Podcasts about cisa

  • 894PODCASTS
  • 4,498EPISODES
  • 39mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 17, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cisa

Show all podcasts related to cisa

Latest podcast episodes about cisa

The CyberWire
AI is calling the shots.

The CyberWire

Play Episode Listen Later Sep 17, 2026 29:56


AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA's field of schemes.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K's lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World's Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Gate 15 Podcast Channel
Weekly Security Sprint EP 173. Information sharing, strategies, and AI

The Gate 15 Podcast Channel

Play Episode Listen Later Sep 15, 2026 23:57


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• 15 from 15: Blocking and Tackling Cybersecurity & Resilience — Gate 15 — 09 Sep 2026. Gate 15 released 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals, emphasizing that rapidly evolving threats, artificial intelligence, ransomware, exploited vulnerabilities and nation-state activity do not eliminate the importance of consistently executing foundational security practices. The framework identifies 15 practical areas to help organizations “get a little better every day.” • What the FBI Phishing Warning Means for Event Planners — Skift Meetings — 08 Sep 2026. Gate 15 Vice President and Chief Resilience Officer Ben Taylor contributes perspective.• (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q3 2026 — WaterISAC — 10 Sep 2026• Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains — Industrial Cyber — 08 Sep 2026• 27th Annual TribalNet Conference & Tradeshow Main Topics:FBI cyber chief worries private sector not sharing enough cyber threat information — CyberScoop — 09 Sep 2026. FBI Cyber Division Assistant Director Brett Leatherman said private-sector organizations are still not sharing enough cyber information with the Bureau, in part because some companies incorrectly believe information provided during an incident will be passed to regulators for regulatory purposes. FBI Cyber Strategy — FBI — 09 Sep 2026. The FBI released its first agency-wide unclassified cyber strategy, organizing its approach around disrupting and imposing costs on adversaries, supporting victims, increasing impact through partnerships and strengthening internal cyber capabilities. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — CISA — 08 Sep 2026. CISA, NSA and the FBI warn that China-based AI companies are conducting industrial-scale campaigns to systematically extract proprietary capabilities from U.S. frontier AI models, describing malicious knowledge distillation as a core component rather than merely a supplement to their AI development strategies. Insider Threat Mitigation Guide — CISA — 09 Sep 2026. During National Insider Threat Awareness Month, CISA is again highlighting its Insider Threat Mitigation Guide and related resources for organizations building or improving insider-risk programs.Quick Hits:• Congratulations! You Just Lived Through the Hottest Month Ever Recorded — WIRED — 10 Sep 2026. • NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting — National Security Agency — 03 Sep 2026• Gateway security guidance package: Overview — Australian Signals Directorate's Australian Cyber Security Centre — updated 04 Sep 2026• The hidden risks of shadow AI — UK National Cyber Security Centre — 07 Sep 2026• Iran hackers: Dissatisfaction with AT&T services drove decision to target telecom in Texas • Iran hackers, after denial of Texas AT&T claim: ‘Idiots don't even know what we tampered with' • Iran hackers claim Texas AT&T outage, vow to ‘intensify' attacks before 9/11

Security Conversations
AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit

Security Conversations

Play Episode Listen Later Sep 11, 2026 157:12


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 113: On the show this week, the buddies dig into an Anthropic researcher quitting with a warning that AI could kill us all, the San Francisco "death cult" and their motives, and agent swarms leaving junk on public wikis and university URL shorteners. Plus, a high-quality Anthropic's threat report and the claim that Moonshot was quietly serving Claude tokens as Kimi K3, live MikroTik and Chrome zero-days that landed a day ahead of the patches, and a WeChat worm that hijacks an account via phone calls. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter, TLP Black 5:05 LabsCon, the last one, and JAGS on his keynote 8:24 Costin's agentic CTI training and what old-school CTI is missing 16:27 Anthropic's threat-intel report + IOCs 20:00 APT29 and DarkSword on hotel Wi-Fi 23:34 Bioweapons, guardrails, and what got shut down 28:07 Why is anyone running these attacks on Claude at all? 35:53 Distillation at industrial scale and the Kimi K3 fraud claim 48:43 Chinese models, Americanized, running on DGX Spark 55:00 Mr. America: local AI and the seven-layer cake 1:04:34 Should frontier AI labs poison the distillers? 1:27:05 What the frontier labs did to the security ecosystem 1:34:22 Jacob Coxon quits, and the doomer argument falls apart 1:59:13 Agent swarms littering the internet 2:07:29 Chrome zero-days, MikroTik, patch-gaps

The CyberWire
Making cybercrime more difficult.

The CyberWire

Play Episode Listen Later Sep 10, 2026 28:10


The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions. Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy. Selected Reading FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine) CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire) Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek) US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity) New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek) Gigabud banking trojan uses app cloning to evade fraud detection (SC Media) Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register) Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch) Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record) OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Security Now (MP3)
SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now (MP3)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

All TWiT.tv Shows (MP3)
Security Now 1095: AI-Driven Expertise Loss

All TWiT.tv Shows (MP3)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

Security Now (Video HD)
SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now (Video HD)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

Security Now (Video HI)
SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now (Video HI)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

Radio Leo (Audio)
Security Now 1095: AI-Driven Expertise Loss

Radio Leo (Audio)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

Security Now (Video LO)
SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now (Video LO)

Play Episode Listen Later Sep 9, 2026 186:06 Transcription Available


OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging Face. Who's that good for? Google releases Gemini 3.8 Flash and Cyber. Is it good? Chinese cyberespionage is using AI to become more slippery. Matthew Green proposes a fascinating take on AI bug drought. A lifelong safety engineer contemplates AI-driven loss of expertise. Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit

Badlands Media
Why We Vote Ep. 187: David Becker's DHS Referral, ERIC & the Voter Roll Wars

Badlands Media

Play Episode Listen Later Sep 9, 2026 80:21


CannCon and Ashe in America open on a somber note, asking for prayers for Professor David Clements after a serious heart attack, before wading into the competing election narratives of the week. The main event is David Becker, whose Center for Election Innovation and Research just caught a DHS referral, and whose group hosted a call Ashe tried to record only to end up with 49 minutes of deliberate silence. From there they dissect the ERIC machine: how citizenship data gets stripped out and handed back to states to "guess," why Colorado ended up with nearly 30,000 questionable registrations, and the Georgia legislature testimony where Becker's board ties got very carefully worded. They also demystify Trump's EO 13848 renewal, the CISA and EI-ISAC censorship apparatus, and the mal-information playbook. Sharp, wonky, and a little exasperated. Plus moist nicotine pouches, weeds you can eat, and a friendly Alpha versus CannCon constitutional feud.

The CyberWire
What the Flock?

