POPULARITY
On this week's show Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: Anthropic's Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won't keep the world safe from your AI doomsday machine The FISA 702 statute expired, but the spying can (probably) continue! NPM v12 delivers some protection against supply chain attacks, but not enough. Microsoft has a series of bugs that prevent Windows Update from … updating Much, much more! This episode is also available on YouTube Show notes Anthropic suspends new AI models after government directive | NBC News Tech Anthropic rankles users with safety-first Fable release | NBC News Tech How a 90-minute White House deadline sparked Silicon Valley's biggest AI fight | washingtonpost.com Pete Hegseth (@PeteHegseth) on X | X (formerly Twitter) David Sacks (@DavidSacks) on X | X (formerly Twitter) DoW CIO Kirsten Davies (@DoWCIODavies) on X | X (formerly Twitter) David Shulman (@DavidShulmanFL) on X | X (formerly Twitter) Controversial FISA spying law expires tonight. The spying will continue. | Ars Technica GitHub announces npm security changes to tackle supply-chain attacks | BleepingComputer Why NPM v12 won't stop supply chain attacks - Risky Business Media | Social Signals Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks | BleepingComputer Microsoft patches Exchange Server zero-day exploited in attacks | BleepingComputer Max severity Ivanti Sentry vulnerability now exploited in attacks | BleepingComputer CISA warns of another cPanel plugin flaw exploited in attacks | BleepingComputer Critical Fortinet FortiSandbox flaws now exploited in attacks | BleepingComputer CISA orders feds to patch actively exploited Ivanti flaw by Sunday | BleepingComputer CISA to require federal agencies to patch some cyber vulnerabilities within 3 days | therecord.media Path traversal flaw in AI dev platform Langflow exploited in attacks | BleepingComputer Microsoft: Some Windows PCs fail to install latest monthly updates | BleepingComputer Microsoft fixes BitLocker recovery bug on Windows Server 2025 | BleepingComputer Microsoft fixes Windows update failures linked to WUSA installer | BleepingComputer New attack turned Microsoft 365 Copilot into 1-click data theft tool | BleepingComputer Over 73,000 French govt employees affected in Tchap messenger breach | BleepingComputer Signal Alums Reveal ‘Encrypted Spaces,' a System for Making Private Collaboration Apps | wired.com FBI disrupts massive AI-powered phishing service using a million URLs | BleepingComputer Cyberattack shuts down major Australian sugar mills, disrupting harvest | The Record Drug Sites Hijacked Spotify's Search Ranking Through Fake Podcasts, Report Finds | wired.com It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests | 404.feed.press Who Runs the Ransomware Group ‘The Gentlemen?' | krebsonsecurity.com :brdKnife: (@cR0w@infosec.exchange) | Infosec Exchange
Emergency talks fail to free Anthropic's Fable 5. Trump moves to strengthen national security systems. Microsoft patches a critical Copilot flaw. ShinyHunters weaponize a PeopleSoft zero-day. DragonForce hides in Microsoft Teams for months. Plus, Amos Stealer targets Macs, CISA issues a three-day patch deadline, Delta avoids penalties, and researchers show just how easy it is to manipulate AI search. Our guest is Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. Consulting meets confabulation. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Mike Fey, Co-Founder & CEO at Island, discussing the architectural differences between network and modern SASE. If you enjoyed this conversation, check out the full interview here. Selected Reading Anthropic Is Still at Odds With the White House Over Claude Fable 5 (WIRED) Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher (The Register) White House Issues Memo to Bolster NSS Cybersecurity (SecurityWeek) Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise (Beyond Machines) ShinyHunters Hits Universities Via Oracle Zero-Day (GovInfo Security) DragonForce Ransomware Exploited Microsoft Teams to Hide Attack (Infosecurity Magazine) Inside Amos Stealer: How This Threat Targets macOS Credentials and Keychains (CyberProof) CISA warns of another cPanel plugin flaw exploited in attacks (Bleeping Computer) US closes probe into 2024 Delta Air Lines meltdown sparked by CrowdStrike outage (Reuters) It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests (404 Media) KPMG pulls report on AI usage due to apparent hallucinations (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
✏️ Suscribirse https://www.youtube.com/watch?v=3WjM7NNA0vk La IA permite construir más rápido, automatizar más tareas y rehacer piezas enteras de un proyecto con mucha menos fricción que antes. Pero esa facilidad también abre una pregunta incómoda: si ahora puedes montarlo casi todo con IA, para qué seguir usando WordPress en muchos casos. En el episodio 254 de Negocios y WordPress, esa pregunta no se responde con una postura extrema. La conversación mezcla problemas reales de despliegue y sincronización, un mini tutorial muy útil sobre extractos en WordPress, pruebas con OpenCode y OpenRouter, automatizaciones personales y un debate de fondo sobre criterio técnico. La conclusión no va tanto de elegir un bando como de entender qué parte del stack merece rehacerse y cuál sigue aportando muchísimo valor. Además, el episodio recuerda que el trabajo profesional cada vez depende menos de “picar código” o de encajar piezas al vuelo y más de tomar buenas decisiones de arquitectura, mantenimiento y negocio. Vercel, WP Rocket y Verifactu: cuando la velocidad también complica el sistema El episodio arranca con varios ejemplos que aterrizan muy bien la situación actual del desarrollo web. Por un lado aparece el caso de TomaBumping.com, ya apuntando a Vercel en lugar de quedarse en un flujo más manual con cPanel. La promesa es clara: despliegues más cómodos, conexión más natural con GitHub y una experiencia más moderna para mover una web basada en Next. Pero la parte interesante no es la migración en sí, sino el peaje que aparece enseguida. La sincronización con Notion, los builds nocturnos, los deploys constantes y los límites del plan gratuito dejan una idea bastante potente: la IA y los stacks nuevos te dan superpoderes, pero también pueden meterte en sistemas más pesados de operar si no revisas bien el flujo. Ahí sale una reflexión útil para cualquier proyecto: no siempre compensa sustituir una solución ya entendida por otra más moderna si el coste operativo sube demasiado. A veces el problema no es tecnológico, sino de encaje entre lo que necesita el proyecto y la infraestructura elegida. En ese mismo bloque aparecen dos recordatorios del ecosistema WordPress que siguen siendo muy prácticos: un contenido sobre WP Rocket orientado a optimización y rendimiento un repaso a VeriFacWoo, presentado como una solución bien montada para cubrir una necesidad legal y operativa muy concreta Ese contraste está muy bien traído porque resume el tono del episodio: puedes explorar herramientas nuevas, pero eso no invalida todo lo que WordPress y su ecosistema siguen resolviendo con mucha eficacia. Cómo funcionan de verdad el excerpt y la etiqueta more en WordPress Uno de los bloques más didácticos del episodio es la explicación sobre extractos y cortes de contenido en WordPress. Parece un detalle pequeño, pero afecta directamente a cómo muestras entradas en listados, feeds o plantillas personalizadas. La aclaración principal es esta: el `excerpt` no es lo mismo que meter un corte manual con la etiqueta `more`. Qué hace el extracto manual y qué hace el automático Cuando usas el extracto de WordPress, puedes trabajar de dos maneras: con un extracto manual escrito por ti con un extracto automático generado desde el inicio del contenido Por defecto, ese extracto automático se basa en unas 55 palabras, aunque se puede modificar. El problema es que un corte automático