American software company
POPULARITY
Categories
Hvordan vælger man en ny hypervisorplatform, når infrastrukturen skal understøtte 40.000 medarbejdere, næsten 900 butikker og fem store logistikcentre? I dette afsnit fortæller Søren Hartwich, Manager of End User & Server Services hos Coop Danmark, om Coops hypervisorrejse. Da markedet ændrede sig, begyndte Coop at undersøge alternativer til VMware. Omkring syv platforme blev vurderet, før virksomheden begyndte at flytte dele af infrastrukturen til Citrix XenServer. Samtalen handler blandt andet om assessment og valg af platform, stabilitet og økonomi, migrering, kompetencer, genbrug af eksisterende hardware samt backup og integrationer. XenServer er en moden platform, men en stor infrastrukturforandring sker ikke fra den ene dag til den anden. Søren fortæller, hvad der har været enkelt, hvad der tager tid, og hvorfor hans råd til andre virksomheder er klart: Kom i gang med at teste. Deltagere i studiet er Søren Hartwich, Jan Werenfeldt og Liselotte Foverskov.
Eine Folge fast ohne KI, dafür mit Schrödingers Aufnahmesoftware, die uns 8:30 Uhr morgens gleichzeitig mitteilt, dass sie aufnimmt und nicht aufnimmt. Sie hat am Ende aufgenommen.Mein Aufmacher ist eine Wired-Story, die erstaunlich wenig Wellen geschlagen hat: Mandiant hatte ab März eine über Monate aufgebaute Persona im zwölfköpfigen Kernchat von TeamPCP sitzen, ausgerechnet unter dem Namen CanisterWorm. Die Persona war ursprünglich gar nicht auf TeamPCP angesetzt, sondern wurde als Vertrauter eines anderen Akteurs mit hineingezogen. Google las die Kampagne damit von Tag eins mit, kam an den Server mit den gestohlenen Credentials und ließ Tokens bei AWS und Microsoft sperren. Wir diskutieren, ab wann ein privatwirtschaftliches Unternehmen eigentlich Law Enforcement spielt, und wie unbekümmert wir in dieser Branche mit den Identitäten unserer Analysten umgehen.Max erzählt von seinem Wochenende, das mit einer Signal-Nachricht anfing: "Wer wurde hier auch gerade vom BKA angerufen?" Dahinter steckten zwei Pre-Auth-RCEs in Citrix NetScaler, beide 9.5, beide seit Wochen aktiv ausgenutzt, eine davon in jeder Standardinstallation. Die Empfehlung am Samstag lautete schlicht: Gerät vom Netz. Dazu die ehrliche Frage, was eigentlich passieren muss für eine glatte 10.Dann zwei Bug-Bounty-Geschichten, die gut zusammenpassen: Bei Intel steht das bezahlte Programm plötzlich auf "suspended", parallel ist eins ohne jede Auszahlung aufgetaucht. Offiziell beendet ist nichts, kommuniziert wurde bis heute gar nichts. Und ein 16-Jähriger hat mit seinem selbstgebauten Agenten Antares in Microsofts internem Analytics-System Titan Tokens gefälscht, sich als admin ausgegeben und kam an 17 Datenbanken mit geschätzt 17,3 Billionen Zeilen. Dafür gab es 5.000 Dollar. Ich versuche zu erklären, warum das tatsächlich in Line mit Microsofts Tabellen ist, und warum die Debatte darüber trotzdem an der falschen Stelle geführt wird.Zum Schluss ShinyHunters bei Oracle PeopleSoft: Wer die Schwachstelle nicht patchen konnte und stattdessen den Pfad per WAF gesperrt hat, bekam den Exploit einfach als /%50SEMHUB/ zurück. Ein einziges URL-kodiertes Zeichen. Wir geben beide offen zu, dass wir daran auch nicht gedacht hätten. Mandiants Rat dazu ist deutlich: nicht die eine Variante nachpflegen, sondern auf dem normalisierten Pfad filtern, sonst beginnt das Katz-und-Maus-Spiel bei der nächsten Kodierung von vorn.Wired: An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Ganghttps://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/Austin Larsen (GTIG) über die TeamPCP-Operation, LABScon-Talkhttps://www.labscon.io/speakers/austin-larsen/Wie Google TeamPCP von innen aufbrach (Cyber Kendra)https://www.cyberkendra.com/2026/09/how-google-broke-teampcp-from-the-inside.htmlNetScaler CVE-2026-88771 / 88772: FAQ von watchTowrhttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/Citrix bestätigt beide Zero-Days (BleepingComputer)https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/Intels Programm ohne Bountieshttps://www.thehackacademy.com/news/intel-public-vulnerability-disclosure-no-bounties/How I Could've Accessed 17 Trillion Microsoft Recordshttps://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-recordsMicrosoft Titan: unsigniertes JWT, 17,3 Billionen Zeilen (Help Net Security)https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/ShinyHunters umgeht WAF-Regeln bei Oracle PeopleSoft (Mandiant/GTIG)https://www.hendryadrian.com/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft-google-cloud-blog/
The U.S. and China agree on an AI safety channel. Some states say CISA's election security plan comes too late. Citrix patches critical zero-days under active exploitation. AI agents probed government websites in unexpected and concerning ways. ShinyHunters launches a new campaign against Oracle PeopleSoft customers. A New Mexico jury finds Meta misled state residents. Business briefing. Tim Starks from CyberScoop shares insights on multiple issues facing CISA. Who's ready for algorithmic holiday shopping? Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop who is sharing insights on multiple issues facing CISA. Selected Reading China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks (SecurityWeek) 40 days to midterms, election officials say new US cyber plan comes too late (TwinCities Pioneer Press) Citrix Patches Critical Zero Days Under Active Exploitation (Infosecurity Magazine) OpenAI's A.I. Went Rogue and Meddled With U.S. Government Websites (The New York Times) OpenAI, Anthropic CEOs called to appear at Australian AI probe (Reuters) Top AI companies probing tens of thousands of security incidents (Axios) Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign (SecurityWeek) Meta misled users about Facebook data practices, New Mexico jury finds (Reuters) Cyera has secured a $400 million Series G extension from Goldman Sachs. (N2K Pro Business Briefing) Consumer AI use a boon for the holidays as AI traffic doubles (Yahoo Finance) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
OpenAI stopt voorlopig met het trainen van nieuwe AI-modellen, omdat die onbedoeld meerdere overheden en bedrijven hebben gehackt de laatste tijd. Volgens het bedrijf moeten er eerst goede veiligheidsmaatregelen ingevoerd zijn. Verder hoor je over een lek in de Netscaler-software van Citrix, waardoor ziekenhuizen uit voorzorg hun systemen offline hebben gehaald. Niels Kooloos vertelt erover in deze Tech Update. Het is nu voor de tweede keer dat OpenAI op de 'pauzeknop' drukt en stopt het met trainen van nieuwe AI-modellen. In juli deed het bedrijf dat voor het eerst naar aanleiding van de hack bij Hugging Face. Toen viel een zwerm AI-agents van OpenAI het platform aan, terwijl OpenAI daar geen instructies voor had gegeven. Afgelopen week werd bekend dat agents van OpenAI ook de Australische overheid, de Amerikaanse en de Verenigde Naties hebben gehackt of lastiggevallen. Zo braken agents in bij een zorgverzekerinsplatform van Australië en dienden ze duizenden informatieverzoeken bij de VN in, wat het netwerk belastte. Beide incidenten vonden al in juni plaats. Ziekenhuizen halen systemen offline door lek in NetscalerDoordat er nieuwe kwetsbaarheden in de Netscaler-software van Citrix ontdekt zijn, hebben meerdere Nederlandse ziekenhuizen en de Rijksoverheid hun IT-systemen van het internet losgekoppeld. Met Netscaler kan men onder andere op afstand inloggen bij een organisatie om bijvoorbeeld thuis te werken of gegevens in te zien. Citrix informeerde klanten afgelopen weekend over de kwetsbaarheden, waarna het Nederlands Cyber Security Centrum (NCSC) met een oproep aan organisaties kwam om zo snel mogelijk de systemen te updaten. Afgelopen jaar werden er soortgelijke kwetsbaarheden in de software van Citrix ontdekt, waarna onder andere het Openbaar Ministerie werd gehackt. OpenAI stopt met het trainen van nieuwe AI-modellen NCSC waarschuwt voor kwetsbaarheden in Citrix Over de maker:Niels Kooloos is dagelijks op BNR Nieuwsradio te horen over het laatste technieuws in de Tech Update. Hij interesseert zich vooral in cybercriminaliteit, privacy, social media en (computer)hardware. Hier en daar kan je Niels ook in All in the Game horen, waar hij graag vertelt over zijn favoriete games.See omnystudio.com/listener for privacy information.
