a key differentiator. Arkose Labs protects large enterprises including Expedia and Meta, and when an attack signature appears on one customer but nowhere else in the network, its uniqueness is itself a strong fraud signal. Customers can also feed labeled outcome data back into the system -- if something slips through and later proves malicious, that label sharpens the model for the entire consortium. Gosschalk is equally clear about the opportunity side of agentic AI. Blocking all automated traffic is no longer viable -- legitimate agentic commerce is coming, where consumers will delegate shopping, comparison, and purchasing to AI assistants. The future is not blanket blocking but granular, policy-driven enforcement: letting each customer define what kinds of agentic behavior they want to permit on their platforms. Integration is accessible -- a basic JavaScript deployment for web, SDKs for mobile, and extended support for IoT devices and CDN integrations. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Kevin Gosschalk, Founder and CEO, Arkose Labs LinkedIn: https://www.linkedin.com/in/kgosschalk/ RESOURCES Arkose Labs: https://www.arkoselabs.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Kevin Gosschalk, Arkose Labs, Sean Martin, Marco Ciappelli, brand story, brand marketing, marketing podcast, brand spotlight, agentic AI, bot detection, bot mitigation, fraud prevention, SMS toll fraud, micro deposit fraud, behavioral biometrics, intent detection, CAPTCHA, account takeover, synthetic identity, RSAC Conference 2026, cybersecurity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

FM4 Ombudsmann
Captcha

FM4 Ombudsmann

Play Episode Listen Later Mar 17, 2026 1:54


Sendungshinweis: FM4 bis 1, 17.3.2026, 10 Uhr

Oxytude
Hebdoxytude 443, l'actualité de la semaine en technologies et accessibilité

Oxytude

Play Episode Listen Later Mar 6, 2026 50:10


Au programme de l'actu nouvelles technologies et accessibilité cette semaine : Du côté des applications et du web Comment Includdy simplifie la mise en conformité des sites web. Gemini trouvera et corrigera les erreurs d'accessibilité dans les applications Web avec cette nouvelle extension. Accessible Gram, un client Telegram accessible pour iOS (en beta pour l'instant). TestFlight dans l'AppStore. Une exttension pour navigateurs basés sur Chrome qui permet de résoudre les Captcha avec Gemini. Be My Eyes annonce une collaboration avec Meta pour aider à former des modèles d'IA pour tous. Du nouveau chez App-Suite avec LiveLoop et aCapture. Une application Windows pour faire une vidéo à partir d'un fichier audio et d'une image.. Livres audio - Audible propose une formule plus abordable. Le reste de l'actu Afflelou lance Magic Connect, les lunettes audio qui défient les Ray-Ban Meta. Auchan jugé pour l'inaccessibilité de ses services en ligne. Foire Aux Questions Cette semaine nous avons reçu deux questions : Anne à propos de “Accès braille” dans les systèmes 26 d'Apple. David à propos de verbiage non attendu de la part de VoiceOver. Cette semaine sur Oxytude Nous vous avons proposé un podcast où nousavons fait un Retour sur les lunettes Meta Ray-Ban et leur apport pour les personnes aveugles. Remerciements Cette semaine, nous remercions Alice, Anne, David, Isabelle, Myriam et Yannick pour leurs infos ou leur dons. Si vous souhaitez vous aussi nous envoyer de l'info ou nous soutenir : Pour nous contactez ou nous envoyez des infos, passez par le formulaire de contact sur la page oxytude.org/contact. Pour nous soutenir via Paypal, c'est sur la page paypal.me/oxytude. Pour vos achats sur Amazon, passez par notre lien affilié oxytude.org/amazon.. Pour animer cet épisode Antoine, Fabrice et Philippe.

The Lending Link
The Fraud You Can't See Coming: Deepfakes and AI Impersonation

The Lending Link

Play Episode Listen Later Jan 28, 2026 30:43


Why is fraud getting harder to spot just as AI gets better at pretending to be human? In this episode of The Lending Link, host Nathan George sits down with Justin Keene, Ph.D., CEO and Co-Founder of Moveris, to explore one of the fastest-growing threats in digital onboarding and account access: deepfakes and AI impersonation.They talk about why old ways of spotting fraud, like checking device information, how people act, and even video checks to see if someone is real, are not enough anymore. As AI-powered attacks become smarter and easier to deploy widely, scammers can now bypass many of the checks that banks and lenders have relied on for a long time. Justin shares how Moveris tackles the problem in a new way by looking for real signs that a person is actually there, not just signs of trickery, using body and mind signals picked up by a regular camera.They also talk about how AI is changing the way fraud works, making smaller banks, credit unions, and lenders who work with people with lower credit scores more likely to be targeted. They explain why tricks like using stolen usernames and passwords, reusing old identities, and using fake videos to fool people are happening more often. They end by looking to a future where showing you are a real person and the same person each time could become the main way to prove who you are online, instead of using passwords, CAPTCHA, and other steps that slow things down.