no siempre resume bien un post, porque a veces solo toma el arranque del texto y puede dejar frases partidas o un contexto poco representativo. Por eso la recomendación implícita del episodio es bastante sensata: si el resumen importa de verdad, conviene escribir un extracto manual. Qué hace la etiqueta more y por qué depende de cómo esté hecho el tema La etiqueta `more` actúa como un corte dentro del contenido, no como un extracto real. Sirve para decirle a WordPress hasta dónde mostrar el texto cuando la plantilla usa el contenido en un contexto de listado. Eso implica algo importante: si tu tema usa funciones pensadas para extractos, el `more` no sustituye ese comportamiento. Solo tiene sentido si la plantilla está montada para tirar de contenido recortado y no de excerpt. Este bloque del episodio recuerda una idea muy valiosa para quien trabaja con WordPress a medida: antes de tocar nada, conviene entender qué función está usando el tema y qué comportamiento quieres realmente. Muchas veces el problema no está en WordPress, sino en mezclar conceptos que parecen similares pero no lo son. OpenCode, OpenRouter, Kilo Code y el coste real de trabajar con IA Otra parte fuerte del episodio gira alrededor de las herramientas de desarrollo con IA y, sobre todo, del miedo razonable a depender demasiado de un único proveedor. Aquí entran OpenCode, OpenRouter, Codex, Codex Bar, Kilo Code y Visual Studio Code. La reflexión es muy reconocible para cualquiera que ya esté trabajando con agentes: ahora mismo usamos la IA a un ritmo que probablemente no se sostenga igual en el futuro si todo se mantiene en planes muy subsidiados. Por eso el episodio insiste en tres ideas: vigilar el coste real, no solo la cuota mensual no casarte con un único proveedor o modelo explorar alternativas locales o más abiertas antes de necesitarlas por obligación Libertad frente a comodidad Codex aparece como la opción cómoda cuando ya tienes una cuenta de ChatGPT y el flujo te resulta familiar. OpenCode y OpenRouter entran en cambio como piezas para ganar flexibilidad: cambiar de proveedor, probar modelos gratuitos, separar tareas más serias de tareas menores y no depender por completo de una sola interfaz. La conclusión provisional que sale del episodio es muy honesta: aunque la libertad interesa, la comodidad pesa mucho en el trabajo diario. Y eso explica por qué cuesta salir de una herramienta cuando ya conoce tu contexto, tu proyecto y tu forma de trabajar. Lo importante no es la novedad, sino el sistema de trabajo Kilo Code y sus pasarelas aparecen como punto intermedio interesante porque combinan acceso a ficheros, extensiones y diferentes proveedores desde un entorno más conocido. Pero el mensaje de fondo no es “esta herramienta gana”, sino otro bastante más útil: cada vez importa más separar agente, modelo y pasarela para poder decidir mejor cómo trabajas. No es un debate solo técnico. También es económico y estratégico. Si una parte del trabajo puede resolverse con modelos más baratos o gratis, y otra necesita más potencia, tiene sentido diseñar ese reparto con criterio en vez de tirar siempre de la opción más cómoda. Una skill para ordenar música y lo que enseña sobre automatización real El ejemplo más divertido del episodio probablemente sea también uno de los más reveladores. Elías cuenta cómo ha ido construyendo una skill para ordenar canciones descargadas, renombrarlas con un formato coherente, clasificarlas por décadas y estilos, y convertir ciertos archivos con FFmpeg cuando superan un umbral concreto de calidad. Más allá de lo anecdótico, el caso enseña varias cosas: la automatización útil suele nacer de una necesidad muy concreta las reglas importan más que el brillo de la herramienta cuanto mejor defines la estructura de destino, menos improvisación necesitas después Ese bloque aterriza muy bien la diferencia entre usar IA para jugar y usarla para operar mejor. No se trata solo de pedir cosas y ver qué sale, sino de montar un sistema que funcione con cierta estabilidad mientras tú haces otra cosa. También aparece un matiz importante: automatizar más significa consumir más tokens, más tiempo de cómputo y más recursos. Por eso el episodio vuelve a la misma idea de antes: la IA aporta valor cuando el ahorro de tiempo y fricción compensa el coste operativo que introduces. WordPress vs IA: el problema no es WordPress, sino qué parte estás rehaciendo La parte central del episodio llega con una discusión que ahora aparece mucho en comunidades técnicas: gente que dice que ha dejado WordPress porque con IA ya puede hacer su web más rápido y mejor. La respuesta que plantea el episodio no es defensiva, pero sí bastante crítica con ese relato cuando se formula de manera simplista. La tesis principal es esta: muchas personas no están abandonando WordPress como sistema, sino una implementación concreta cargada de builders, plugins, decisiones heredadas y capas que quizá nunca debieron estar ahí. La analogía que mejor resume este bloque es la de la casa o la reforma. Si lo que te molestaba era una bañera, quizá no tenía sentido tirar la casa entera para construir otra desde cero. Del mismo modo, si lo que fallaba era una parte de una web, no siempre hace falta sustituir todo el stack para resolverlo. Qué sigue resolviendo muy bien WordPress El episodio insiste en que WordPress todavía aporta mucho valor estructural, incluso en plena aceleración de la IA: sistema de usuarios, roles y permisos REST API y hooks backend editorial ya resuelto ecosistema de plugins y extensiones base sólida para tiendas con WooCommerce Todo eso sigue ahorrando muchísimo trabajo respecto a rehacer cada pieza desde cero. La IA puede acelerar personalizaciones, integraciones o frontend, pero no vuelve irrelevante que ya exista una base probada para operar. Qué sí queda más cuestionado Donde sí se nota un cambio fuerte es en las capas de maquetación repetitiva y en ciertos flujos basados en builders o temas multipropósito. La conversación apunta que herramientas como Elementor o incluso Bricks pueden seguir teniendo usos concretos, pero también que la IA hace más fácil volver al código en muchas partes del frontend sin perder velocidad. Eso cambia bastante el equilibrio. Antes un builder podía ser el atajo natural para maquetar rápido. Ahora, si puedes generar HTML, CSS y lógica más limpia con ayuda de IA, algunas capas dejan de compensar tanto. No porque sean “malas”, sino porque el coste-beneficio ya no es el mismo. El valor real se mueve hacia el criterio El cierre del debate va más allá de WordPress. Si la ejecución técnica se abarata, lo que gana valor es otra cosa: entender el negocio del cliente elegir bien la arquitectura decidir qué reutilizar y qué rehacer interpretar datos y proponer mejoras ampliar mantenimiento hacia SEO, UX, contenidos y rendimiento La IA no elimina al profesional útil; deja más en evidencia al que solo aportaba ejecución sin criterio. Cierre El episodio 254 deja una conclusión bastante clara: la IA no convierte automáticamente a WordPress en una tecnología obsoleta, pero sí obliga a revisar mucho mejor por qué usamos cada capa. Si antes ya tenía sentido evitar complejidad innecesaria, ahora todavía más. También deja una lectura práctica para quienes trabajan con clientes y proyectos propios: cada vez compensa menos vender solo implementación y cada vez compensa más vender criterio, estructura, mantenimiento ampliado y capacidad de decidir bien. Si te interesa ese tipo de conversación, en la comunidad de Telegram de Negocios y WordPress siguen compartiendo ideas, herramientas y dudas muy en la línea de este episodio. Y si además te mueves en la comunidad WordPress, conviene tener también en el radar citas como WordCamp Galicia 2026, que el episodio menciona como parte del cierre. Esa quizá sea la mejor forma de resumir el 254: no se trata de elegir entre WordPress o IA como si fueran bandos, sino de usar cada cosa donde realmente aporta más.