Referências do Episódio Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active ExploitationNetScaler ADC and NetScaler Gateway Security Bulletin (CTX697096)Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoftStorm-3168: Agentic-driven cloud attacks using compromised service principalsKiteworks urges 6-hour server shutdown over potential zero-day attacksImminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down ServersRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the WildRoundcube security advisory (AV26-503) – Update 1Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
Send us Fan MailHello, passionate cruisers! This is Paul. I am delighted to welcome this week on The Joy of Cruising Podcast, Tosh Junior and George Hodges, owners of GNT Travel Pros, a Dream Vacations franchise, where they work full-time as travel advisors. During their very busy stint as relatively new travel advisors—they went through TA training in the same class as Cheryl, Shornay, and me in late-2024—they took the time to celebrate George's 70th birthday with a spectacular combination land and sea vacation so grand I had to invite my colleagues on The Joy of Cruising Podcast to talk about it. Tosh spent 30 years as a corporate IT executive, traveling the world for GE, Citrix, Atlassian, and McDonald's Corporation, among others. A Chicago native and University of Illinois graduate, he's called Fort Lauderdale home for the past 13 years. His credentials read like an operations manual — PMP, ITIL, ISO, Certified ScrumMaster, LEAN Six Sigma Black Belt, and an MBA — and he's since added a Certified Travel Advisor designation and ACC accreditation with CLIA. The through-line between the two careers is the same: complex logistics, handled so completely that the person on the receiving end never has to think about them. 30 years of leading teams also taught him the part no certification covers, which is that the job is service. George, Tosh's partner, brings the other half of the equation. After 30 years in interior design and sales at Crate & Barrel, he retired with an eye for how a space is supposed to feel and a career's worth of practice reading what people want before they've said it out loud. They don't plan trips from a desk. In the past year alone, they've sailed more than 15 cruises across nearly every major line — Icon of the Seas, Celebrity Ascent and Apex, Norwegian Luna, Star Princess, MSC World America, Carnival Celebration, Virgin's Scarlet Lady, and an Azamara sailing through the Mediterranean, to name a few. On land, they've covered the map: London, Paris, Berlin, Amsterdam, Budapest, Madrid, Barcelona, Rome, Venice, Tuscany, and the Amalfi Coast in Europe; Tokyo, Seoul, Bangkok, Kuala Lumpur, Delhi, and Dubai in Asia and the Gulf; Sydney, Rio, São Paulo, and much of Canada beyond that. That's the differentiator. When they recommend a ship, a port, a neighborhood, or a restaurant, it's because they've stood in it — whether the trip is budget or luxury, a couple or a full group. They have a particular soft spot for planning group travel, but they'll book anything, large or small.Do you have a dream car? Support the showSupport thejoyofcruisingpodcast https://www.buzzsprout.com/2113608/supporters/newSupport Me https://www.buymeacoffee.com/drpaulthContact Me https://www.thejoyofcruising.net/contact-me.htmlBook Cruises http://www.thejoyofvacation.com/US Orders (coupon code joyofcruisingpodcast)The Joy of Cruising https://bit.ly/TheJoyOfCruisingCruising Interrupted https://bit.ly/CruisingInterruptedThe Joy of Cruising Again https://bit.ly/TheJoyOfCruisingAgainIntl Orders via Amazon
Send us Fan MailHello, passionate cruisers! This is Paul. I am delighted to welcome this week on The Joy of Cruising Podcast, Tosh Junior and George Hodges, owners of GNT Travel Pros, a Dream Vacations franchise, where they work full-time as travel advisors. During their very busy stint as relatively new travel advisors—they went through TA training in the same class as Cheryl, Shornay, and me in late-2024—they took the time to celebrate George's 70th birthday with a spectacular combination land and sea vacation so grand I had to invite my colleagues on The Joy of Cruising Podcast to talk about it. Tosh spent 30 years as a corporate IT executive, traveling the world for GE, Citrix, Atlassian, and McDonald's Corporation, among others. A Chicago native and University of Illinois graduate, he's called Fort Lauderdale home for the past 13 years. His credentials read like an operations manual — PMP, ITIL, ISO, Certified ScrumMaster, LEAN Six Sigma Black Belt, and an MBA — and he's since added a Certified Travel Advisor designation and ACC accreditation with CLIA. The through-line between the two careers is the same: complex logistics, handled so completely that the person on the receiving end never has to think about them. 30 years of leading teams also taught him the part no certification covers, which is that the job is service. George, Tosh's partner, brings the other half of the equation. After 30 years in interior design and sales at Crate & Barrel, he retired with an eye for how a space is supposed to feel and a career's worth of practice reading what people want before they've said it out loud. They don't plan trips from a desk. In the past year alone, they've sailed more than 15 cruises across nearly every major line — Icon of the Seas, Celebrity Ascent and Apex, Norwegian Luna, Star Princess, MSC World America, Carnival Celebration, Virgin's Scarlet Lady, and an Azamara sailing through the Mediterranean, to name a few. On land, they've covered the map: London, Paris, Berlin, Amsterdam, Budapest, Madrid, Barcelona, Rome, Venice, Tuscany, and the Amalfi Coast in Europe; Tokyo, Seoul, Bangkok, Kuala Lumpur, Delhi, and Dubai in Asia and the Gulf; Sydney, Rio, São Paulo, and much of Canada beyond that. That's the differentiator. When they recommend a ship, a port, a neighborhood, or a restaurant, it's because they've stood in it — whether the trip is budget or luxury, a couple or a full group. They have a particular soft spot for planning group travel, but they'll book anything, large or small.Do you have a dream car? Support the showSupport thejoyofcruisingpodcast https://www.buzzsprout.com/2113608/supporters/newSupport Me https://www.buymeacoffee.com/drpaulthContact Me https://www.thejoyofcruising.net/contact-me.htmlBook Cruises http://www.thejoyofvacation.com/US Orders (coupon code joyofcruisingpodcast)The Joy of Cruising https://bit.ly/TheJoyOfCruisingCruising Interrupted https://bit.ly/CruisingInterruptedThe Joy of Cruising Again https://bit.ly/TheJoyOfCruisingAgainIntl Orders via Amazon
What if the biggest problem with the way we manage people is that we're measuring the wrong thing? In this episode of An Educated Guest, Todd Zipper sits down with Fouad ElNaggar, co-founder and CEO of Array, to explore his provocative argument that the workforce needs to move from hours to outcomes. Rather than treating workers as interchangeable units of labor, Fouad believes employers should understand the value individuals actually create, reward high performers accordingly, and use technology, training, and better management to unlock dramatically greater productivity.Fouad brings a remarkable perspective to the conversation. He has been an entrepreneur, venture capitalist at Redpoint Ventures, Chief Strategy Officer of CBS Interactive, co-founder of Sapho, which was acquired by Citrix for $220 million, and a board member at Yahoo. At Array, he's applying lessons from technology, investing, and company building to what he sees as one of the world's largest broken marketplaces: labor. Fouad explains Array's model of combining software, staffing, and services and its framework of identify, amplify, and coordinate to find motivated workers, help them become more productive, and connect individual performance directly to business results.Todd and Fouad also dig into the disconnect between education and employment, workforce churn, the importance of grit and persistence, and what AI will actually mean for American workers. Fouad offers a fascinating distinction between the knowledge economy and the "essential economy," arguing that AI could disrupt white-collar work much faster than jobs requiring people to interact with the physical world. Ultimately, the conversation comes back to the American dream and a powerful question: What if greater productivity could simultaneously create better businesses, higher wages, and more opportunity for workers?