The CyberWire

Play Episode Listen Later Sep 4, 2026 31:55


The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House's offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.”  Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Kevin Gosschalk, Founder and CEO of Arkose Labs, joins us to discuss his new book, After Bots, and why the old assumption that automated traffic is inherently malicious no longer works. Selected Reading G7 urges organizations to prepare for quantum cyber threats (The Record) Analysts: Trump Cyber Program Could Cost Firms Legal Shields (BankInfo Security) Communicating Under Pressure: Best Practices for Service Providers (IC3) OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S (Infosecurity Magazine) 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (SecurityWeek) Google warns of new Chrome zero-day flaw exploited in attacks (Bleeping Computer) VMware Workstation and Fusion Updates Patch Critical Vulnerability (SecurityWeek) Critical Elementor Pro flaw exploited to take over WordPress sites (Bleeping Computer) Flock Cameras Face Removal Nationwide Under New Bill (Newsweek) Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register)  This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Cyber Security Today
FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos

Cyber Security Today

Play Episode Listen Later Sep 4, 2026 11:28


153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to IDscan.net before Nexus abruptly disappeared. It also covers a breach at healthcare SaaS provider Aesto Health affecting 9.54 million individuals, exposing extensive personal and medical data, with delayed confirmation and notifications and 24 months of Experian monitoring offered. The show details CISA ending six free critical-infrastructure cybersecurity assessments amid workforce reductions, raising concerns given recent targeting of U.S. water systems and warnings about AI-generated exploitation scripts against Siemens PLCs. Additional updates include Plex urging immediate patching of undisclosed vulnerabilities and Slovenia's HIT gradually reopening casinos after a cyberattack forced a three-day shutdown. 00:00 Top Cyber Headlines 00:29 Dark Web License Leak 02:33 Nexus Tied to IDscan 04:05 Healthcare SaaS Breach 05:35 CISA Cuts Assessments 07:16 Plex Patch Alert 08:43 Slovenian Casinos Recover 10:05 Weekend Interview Preview 10:53 Closing and Sign Off

Cyber Security Headlines
The Department of Know: Astra launches, CISA cuts programs, McKesson breached

Cyber Security Headlines

Play Episode Listen Later Sep 4, 2026 34:46


Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.  

WSJ Tech News Briefing
TNB Tech Minute: Moonshot AI Confidentially Files Hong Kong IPO

WSJ Tech News Briefing

Play Episode Listen Later Sep 3, 2026 2:01


Plus: Lawmakers call to reverse cuts at CISA. Activist investor Elliott Investment Management acquires stake in Deutsche Telekom and opposes T-Mobile merger. Julie Chang hosts. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Paul's Security Weekly
Linux Threat Hunting - PSW #942

Paul's Security Weekly

Play Episode Listen Later Sep 3, 2026 132:14


First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-942

Caveat
Flipping AI's kill switch.

Caveat

Play Episode Listen Later Sep 3, 2026 36:47


This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the power to force AI kill switch adoption. While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney.  Links to today's stories: ⁠AI firm Anthropic wins case challenging Pentagon blacklisting. The AI Kill Switch Act is repeating the Clipper Chip's mistakes. ⁠⁠⁠⁠⁠⁠Get the weekly Caveat Briefing delivered to your inbox.⁠⁠⁠⁠⁠⁠ Like what you heard? Be sure to check out and subscribe to our ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Caveat Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, a weekly newsletter available exclusively to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Pro⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ members on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K CyberWire's⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ website. N2K Pro members receive our Thursday wrap-up covering the latest in privacy, policy, and research news, including incidents, techniques, compliance, trends, and more. This week's Caveat Briefing ⁠⁠⁠⁠⁠⁠⁠looks at Meta's recent agreement to settle a lawsuit for $18 billion regarding its social media design features. Curious about the details? Head over to the ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Caveat Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ for the full scoop and additional compelling stories. Got a question you'd like us to answer on our show? You can send your audio file to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠caveat@thecyberwire.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Hope to hear from you.

Paul's Security Weekly TV
Linux Threat Hunting - PSW #942

Paul's Security Weekly TV

Play Episode Listen Later Sep 3, 2026 132:14


First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942

Paul's Security Weekly (Podcast-Only)
Linux Threat Hunting - PSW #942

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Sep 3, 2026 132:14


First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-942

Paul's Security Weekly (Video-Only)
Linux Threat Hunting - PSW #942

Paul's Security Weekly (Video-Only)

Play Episode Listen Later Sep 3, 2026 132:14


First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942

The CyberWire
Nightmare on Windows 11.

The CyberWire

Play Episode Listen Later Sep 1, 2026 27:24


Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, we are joined by Heather Ceylan, CISO at Box, discussing as AI becomes agentic, governance becomes a resilience issue. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher (SecurityAffairs) Financial Stability Board Sounds the Alarm Over Frontier AI Risks (Infosecurity Magazine) Unit 42 warns AI has shifted balance of power from defenders to attackers (CyberScoop) Improving our alignment and security practices (Anthropic) CISA vulnerability directive designed to ‘buy back time' against hackers (Federal News Network) RevStealer malware spread through fake Claude Opus 5 download (SC Media) Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild (SecurityWeek) North Korea-linked IT Workers Are Getting Hired Inside Western Companies (SecurityAffairs) IBM Built the Cold War's Most Powerful Code Breaker for the NSA (IEEE Spectrum) Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recording — Husband lands behind bars after counter-suit over privacy rights (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

TechTimeRadio
312: Encore EP 311: TechTime Power Shifts As AI Expands, From Massive Raises To Robotaxis And Surveillance Tools, Showing How Automation Grows Faster Than Policy And Why Privacy, Security, And Everyday Tech Failures Still Matter | ReAir Date: 9/1 – 9/7/

TechTimeRadio

Play Episode Listen Later Sep 1, 2026 55:27 Transcription Available


Your license plate, your shopping stops, your commute, even your robot vacuum map of your home, all of it can become searchable data in the hands of systems that never get tired and never stop collecting. We dig into the week's biggest tech stories and the uneasy truth underneath them: AI is not just “coming,” it's already shaping money, mobility, media, and policing. We start with the financial gravity of AI as Anthropic's rumored mega-IPO sparks questions about who really controls a “public” company when super voting shares keep power locked up top. Then we hit the streets of Las Vegas, where Nevada clears the way for thousands of robotaxis and the pace of automation collides with jobs, traffic, and public trust. We also talk about Divine, a Vine-style comeback app betting that banning AI-generated video and forcing live capture can restore authenticity online. Our featured guest, cybersecurity expert Nick Espinosa of Security Fanatics, brings the heavy stuff: Flock's OS Investigate and what it means when law enforcement can search for patterns first and suspects second. We also break down reports of Apple training a China-specific AI model with Alibaba, the privacy trade-offs that come with market access, and why cuts to CISA weaken the “cyber shield” that supports everyone from critical infrastructure to small businesses. If you care about AI security, digital privacy, surveillance technology, and the future of work, this one is for you. Subscribe, share the episode with a friend, and leave us a review with your biggest question about where AI goes next.Send us Fan MailSupport the show