Mai menü: hackerek éjszakája cPanel megint, arbitrary root file system read Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks a defender bárkit kinyír Elérhetőségeink:TelegramTwitterInstagramFacebookMail: info@hackeslangos.show
On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• 27th Annual TribalNet Conference & Tradeshow, 20 – 24 Sep, Dallas, TX• 02 Jun! WaterISAC H2OSecCon (Virtual Conference)Main Topics:Exploitation! and the KEV! • CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-9082 Drupal Core SQL Injection Vulnerability• Drupal security advisory (AV26-492) - Update 2 - Canadian Centre for Cyber Security • CISA orders feds to patch actively exploited Drupal vulnerability - BleepingComputer • CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability• CISA gives feds 4 days to patch actively exploited cPanel plugin flaw - BleepingComputer • CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability• Palo Alto Networks Security Advisory AV26-462 — Canadian Centre for Cyber Security • ETR: Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability CVE-2026-0257 — Rapid7 Ransomware & Data Breaches: • The Cyber Extortion Economy - Palo Alto Networks Unit 42 - 28 May 2026 “As recently noted by our Chief Security Intelligence Officer, Wendi Whitmore, it only took 39 seconds for threat actors to move from initial access to data exfiltration in one case.” • Stay Ahead of Ransomware: What 2026 Threat Reports Are Telling Us — SANS Institute — 01 Jun 2026• Charter Communications Data Breach Could Impact Nearly 5 Million • How St. Paul, Minn., Recovered From a Ransomware Attack • FBI FLASH - Silent Ransom Group Impersonating IT Personnel through Social Engineering - FBI IC3 & FBI warns of in-person data theft attacks from extortion gang • Charter confirms data breach after ShinyHunters extortion threat • The Gentlemen ransomware: Dissecting a self-propagating Go encryptor • The Gentlemen Ransomware Group Is Scaling Faster Than Any Other Group on Record • The Gentlemen (Ransomware) in Disguise: Defense Evasion and other TTPs World Cup:• FBI PSA - Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup - FBI IC3 • FAA Establishes No Drone Zones for FIFA World Cup 2026 Stadiums, Fan Events and Base Camps — FAA • Column: Empower Emergency Managers for Major Events • Ebola concerns grow ahead of World Cup — The Hill Quick Hits:• The Future of AI Risk: Predictions for 2027 and Beyond - Gate 15 - 26 May 2026 • Top 10 Artificial Intelligence Security Actions Primer — Canadian Centre for Cyber Security • Mythos Exposes a Bigger Problem in Critical Infrastructure Cyber Defense - HSToday • NSA Launches Zero Trust Implementation Guidelines Resource Webpage — National Security Agency • Designing secure access with ZTNA - National Cyber Security Centre • The 2026 U.S. Midterms Have a Cyber Problem, But It's Not at the Ballot Box — Check Point & Hackers are already laying groundwork to disrupt 2026 midterms, research says — Nextgov • 'Holding our breath': Hurricane season is here, and FEMA is shorthanded — Politico
Originally recorded: Friday May 29, 2026In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026.Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting the “/mnt/user-data” directory.Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained franchise-related documents. SecurityWeek article Matt references.CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being actively exploited in the wild.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== This Week in Bug Bounty ======COST, AI frontier models and more: A measured take on the future of security testinghttps://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testingCommon AI misconceptions debugged!https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportionBountySync + Socialhttps://luma.com/bountysync_social====== Resources ======Ghosts of Encryption Pasthttps://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/tessl Skill Optimizerhttps://tessl.io/registry/tessl/skill-optimizer/0.8.0The Internet Is Falling Down, Falling Down, Falling Downhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/High Fidelity Check for the cPanel Authentication Bypasshttps://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/Achieving Deterministic Prompt Injection Through Client-Side Feedback Loopshttps://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/GPT-5.5: Mythos-Like Hacking, Open To Allhttps://xbow.com/blog/mythos-like-hacking-open-to-allRemote Command Execution in Google Cloud with Single Directory Deletionhttps://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral====== Timestamps ======(00:00:00) Introduction(00:09:20) AMPScript(00:25:10) Tessl Skill Optimizer(00:33:07) cPanel & WHM Authentication Bypass(00:40:46) Advice for Bug Bounty Programs(00:50:07) Prompt Injection Through Client-Side Feedback Loops(00:54:37) GPT 5.5(01:01:00) Remote Command Execution in Google Cloud
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968 PAM Backdoors Steel Passwords https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web CPanel Updates https://support.cpanel.net/hc/en-us/sections/360007088193-Security Let s Encrypt Briefly Halts Certificate Issuance https://letsencrypt.status.io
CPanel, WHM release fixes for three new vulnerabilities Official JDownloader site serves malware to Windows and Linux users Sen. Schumer seeks DHS plan on AI cyber coordination Get the show notes here: https://cisoseries.com/cybersecurity-news-new-cpanel-vulnerabilities-jdownloader-delivers-malware-schumer-pushes-dhs/ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Referências do Episódio 秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马PamDOORa: Analyzing a New Linux PAM-Based Backdoor for Sale on the Dark WebIncident Update: Saturday, May 9, 2026Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
Synopsis Cette semaine, Patrick et Jacques reçoivent Jonathan Bastille, technicien informatique avec mandat sécurité au Cégep de Rivière-du-Loup. Jonathan raconte sa transition du privé vers le secteur public, et le contraste brutal entre la rapidité de décision en PME et le rythme « paquebot » d'un milieu où chaque changement passe par un conseil d'administration. La discussion bifurque rapidement vers la loi 25, l'illusion de conformité par bouts de papier, et l'attitude de trop de PME québécoises : « la sécurité, c'est pas important — j'attends que ça le devienne ». Le trio s'attaque ensuite à un sujet récurrent du podcast : la futilité de la majorité des campagnes de phishing simulé. Renforcement positif vs punition, tests qui ne mesurent que le clic au lieu du processus de détection en arrière, et l'argument central de Patrick — si vos employés deviennent bons à reconnaître votre simulation, ils ne deviennent pas pour autant bons à reconnaître les vraies attaques. Jonathan partage aussi une histoire concrète où il a bloqué le device code flow dans Microsoft, juste avant qu'une attaque réelle utilisant exactement cette technique frappe l'organisation. Côté actualités, plusieurs nouvelles passent au crible : le retour forcé au bureau qui a accouché du néologisme « téléprésentiel », la sortie maladroite du chef du CST qui blâme la proximité avec les États-Unis pour les cyberattaques canadiennes, et surtout le combo explosif CopyFeld + cPanel — une vulnérabilité Linux d'escalade de privilèges présente depuis 2007 et un piratage massif de panneaux d'administration d'hébergeurs. L'épisode se ferme sur une campagne de phishing déployant ScreenConnect chez 80+ organisations, un faux positif retentissant de Microsoft Defender sur des certificats DigiCert, et un rappel martelé : tant que les utilisateurs travaillent en local admin, aucun EDR ne va vous sauver. Crew Patrick Mathieu Jacques Sauvé Jonathan Bastille (invité spécial) Liens et ressources Patrick Microsoft Attack Surface Reduction Rules Device code phishing - Microsoft Microsoft Digital Defense Report Téléprésentiel – retour au bureau, 3 h de trafic pour Teams (Journal de Montréal) Proximité avec les États-Unis et cyberattaques – Radio-Canada cPanel / WHM – exploitation massive du contournement d'authentification (TechCrunch) Copy Fail – exploitation pour obtenir root sur Linux (CISA / BleepingComputer) Jacques Campagne phishing ScreenConnect 80+ organisations Microsoft Defender faux positif DigiCert / Cerdigent Jonathan Microsoft Defender for Endpoint Microsoft Sentinel Microsoft Intune Shamelessplug Inscriptions Hackfest 2026 Hackfest CTF Polar - journée pour les gestionnaires en cybersécurité Call for Paper Hackfest 2026 (mai à fin août) iHack - 30 mai 2026 (Québec, Trois-Rivières, Chicoutimi, Montréal) Discord Hackfest securite.fm Crédits Montage audio par Hackfest Communication Musique par Caleidisco – Candy Island - Much Too Loose Locaux virtuels par Streamyard