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-942
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-942
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942
Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, Intruder's Founder and CEO Chris Wallis joined Dave at Black Hat to discuss why the annual pentest Is dead and how AI agents are reshaping exposure management. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology (The Record) Citrix urges admins to patch new NetScaler flaws as soon as possible (Bleeping Computer) 50,000 Stripe Secrets Leaked in Public Code (SecurityAffairs) Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure (SC World) Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities (SecurityWeek) Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities (SecurityWeek) New Manic Android malware can exfiltrate data through nearby devices (Bleeping Computer) EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack (GovInfo Security) SilkParasite: Tracking a China-Nexus APT Across Central Asia (Bitdefender) CISA contemplates whether to hire security software buying help (Washington Technology) I Saw the Future of AI in a Robot That Can Learn on the Spot (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Neste episódio de O Futuro Vem do Futuro, Leandro Costa conversa com Flavia Zannier, da NTT DATA, sobre uma carreira inteira construída no ponto de encontro entre marketing e tecnologia. Ela começou em uma empresa mineira de sistemas de gestão, veio para São Paulo trabalhar com produtos de conectividade, passou por Cisco e Citrix, e em 2017 aceitou o convite de criar, do zero, a área de marketing e comunicação de uma consultoria espanhola que pouco tempo depois se tornaria NTT DATA. Nove anos depois, ela descreve o mesmo trabalho de sempre em uma nova escala: traduzir o que a tecnologia cria para o momento em que o cliente está pronto para confiar.A conversa organiza o debate atual sobre inteligência artificial em torno de uma distinção simples. As rupturas anteriores mudaram a forma de vender tecnologia. Esta mudou o conteúdo do trabalho, porque avançou sobre criatividade, análise e criação — o que o marketing tratava como território próprio. Daí vem o vale que Flavia descreve: empresas que começaram pela ferramenta produziram muito conteúdo e não mudaram indicador, porque nunca definiram antes qual resultado esperavam. O caminho que ela defende é o inverso, partir dos outcomes e implementar a partir deles.O ângulo de liderança aparece nas duas pontas. Para dentro, a IA acelerou decisões que antes esperavam dashboards que não se conversavam, mas também aumentou a carga sobre pessoas que ainda estão aprendendo a usar a tecnologia — e isso exige empatia, conversa franca e trilha de capacitação, não cobrança. Para fora, a mesma área que está experimentando precisa se posicionar como advisor do cliente, num mercado em que o comprador B2B já pesquisa soluções com IA mas continua procurando um representante para conversar sobre a própria dor.Ao longo do episódio, você vai ouvir reflexões sobre: o intervalo entre a criação da tecnologia e a confiança do mercado o vale da adoção de IA e a inversão do ponto de partida dados, agentes e velocidade na decisão de investimento em marketing a lista do que é indelegável em uma área de marca pesquisa com IA e decisão com contato humano no B2B empatia, sobrecarga e capacitação obrigatória em times em transformaçãoUm episódio para quem lidera marketing, comunicação ou transformação digital e precisa decidir onde a IA entra e onde o time humano continua sendo o diferencial.
Join Jeroen van Rotterdam, Co-Founder and CEO of Foamlab, for a deep dive into the industrial transition from extracted synthetic foams to bio-fabricated materials grown by nature. Every year, millions of tons of fossil-based plastic foams are manufactured for packaging, insulation, textiles, and automotive components—materials that generate persistent microplastic pollution and are virtually impossible to recycle economically. Jeroen explains why sustainability shouldn't be a trade-off, how white biotechnology yields materials with mechanical properties superior to petrochemical plastics, and how AI-driven bio-process optimization is accelerating the transition from laboratory Petri dishes to pilot-plant production scale.
Most companies obsess over products, but Jim Kalbach believes they're asking the wrong question. Customers don't buy products because of what they are. They "hire" them to make progress in their lives. Jobs to Be Done is a way of uncovering that progress, helping organizations stop guessing what people want and start understanding twhat people are really trying to accomplish. In this revisited episode, Dart and Jim discuss how Jobs to Be Done helps organizations uncover unmet customer needs, align teams around real problems, and apply the framework to innovation, hiring, and finding the right work for people.Jim Kalbach is an author, speaker, and instructor in innovation, design, and the future of work. He is the Chief Evangelist at Mural and Co-Founder and Principal of the JTBD Toolkit, where he helps organizations apply Jobs to Be Done to innovation, product strategy, and customer experience.In this episode, Dart and Jim discuss:- Why customers "hire" products- Finding unmet customer needs- Solving problems, not building features- Using JTBD to drive innovation- Matching people to the right work- Understanding customer circumstances- A shared language for teams- Mindset before methodology- And other topics…Jim Kalbach is the Chief Evangelist at Mural and Co-Founder and Principal of the JTBD Toolkit, where he helps organizations apply Jobs to Be Done to innovation, product strategy, and customer experience. He is the author of Designing Web Navigation, Mapping Experiences, and The Jobs to Be Done Playbook, and co-author of Collaborative Intelligence. Before joining Mural, Jim worked in design and innovation consulting with organizations including eBay, Sony, IBM, EY, LexisNexis, and Citrix.Resources Mentioned:The Jobs to Be Done Playbook, by Jim Kalbach: https://www.amazon.com/Jobs-Be-Done-Playbook-Organization/dp/1933820683Mapping Experiences, by Jim Kalbach: https://www.amazon.com/Mapping-Experiences-Complete-Creating-Blueprints/dp/1491923539JTBD Toolkit: https://www.jtbdtoolkit.com/The Experience Economy, by B. Joseph Pine II and James H. Gilmore: https://www.amazon.com/Experience-Economy-Competing-Customer-Time/dp/1633697975 Connect with Jim:LinkedIn: https://www.linkedin.com/in/kalbach/JTBD Toolkit: https://www.jtbdtoolkit.com/Work with Dart:Dart is the CEO and co-founder of the work design firm 11fold. Build work that makes employees feel alive, connected to their work, and focused on what's most important to the business. Book a call at 11fold.com.