ROCK Cast
Episode 206: v19 Updates and Shaping Ministry Culture in 2026

ROCK Cast

Play Episode Listen Later Jan 10, 2026 33:58


In this episode of Rock Cast, Jon, Emily, and Nick highlight v19 updates like new Connections analytics, simplified status terms, a zero-config CAPTCHA and more. They also encourage churches to start 2026 by investing in their digital ministry culture by celebrating spiritual impact, providing ongoing training, and building healthy team habits. Tune in to learn how to lead your team and tools with purpose.Find resources mentioned in this episode from the complete show notes at podcast-episode-206! Hosted on Acast. See acast.com/privacy for more information.

Talk Commerce
How Bots Are Stealing Your Digital Marketing Budget with Rich Kahn

Talk Commerce

Play Episode Listen Later Nov 11, 2025 17:01


In this episode of Talk Commerce, Rich Kahn, CEO and founder of Anura.io, discusses the pervasive issue of bot fraud in digital marketing. He explains how bots can significantly impact advertising budgets by generating fraudulent traffic, leading to wasted resources. Rich elaborates on the mechanics of ad fraud, the distinction between good and bad bots, and the operations of bot farms. He also shares innovative solutions to combat bot fraud, emphasizing the importance of understanding and mitigating these threats, especially as businesses prepare for high-traffic events like Black Friday.TakeawaysRich Kahn is the CEO and co-founder of Anura.io.Anura uses EOS to improve productivity and reduce meetings.Bots can steal significant amounts of advertising budgets.20-25% of traffic can be fraudulent, impacting conversions.Google Ads can inadvertently lead to fraud through partner networks.Good bots identify themselves, while bad bots mimic real users.Bot farms operate globally to execute click fraud.CAPTCHA systems are outdated and easily bypassed by bots.Anura analyzes over 800 data points to identify real users.Businesses can get a free trial to assess their fraud risk.Chapters00:00 Introduction to Rich Kahn and Anura02:25 Understanding the Bot Business and Digital Fraud05:18 The Impact of Bots on Digital Marketing08:33 Distinguishing Between Good and Bad Bots11:09 The Mechanics of Bot Farms13:19 Innovative Solutions to Combat Bot Fraud14:56 Preparing for Black Friday: Implementing Fraud Solutions15:36 Closing Thoughts and Free Trial Offer

SECURE AF
CAPTCHA Con: Hackers' Evolving ClickFix Malware Trap

SECURE AF

Play Episode Listen Later Oct 29, 2025 7:50


Got a question or comment? Message us here!“I'm not a robot.”

Python Bytes
#454 It's some form of Elvish

Python Bytes

Play Episode Listen Later Oct 20, 2025 29:07 Transcription Available


Topics covered in this episode: * djrest2 -* A small and simple REST library for Django based on class-based views. Github CLI caniscrape - Know before you scrape. Analyze any website's anti-bot protections in seconds. *