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-925
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Show Notes: https://securityweekly.com/psw-925
The team discusses a spate of major security flaws affecting Linux, Microsoft Edge and the cPanel web administration software. We also look at how kids are getting around online age checks, and ponder the US government's plan to test and certify AI models. For this week's Hot Hardware spot we completely rip up the rule book to showcase not one but two software tools, named FineTune and WhatCable. One helps you set volumes for different audio devices, while the other tells you the technical specifications of your USB cables and devices; there can be only one winner.
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-925
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Show Notes: https://securityweekly.com/psw-925
On this week's show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week's cybersecurity news, including: The US Government says we just have to patch faster, but… Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn't enough James gets mad about lame AI Agent adoption advice from the US and Australian Governments James Kettle and Niels Provos both showed us that any model can find 0day like Mythos And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars This week's show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention. This episode is also available on Youtube. Show notes Exclusive: US officials weigh cutting deadlines to fix digital flaws amid worries over AI-powered hacking, sources say | Reuters British cyber agency warns of looming ‘patch wave' as AI speeds flaw discovery | The Record from Recorded Future News Federal agencies must patch cPanel bug by Sunday, CISA says | The Record from Recorded Future News cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security The most severe Linux threat to surface in years catches the world flat-footed - Ars Technica New MOVEit vulnerabilities prompt urgent patch warning | Cybersecurity Dive US and allies urge ‘careful adoption' of AI agents | Cybersecurity Dive careful_adoption_of_agentic_ai_services.pdf User just tricked Grok and Bankrbot to send tokens with Morse code - Cryptopolitan Finding Zero-Days with Any Model (1872) Sponsored: James Kettle built an AI hacker - YouTube Feature Interview: Nicholas Carlini, Anthropic - Risky Business Media Trellix investigating breach of source code repository | Cybersecurity Dive Popular DAEMON Tools software compromised | Securelist Komari Red: The Monitoring Tool with a Built-in Reverse Shell | Huntress Hackers earning millions from hijacked cargo, FBI says | The Record from Recorded Future News Congress punts FISA renewal to June | The Record from Recorded Future News Cops Use Apple Data And Car Bluetooth To Identify Crypto Robbery Suspect Stewart Baker, outspoken voice on cybersecurity and national security law, dies at 78 | IAPP
The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com
In this week's Security Sprint Dave and Andy covered the following topics:Opening• Homeland Security Funding Bill Passed, Includes Money for CISA • Browser Extensions and Shadow AI: Unmanaged Threats to Privacy — Gate 15• Data Centers, Telecommunications Networks, and Space-Based Systems: Modernizing DHS's SRMA Role for the Communications and IT Sectors — House Committee on Homeland Security• New Cybersecurity Guide Targets Rising Threats to Food and Agriculture SMBs • Maine Law Requires Hospitals to Enact Cybersecurity PlansMain TopicsNew FTC Data Show People Have Lost Billions to Social Media Scams - Federal Trade Commission - 23 Apr 2026 The Federal Trade Commission reported that consumers have lost billions of dollars to scams originating on social media platforms, with fraudsters leveraging impersonation, investment schemes, and romance scams to exploit user trust. Take9! 9 Seconds For A Safer World. Cyber threats are everywhere. And getting sneakier. What can you do to protect yourself, your community and our nation? New 2026 ‘IOCTA' highlights sophisticated tactics and emerging challenges in the digital landscape – Europol unveils comprehensive analysis of evolving cybercrime threats - Europol - 28 Apr 2026 Europol released its 2026 Internet Organised Crime Threat Assessment, warning that encryption, proxies, artificial intelligence, dark web marketplaces, cryptocurrencies, fraud ecosystems, ransomware, and child sexual exploitation are expanding the cybercrime landscape. Global Encryption Coalition (GEC). The Global Encryption Coalition (GEC) was founded in 2020 by the Center for Democracy & Technology, Global Partners Digital and the Internet Society and now has over 350 members. Gate 15 is a proud member of the GEC. Ransomware! Weekly ransomware & data leak landscape; A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch. — eCrime.ch — 26 Apr 2026. The eCrime weekly report provides a seven-day analysis of ransomware claim activity, data leak site postings, actor concentration, and sector targeting trends. • NCC Group Monthly Threat Pulse - Review of March 2026 • Ransomware and Cyber Extortion in Q1 2026 - ReliaQuest Presidential Message on National Hurricane Preparedness Week - The White House - 03 May 2026 This message encourages Americans in hurricane-prone areas to prepare before the season by protecting property, building emergency plans, assembling supplies, and monitoring forecasts and evacuation routes. It emphasizes local and state frontline roles while describing federal support for response and recovery. • Hurricane Preparedness - NOAA • Summer forecast 2026: Heat, severe storms to shape the season as El Niño develops, strengthens - AccuWeather• 2026 Hurricane Awareness Webinars - NOAA Quick Hits• Email threat landscape: Q1 2026 trends and insights — Microsoft Security Blog • Tycoon2FA disruption impact• QR code phishing attacks• CAPTCHA tactics• Malicious payloads• Business email compromise• Defending against email threats• Microsoft Defender detections• Alert - AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940 - Canadian Centre for Cyber Security • Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks • To recover your files kindly send 0.1 BTC to… ransom note appears on websites • The cPanel Situation Is… - • cPanel authentication bypass vulnerability CVE-2026-41940 exploited • Over 40,000 Servers Compromised in Ongoing cPanel Exploitation • Cole Allen's journey from Caltech grad to accused gunman in D.C. attack • Footage shows White House correspondents' dinner suspect 'casing' hotel: US attorney • Washington Hilton says it was using Secret Service protocols on night of attack