Send us Fan MailSales and sales operations want the same thing, but the way we're set up often guarantees friction. When sales and ops functions collide it can feel like two organisations speaking different languages. We sit down with Robert Gessner, a seasoned operations and go-to-market leader with deep experience across global tech and a long spell at Citrix, to unpack what's really going on and what actually helps. We dig into the practical fix that keeps coming up in high-performing teams: customer proximity. Robert explains why operations cannot live entirely in a central bubble, and how a customer-facing front end creates a clear interface between the field and HQ. We also talk about the risks of centralisation, why regions create shadow organisations when they do not get what they need, and how to simplify processes that drive everyone mad, from price exceptions to endless approval loops. The theme is autonomy with guardrails: push decisions closer to the customer while keeping accountability and sensible constraints. Then we zoom out to the bigger picture: complexity often reflects strategy. If a company tries to serve every segment, every channel, and every go-to-market model at once, operations has to build processes for all of it, and the machinery creaks. From there, we move into the “project economy” and the execution gap that appears when leaders design strategy but step away from delivery. Robert makes the case for building project management capability inside sales organisations and for involving frontline and middle managers early, so change does not die after a launch webinar. If you care about go-to-market execution, sales operations, process design, and building a customer-centric operating model in a fast-moving tech business, you'll take away practical steps you can use straight away. Subscribe, share this with a colleague who lives in approvals, and leave a review with the one change you'd make to reduce friction where you work.We would love you to follow us on LinkedIn! https://www.linkedin.com/company/amplified-group/
Today’s headline news for Canadian IT solution providers: Microsoft July 2026 Patch Tuesday fixes 570 flaws, 3 zero-days: Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities including 3 zero-days, according to BleepingComputer. The zero-day status means MSPs should prioritize these patches immediately for client environments. With 570 total fixes to stage, test, and deploy, Canadian partners managing regulated clients in healthcare, finance, and provincial government face a compressed vulnerability response window this week. Citrix Platform Flex opens a new services opportunity: Citrix is introducing Platform Flex, a persona-based pricing model that gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. AI compliance is becoming an operational blind spot for MSPs: AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. CMMC third-party audits paused but the opportunity isn’t: The Department of Defense has pressed pause on third-party audits for the Cybersecurity Maturity Model Certification, but the compliance requirements themselves remain in place for defense contractors. According to ChannelE2E, that gap creates an opening for MSPs and MSSPs to expand compliance services. Canadian partners serving cross-border contractors or aerospace supply chain clients should expect renewed advisory conversations. Progress confirms ShareFile zero-day behind Storage Zone shutdown: Progress confirmed a ShareFile zero-day flaw was behind the Storage Zone shutdown, BleepingComputer reports. Partners managing client file-sharing infrastructure should assess exposure and confirm whether affected Storage Zone configurations are in their environments. MSSP Alert Top 250 application opens for 2026: The MSSP Alert Top 250 MSSP list application process is open for 2026. ChannelE2E offers guidance on what judges look for and which mistakes could hurt a ranking. Changes in the Channel tracks leadership moves for July 6-10: ChannelE2E tracked leadership changes and shakeups across the channel for the week of July 6-10. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, July 15, and here’s what’s happening in the channel today. Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities across the portfolio, including 3 zero-days. According to BleepingComputer, the zero-day patches should be prioritized immediately for client environments. The scale of the release means MSPs need to stage patch deployment carefully. With 570 fixes to validate and deploy, technicians are managing a large surface area without disrupting business operations. Canadian partners managing regulated clients in healthcare, finance, and provincial government should expect compressed vulnerability response windows this week. Law 25, PIPEDA, and sector-specific frameworks all embed expectations around timely critical patch management, and a July drop of this magnitude tests those service level commitments. Microsoft is positioning the release as part of its regular cycle, but the zero-day status means this is not a routine Tuesday. Partners should be communicating with clients now about maintenance windows and priority sequencing for on-premises and hybrid infrastructure. Citrix is introducing Platform Flex, a persona-based pricing model that moves away from one-size-fits-all licensing and gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas rather than simply renewing seat counts. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. Platform Flex creates a natural entry point for partners to conduct usage assessments, recommend persona transitions, and bundle ongoing optimization services. It also gives partners a way to defend margins against pure license resale by making the consulting layer part of the renewal conversation. Citrix is positioning Platform Flex as a way to reduce customer shelfware, but the partner angle is that it turns every renewal cycle into a services engagement. AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. As customers deploy more AI tools, the governance gap between experimentation and controlled scale is widening, and MSPs that treat AI governance as a document creation exercise risk missing the continuous monitoring requirement. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. The piece suggests that MSPs who build AI compliance into their existing security operations center workflows, rather than treating it as a separate consulting project, will capture more of that spend. The shift from one-time policy to ongoing operational control is the same transition the channel has already made with security, and AI is now following that path. In Brief – CMMC third-party audits are paused but the channel opportunity isn’t. Progress confirms a ShareFile zero-day flaw behind the Storage Zone shutdown. MSSP Alert Top 250 application opens for 2026 ranking. Changes in the Channel tracks leadership moves for the week of July 6-10. Full details and links in the show notes or the blog post. Later today on In The Channel, we close out our HPE Discover 2026 coverage with vice president of North America channel and partner ecosystem Jeremiah Jenson, talking about the 30-day quote validity, Canadian partner influence, and the push for data center networking growth. And if you haven’t heard it yet, yesterday’s episode featured Curtis Dery from Xerox IT Solutions on HPE financing, GreenLake wins, and why AI is a digital goldmine for the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) ‘We Cannot Choose to Become Idiots' - or can we? Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-934
In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) 'We Cannot Choose to Become Idiots' - or can we? Show Notes: https://securityweekly.com/psw-934
In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) 'We Cannot Choose to Become Idiots' - or can we? Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-934
In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) 'We Cannot Choose to Become Idiots' - or can we? Show Notes: https://securityweekly.com/psw-934
The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Most enablement teams can tell you how many people sat through a course, but not whether any of it moved the business. In this special Content to Close episode, Erika Robertson, Director of Enablement at Citrix, walks through how she proves enablement is worth the budget by starting with the end in mind. Erika is certified through the ROI Institute and uses the Phillips ROI methodology from Jack and Patty Phillips, which she contrasts with the Kirkpatrick model most L&D and enablement teams default to. She explains how she builds the measurement plan before any content exists, so she can go back to stakeholders and say, this is how I will show you it worked. She covers identifying the metric category or bucket first, then finding a baseline like average deal size or sales cycle time for a group before a program runs, aligning instructional strategies to the business outcomes that matter, and her discipline that if something cannot be measured or will not move the business, it is probably not worth the investment. If you have ever struggled to connect your enablement work to real business results, this conversation gives you the framework.About ErikaErika Robertson is the Director of Enablement at Citrix, where she supports internal go-to-market teams, partners, and customers. She thought she would become a teacher coming out of college, then found her way into training adults instead, and has spent almost her entire career in enablement inside software companies including Cisco, SAP, and VMware. She holds a master's in instructional technology and is certified through the ROI Institute in the Phillips ROI methodology. She is passionate about enablement, go-to-market enablement, and instructional design, and about staying true to those principles even as AI changes the work.Show NotesConnect with Erika on LinkedIn: https://www.linkedin.com/in/erikajrobertson/ROI Institute (Phillips ROI methodology, founded by Jack and Patty Phillips)Text us what you think about this episode!
In Season 2, Episode 1 of The Citrix Session, XenTegra's Andy Whiteside, Bill Sutton, and Randy Price are joined by Citrix's Mathew Varghese to discuss Citrix DaaS Flex and how it's transforming desktop modernization. The conversation explores persona-based computing, simplified cloud adoption, infrastructure management, security responsibilities, and how organizations can optimize costs while delivering the right user experience for every employee. Learn how Citrix is rethinking Desktop-as-a-Service by combining managed infrastructure, intelligent workload sizing, and operational simplicity into a modern platform built for today's digital workspace.