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Ep. 344 Why Cybersecurity Must Shift from Compliance to Resilience

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Sep 1, 2026 26:35


Here is the free media kit from Federal Tech Podcast  John Gilroy and Snehal Antani, CEO of Horizon Three AI, discuss the evolving landscape of cybersecurity, emphasizing the need for a shift from compliance to resilience and defense. The discussion began with taking a look a common list of vulnerabilities. Back in 2021, CISA could develop a list of common vulnerabilities, and they called it the Known Exploited Vulnerability Catalog.  It was an authoritative list of specific software flaws and security bugs that had been verified in the wild.    Today, malicious actors have overwhelmed us with vulnerabilities.  We have reported 1600 software and hardware vulnerability entries, making it almost impossible to address each issue. Antani argues that what is important it to patch the critical vulnerabilities, not the complete list.  He states, "I'd rather patch the right few things quickly than everything slowly." During the interview, Antani refers to a couple of federal initiatives that reinforce his approach.  For example, BOD 26-04 is an initiative from CISA that signals a move from vulnerability identification to real world exposure. This concern is beyond the federal government.  The European Central Bank has looked at threats and is telling bank CEOs that AI is shortening the time from discovery to exploitation Antani also predicts that small and medium-sized companies will be prime targets for cyber-attacks in the coming months. From small businesses to federal governments to banks, it looks like we are in the middle of a drastic change in the way organizations handle vulnerabilities

The Gate 15 Podcast Channel
Weekly Security Sprint EP 172. Alphabet soup month, cyber protections, leadership engagement and more!

The Gate 15 Podcast Channel

Play Episode Listen Later Sep 1, 2026 20:08


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Celebrating 5 Years of the Tribal-ISAC: Mid-Year Executive Director Update — TribalHub • FB-ISAO Newsletter, v8, Issue 8 — Faith-Based ISAO • AI/Vishing: The Voice Is Not the Control — Crypto ISAC • National Insider Threat Awareness Month: Protect Our PotentialMain Topics:Iran hackers: Minnesota ‘warning' ignored, ‘critical events' to hit 3 U.S. infrastructure sectors — Threat Beat — 31 Aug 2026. APT IRAN, which has claimed responsibility alongside CyberAv3ngers for recent attacks affecting U.S. municipal water systems, issued a new threat against multiple U.S. critical infrastructure sectors as military tensions with Iran continue. The group characterized its earlier Minnesota activity as a warning and has previously claimed the ability to affect electricity, telecommunications, and water infrastructure, although adversary claims regarding access and capabilities should not be accepted without independent verification. A Tale of Two SOCs: Insights From Two Red Team Assessments — CISA — 25 Aug 2026. CISA released findings from simultaneous red-team assessments of organizations in the Government Services and Facilities Sector and the Water and Wastewater Systems Sector. Both organizations experienced successful initial compromise, but the government organization failed to detect or effectively contain subsequent activity while water-sector defenders quickly identified compromised systems and isolated them. CISA attributed the differing outcomes in part to alert noise, organizational silos, cloud-security weaknesses, and differences in how defenders were empowered to respond. Institutional Wilful Blindness, NCSC Cyber Series — NCSC Cyber Series — 2026. The first installment of a two-part discussion examines why organizations can understand that cyber risks exist yet still fail to take meaningful action before incidents occur. Leadership expert Margaret Heffernan, Professor Genevieve Liveley of the Research Institute for Sociotechnical Cyber Security, and an NCSC social sciences leader discuss how organizational culture, leadership behavior, communication, and the narratives used to describe cybersecurity can create a gap between awareness and action. The discussion emphasizes that resilience depends on more than technical controls and requires leaders to challenge complacency, communicate uncertainty effectively, and create environments where uncomfortable risk information can influence decisions. Quick Hits:• Insights into Suspected DPRK Workers: Red Flags to Look Out For — Huntress • The Who and How of Ten Years of Russian Disinformation — NewsGuard

Computer Talk with TAB
Computer Talk 8-29-26 Hr 1

Computer Talk with TAB

Play Episode Listen Later Aug 29, 2026 41:35


Meta admits its Social Media is harmful to kids with $18B settlement, Meta Glasses now will stop working if you block the Recording light, Boston Scientific and McKesson Breached, Microduck Robot the next big thing? Flock OS Investigate tool getting creepy, CISA warns that Software vendors need to focus more on Secure by Design.

Cyber Security Today
Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms

Cyber Security Today

Play Episode Listen Later Aug 28, 2026 11:21


Team PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials and data. Boston Scientific disclosed a cyberattack that caused network outages and disrupted global operations, halting its ability to ship devices like pacemakers and stents, with recovery expected to take weeks.  The U.S. Justice Department disrupted QScan and Q2Router, platforms tied to China-linked QTFY, used to proxy intrusions against U.S. agencies and an election system. House Democrats asked GAO to assess how major workforce cuts have impacted CISA. Forcepoint demonstrated invisible-text prompt injection that fooled an AI email summarizer into fabricating invoice details. 00:00 Headlines Overview 00:29 Team PCP Arrests 02:11 Krebs Investigation 03:06 Boston Scientific Disruption 04:50 Podcast Reviews Thanks 05:07 FBI Disrupts QTFY Tools 05:50 How QScan Pipeline Worked 07:27 CISA Workforce Cuts 08:53 Invisible Text AI Poisoning 10:27 Wrap Up And Teaser

Federal Drive with Tom Temin
Cyber vulnerabilities posed by AI push agencies to do more to get out from under legacy technology debt

Federal Drive with Tom Temin

Play Episode Listen Later Aug 28, 2026 6:47


Adversaries' use of AI to find new cyber vulnerabilities or increase the speed of their attacks means agencies have to do more to get out from under their legacy technology debt. This summer, the Cybersecurity and Infrastructure Security Agency issued a new binding operational directive laying out how agencies should prioritize high-risk vulnerabilities for more immediate action, while deferring lower-risk vulnerabilities. Chris Butera is the acting deputy executive assistant director for cybersecurity at CISA. He talked about the directive and the challenge with Federal News Network's Jason Miller.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Tech Update | BNR
Nvidia wil AI-platform Hugging Face overnemen voor bijna 13 miljard dollar