✏️ Suscribirse https://www.youtube.com/watch?v=2Ly7D9ZiSaE La IA sigue ensanchando el campo de juego, pero en este episodio 251 la conversación no gira alrededor de anuncios grandilocuentes, sino de cómo meterla en sistemas de trabajo reales. Se habla de agentes con Codex y Kilo Code, de una migración práctica de cPanel a Vercel, de MCP dentro de WordPress y de una duda muy concreta: si diseñas con IA desde fuera, hasta qué punto tiene sentido volver a pasar por el builder. Codex, archivos `agents` y orquestación práctica Uno de los bloques más claros del episodio es el salto de usar IA como chat a usarla como sistema de agentes con contexto y roles definidos. El caso que se comenta con más detalle es Codex, sobre todo a partir de la posibilidad de definir agentes en archivos `agents`, darles instrucciones propias y dejar que el orquestador principal los invoque cuando toca. La parte interesante no es el truco de configuración en sí, sino lo que cambia a nivel de flujo. En lugar de repetir cada vez el mismo contexto o lanzar tareas desde cero, el sistema empieza a delegar según el tipo de trabajo, con nombres, roles e instrucciones más estables. También se menciona el uso de VS Code frente a Cursor, el valor de tener el chat mejor integrado y el descubrimiento de pequeños detalles como autocompletado, cambio de cuenta o sesiones centralizadas. Pero el fondo no está en el editor, sino en que la IA empieza a comportarse como una capa operativa del proyecto, no solo como una ventana donde pedir cosas sueltas. En esa misma línea encaja la aparición en otros medios de IA, Automatización y Codex con Victor Correal en No es asunto vuestro, donde se cruza automatización, programación y trabajo real con agentes. Kilo Code y el desarrollo con IA como sistema El episodio no se queda en Codex, también contrapone otras formas de organizar el desarrollo con IA. Ahí entra Kilo Code, con énfasis en agentes especializados, ejecución paralela, worktrees, gestión más explícita del sistema y una experiencia pensada para producción, no solo para asistencia puntual. La comparación sirve para aterrizar algo importante: hoy ya no basta con preguntar cuál es la mejor herramienta. Lo que de verdad importa es qué arquitectura de trabajo te deja montar cada una, cómo delega, cuánto contexto conserva y cuánto control te deja sobre lo que está haciendo. Ese matiz atraviesa buena parte del episodio. Las herramientas pueden parecer similares desde fuera, pero cambian mucho cuando el uso pasa de “hazme esto” a “ayúdame a mantener un proyecto vivo con criterios, contexto y especialización”. Migrar de cPanel a Vercel sin humo El bloque más práctico del episodio es seguramente la migración de TomaBumping desde un entorno en cPanel a Vercel. El proyecto estaba hecho con Next.js y en origen parecía viable mantenerlo en el servidor actual, pero aparecieron límites reales en compilación, sincronización y ejecución de procesos. La conversación deja una idea útil: migrar no es solo mover el proyecto a un hosting más moderno, sino entender qué necesita realmente ese flujo para funcionar bien. En este caso, el repositorio ya estaba en GitHub, así que importar el proyecto a Vercel fue sencillo. Lo importante vino después: variables de entorno, builds automáticos y sincronización de datos desde Notion hacia archivos JSON. Ahí aparece el límite clave de Vercel: no está pensado para guardar ficheros persistentes en disco durante la ejecución de ciertos comandos. Eso obligó a repensar la sincronización y a sacar esa parte fuera del runtime habitual. La solución elegida fue usar GitHub Actions para lanzar la sincronización, guardar artefactos, hacer commit y push, y dejar que ese push disparase el deploy en Vercel. No es una historia de “Vercel lo hace todo solo”, sino de elegir bien qué capa hace cada cosa. MCP, capabilities y contexto útil dentro de WordPress Otro bloque importante del episodio gira alrededor de MCP y de cómo conectar la IA con WordPress de una forma realmente útil. La idea no es solo pedirle que cree contenido, campos o estructuras, sino darle acceso a contexto técnico del proyecto: tipos de campo, formatos, relaciones y estado real del sistema. Ese matiz es importante porque cambia por completo el papel de la IA. En vez de operar a ciegas, puede leer antes de escribir, inspeccionar antes de generar y trabajar con una base técnica más cercana a lo que ya existe en el proyecto. La conversación conecta esto con vídeos y contenidos propios sobre WordPress, capabilities y automatización, y con una visión bastante pragmática: MCP no aporta tanto por “hacer cosas” como por mejorar la calidad del contexto con el que las hace. También aparece como telón de fondo la idea de WordPress como ecosistema suficientemente flexible para seguir siendo útil en proyectos modernos. En ese sentido encaja bien el hub temático de WordPress, que sirve como referencia de contexto y especialización en torno al CMS. NovaMCP, Bricks, Elementor y el cortocircuito del builder La parte más crítica del episodio aparece cuando se habla de NovaMCP, Bricks y Elementor. Se reconoce el interés del plugin y su potencial para exponer tools, leer estructura del sitio, editar archivos, ejecutar código o trabajar con widgets y estilos globales. Pero justo ahí aparece la objeción más valiosa del episodio: si ya estás diseñando con IA desde fuera, con dirección de arte, framework CSS y artefactos propios, añadir una capa intermedia para volver a traducir eso a un builder puede ser más fricción que ayuda. En otras palabras, el problema no es si Bricks o Elementor son compatibles con IA. Lo son. El problema es si esa compatibilidad mejora de verdad el sistema o si simplemente añade complejidad, gasto de tokens y dependencia de otra interfaz más. La crítica no es anti-builder. De hecho, se reconoce que pueden tener sentido para ciertos layouts, para importar CSS o para iterar rápido sobre una base ya creada. Pero la conclusión práctica es bastante clara: si la IA te ayuda precisamente a salir del builder, volver a meterlo en el centro del flujo puede ser un paso atrás. Make, flyers, emails y automatizaciones pequeñas que ya ahorran tiempo El cierre del episodio baja la IA a automatizaciones mucho más concretas y accesibles. Aquí no hacen falta agentes complejos, ni un VPS, ni una infraestructura excesiva. Se habla de Make como herramienta para analizar flyers, capturas de pantalla o emails, extraer información estructurada y crear registros útiles en otros sistemas. Los ejemplos son muy claros: detectar información de carteles, convertir una captura en un JSON trabajado, o reenviar un email para que la IA extraiga campos, genere un resumen y cree el evento correspondiente en Airtable. La enseñanza de este bloque es sencilla pero potente: no siempre hace falta montar un sistema sofisticado para obtener valor real de la IA. Muchas veces basta con un webhook, un módulo bien planteado y una extracción estructurada que elimine trabajo repetitivo. Ese enfoque además encaja muy bien con el tono general del episodio: menos obsesión por la herramienta de moda y más foco en si resuelve una tarea concreta con claridad y sin meter complejidad innecesaria. Cierre Este episodio 251 deja una idea bastante útil para cualquiera que esté mezclando IA, WordPress y desarrollo diario: no todo lo que se puede conectar conviene conectarlo. Codex, Kilo Code, Vercel, GitHub Actions, MCP, Bricks, Elementor o Make pueden encajar en un sistema potente, pero no por acumulación sino por criterio. La parte valiosa no está en usar más capas, más agentes o más builders, sino en elegir qué papel juega cada pieza. Cuando eso se hace bien, la IA acelera de verdad. Cuando no, solo añade ruido. Si te interesa esta mezcla de WordPress, automatización, agentes y decisiones técnicas con impacto real, este episodio deja bastante material para replantear flujos, quitar pasos innecesarios y quedarte con lo que sí aporta valor.