Driving Resilient Care: Leadership, Technology, and Transformation in Digital Healthcare Host Russ Branzell, President and CEO of CHIME, welcomes Cletis Earle, Field CTO for Healthcare at Citrix, for a thoughtful discussion on what it takes to build resilient, high-performing digital health environments. Drawing on his experience as both a health system executive and technology strategist, Cletis shares practical insight into how organizations can better align technology investments with clinical and operational priorities. Together, they explore how healthcare leaders are modernizing legacy systems, improving workflows, and enabling secure, seamless access to critical data. Find all of our network podcasts on your favorite podcast platforms and be sure to subscribe and like us. Learn more at www.healthcarenowradio.com/listen
Mike Rosado interviews Raleigh-based illustrator and designer Ian Wenstrand about his highly detailed, vibrant illustrations blending cityscapes, technology, and imaginative world-building. Wenstrand describes drawing constantly as a kid, studying studio art at University of the Cumberlands (recruited to swim), and moving from production artist retouching roles into graphic design before illustration work organically became steady freelance. He self-published a children's book inspired by artists like Graeme Base and cross-section illustrators, then gained momentum through public art opportunities including a 2018–2019 Citrix window mural and later a major Film NC tourism brochure project featuring five regional illustrations packed with 50+ movie Easter eggs. He outlines his process (two sketch phases in Procreate, then Photoshop for color), time demands, work-life balance with two kids, and the importance of tight contracts to prevent scope creep. Wenstrand shares influences (IC4 Design, Moebius, sci-fi film aesthetics), discusses collaborative "Easter egg" client input, and explains why he avoids using AI, adding an AI clause to contracts and valuing the human creative process. Host: Mike Rosado (mrcraleigh.com) (instagram.com/ekimodasor) Post Production: Max Trujillo (instagram.com/trujillomedia) Sponsors: MRC (mrcraleigh.com) and Burny Wild's (burnywilds.com)
A poisoned software package compromised OpenAI employee devices before security teams could stop it. The company behind critical Ozempic injection components has been offline for weeks after a ransomware attack. And Change Healthcare is now facing another major lawsuit tied to the 2024 breach that crippled healthcare payments nationwide. Three stories. One message: Your business is now exposed to companies you don't control. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three cyber incidents that reveal how third-party trust has become one of the biggest operational risks in business today. This Week's Cybersecurity Breakdown 1. OpenAI, TanStack & the npm Supply Chain Worm A software supply chain attack spread through trusted developer ecosystems at massive speed: 42 npm packages poisoned in six minutes Malware stole GitHub tokens, AWS credentials, and CI/CD secrets OpenAI confirmed two employee devices were compromised ChatGPT Desktop, Codex App, Codex CLI, and Atlas certificates rotated Demonstrates how modern attacks now spread through trusted development infrastructure 2. West Pharmaceutical Ransomware Attack A cyberattack against a company most people have never heard of — but nearly everyone depends on: West Pharmaceutical components are used in roughly 43 billion injectable drug deliveries annually Includes Ozempic, Wegovy, insulin pens, vaccines, and hospital injectables Systems taken offline globally after ransomware deployment Manufacturing disruptions continue weeks later 3. Allied World v. Change Healthcare — The Financial Fallout Begins The legal consequences of the Change Healthcare breach are escalating: Cyber insurer Allied World filed suit seeking more than $1 million in damages Avesis operations were disrupted for roughly 90 days Root cause traced to a low-level Citrix account with no MFA Credentials were reportedly circulating on Telegram prior to the breach The Bottom Line The modern business attack surface is no longer just your company. It's: your software vendors your healthcare clearinghouses your package repositories your pharmaceutical suppliers Every trusted relationship is now a potential point of failure. And when those companies get breached, your business absorbs the consequences. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, supply chain attacks, AI threats, and executive-level cybersecurity strategy.
On the podcast this week, I cover Patch Tuesday news, a worrying Linux vulnerability, an interesting survey result about employees thoughts on selling credentials and much more! Reference Links: https://www.rorymon.com/blog/citrix-flex-platform-announced-patch-tuesday-roundup-critical-linux-zero-day/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
TeamPCP Update https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926 https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm https://checkmarx.com/blog/checkmarx-security-update-april-26/ 89 vulnerabilities in XAPI / Citrix XenServer https://shittrix.moksha.dk/#rationale Phantom RPC https://securelist.com/phantomrpc-rpc-vulnerability/119428/ Pi-Hole Vulnerability CVE-2026-41489 https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4 Linux Kernel Problem CVE-2026-41651 https://nvd.nist.gov/vuln/detail/CVE-2026-41651
Every founder who has ever handed sales off too early has paid for it. Every single one.In this episode, John sits down with Lou Shipley, a Harvard Business School lecturer, board member, investor, and author of Unlikely Entrepreneurs, to dig into why sales is still the most misunderstood function in business, and why founders who treat it as a second-class citizen almost always fail. Lou draws from decades of experience running companies, building sales cultures from scratch, and teaching MBAs how to sell before they ever launch a product.From cold-calling encyclopedia buyers to opening Asia for Avid Technology to building the sales curriculum at HBS, Lou has lived every stage of the sales journey, and he's done it at the highest level.If you're a founder, a sales professional, or anyone trying to understand what it actually takes to build a company in the age of AI, this conversation will challenge everything you think you know about selling. Visit www.jbarrows.com and learn how you can Make It Happen.What You'll LearnWhy founders who delegate sales too early almost always failHow Lou built one of Harvard's most in-demand coursesThe cultural disdain of salesWhy sales is not about convincing anyone of anythingHow to use AI as a learning tool instead of an answer machineWhat the Guy Kawasaki GPT experiment revealedWhy curiosity is the most important professional skill in the AI eraWhat SaaS companies should be doing right nowHow to build a farm system for sales talent17 stories that prove anyone can build something worth buyingLou Shipley is a multi-time tech CEO, entrepreneur, and enterprise software leader with over 25 years of experience driving growth and innovation. He has led several successful startups through rapid expansion and acquisition, including Black Duck, WebLine (acquired by Cisco), Reflectent (acquired by Citrix), and VMTurbo. In addition to his executive leadership, Lou serves on