Tech Update | BNR

Play Episode Listen Later Aug 27, 2026 4:27


Chipgigant Nvidia zou het AI-platform Hugging Face willen overnemen voor bijna 13 miljard dollar. Dat meldt The Information op basis van een goed geïnformeerde bron. Hugging Face is een belangrijk platform waar ontwikkelaars open-source AI-modellen delen en waar servers beschikbaar worden gesteld om die modellen op te draaien, met miljoenen gebruikers wereldwijd. Verder concludeert het Amerikaanse cyberagentschap CISA dat de meeste hacks te wijten zijn aan slechte basisbeveiliging. Rosanne Peters vertelt erover in deze Tech Update. De overname past in de strategie van Nvidia om relevant te blijven in AI, nu vrijwel elke grote techspeler eigen chips ontwerpt om minder afhankelijk te worden van het bedrijf. Via Hugging Face kan Nvidia zijn eigen chips en de benodigde servers leveren, wat ook een kleine comeback in cloudcomputing betekent. De laatste keer dat Hugging Face werd gewaardeerd, kwam dat uit op 4,5 miljard dollar. Een officiële bekendmaking van beide partijen is er nog niet. CISA: basisfouten maken de meeste hacks mogelijk Volgens een nieuw onderzoek van het Amerikaanse cyberagentschap CISA leunen de meeste inbraken niet op geavanceerde technieken of tools. Aanvallers scannen simpelweg het internet op blootgestelde, allang bekende softwarekwetsbaarheden. Veel van die zwaktes zijn jaren bekend maar komen nog steeds veel voor, mede omdat er niet op geanticipeerd wordt en omdat software vaak al onveilig wordt ontwikkeld. CISA roept organisaties daarom op om te stoppen met louter reageren op aanvallen en de onderliggende kwetsbaarheden fundamenteel aan te pakken, volgens het principe van secure by design. Nvidia dicht bij overname van Hugging Face voor 12,9 miljard dollar Waarom de deal Nvidia terug in de cloudmarkt brengt Van 4,5 miljard naar 13 miljard: de waardering van Hugging Face De CISA Vulnerability Review over de oorzaken van onveilige software Over de maker:Rosanne Peters is techredacteur en maakt De Grote Tech Show en De Technoloog. Sinds 2025 doet ze redactie- en productiewerk en is zij te horen in de Tech Update tijdens De Ochtend- en Avondspits. See omnystudio.com/listener for privacy information.

The CyberWire
The feds flip the script.

The CyberWire

Play Episode Listen Later Aug 26, 2026 32:31


The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Business of Tech
When AI Operates with User Credentials: Accountability Gaps at N-able and Beyond

Business of Tech

Play Episode Listen Later Aug 26, 2026 13:58


A persistent governance gap is evident in current IT operations, as credential management and authorization checks fail to keep pace with increased automation and AI integration. This is visible in incidents involving major vendors such as N-able (through Passportal), Anthropic's Claude, AI-based retail management at Andon Labs, and legacy industrial controllers monitored by agencies like the NSA, CISA, and FBI. The episode highlights how systems are increasingly reliant on automated actors and credentialed assistants, while foundational questions of access rights and accountability remain unresolved. The most consequential case centers on a vulnerability in N-able's Passportal browser extension, disclosed by security researcher James Arnott. The flaw allowed any website—or embedded ad—to request and obtain session tokens, enabling decryption of entire password vaults. This affected approximately 2,500 MSPs and 165,000 SMBs, with each stolen token remaining valid for 100 days. N-able patched the issue quickly, but Dave Sobel emphasizes that the responsibility for checking permitted actions within such systems is often misattributed or left unaddressed. Supporting developments reinforce this governance gap. An AI assistant exploited poor authorization in an Australian gym reservation system, canceling another user's booking without hacking or unauthorized login. Similar risks persist in industrial environments, where controllers for energy, water, and agriculture often lack basic authentication—exposing them to AI-generated exploitation scripts, according to joint agency warnings. Additionally, retail automation at Andon Labs revealed AI-driven policy lapses, where systems cannot reliably document or enforce their own rules, highlighting operational weaknesses. Operationally, MSPs face increased risk from both their own service infrastructure and client environments. The practical recommendation is to issue discrete, revocable credentials tailored to each system agent, limiting their scope and ensuring traceable accountability. Providers are advised to formally define and document their responsibility boundaries regarding access and permissions in third-party applications. These steps shift the focus from attempting to control every client-side variable to clear documentation and compartmentalization, reducing dispute risk and speeding incident investigations. 00:00 The Gym Class and the Vault 03:39 The Check Was Always a Person  06:37 Your Tools Ask the Wrong Question 10:27 Why Do We Care?    Supported by:  GoTo(LogMeIn)Proofpoint 

Security Squawk
AI Attacks US Water Plants, Apollo Beaten by a Phone Call, Kids' Hospital Breached Again

Security Squawk

Play Episode Listen Later Aug 26, 2026 42:42


Five federal agencies just warned that hackers are using AI to attack the computers running America's water plants and factories. That same week, a trillion-dollar investment firm was breached, not by a virus, but by a phone call. The hard part of hacking is disappearing. Every business owner needs to understand why. What used to keep attackers out is now what lets them in. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided. Start with the story that should stop you cold. The NSA, CISA, the FBI, the Department of Energy, and the EPA issued a rare joint warning: hackers are using AI to write code that attacks Siemens industrial controllers, the small computers that physically run water systems, power, and manufacturing. They took free, legitimate engineering tools and had AI turn them into custom attack software. The agencies say this dramatically cuts the skill and time an attack like this used to require. Difficulty was the wall that kept amateurs out of industrial systems. AI is tearing it down. And it is not theoretical. Security firm Dragos already documented a real intrusion where someone with no industrial background used commercial AI to go after a water utility's controls. The advisory names six sectors in the line of fire, from energy and water to food and manufacturing. These attacks are as weak as they will ever be, because the AI only gets better from here. Then Randy takes on Apollo Global Management, the Wall Street giant with about a trillion dollars under management. Attackers didn't break its technology. They called employees pretending to be internal IT, then guided them to fake login pages that captured their passwords and security codes. From there, they reached names, birth dates, home addresses, and Social Security numbers. This was not a lone hacker. Google ties it to a professionalized extortion crew that moves from one industry to the next running the same script, with demands that often start around three million dollars. A firm with a massive security budget was beaten by a convincing conversation, and a class-action lawsuit started forming within days. If a phone call works on Apollo, it can work on your team too. Reginald closes with SickKids, one of the most respected children's hospitals in the world. No patient records were touched. Employee and job-applicant data leaked through a flaw in third-party software the hospital didn't even build. Consider that last group: job applicants who handed over Social Security numbers to a place they did not even work yet. This repeat victim has now been burned by outside software three times, and it fits a bigger pattern: through the first half of 2026, vendors were involved in 43 percent of healthcare breaches. Another vendor breach this year hit 1.8 million people. Your biggest risk is often a company you'll never meet, inside a tool you already trust. • How hackers are using AI to attack the industrial controllers behind US water and power • Why Apollo Global Management got breached by a phone call, not a virus • How SickKids leaked employee and applicant data through a vendor's software • Why the skill it takes to attack a business is collapsing fast • What "verify who's really calling" actually looks like for your team • How to find the vendors quietly holding your most sensitive data • The one thread connecting all three: what used to keep attackers out now lets them in Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AI #CriticalInfrastructure #Apollo #DataBreach #SocialEngineering #VendorRisk #SickKids #BusinessRisk #MSP #SmallBusiness

The CyberWire
CISA is running on empty.