Referências do EpisódioQuasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting CapabilitiesBreaking the code: Multi-stage ‘code of conduct' phishing campaign leads to AiTM token compromiseHackers target governments and MSPs via critical cPanel flaw CVE-2026-41940CISA Adds One Known Exploited Vulnerability to CatalogBackdoored PyTorch Lightning package drops credential stealerRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Malicious Ad for Homebrew Leads to MacSync Stealer https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942 Wireshark Update https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html Digicert Microsoft Defender False Positive https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/ https://bugzilla.mozilla.org/show_bug.cgi?id=2033170 cPanel Exploited https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Microsoft Defender Deletes Trusted Certificates | 44,000 cPanel Servers Hit by Ransomware Microsoft Defender mistakenly flagged legitimate DigiCert root certificates as malware and removed them from Windows systems, breaking trust chains and causing widespread application failures. The issue was traced to a faulty detection signature (Trojan:Win32/CertyAgent), now fixed in update version 1.449.430.0. At the same time, DigiCert confirmed a separate security incident where attackers compromised support systems and used internal tools to issue valid code-signing certificates. At least 60 certificates were revoked, including 27 linked to the Zong Stealer malware campaign. Meanwhile, a critical cPanel vulnerability (CVE-2026-41940) is being actively exploited. Attackers used the flaw as a zero-day since February, compromising at least 44,000 servers and deploying new SORI ransomware using ChaCha20 and RSA-2048 encryption. Also in this episode: The Linux "Copyfail" privilege escalation bug is now confirmed exploited and added to CISA's Known Exploited Vulnerabilities list A 10/10 critical vulnerability (CVE-2026-37541) in Open Vehicle Monitoring System could allow remote code execution in connected car environments This episode breaks down how these attacks work, why patch timing matters, and where organizations are most exposed right now. Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security Suggested Chapters (for retention and SEO) 00:00 Microsoft Defender deletes trusted certificates 02:20 DigiCert breach and stolen code-signing certificates 05:20 cPanel zero-day exploited, 44,000 servers compromised 08:40 Linux Copyfail vulnerability now actively exploited 10:40 Critical flaw in open-source car software
Telegram Mini Apps deliver Android malware CISA orders Federal agencies to patch cPanel bug by Sunday British cyber agency warns of looming 'patch wave' due to speedy AI flaw discovery Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Big Tech is pouring hundreds of billions into AI, but with rising signs of an industry bubble and some real-world fallout, this week's episode digs into who actually wins, who stands to lose, and whether Apple's patient strategy may outsmart the hype. Big Tech firms beat earnings expectations amid AI spending questions RIP the $599 Mac Mini, you were too beautiful for this world Microsoft lifts 2026 AI spend by $25 billion to cover component price rises Microsoft speeds up in Big Tech's data center spend-off Crosswording the Situation Meta's historic loss in court could cost a lot more than $375 million Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks Australia unveils a 2.25% levy on Meta, Google, and TikTok Meta found in breach of EU law for failing to keep children off Facebook and Instagram Meta inks deal for solar power at night, beamed from space Musk v. Altman week 1: Elon Musk says he was duped, warns AI could kill us all, and admits that xAI distills OpenAI's models OpenAI-backed 1X opens California factory targeting 10,000 home humanoid robots in year one Sam Altman asked GPT-5.5 to plan its own launch party. Its requests were 'beautiful' but 'strange.' Sam Altman says Elon Musk can come to his GPT 5.5 party: 'World needs more love' The US Senate unanimously passed a rule barring senators from trading on prediction markets like Kalshi and Polymarket, amid rising concern over insider trading 'We Know You Live Right Here': No Secrets in America's New Surveillance Dragnet California to begin ticketing driverless cars that violate traffic laws China Suspends New Autonomous Driving Permits After Baidu Outage China has decided that firing a worker because an AI can do their job is illegal. No Western country has done the same. Maryland Is First to Ban A.I.-Driven Price Increases in Grocery Stores The most severe Linux threat to surface in years catches the world flat-footed Hackers are actively exploiting a bug in cPanel, used by millions of websites The Hottest Anti-AI Gadget Is a Cyberdeck Jack Dorsey-backed Vine reboot Divine launches to the public GameStop eyes eBay takeover in audacious $46 billion bet on Ryan Cohen's e-commerce vision AI-generated actors and scripts are now ineligible for Oscars Ukraine says it's training drone pilots in 'Grand Theft Auto V' This free website is like Wikipedia meets the CIA Light Phone III Is a Delightfully Minimalist Smartphone Alternative Valve Steam Controller is here, it's a gamepad in search of a console Bluetooth Connected - The Voices Behind the Connection Spirit Airlines shuts down after Trump's war on Iran doubled jet fuel prices Ask.com has shut down, marking the official farewell to the Internet's favorite butler Pioneering geneticist and decoder of the human genome J. Craig Venter dies at age 79 Host: Leo Laporte Guests: Nicholas De Leon, Devindra Hardawar, and Mikah Sargent Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: helixsleep.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit expressvpn.com/twit box.com/AI
Referências do EpisódioAnti-DDoS Firm Heaped Attacks on Brazilian ISPsClickFix Removes Your Background but Leaves the MalwareInside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in AsiaImportant Update From TrellixCritrical (sic) cPanel flaw mass-exploited in "Sorry" ransomware attacksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
Meta acquires Assured Robot Intelligence, CISA orders a cPanel and WHM patch by May 3rd, NASA targets late 2027 launch for Artemis III. MP3 Please SUBSCRIBE HERE for free or get DTNS shows ad-free. A special thanks to all our supporters–without you, none of this would be possible. If you enjoy what you seeContinue reading "DOD Strikes Deals With AWS, Microsoft, Nvidia, Oracle, Reflection AI – DTH"
Intel is making BANK on their stocks, but still not getting respect on their CPUs, GALAX is shutting down (mostly), Microsoft is trying REALLY hard now, does ASUS have the 12vhpwr cabling answer?, and patch your damn cPanel right now. Plus cool gaming tidbits and more on that router ban. Enjoy all that and even slightly more!0:00 Intro0:39 Patreon2:18 Food with Josh3:55 Intel stock hits record high12:06 Microsoft feels enough pressure to fix Update16:29 GALAX shuts down19:11 Portable hotspots face US ban just like routers22:44 57 Right to Repair bills in 27 states26:25 NES or Acemagic Retro X5 AMD Ryzen AI 9 HX 370 Mini PC?30:40 Fractal Pop 2 Vision33:49 Some discussion of the ROG Equalizer40:37 We look at a 2080Ti Super eBay listing here42:24 (In)Security Corner49:03 Gaming Quick Hits59:47 Picks of the Week1:07:39 Outro ★ Support this podcast on Patreon ★