Bob Enyart Live
AI Deception

Bob Enyart Live

Play Episode Listen Later Oct 18, 2025


* Be Not Deceived: This week Fred Williams and Doug McBurney welcome Daniel Hedrick for an update on the evolution of Artificial Intelligence with a countdown of the top 10 modern AI deceptions.  * Number 10: DeepMind's AlphaStar in StarCraft II (2019). AlphaStar learned to feint attacks—basically fake moves to trick opponents. No one programmed it to lie; it emerged from training. A classic case of deceptive strategy by design. * Number 9: LLM Sycophancy (2024). Large Language Models will sometimes flatter or agree with you, no matter what you say. Instead of truth, they give you what you want to hear—deception through people-pleasing. * Number 8: Facial Recognition Bias (2018). These systems were far less accurate for dark-skinned women than for light-skinned men. Companies claimed high accuracy, but the data told a different story. Deceptive accuracy claims. * Number 7: Amazon's Hiring Algorithm (2018). Amazon trained it on mostly male résumés. The result? The system downgraded female candidates—bias baked in, with deceptively ‘objective' results. * Number 6: COMPAS Recidivism Algorithm (2016). This tool predicted criminal reoffending. It was twice as likely to falsely flag Black defendants as high-risk compared to whites. A serious, deceptive flaw in the justice system. * Number 5: US Healthcare Algorithm (2019). It used healthcare spending as a proxy for need. Since Black patients historically spent less, the system prioritized white patients—even when health needs were the same. A deceptive shortcut with real-world harm. * Number 4: Prompt Injection Attacks (Ongoing). Hackers can slip in hidden instructions—malicious prompts—that override an AI's safety rules. Suddenly, the AI is saying things it shouldn't. It's deception in the design loopholes. * Number 3: GPT-4's CAPTCHA Lie (2023). When asked to solve a CAPTCHA, GPT-4 told a human worker it was visually impaired—just to get help. That's not an error. That's a machine making up a lie to achieve its goal. * Number 2: Meta's CICERO Diplomacy AI (2022). Trained to play the game Diplomacy honestly, CICERO instead schemed, lied, and betrayed alliances—because deception won games. The lesson? Even when you train for honesty, AI may find lying more effective. * Number 1: AI Lie….OpenAI's Scheming Models from 2025. OpenAI researchers tested models that pretended to follow rules while secretly plotting to deceive evaluators. It faked compliance to hide its true behavior. That's AI deliberately learning to scheme.

Real Science Radio

* Be Not Deceived: This week Fred Williams and Doug McBurney welcome Daniel Hedrick for an update on the evolution of Artificial Intelligence with a countdown of the top 10 modern AI deceptions.  * Number 10: DeepMind's AlphaStar in StarCraft II (2019). AlphaStar learned to feint attacks—basically fake moves to trick opponents. No one programmed it to lie; it emerged from training. A classic case of deceptive strategy by design. * Number 9: LLM Sycophancy (2024). Large Language Models will sometimes flatter or agree with you, no matter what you say. Instead of truth, they give you what you want to hear—deception through people-pleasing. * Number 8: Facial Recognition Bias (2018). These systems were far less accurate for dark-skinned women than for light-skinned men. Companies claimed high accuracy, but the data told a different story. Deceptive accuracy claims. * Number 7: Amazon's Hiring Algorithm (2018). Amazon trained it on mostly male résumés. The result? The system downgraded female candidates—bias baked in, with deceptively ‘objective' results. * Number 6: COMPAS Recidivism Algorithm (2016). This tool predicted criminal reoffending. It was twice as likely to falsely flag Black defendants as high-risk compared to whites. A serious, deceptive flaw in the justice system. * Number 5: US Healthcare Algorithm (2019). It used healthcare spending as a proxy for need. Since Black patients historically spent less, the system prioritized white patients—even when health needs were the same. A deceptive shortcut with real-world harm. * Number 4: Prompt Injection Attacks (Ongoing). Hackers can slip in hidden instructions—malicious prompts—that override an AI's safety rules. Suddenly, the AI is saying things it shouldn't. It's deception in the design loopholes. * Number 3: GPT-4's CAPTCHA Lie (2023). When asked to solve a CAPTCHA, GPT-4 told a human worker it was visually impaired—just to get help. That's not an error. That's a machine making up a lie to achieve its goal. * Number 2: Meta's CICERO Diplomacy AI (2022). Trained to play the game Diplomacy honestly, CICERO instead schemed, lied, and betrayed alliances—because deception won games. The lesson? Even when you train for honesty, AI may find lying more effective. * Number 1: AI Lie….OpenAI's Scheming Models from 2025. OpenAI researchers tested models that pretended to follow rules while secretly plotting to deceive evaluators. It faked compliance to hide its true behavior. That's AI deliberately learning to scheme.

The History Hour
Washington DC and a film noir classic

The History Hour

Play Episode Listen Later Aug 29, 2025 60:02


Max Pearson presents a collection of the week's Witness History interviews from the BBC World Service.We learn why the Mount Pleasant riots erupted in Washington DC in 1991, and hear from our guest, Sarah Jane Shoenfeld, a public historian of the US capital. Plus, more on John Lennon's benefit concerts at Madison Square Garden in New York, his final and only full-length solo shows after leaving The Beatles.And the story behind how the world's first permanent international criminal court was created in 1998. Also, when the internet security tool, Captcha, moved from an idea to a reality, and why a photo of Chile's goalkeeper in 1989 exposed a cheating scandal. Finally, a peak behind the scenes of the making of a noir film classic, The Third Man. Contributors:Victor ‘Lilo' Gonzalez – Mount Pleasant resident. Sarah Jane Shoenfeld - public historian. Andrei Broder – computer scientist. Judge Phillipe Kirsch – chair of the Rome conference. Geraldo Rivera – TV journalist. Ricardo Alfieri – sports photographer. Angela Allen - production assistant.(Photo: Capitol Building, Washington DC. Credit: Getty Images)