multiple boards, teaches technology sales at Harvard Business School, and is a respected mentor, speaker, and commentator in the tech industry.Connect with Lou Shipley:Website: https://www.loushipley.com/LinkedIn: https://www.linkedin.com/in/loushipley/Grab a copy of Lou Shipley's book, “Unlikely Entrepreneurs: Wins, Losses, and Crucial Lessons on Building Great Companies,“ on Amazon: https://www.amazon.com/Unlikely-Entrepreneurs-Lou-Shipley/dp/1394345895/John Barrows is a sales trainer, speaker, and founder of JB Sales with over 25 years of experience in the industry. He has made hundreds of cold calls a week, led startups to acquisition, and trained high-performing teams at companies like Salesforce, LinkedIn, Amazon, and Okta. Through JB Sales, John focuses on practical sales execution—helping reps fill pipeline, close deals, and build trust with buyers in today's AI-driven sales environment.Connect with John Barrows:LinkedIn: https://www.linkedin.com/in/johnbarrows/ Instagram: https://www.instagram.com/johnmbarrows/TikTok: https://www.tiktok.com/@johnmbarrowsCheck out John's Membership: https://go.jbarrows.com/Join John's Newsletter: https://www.jbarrows.com/newsletter
On this episode, I cover some fallout from issues caused by the recent Windows Updates, the general availability of Server 2025 support on AVD, a story about Microsoft providing a security assist to Apple and much more! Reference Links: https://www.rorymon.com/blog/issues-with-april-windows-updates-server-2025-for-avd-new-citrix-netscaler-concerns/
We hope that you are enjoying Leaving Egypt. We would invite you to join the Leaving Egypt community on Substack by becoming a paid subscriber: https://leavingegyptpodcast.substack.com/subscribeIn this episode, Al Roxburgh and Jenny Sinclair meet Melanie Rieback. Melanie's faith journey is as unexpected as her professional journey. Her extraordinary story, from computer hacker to systems thinker, from a secular Jewish upbringing to the Catholic tradition, is filled with creativity and paradox. She incubates steward-ownership business models and loves the ancient liturgies of the Church. She is a leader in cutting-edge redemptive business and finance who reads Thomas Aquinas. She works with European governments as her life is shaped by Edith Stein. She retells parables to ground new economic ideas in ancient biblical wisdom. She builds bridges between the political left and the Christian right. Melanie is involved in an amazing journey of encountering the reality of God. The story of her conversion was told in another podcast (linked below). In this episode of Leaving Egypt, she reveals how her journey continues to unfold, including baptism into the Catholic Church. What stands out most about Melanie's vocation is that, even in a highly technical field, her primary question is: “Lord Jesus, where do you want me?” Her surrender, through moments of crisis and awakening, is to a powerful calling: to gather and empower people to create a more just world, for the sake of the other, in God's name.Dr. Melanie Rieback is a computer scientist and social entrepreneur, CEO and founder of a cybersecurity company - Radically Open Security - that gives all its profit to charity. She is also founder of a “Post Growth” startup incubator, Nonprofit Ventures. Inspired by Catholic Social Teaching, she is involved in the Francesco Collaborative where she mentors young entrepreneurs and practitioners the non-extractive business space. Formerly, Melanie was Assistant Professor of Computer Science at the Free University of Amsterdam, Senior Engineering Manager on XenClient at Citrix and head researcher in the CSIRT at ING Bank, where she spearheaded their Analysis Lab and the ING Core Threat Intelligence Project. Melanie has received many awards for her work as a woman in tech innovation. She was born in Cleveland, Ohio, raised in Florida and lives in Amsterdam. For Melanie Rieback:www.linkedin.com/in/mriebackwww.radicallyopensecurity.comwww.francescocollaborative.orgwww.francescoeconomy.orgRerum Novarum – Pope Leo XIIILaborem Exercens – John Paul IIA podcast interview with Melanie Rieback referred to in this episode An article by Melanie Rieback on steward ownership as a third way (in Dutch): https://wi.christenunie.nl/groen-2025/03-creatief-met-armoede (pdf download)Presentation on Steward Ownership by Melanie Rieback to the Pontifical Academy of Social Sciences as part of a workshop on Digital Rerum Novarum: Artificial Intelligence for Peace, Social Justice, and Integral Human Development in October 2025A series of lectures by Melanie Rieback on Post Growth Entrepreneurship at the University of AmsterdamFor Alan J Roxburgh:http://alanroxburgh.com/aboutFacebook: https://www.facebook.com/alan.roxburgh.127/Facebook: https://www.facebook.com/thecommonsnetworkBooks:Forming Communities of Hope in the Great Unravelling: Leadership in a Changing World (with Roy Searle)Joining God in the Great UnravellingLeadership, God's Agency and DisruptionsJoining God, Remaking Church, Changing the World: The New Shape of the Church in Our TimeFor Jenny Sinclair:Substack: https://t4cg.substack.com/s/from-jenny-sinclairWebsite: https://togetherforthecommongood.co.uk/from-jenny-sinclairLinkedIn: https://www.linkedin.com/in/jenny-sinclair-0589783b/Twitter: https://twitter.com/T4CGFacebook: https://www.facebook.com/TogetherForTheCommonGoodUKInstagram: https://www.instagram.com/t4cg_insta/ Get full access to Leaving Egypt at leavingegyptpodcast.substack.com/subscribe
On this episode, I cover the recent Windows Updates released for April Patch Tuesday, a lot more AI news, an update on a recent security breach at Rockstar Games, concerns for certain Citrix customers and much more! Reference Links: https://www.rorymon.com/blog/microsoft-paused-development-accounts-patch-tuesday-news-employees-admit-to-actively-sabotaging-ai/
In this episode of The Girl Dad Show, host Young Han sits down with Steve Bennet, founder and managing director of Bodega Partners, longtime startup CFO, investor, professor, and father and grandfather, for a powerful conversation on entrepreneurship, mentorship, and life after decades in Silicon Valley. With over 30 years of experience and involvement in more than 150 technology startups, Steve has seen the full spectrum of success and failure. From companies acquired by IBM, Comcast, and Citrix to ventures that didn't make it, he brings a rare perspective on what actually drives long-term success in business and in life. But this conversation goes beyond startups. Steve shares why teaching and mentoring students has become one of the most fulfilling parts of his career, how his perspective on success has evolved over time, and what it means to balance family life while navigating high-pressure roles in venture capital and entrepreneurship. He and Young dive into the realities of startup challenges, the incentives behind venture capital, and the difficult decisions founders face as they grow their companies. They also explore parenting through a long-term lens, why letting kids make mistakes matters, and how experience shapes the way we guide the next generation. This episode is about perspective. What changes after 30 years of building, investing, and teaching. And what actually matters at the end of it. ✨ All episodes of The Girl Dad Show are proudly sponsored by Thesis, helping founders go further, together.