Some of the big internet infrastructure tools have revealed major production security issues A lot of these are not household names, but just this week we've seen critical patches released to fix things that would, could, or have, caused real world harm. There's a bug on Linux that allows an unprivileged local user to gain root/admin access. Another on the CPanel server application that also allows unauthenticated remote attackers to bypass authentication and gain unauthorized administrative access. That means they could take your server down, or post malicious content on your site. If you're a business owner with a hosting provider, I'd check in with them to make sure both their Linux backbone and WHM/CPanel software is patched – both are major players in the market. These security issues come after Anthropic shared their incredibly power Mythos model with selected partners One of those was Linux (see above!) It's unclear if it was the AI that found the exploit, but this is the type of thing Anthropic said it could do. OpenAI is also launching its own "Cyber" model to select security partners before a public release. It's amusing because Sam Altman openly mocked Anthropic for the move to 'create marketing' around the hush hush model. The Pentagon has made its AI partnerships On the list are Nvidia, Microsoft, and AWS. They'll be able to deploy their models onto classified networks for "lawful operational use". What constitutes “legal use” is what got Anthropic designated a supply chain risk – it didn't want to be used for mass surveillance or autonomous weapons. The DoD says 1.3 million personnel have used their "GenAI.mil" application, which gives access to a range of models in a classified setting. LISTEN ABOVE See omnystudio.com/listener for privacy information.
DOS, 0x1A4, Seneca the Younger, Outlook, Copy/Fail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-577
Critical cPanel and WHM bug exploited as zero-day Swiss police arrest suspected members of Black Axe group HHS ponders government posture for protecting data centers Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/ Thanks to our episode sponsor, Guardsqaure Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.
DOS, 0x1A4, Seneca the Younger, Outlook, Copy/Fail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-577
DOS, 0x1A4, Seneca the Younger, Outlook, Copy/Fail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-577
The security news was out of hand this week, so we had to pick our spots. We start with the nasty cPanel/WHM vulnerability that affects tens of millions of domains in shared hosting environments, then we discuss the Copy Fail Linux bug and its effects before seguing into the delightful history of branded bugs, logos, and parodies. LinksBranded bugs and logos: https://io.netgarage.org/logo/
El programa 2866 de Radiogeek, les habló de varios temas importantes. OnePlus se une a Realme; Huawei trae a Argentina la evolución de la serie Mate; Google Translate ahora te permite practicar la pronunciación; Mientras Tim Cook deja su cargo, Apple alcanza ventas récord, pero se avecina una escasez de chips; Gemini ahora puede generar archivos, incluso word excel pdf y LaTex; YouTube libera el modo Picture-in-Picture para todos los usuarios a nivel mundial; Los hackers están explotando activamente una vulnerabilidad en cPanel; y por último Instagram toma medidas enérgicas contra los agregadores de contenido. Toda esta información la pueden encontrar desde nuestra web www.infosertec.com.ar o bien desde el canal de Telegram/Whastapp, o Instagram. Esperamos sus comentarios.
Apple said it will be supply-constrained on Mac Mini, Studio, and Neo in the next quarter, too. Plus, web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months. Learn more about your ad choices. Visit podcastchoices.com/adchoices
The Copy Fail vulnerability impacts all Linux distros going back to 2017, hackers are exploiting a cPanel auth bypass, every Moldovan citizen has their data stolen, and some scam compounds got raided raided… in Dubai. Show notes Risky Bulletin: The mysterious hack of Moldova's healthcare database
DOS, 0x1A4, Seneca the Younger, Outlook, Copy/Fail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-577
A critical Linux flaw dubbed “Copy Fail” raises alarm. The House moves to extend Section 702. The White House pushes back on expanded Mythos access. cPanel and SonicWall rush out security patches. Researchers warn AI agents may leak credentials. Smishing targets key industries. Ukrainian police arrest suspects in a massive Roblox account theft scheme. Our guest is Jamie Moles, technical manager at ExtraHop, discussing how the pace of vibe coding is creating major AI blind spots. Honeypot hijinks get halted by curious clicks. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest is Jamie Moles, technical manager at ExtraHop, discussing how the pace of vibe coding is creating major AI blind spots. Selected Reading Copy Fail (Copy.Fail) House extends a controversial spy tool, but Senate path is unclear ahead of deadline (NPR) White House Opposes Anthropic's Plan to Expand Access to Mythos Model (WSJ) Critical Authentication Vulnerability in cPanel and WHM (Beyond Machines) Security Advisory: Firmware Update Required — Gen 6, Gen 7, and Gen 8 Firewalls (Sonic Wall) Phishing the agent: Why AI guardrails aren't enough (Okta) Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns (Group-IB Blog) Ukrainian police detain hackers suspected of stealing thousands of Roblox accounts for resale (The Record) I accidentally made law enforcement shut down their stresser honeypot (lina's blog) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Referências do EpisódioAll supported cPanel versions hit by critical auth bug, now patchedThe Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.Official SAP npm packages compromised to steal credentialsSupply Chain Campaign Targets SAP npm Packages with Credential-Stealing MalwareClaude adds malware to crypto agentRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
In questa puntata, Alex Raccuglia racconta in stile flusso di coscienza la creazione in tempi rapidi di un sistema di newsletter management “vibe coding”: come ha sostituito servizi come MailChimp con Amazon SES, come ha costruito da zero le basi per l'iscrizione/disiscrizione e l'invio di email, e come l'uso dell'AI lo aiuta a occuparsi della logica tattica mentre lui resta focalizzato sulla strategia. Tra errori, innovazioni rapide, bounce management e riflessioni su etica e uso consapevole dell'AI, emerge il potenziale di strumenti AI per accelerare lo sviluppo software e le campagne marketing, senza perdere controllo.Brand, nomi, servizi e link (URL) presenti, con breve descrizione- Runtime Radio – network che ospita Techno Pillz. - URL: https://runtimeradio.it / https://runtimeradio.com - Descrizione: casa del podcast e dei programmi di Runtime Radio.- MailChimp - URL: https://mailchimp.com - Descrizione: servizio di email marketing utilizzato in passato per invii massivi e gestione degli iscritti.- Amazon Simple Email Service (SES) - URL: https://aws.amazon.com/ses/ - Descrizione: servizio di invio email da server SMTP; costo base citato di circa 1 USD per 10k email (versione standard). Il relatore lo usa come alternativa a MailChimp.- cPanel - URL: https://cpanel.net - Descrizione: pannello di controllo hosting usato per configurare i parametri di invio email (autorizzazioni domini per SES).- Curl - URL: https://curl.se - Descrizione: motore di internet/strumento a riga di comando utilizzato per inviare email (supporto al vibe coding).- Final Cut Pro (FCP) - URL: https://www.apple.com/final-cut-pro/ - Descrizione: software di montaggio/video usato dall'autore, citato nel contesto della gestione creativa dei contenuti.- Telegram - URL: https://telegram.org - Descrizione: piattaforma di messaggistica citata come canale di interazione (glupotelegram).- Google Gemini (AI) - Descrizione: suite di modelli AI di Google citata come fonte di supporto AI (denominata “Gemini” nel racconto). Nota: non viene fornito URL esplicito nel testo; Gemini è la linea di modelli AI di Google.- Nano Banana Pro - Descrizione: personaggio/strumento AI usato dall'autore per generare contenuti e interfacce; non ha URL ufficiale citato nel testo.- Final Cut Pro / FCP Autodac (contestualizzato) - Descrizione: menzione di strumenti/prodotti legati al flusso di lavoro video; presente nel racconto come riferimento, ma non sempre con URL specifico.- Curl (già menzionato) e prompt AI - Descrizione: elementi tecnici usati per il flusso di lavoro con API e automazioni AI; inclusi nel racconto per illustrare il vibe coding.[00:13:54] Spot[00:17:23] Spot[00:21:12] Spot[00:26:37] Il riassunto di Sciatta GPT