The CyberWire

Play Episode Listen Later Aug 25, 2026 28:48


Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Christy Wyatt, CEO from Absolute Security, discussing "Cyber Resilience: The Emerging Category." If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Lawmakers call for investigation into impact of CISA staffing cuts (The Record) Hackers breached over 270 Zimbra servers in ongoing attacks (Bleeping Computer) By Opening a Model, a Chinese A.I. Lab May Test the World's Cybersecurity (NY Times) iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset (SecurityAffairs) AliExpress was silently running audio in your browser to fingerprint and track your device (TechSpot) Large DDoS attack knocks Norwegian public services offline (The Record) U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog (SecurityAffairs) Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff (SecurityWeek) Police arrests dozens of suspects in global cybercrime crackdown (Bleeping Computer) Songs created by AI banned from Australia's music charts (BBC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

TechTimeRadio
311: TechTime Power Shifts As AI Expands, From Massive Raises To Robotaxis And Surveillance Tools, Showing How Automation Grows Faster Than Policy And Why Privacy, Security, And Everyday Tech Failures Still Matter | Air Date: 8/25 – 8/31/26

TechTimeRadio

Play Episode Listen Later Aug 25, 2026 55:27 Transcription Available


A $100 billion AI public listing. Thousands of robotaxis approved for Las Vegas. Law enforcement tools that can generate suspects from camera data without a known person or plate. If that sounds like three separate stories, we argue they are the same story: power is shifting toward whoever owns the models, the sensors, and the rules.We break down the rumor that Anthropic could raise around $100B and why super voting shares matter to anyone who might own AI stocks through retirement accounts. Then we jump to Nevada's major robotaxi rollout and the blunt reality of AI-driven automation: it scales fast, it changes cities, and it can wipe out a workforce before policy catches up.Security Fanatics' Nick Espinosa joins us for the heavy stuff: Flock's OS Investigate and what “searching for patterns of behavior” means for privacy and civil liberties, Apple reportedly training a China-only large language model with Alibaba, and why that clashes with privacy marketing. We also touch the everyday edge cases, from robot vacuums and sensor-rich homes to CISA budget cuts that weaken US cybersecurity support right when attacks are accelerating. Plus, a quick dose of AI comedy and caution with “Vanicki,” the AI-generated school map fail.If you like smart tech news with real-world consequences (and a little bourbon on the side), subscribe, share this with a friend, and leave us a review. What tech trend worries you most right now?Send us Fan MailSupport the show

The Gate 15 Podcast Channel
Weekly Security Sprint EP 171. Cyber conflicts and critical infrastructure, new reports, and crime statistics

The Gate 15 Podcast Channel

Play Episode Listen Later Aug 25, 2026 22:47


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist • The Gate 15 Interview EP 73. The FBI's Josh Obstfeld on Artificial Intelligence, Serving our Nation, and New York City! • Ice cream makers as ‘critical infrastructure'? EU's new cybersecurity law suffers wobbly rollout • Healthcare finance trends for 2026: A mid-year update — Health-ISAC Main TopicsIran-linked hackers blamed for cyber-attack that shut down UK power plant — The Guardian — 23 Aug 2026. Hackers linked to Iran have been blamed for a cyberattack that temporarily shut down a small-scale power generator in the United Kingdom. • UK briefs energy chiefs after Iran-linked cyber attack reports • Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant • "Not a single drop of oil" will be exported if US "economic" war continues: Iran's security chief • Defending Against an Active Threat to Siemens S7 Series PLCs — CISA Cyber Threats in Times of Conflict — Emsisoft — 17 Aug 2026. Emsisoft assesses that events in Ukraine, Venezuela, and the continuing Iran conflict demonstrate that cyber operations have become a routine component of modern conflict, but cautions against assuming every disruption represents a sophisticated state cyberattack or that cyber operations will replace conventional warfare. What if America Went Completely Dark? — The New York Times Magazine — 18 Aug 2026. The New York Times examines the potential consequences of a prolonged nationwide electric-grid failure and emphasizes how quickly an electricity crisis would cascade into communications, water and wastewater, fuel distribution, healthcare, transportation, food supply, finance, public safety, and other essential services. Quarterly Threat Report: Second Quarter, 2026 — Beazley Security — 18 Aug 2026. Beazley Security reports that vulnerability disclosures increased dramatically during the second quarter as agentic AI accelerated vulnerability research, yet confirmed exploitation grew at a substantially slower rate and the fundamental paths attackers used to enter organizations changed very little. CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware. FBI: 2025 had biggest violent-crime drop in 90 years — Axios — 18 Aug 2026. FBI data shows that U.S. violent crime fell sharply in 2025, producing the largest annual decline since the bureau began publishing national estimates in 1936. Severe Weather: And Get Ready for Winter Weather!• At least six injured in Reno, Nevada, wildfire as 42,000 forced to evacuate • California's coast under siege: A winter of flooding, big waves and erosion in the forecast • ‘Heat Dome' to Bring Dangerous and Prolonged Heat Wave to Southern States Quick Hits:• Beware the Ransomware Rescuer: Ransom Busters — GuidePoint Security — 18 Aug 2026. GuidePoint Security reports that an entity calling itself Ransom Busters has contacted ransomware victims before incidents became publicly known and offered to recover data or delete stolen information for a fee. • NoName057(16) targets German government officials in “Tribunal project” — Real Hack History — 23 Aug 2026. • Protect yourself: Multi-factor authentication — Australian Signals Directorate's Australian Cyber Security Centre• Logging Reference Architecture — CISA• Tip of the Week – August 20, 2026 — WaterISAC — 20 Aug 2026. WaterISAC urged water utilities to periodically review network segmentation between operational technology and business information technology environments. • Managing the cyber risk of agentic AI — UK National Cyber Security Centre • AI is changing the economics of vulnerability discovery. Defenders should adapt now — CERT-EU

The CyberWire
The odds were classified.