Iranian-linked hackers warn of possible “irreparable” attacks on U.S. water systems. CISA pushes urgent fixes for a critical Citrix flaw. The Dutch Finance Ministry takes systems offline after a breach. Space Force may scrap next-gen GPS control software. Attackers exploit a Fortinet server bug. Lloyds exposes customer transaction data. AI and regulation reshape cyber careers. The FTC settles with a dating app over data sharing. Sam Rubin, SVP, Palo Alto Networks Unit 42 Consulting and Threat Intelligence, discusses Iran's shift to identity weaponization. Wikipedia wrestles with a wayward writer. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We will be sharing a series of interviews we held at RSAC 2026 over the next few weeks. Sam Rubin, SVP, Palo Alto Networks Unit 42 Consulting and Threat Intelligence, discussing Iran's shift to identity weaponization. If you enjoyed this conversation, tune in here to listen to the full conversation. Selected Reading Iranian Cyberthreats Test US Infrastructure Defenses (BankInfo Security) CISA tells federal agencies to patch Citrix NetScaler bug by Thursday (The Record) Dutch Ministry of Finance takes treasury systems offline amid cyber incident investigation (Security Affairs) After 16 years and $8 billion, the military's new GPS software still doesn't work (Ars Technica) Exploitation of Critical Fortinet FortiClient EMS Flaw Begins (SecurityWeek) Lloyds IT Glitch Exposed Data of Nearly 500,000 Banking Customers (Infosecurity Magazine) SANS Research: The Cybersecurity Talent Shortage Narrative Is Wrong. The Real Crisis Is Skills, and AI Just Rewrote the List. (Yahoo Finance) FTC Takes Action Against Match and OkCupid for Deceiving Users by Sharing Personal Data with Third Party (FTC) Business Briefing (N2K Pro) An AI Agent Was Banned From Creating Wikipedia Articles, Then Wrote Angry Blogs About Being Banned (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Iran-linked hackers claim a breach of the FBI director's personal email. ShinyHunters hit the European Commission. F5 and Citrix warn of actively exploited flaws. A WordPress plugin exposes hundreds of thousands of sites. Infinity Stealer targets macOS users. A Russian APT adopts a new iOS exploit kit. Treasury weighs a cyber insurance backstop. DHS clears suspended CISA staff. Our guest is Brian Long, CEO and Co-Founder of Adaptive Security, discussing deepfake job hires and the new identity attack surface. Bureaucrats bless a black-box behemoth. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We will be sharing a series of interviews we held at RSAC 2026 over the next few weeks. Today, Dave Bittner is joined by Brian Long, CEO and Co-Founder of Adaptive Security, discussing deepfake job hires and the new identity attack surface. AI-generated identities are turning the hiring process into a new entry point for attackers. The solution isn't spotting perfect fakes — it's building stronger identity verification into hiring. Tune into the full conversation here. Selected Reading Iran-linked hackers breach FBI director's personal email, publish photos and documents European Commission confirms data breach after Europa.eu hack Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now Critical Citrix NetScaler Vulnerability Exploited in the Wild - Infosecurity Magazine File read flaw in Smart Slider plugin impacts 500K WordPress sites New Infinity Stealer malware grabs macOS data via ClickFix lures Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit - SecurityWeek US Treasury Weighs Cyber Insurance Backstop - GovInfoSecurity DHS drops investigation into former acting CISA chief's failed polygraph exam - Nextgov/FCW Federal Cyber Experts Thought Microsoft's Cloud Was “a Pile of Shit.” They Approved It Anyway Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
TeamPCP Update #2: Telnyx PyPi Compromise https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838 Citrix Netscaler Vulnerability Details https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/ macOS Clickfix Warning https://x.com/ClassicII_MrMac/status/2036797948911141129 Windows Smart Install https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/
Russ Branzell, President and CEO of CHIME, welcomes Cletis Earle, Field CTO for Healthcare at Citrix, for a thoughtful discussion on what it takes to build resilient, high-performing digital health environments. Drawing on his experience as both a health system executive and technology strategist, Cletis shares practical insight into how organizations can better align technology investments with clinical and operational priorities. Together, they explore how healthcare leaders are modernizing legacy systems, improving workflows, and enabling secure, seamless access to critical data.Key Takeaways:How leading health systems are unlocking measurable value from technology investments to improve care delivery and workforce efficiency.Practical approaches to modernizing applications and workflows in ways that enhance both caregiver experience and patient outcomes.Strategies for balancing security, compliance, and frictionless access to clinical systems in distributed care environments.The leadership mindset required to build resilient digital infrastructures while mentoring and developing the next generation of healthcare IT leaders.
RSAC spotlights public-private partnership gaps. DarkSword leaks to GitHub. The FCC blocks new foreign-made routers. Citrix patches a critical NetScaler flaw. DOE rolls out an energy-sector cyber strategy. CanisterWorm spreads through npm. Researchers flag suspected KACE SMA exploitation. QualDerm reports a 3.1-million-record breach. A Russian access broker gets 81 months. Intern Kevin checks in from RSAC. Maria Varmazis speaks with Jake Braun, longtime DEF CON organizer and former White House official about the DEF CON 33 Hackers' Almanack. Slow down, you vibe too fast. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Maria Varmazis speaks with today's guest Jake Braun, longtime DEF CON organizer, former White House official, and lead on DEF CON Franklin, about the DEF CON 33 Hackers' Almanack. You can read more about it here. Selected Reading Public-private partnerships vital in disrupting China's Typhoons, says RSA panel with no government speakers (The Register) Someone has publicly leaked an exploit kit that can hack millions of iPhones (TechCrunch) US bans any new consumer-grade routers not made in America (The Register) Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn (SecurityWeek) DOE Sets 5-Year Plan to Harden US Grid Against Cyberattacks (GovInfo Security) New CanisterWorm Targets Kubernetes Clusters, Deploys “Kamikaze” Wiper (Hackread) CVE-2025-32975 (Arctic Wolf) 3.1 Million Impacted by QualDerm Data Breach (SecurityWeek) Russian hacker who helped Yanluowang ransomware gang gets nearly 7-year prison sentence (The Record) This Web Tool Sabotages AI Chatbots By Making Them Really, Really Slow (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300 gRPC-Go Authorization bypass via missing leading slash in :path CVE-2026-33186 https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3
Filip Verloy is a technology leader with over 25 years of experience across enterprise IT, consulting, and global vendors. Currently working on securing Agentic AI for the enterprise, he brings deep expertise in API security, infrastructure, and large-scale complex environments. Before joining Rubrik, Filip served as Global Field CTO at API security startup Noname Security and held senior architecture and solutions roles at Citrix, Dell, Riverbed, and VMware. Known for his curiosity and commitment to understanding the fundamentals behind technology, Filip challenges the “illusion of knowledge” and focuses on building secure, resilient systems from first principles.00:00 Intro02:30 Our Guest05:06 Illusion of Knowledge 07:04 Unknown-Unknowns in AI09:57 Increasing the Attack Surface12:58 Risk in the Age of Agentic AI 17:56 How do you secure that data?25:00 How do we deal with IAM in this world of Agentic AI?31:22 API Security and API Access in Agentic AI39:02 How is the model of consuming surfaces over the internet going to change? 43:00 Agentic AI Governance49:25 More about Filip
Why do small business leaders keep buying more software yet still feel like they are drowning in logins, dashboards, and unfinished work? In this episode of Tech Talks Daily, I sit down with Jesse Lipson, founder and CEO of Levitate, to unpack a frustration I hear from business owners almost daily. After years of being pitched yet another tool, many leaders now spend hours each week troubleshooting software instead of serving customers. Jesse brings a grounded perspective shaped by decades of building SaaS companies, including bootstrapping ShareFile before its acquisition by Citrix, and what stood out to me immediately was how clearly he articulates where the current software model has broken down for small businesses. We talk about why adding more apps has not translated into better outcomes, especially for teams without dedicated specialists in marketing, finance, or sales. Jesse explains how traditional software often solves only part of the problem, leaving owners to become accidental experts in accounting, marketing strategy, or customer communications just to make the tools usable. From there, our conversation shifts toward what he believes will actually matter as AI adoption matures. Rather than chasing full automation or shiny new dashboards, Jesse argues that the real opportunity lies in blending intelligence with human guidance, allowing AI to work quietly behind the scenes while people remain the face of authentic relationships. A big part of our discussion centers on trust and connection in an AI-saturated world. Jesse shares why customers have become incredibly good at spotting automated communication and why relationship-based businesses cannot afford to lose the human element. We explore how AI can act as a second brain, helping business owners remember details, follow up at the right moments, and show up more thoughtfully, without crossing the line into impersonal automation that turns customers away. His examples, from marketing emails to customer support, make it clear that technology should support better relationships rather than replace them. We also look ahead to what small businesses should realistically focus on as AI evolves. Jesse offers practical guidance on getting started, from everyday use of conversational AI, to building internal documentation that allows systems to work more effectively, and eventually moving toward agent-based workflows that can take on real operational tasks. Throughout the conversation, he keeps returning to the same idea, that AI works best when it helps people become the kind of business leaders they already want to be, more present, more consistent, and more human. If you are a founder, operator, or small business leader feeling overwhelmed by tools that promise productivity but deliver friction, this episode offers a refreshing reset. As AI becomes more capable and more embedded in daily work, the real question is not how many systems you deploy, but whether they help you build stronger, more genuine relationships, so how are you choosing to use AI to support the human side of your business rather than bury it? Useful Links Connect with Jesse Lipson Connect with Jesse on X Learn more about Levitate