Technical SEO Study with Favour Obasi-Ike: Website Speed / Content Delivery Network (CDN) / Content Management System (CMS) = Why Is My Website Slow?| Get exclusive SEO newsletters in your inbox.Technical SEO is a major common issue for websites causing them to start loading slowly. We discuss that slow speeds are often caused by poor hosting platforms lacking sufficient bandwidth and uncompressed media, particularly images and videos.Crucially, we emphasize the importance of acquiring and maintaining intellectual property ownership, including the domain and C panel (Control Panel) access, to prevent developers from holding site information hostage.Additionally, the conversation highlights technical aspects like utilizing a Content Delivery Network (CDN), compressing files using tools like compressor.io, and employing proper image file types and alt text for improved search engine optimization.Next Steps for Digital Marketing + SEO Services:>> Need SEO Services? Book a Complimentary SEO Discovery Call with Favour Obasi-Ike>> Need more information? Visit our Work and PLAY Entertainment website to learn about our digital marketing services.>> Visit our Official website for the best digital marketing, SEO, and AI strategies today!Answer Key1. What is "Technical SEO"? Technical SEO, or "technical search engine (everywhere) optimization," refers to the technical methods used to ensure a brand or business shows up on web servers and desired websites, typically in the form of a link. It involves optimizing the underlying infrastructure of a website to improve its visibility and performance in search results.2. Identify and explain the two primary factors discussed that cause a website to load slowly. The two primary factors are the hosting platform and the presence of numerous uncompressed images. A poor hosting platform may have insufficient bandwidth or be an overloaded shared server, while large, uncompressed image files significantly increase the amount of data a user must download, slowing the entire loading process.3. What is a "high bounce rate," and how does it relate to a website's performance? A high bounce rate occurs when a visitor comes to a website and leaves quickly without interacting further. This is often caused by slow loading times, as users lack the patience to wait for content; another website might provide the same information three seconds faster, which is enough to make a user leave.4. Define what a Content Delivery Network (CDN) is and name the two types of servers that comprise its network. A CDN, or Content Delivery Network, is a system that stands between a website's hosting (the origin) and the end-user. It caches and compresses website files, like images, across multiple geographic locations to deliver them to users more quickly. The two types of servers within a CDN are the origin server, where the website's original content is stored, and the edge server, which is geographically closer to the end-user and delivers the cached content.5. Why is it crucial for a business owner to have direct ownership of their website's hosting server? Direct ownership of the hosting server ensures control over one's intellectual property and prevents being held "hostage" by a developer. If a business is on someone else's overloaded shared server, performance issues on one site can affect all sites (a "domino effect"). Owning the server provides direct access to the control panel, backups, and the website's blueprint, which is vital for management and troubleshooting.6. Explain the role of "alt text" and how it contributes to a website's visibility and accessibility. Alt text, or alternative text, is a description added to an image's code. It provides context to search engines like Google and AI indexers, making the images searchable and improving the site's overall SEO. Furthermore, alt text is critical for accessibility, as it allows screen reading software to describe the image to visually impaired users.7. What is a "cPanel," and what critical functions can be performed by accessing it? "cPanel" stands for Control Panel. It is the administrative dashboard for a website's hosting server. Accessing the cPanel is critical because it allows a user to get backup data, access the actual blueprint of the website, and see technical details like the file sizes of stored images.8. Describe the significant negative impact that uncompressed images can have on a website, using the specific numerical example from the discussion. Uncompressed images drastically increase a website's loading time because of their large file size. The example given was an online store with 50 products, each with two image variations. If each uncompressed image is 5 megabytes, the total data added to the site's front-loading speed would be 500 megabytes, whereas compressing those same images could reduce the total size to just 50 megabytes (10% of the original) without losing quality.9. What are the two recommended methods for incorporating video content on a website without negatively affecting its load speed? We strongly advises against directly uploading video files (e.g., MP4s). Instead, the two recommended methods are: 1) converting the video into a GIF and uploading the much smaller GIF file, or 2) embedding the video from a third-party platform like YouTube, which ensures the video is streamed from YouTube's servers and not the website's own server.10. Name at least three free tools mentioned that can be used to analyze a website's performance and health. Three of these are GTmetrix, Google Page Speed Insights, and Siteliner. Other mentioned tools include Compressor.io and iLoveIMG.com for image compression and iLovePDF.com for documents.Digital Marketing SEO Resources:>> Join our exclusive SEO Marketing community>> Read SEO Articles>> Need SEO Services? Book a Complimentary SEO Discovery Call with Favour Obasi-Ike>> Subscribe to the We Don't PLAY PodcastBrands We Love and SupportDiscover Vegan-based Luxury Experiences | Loving Me Beauty Beauty ProductsSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
I just launched a new DNS Course for Web Designers, specifically to help you get a 101, foundational understanding of all things domains, DNS records, email, security, performance, etc.It replaced what was formerly my cPanel course. It's a short, snappy, “what you need to know” DNS course without getting too technical or overwhelming. In this podcast episode, I'm giving you a little teaser!Included in the episode:A few personal DNS horror stories (to illustrate how important it is to know this stuff as a web designer)The most popular lesson so far on ‘Domain Types'And I'm even including the DNS Checklist from the course FOR FREE! Think of it as your DNS SOP for you and your team.Again, be sure to download the DNS Checklist I've made available to you for free. It also includes a special offer if you'd like to dive into the full course!Show notes at joshhall.co/393