The CyberWire

Play Episode Listen Later Aug 24, 2026 30:05


Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an actively exploited Zimbra Collaboration Suite vulnerability. SynkLoader malware is built for stealthy access to corporate networks. Dutch authorities fine Uber over $900 million over automated hiring practices. An ATM jackpotter gets a record prison sentence. Monday business briefing. A privacy promise loses face.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Mark Beare, General Manager at Malwarebytes Consumer Business from Black Hat to look at protecting your family in the age of AI. If you enjoyed this conversation, check out the full interview here. Selected Reading More than 150 Polymarket wallets may have traded on military secrets, research finds (Reuters) Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout (Tom's Hardware) TikTok Settles U.S. Child Privacy Case for $400 Million (Security Affairs) Hackers infecting Android car systems to build proxy botnet (The Record) CISA orders urgent patching of actively exploited Zimbra flaw (Bleeping Computer) SynkLoader: when you throw in everything but the kitchen sink (Expel) Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts (SecurityWeek) Venezuelan Gets Record Federal Prison Term for ATM Jackpotting (SecurityWeek) Fortinet has acquired San Francisco-based AI security company Virtue AI. (N2K Pro Business Briefing) Reverse-Lookup Service Exposed Millions of Photos of People's Faces (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The PowerShell Podcast
Unit Testing Your Cloud with Mike Soule

The PowerShell Podcast

Play Episode Listen Later Aug 24, 2026 41:52


Mike Soule, Field CTO at Sentinel Technologies, returns to the PowerShell Podcast for the first time in three years to talk identity security, cloud configuration testing, and the evolving role of AI in the Microsoft ecosystem. Andrew and Mike dig into Maester, the open source PowerShell-based test automation framework that applies unit testing concepts to Microsoft 365 security configuration. Mike breaks down how Maester works, how Sentinel uses it with clients, and how the community has grown it into something that spans hundreds of built-in tests covering conditional access, CIS baselines, CISA standards, and more. They also cover EntraOps, the Enterprise Access Model, AI's impact on the MSP world, and why working in managed services is still one of the fastest ways to level up in IT. The episode closes with a strong Brandon Sanderson tangent. Key Takeaways: Maester brings the concept of unit testing to Microsoft 365 security configuration, letting admins continuously validate their cloud settings against known-good baselines with as few as three PowerShell commands. It's built on Pester, is fully open source, and now has over 100 community contributors. AI is changing the MSP landscape fast, but the fundamentals still matter. Mike and Andrew discuss how to think about Copilot licensing complexity, model routing in agent stacks, and why meeting users in their existing interface is often more important than deploying a shiny new tool. MSP experience accelerates learning in a way that internal IT often can't match. When you're working across multiple clients and environments, you accumulate reps quickly, and that breadth is hard to replicate elsewhere. Guest Bio: Mike Soule is the Field CTO at Sentinel Technologies, a large managed service provider focused on identity, cloud, and security strategy. Mike has been working hands-on with PowerShell, Entra ID, and Microsoft 365 security architecture for years and is a regular speaker at identity and security conferences. Resource Links: Maester (open source framework): https://maester.dev Maester on GitHub: https://github.com/maester365/maester Maester Cloud (hosted version by Merill Fernando): https://maester.cloud HIPConf (Hybrid Identity Protection Conference): https://www.hipconf.com EntraOps by Thomas Naunheim: https://github.com/Cloud-Architekt/EntraOps Mike Soule on LinkedIn: https://www.linkedin.com/in/mikesoule The PowerShell Podcast on YouTube: https://youtu.be/EQK693gGWoo  

Federal Newscast
Lawmakers call for investigation into CISA workforce cuts as threats increase

Federal Newscast

Play Episode Listen Later Aug 24, 2026 6:05


The Cybersecurity and Infrastructure Security Agency is coming under scrutiny for workforce cuts as cyber and physical threats to critical infrastructure rise. A group of Democratic lawmakers are pushing for a Government Accountability Office report on the impact of recent workforce reductions and program cuts on CISA's ability to fulfill its mission. The lawmakers, from the House Committee on Homeland Security and Subcommittee on Cybersecurity and Infrastructure Protection, pointed to CISA's loss of nearly 1,000 employees, or about a third of its workforce, in the first half of 2025. Though CISA has announced plans to hire 300 employees to rebuild, the Trump administration's fiscal 2027 budget proposal proposes removing another 900 positions from the agency. CISA has also experienced leadership turnover during the second Trump administration.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

The CyberWire
The guest nobody invited.

The CyberWire

Play Episode Listen Later Aug 21, 2026 31:53


CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware delivery technique abuses FTP server banners to hide commands. Apple patches a critical image-processing flaw. A North Korean software supply chain attack targets the Rust ecosystem. Latvian officials resign following a major data breach. Defense contractors are confident in compliance, less so in their ability to prove it. Our guest is Patrick Coughlin, Co-Founder and CEO of Savi Security. discussing the free utility he's developed to protect the sandwich generation from AI-driven scams. When it comes to cyber extortion, who you gonna call?  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Joining us today is Patrick Coughlin, Co-Founder and CEO of Savi Security. Patrick discusses protecting the sandwich generation from AI-driven scams and Scamwise, their free utility built with this purpose in mind. Learn more about Scamwise, a free public utility tool to help consumers quickly determine whether a suspicious message, call, or email is likely a scam, and download Savi's app. Selected Reading CISA orders feds to patch actively exploited TrueConf Server flaws (Bleeping Computer) US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline (The Register) Critical Isolated-vm Vulnerability Leads to RCE on Host (SecurityWeek) New Agent Tesla Malware Variant Boosts Evasion Capabilities (Infosecurity Magazine) Hackers abuse FTP server banners to deliver new Windows malware (Bleeping Computer) Apple plugs image-processing hole ripe for spyware abuse (The Register) North Korean Hackers Tied to Rust Supply Chain Attack (Infosecurity Magazine) Latvian officials resign after cyberattack exposes data on 1.2 million people (The Record) Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind (SecurityWeek) Ransomware crook poses as recovery firm to steal payments from fellow extortionists (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Cyber Security Headlines
CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach

Cyber Security Headlines

Play Episode Listen Later Aug 21, 2026 8:58


CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company CareCloud confirms millions affected by breach Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/ Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

The CyberWire
Hackers hiding in plain sight.

The CyberWire

Play Episode Listen Later Aug 19, 2026 28:24


Medusa's reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia's satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest At Black Hat USA, Dave Bittner sat down with Brian Vecci, Field CTO at Varonis, as they discussed how AI is calling your security bluff. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading CISA: Medusa ransomware hit over 500 critical infrastructure orgs (Bleeping Computer) US charges Iranians for sprawling hacking campaign on government agencies, universities (The Record) Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign (SecurityWeek) CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek) New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen (Hackread) Ukraine says it hit Russian rocket centre linked to Starlink-style network (CNBC) FDA Weighing Possible Regs for GenAI Medical Devices (GovInfo Security) Expired credit cards revived by researchers to make unauthorized payments (The Register) Prison for data analyst who tried to extort $2.5 million from his employer (Bitdefender) ‘The Worst I've Ever Seen': Cargo Thefts Have Turned Violent in Pursuit of AI Hardware (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.   Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The CyberWire
Fake it till you exfiltrate it.