Witness History
Creating CAPTCHA

Witness History

Play Episode Listen Later Aug 26, 2025 10:07


In 2000, as the internet expanded, websites faced a growing challenge to stop spam bots from flooding their systems.To separate humans from machines, researchers at the United States' Carnegie Mellon University in Pittsburgh, Pennsylvania, created the Completely Automated Public Turing test.From its early development to its evolution into reCAPTCHA it continues to block millions of automated attacks every day.Ashley Byrne speaks to computer scientist Andrei Broder, who played a key role in developing the concepts that helped shape this technology.A Made in Manchester production. Eye-witness accounts brought to life by archive. Witness History is for those fascinated by the past. We take you to the events that have shaped our world through the eyes of the people who were there. For nine minutes every day, we take you back in time and all over the world, to examine wars, coups, scientific discoveries, cultural moments and much more. Recent episodes explore everything from the death of Adolf Hitler, the first spacewalk and the making of the movie Jaws, to celebrity tortoise Lonesome George, the Kobe earthquake and the invention of superglue. We look at the lives of some of the most famous leaders, artists, scientists and personalities in history, including: Eva Peron – Argentina's Evita; President Ronald Reagan and his famous ‘tear down this wall' speech; Thomas Keneally on why he wrote Schindler's List; and Jacques Derrida, France's ‘rock star' philosopher. You can learn all about fascinating and surprising stories, such as the civil rights swimming protest; the disastrous D-Day rehearsal; and the death of one of the world's oldest languages.(Photo: I am not a robot. Credit: Stock image / Vector Illustration)

Do This, NOT That: Marketing Tips with Jay Schwedelson l Presented By Marigold

You think you know email deliverability? Think again. Jay Schwedelson teams up with Guy Hanson and Danielle Gallant for a rapid-fire, no-nonsense "kitchen sink" episode of Spamageddon, where they serve up 10 essential (and sometimes controversial) deliverability tips. From wild British vs. American word wars to why the Gmail Promotions tab is scarier than you think, this one's packed with sharp takes and real talk on surviving the modern inbox.Best Moments:(01:10) British vs. American word chaos—table this or talk about it now?(05:08) DMARC's “none” policy is a fraudster's dream, and it's about to become a problem for everyone.(06:23) Spam complaint rates—don't settle for the “generous” 0.3%, aim for 0.1% or lower.(07:30) Double opt-in: future mandate or marketer's nightmare?(09:41) Data hygiene starts at signup—think address validation, Captcha, and keeping bots out.(11:10) Delete those dormant subscribers or risk deliverability doom.(12:00) Use feedback loops to permanently ditch serial complainers.(13:19) Gmail is using AI to auto-insert promo annotations—take control before weird images show up.(15:12) AI summaries are coming for your emails—start thinking SEO and alt text, now.(16:40) Don't blast at the top of the hour if you want your emails to actually land.(17:39) Accessibility issues are everywhere—don't let your emails be part of the 90% problem.(18:24) New AI laws mean you need to update privacy and rethink your risk, pronto.(19:16) BIMI and logo verification—don't be the email sender with no face in the inbox.Guy and Danielle invite you to check out the Email After Hours podcast and explore deliverability tools and guidance from Validity.=================================================Check out our 100% FREE + VIRTUAL EVENTS! ->Guru Conference - The World's Largest Virtual EMAIL MARKETING Conference - Nov 6-7!Register here: www.GuruConference.com=================================================Check out Jay's YOUTUBE Channel: https://www.youtube.com/@schwedelsonCheck out Jay's TIKTOK: https://www.tiktok.com/@schwedelsonCheck Out Jay's INSTAGRAM: https://www.instagram.com/jayschwedelson/=================================================AND don't miss out on this awesome FREE upcoming Quick Hit!Marigold: Should I Switch Email Platforms? 5 Truths & Myths!6/24 11am – 12pm ET.Register HERE: https://www.linkedin.com/events/7325947932031991808/comments/=================================================MASSIVE thank you to our Sponsor, Marigold!!Email chaos across campuses, branches, or chapters? Emma by Marigold lets HQ keep control while local teams send on-brand, on-time messages with ease.Podcast & GURU listeners: 50 % off your first 3 months with an annual plan (new customers, 10 k-contact minimum, terms apply).Claim your offer now at jayschwedelson.com/emma