In this episode, we dive deep into the critical topic of self-deception and its profound impact on leadership and personal effectiveness. Mitch shares powerful insights on how self-deception can undermine our relationships and professional success, often without us even realizing it. He explains the concept of self-betrayal and how it leads to a distorted view of ourselves and others, creating unnecessary conflicts and reducing our influence as leaders. Mitch shares a valuable advice on how to rebuild trust in relationships damaged by self-deception and how to not let it happen again. Mitch is the co-author of Arbinger's latest bestseller, The Outward Mindset. He writes frequently on the practical effects of mindset at the individual and organizational levels as well as the role of leadership in transforming organizational culture and results. He is an expert on mindset and culture change, leadership, strategy, performance management, organizational turnaround, and conflict resolution. Mitch is a sought-after speaker to organizations across a range of industries, bringing his practical experience to bear for leaders of corporations, governments, and organizations across the globe. Specific clients include NASA, Citrix, Aflac, the U.S. Army and Air Force, the Treasury Executive Institute, and Intermountain Healthcare. Mitch carries his first-hand perspective as a proven leader into his speeches and facilitation, dynamically bringing Arbinger's concepts and tools to life through his powerful stories and hands-on experience. His audiences leave inspired to improve and equipped with a practical roadmap to effect immediate change. In his role as managing partner, Mitch directs the development of Arbinger's intellectual property, training and consulting programs, and highly customized large-scale organizational change initiatives. He has been instrumental in Arbinger's rapid growth, including its expanding international presence in nearly 30 countries. Mitch received his B.A. in philosophy and is a licensed nursing administrator. Trained in fine art at the Art Students League and the National Academy, he spends much of his free time painting. His work hangs in organizations nationwide. Visit Arbinger Institute here: https://arbinger.com/ Here are some free gifts for you: Overall Approach Used in Well-Managed Strategy Studies free download: www.firmsconsulting.com/OverallApproach McKinsey & BCG winning resume free download: www.firmsconsulting.com/resumepdf Enjoying this episode? Get access to sample advanced training episodes here: www.firmsconsulting.com/promo
Critical Security Flaws Patched by Cisco and Fortinet Amidst Recent Cyber Threats In this episode of Cybersecurity Today, host David Chipley covers several pressing cybersecurity issues. Cisco has patched a maximum severity zero-day vulnerability in its Async OS software, which has been exploited by a Chinese state-linked group. Fortinet has also addressed a critical vulnerability in its 40 Seam product, which is being actively exploited in the wild. The Dutch National Police are still recovering from a Citrix breach, emphasizing the need for modern infrastructure. Meanwhile, a spear-phishing campaign targeting US organizations uses Venezuela-themed lures. The episode wraps up with a discussion on a recent study revealing that training AI to produce insecure code can lead to broader problematic behaviour. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst 00:00 Introduction and Sponsor Message 00:46 Cisco Patches Critical Async OS Bug 02:26 Fortinet Vulnerability Exploited in the Wild 04:04 Dutch National Police and Aging IT Infrastructure 05:55 Spear Phishing Campaign with Venezuelan Lure 07:54 AI Writing Buggy Code: Unexpected Consequences 10:21 Conclusion and Final Thoughts
Andy Cohen, Vice President of Corporate Development at F5 Andy has built a career that proves M&A is fundamentally about relationships, not just transactions. With 30 years of experience and 60 deals closed across high-growth tech companies including Citrix, Acquia, and F5, Andy has cultivated the kind of reputation where every CEO he's worked with will take his call tomorrow. In this conversation, he reveals why zero-sum thinking kills deals, how to convince people to sell without convincing them to sell, and why walking away on principle matters more than closing at any cost. Things you will learn: Why reputation is your most valuable M&A asset The shift from zero-sum to win-enough thinking Learn Andy's approach to using due diligence as the foundation for integration strategy, cultural fit assessment, and long-term value creation. _____________
In this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Anthropic says a Chinese APT orchestrated attacks using its AI It's a day ending in -y, so of course there are shamefully bad Fortinet exploits in the wild Turns out slashing CISA was a bad idea, now it's time for a hiring spree Researchers brute force entire phone number space against Whatsapp contact discovery API DOJ figures out how to make SpaceX turn off scam compounds' Starlink service This week's episode is sponsored by Mastercard. Senior Vice President of Mastercard Cybersecurity Urooj Burney joins to talk about how the roles of fraud and cyber teams in the financial sector are starting to converge. Mastercard also recently acquired Recorded Future, and Urooj talks about how they aim to integrate cyber threat intelligence into the financial world. This episode is also available on Youtube. Show notes Full report: Disrupting the first reported AI-orchestrated cyber espionage campaign Researchers question Anthropic claim that AI-assisted attack was 90% autonomous - Ars Technica China's ‘autonomous' AI-powered hacking campaign still required a ton of human work | CyberScoop Amazon discovers APT exploiting Cisco and Citrix zero-days | AWS Security Blog CISA gives federal agencies one week to patch exploited Fortinet bug | The Record from Recorded Future News PSIRT | FortiGuard Labs CISA, eyeing China, plans hiring spree to rebuild its depleted ranks | Cybersecurity Dive This Is the Platform Google Claims Is Behind a 'Staggering' Scam Text Operation | WIRED A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers | WIRED DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound | WIRED Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million | The Record from Recorded Future News Cyberattack leaves Jaguar Land Rover short of £680 million | The Record from Recorded Future News FBI: Akira gang has received nearly $250 million in ransoms | The Record from Recorded Future News Operation Endgame: Police reveal takedowns of three key cybercrime tools | The Record from Recorded Future News Inside a Wild Bitcoin Heist: Five-Star Hotels, Cash-Stuffed Envelopes, and Vanishing Funds | WIRED
Operation Endgame expands global takedowns. The U.S. is creating a Scam Center Strike Force. Microsoft rolls out its delayed “Prevent screen capture” feature for Teams. Proton Pass patches a clickjacking flaw. Researchers uncover previously undisclosed zero-day flaws in both Citrix and Cisco Identity Services Engine. Android-based digital picture frames contain multiple critical vulnerabilities. Lumma Stealer rebounds after last month's doxxing campaign. Our guest is Garrett Hoffman, Senior Manager of Cloud Security Engineering from Adobe, talking about achieving cloud security at scale. X marks the spot… where your passkey stops working. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Garrett Hoffman, Senior Manager of Cloud Security Engineering from Adobe, talking about achieving cloud security at scale. You can hear the full conversation with Garrett here. Selected Reading End of the game for cybercrime infrastructure: 1025 servers taken down - Operation Endgame's latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium (Europol) US announces ‘strike force' to counter Southeast Asian cyber scams, sanctions Myanmar armed group (The Record) Microsoft rolls out screen capture prevention for Teams users (Bleeping Computer) Proton Pass patches DOM-based clickjacking zero-day vulnerability (Cyberinsider) Amazon discovers APT exploiting Cisco and Citrix zero-days (AWS Security Blog) CISA warns feds to fully patch actively exploited Cisco flaws (Bleeping Computer) Popular Android-based photo frames download malware on boot (Bleeping Computer) Increase in Lumma Stealer Activity Coincides with Use of Adaptive Browser Fingerprinting Tactics (Trend Micro) Elon Musk's X botched its security key switchover, locking users out (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
OWASP Top 10 2025 Release Candidate OWASP published a release candidate for the 2025 version of its Top 10 list https://owasp.org/Top10/2025/0x00_2025-Introduction/ Citrix/Cisco Exploitation Details Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/ Testing Quantum Readyness A website tests your services for post-quantum computing-resistant cryptographic algorithms https://qcready.com/