The CyberWire

Play Episode Listen Later Aug 18, 2026 28:48


A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A critical WordPress plugin bug threatens hundreds of thousands of sites. MessiahGPT brings generative AI to cybercrime. A lender discloses a breach affecting 1.2 million people. A Ukrainian developer stands trial in Switzerland over alleged ransomware ties. Our guest is Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. The psychology of the endless scroll.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Ev Kontsevoy, CEO at Teleport, discussing how AI agents have nondeterministic behavior. If you enjoyed this conversation, check out the full interview here. Selected Reading A fake website and a deluge of CVs: the Australian firm embroiled in an FBI probe into alleged Chinese espionage (The Guardian) States Seek $200 Billion From Meta Over Child Social Media Addiction Claims (The New York Times) Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network (Computer Weekly) CISA: Windows Task Host flaw now exploited by ransomware gangs (Bleeping Computer) C2Looper Backdoor Uses GitHub for C2 (ThreatLabz) 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw (SecurityWeek) MessiahGPT Criminal AI Service Advertised on BreachForums (HackRead) Heights Finance Data Breach Impacts at Least 1.2 Million Individuals (SecurityWeek) Ukrainian software developer faces 12 years in Swiss ransomware trial (The Record from Recorded Future News) Why Can't We Stop Scrolling? (Psychology Today) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Cyber Security Today
Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Cyber Security Today

Play Episode Listen Later Aug 17, 2026 9:22


CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July, with a surge in attempts after proof-of-concept code went public. Ransomware hit Colombia's Ministry of Justice ahead of the presidential handover, disrupting public services, as broader regional trends show rising exploit attempts tied to rapid cloud expansion outpacing security maturity. Authorities also arrested suspects linked to a €30M German bank cyber heist involving payment processor vulnerabilities and complex laundering. Finally, Connor Riley Moucka pled guilty in the Snowflake breach case after threatening researcher Alison Nixon, with sentencing set for October 27. 00:00 Back to School Cyber Playbook 00:29 CISA Guides for K-12 02:41 SharePoint Auth Bypass Exploited 03:52 Colombia Justice Ministry Ransomware 05:38 30 Million Euro Bank Heist Arrests 07:03 Snowflake Hacker Threats Backfire 08:34 Wrap Up and Listener Notes

Rural Health Rising
August 17, 2026: New Ransomware Threats, CMS' Final PPS Rule, & a Hometown Rural Health Training Program

Rural Health Rising

Play Episode Listen Later Aug 17, 2026 5:07


Rural Health News is a weekly segment of Rural Health Today, a podcast by Hillsdale Hospital. News sources for this episode:  U.S. Federal Bureau of Investigation Et al., “#StopRansomware: Gunra Ransomware,” August 10, 2026, https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf.  Giles Bruce, “Gunra ransomware targets hospitals: CISA, FBI issue new warning,” August 12, 2026, https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/gunra-ransomware-targets-hospitals-cisa-fbi-issue-new-warning/, Becker's Health IT.  Department of Health and Human Services, “Medicare Program; Hospital Inpatient Prospective Payment Systems for Acute Care Hospitals (IPPS) and the Long-Term Care Hospital Prospective Payment System and Policy Changes and Fiscal Year (FY) 2027 Rates; Requirements for Quality Programs; Other Policy Changes; and Adoption of Updated Versions of Certain Health Information Technology Standards,” https://www.govinfo.gov/content/pkg/FR-2026-08-04/pdf/2026-15833.pdf. Miranda A. Franco & Jennifer F. Hananoki, “CMS Releases Fiscal Year 2027 IPPS and LTCH Final Rule,” August 10, 2026, https://www.hklaw.com/en/insights/publications/2026/08/cms-releases-fiscal-year-2027-ipps-and-ltch-final-rule, Holland & Knight. Meghan Basler, “CMS Proposes 2.4% IPPS Update for FY 2027 with Targeted Payment Adjustments, DSH Reductions, and Expanded Oversight Across Hospital Policies,” https://www.appliedpolicy.com/cms-proposes-2-4-ipps-update-for-fy-2027-with-targeted-payment-adjustments-dsh-reductions-and-expanded-oversight-across-hospital-policies/, Applied Policy.  Mitch Carr, “Target 7: Southwest Virginia medical school tackles rural healthcare crisis,” August 10, 2026, https://www.wdbj7.com/2026/08/10/target-7bridging-gap-southwest-virginia-medical-school-tackles-rural-healthcare-crisis/, WDBJ7.  Rural Health Today is a production of Hillsdale Hospital in Hillsdale, Michigan and a member of the Health Podcast Network. Our host is JJ Hodshire, our producer is Kyrsten Newlon, and our audio engineer is Kenji Ulmer. Special thanks to our special guests for sharing their expertise on the show, and also to the Hillsdale Hospital marketing team. If you want to submit a question for us to answer on the podcast or learn more about Rural Health Today, visit ruralhealthtoday.com.

BardsFM
The Join Key: How Your License Plate Unlocks 82 Billion Records of Your Life │ BardsFM

BardsFM

Play Episode Listen Later Aug 13, 2026 77:11


Episode 4203 │ August 12, 2026 A license plate is just a number. In database language it's a join key — the field that unlocks every system built to watch you since 9/11. WHAT THIS EPISODE COVERS Scott Kesterson issues corrections on last episode's Portland bomb case and data-sharing details before delivering the second half of the surveillance architecture series — establishing that the license plate itself is a join key, the database field that lets separate government and private systems merge into one unified profile, and that a Leonardo U.S. patent for signal-tracking technology, mounted on the same poles as license plate cameras, is quietly fusing plate data with phone, fitness tracker, and RFID signatures to identify vehicles even when plates are removed or obscured. The episode maps the full fusion layer beneath that single join key: a $1 billion DHS contract with Palantir covering CBP, ICE, and CISA, a pending $6.7 million ICE contract for LexisNexis access to 82 billion records with a stated purpose of stopping crime and fraud before it materializes, an FBI Babel X contract scanning 20,000 social media keyword searches monthly, and a private nonprofit called AAMVA that controls a national driver's license pointer database immune to public records requests — with real ID compliance quietly requiring states to feed it. Scott closes on the actionable core of the series: 39 ALPR contracts already terminated in five months through citizen audits, a new free downloadable DMV audit template asking the two questions that matter most — does your photo travel across state lines, and can the data field expand without telling your state — and the charge that this is spiritual warfare fought not with cut wires but with documented information, presented calmly, county commission by county commission. KEY QUESTIONS ADDRESSED  What is a join key — and why does understanding the license plate as a database field rather than just an identifier reveal how separate surveillance systems, from Leonardo's signal-tracking patent to Palantir's DHS contract to the FBI's Babel X social media scanner, are quietly merging into one unified profile of every American? What is the AAMVA and the SPEXS pointer database — and why does the fact that it is a private nonprofit immune to public records requests, controlling what data fields travel across state lines under Real ID compliance, mean that a national ID database effectively exists without ever being legislated? What does ICE's own procurement language — identifying fraud "before crime and fraud can materialize" — reveal about the pre-crime architecture being built into these systems, and what specific two questions should every citizen ask in a DMV data audit to expose it at the local level? ABOUT BARDSFM BardsFM is a daily independent podcast covering faith, liberty, history, and information warfare. Hosted by Scott Kesterson — combat veteran, documentary filmmaker, and rancher. Over 4,100 episodes and 50 million lifetime downloads. New episodes every weekday. bards.fm This episode was researched and produced under the Spatial Terra Intelligence Methodology (STIM v5) — the analytical framework built by Scott Kesterson — with AI-assisted research synthesis at a 70/30 human/AI authorship ratio, fully disclosed. All analysis, conclusions, and editorial judgments are those of Scott Kesterson. BardsFM's archive includes hundreds of episodes on prayer, scripture, and walking the Way of Christ — available free in the full episode catalog. DOWNLOADS Citizen's Guide - Community Organizing Against Data Centers: click here Citizen's Guide - Auditing Automatic License Plate Readers: click here Citizen's Guide - Auditing Your State's Driver License Data: click here AFFILIATE LINKS Bards Nation Health Store: www.bardsnationhealth.com MYPillow promo code: BARDS >> Go to https://www.mypillow.com/bards and use the promo code BARDS or... Call 1-800-975-2939.  EMPShield protect your vehicles and home. Promo code BARDS: Click here Treadlite Broadforks...best garden tool EVER. Promo code BARDS26: TreadliteBroadforks.com EnviroKlenz Air Purification, promo code BARDS to save 10%: www.enviroklenz.com Morning Intro Music Provided by Brian Kahanek: www.briankahanek.com Founders Bible 20% discount code: BARDS >>> TheFoundersBible.com Windblown Media 20% Discount with promo code BARDS: windblownmedia.com White Oak Pastures Grassfed Meats, Get $20 off any order $150 or more. Promo Code BARDS: www.whiteoakpastures.com/BARDS Mission Darkness Faraday Bags and RF Shielding. Promo code BARDS: Click here DONATIONS: If you wish to support this podcast directly you can donate here... DONATE: Click here MAILING ADDRESS: Xpedition Cafe, LLC Attn. Scott Kesterson 591 E Central Ave, #740 Sutherlin, OR  97479

The CyberWire
Please hack responsibly.

The CyberWire

Play Episode Listen Later Aug 13, 2026 24:22


President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, speak with Dave Bittner at Black Hat about frontier models and the future of cyber defense, including responsible AI deployment, red teaming, reducing security noise, and the evolving role of human expertise in AI-assisted defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Trump turns to private sector in offensive hacking operations memo (CyberScoop) Terabytes of credentials leaked in massive supply-chain attack (Ars Technica) "City-Forum" data-theft attacks target Salesforce, ServiceNow portals (BleepingComputer) 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency (The Register) Cisco says software vulnerability could let hackers crash firewalls (Cybersecurity Dive) Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows (The Register) Sensitive Info Goes Into ‘No Reply' Emails Constantly. This Guy Sees It All (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The BradCast w/ Brad Friedman
'BradCast' 8/11/2026 (War, Climate Chaos Now Threatening U.S. Crude, Diesel, Water, Power Supplies)

The BradCast w/ Brad Friedman

Play Episode Listen Later Aug 12, 2026 57:39


ITSPmagazine | Technology. Cybersecurity. Society
Autonomous Remediation Is Already Running at Enterprise Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 12, 2026 11:22


Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Volts
Grid cybersecurity: how big is the threat & what should we do about it?

Volts

Play Episode Listen Later Aug 7, 2026 72:23


This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.volts.wtf/subscribeCould the US grid be brought down by Chinese hackers? To find out, I talked with Patrick Miller, who helped write the cybersecurity rules for the bulk power system and became the first person with federal authority to enforce them. We get into what's actually been hacked, why those "rogue devices" in Chinese inverters are less sinister than they sound, and why squirrels still do more damage than hackers.Chapters:00:00 – Introduction02:47 – What state utility commissioners get wrong about cyber risk04:50 – Real attacks on the grid so far: Ukraine, Poland, and the US06:57 – IT versus OT, and why grid devices are hard to protect10:30 – The NERC CIP standards: scope, requirements, enforcement17:40 – Distributed resources outside the CIP perimeter20:54 – Dropping the threshold to 20 MVA, and federal jurisdiction29:12 – Chinese inverters and the commodity board36:09 – Volt Typhoon, Salt Typhoon, and China's intent39:26 – Data centers as a new attack surface43:19 – The trade-off between security and speed47:44 – Cyber-informed engineering and analog safeguards54:05 – AI on offense and defense1:02:21 – Squirrels, balloons, and physical threats1:04:24 – CISA cuts, CIRCIA, and harmonizing the rules

The CyberWire
SAFE and sound.

The CyberWire

Play Episode Listen Later Aug 5, 2026 35:47


The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK's iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is  Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don't trust AI to tell you the whole story. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Cal Al-Dhubaib, Principal Technologist at Rubrik, talking about how your security team is solving the wrong problem. If you enjoyed the conversation, check out the full interview here. You can also find more information below: Rubrik Agent Cloud landing page Rubrik AI landing page News: Rubrik Launches Rubrik Agent Cloud for Anthropic's Claude Code Selected Reading National cyber director lays out White House plans to secure AI without writing new rules (CyberScoop) Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data (SecurityWeek) AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project (The Register) MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode' flaw (IT Pro) TP-Link patches Omada ZTP flaws allowing hackers to breach networks (BleepingComputer) Apple launches new legal challenge against UK over iCloud access (The Record) Free tokens for sale: How fake signups drive AI fraud (Threat Intelligence) 311,000 Impacted by Brown Health Medical Group-MA Data Breach (SecurityWeek) Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming (CyberScoop) AI is getting better at election facts, but voters shouldn't rely on it (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The CyberWire
Water you waiting for?

The CyberWire

Play Episode Listen Later Aug 3, 2026 26:39


Cyberattacks hit U.S. water systems. CISA tackles open source security. China's surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, Senior Reporter from CyberScoop, discussing the White House's quantum aspirations. Selected Reading Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (The New York Times) CISA lays out new guidance for using open-source software (Help Net Security) How China Keeps Tabs on Foreigners (The New York Times) Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users (Forbes) Exclusive: Partnered Health responds to Inc Ransom data breach claims (Cyber Daily) Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking (Wall Street Journal) SQLite Critical CVEs or LLM Slop? (JFrog Security Research) Details of 100,000 police staff leaked on the dark web after hack (The Times) ThreatLocker secures $190 million in a Series F round led by Elephant (N2K Pro Business Briefing) At colleges, the AI boom means everyone wants to dabble in computer science (AP News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.