Podcasts about cve

  • 633PODCASTS
  • 2,752EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 3, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cve

Show all podcasts related to cve

Latest podcast episodes about cve

Cyber Morning Call
1060 - Primeira correção não funcionou e adversários tomam controle total de servidores de gestão remota de TI

Cyber Morning Call

Play Episode Listen Later Aug 3, 2026 7:15


Referências do EpisódioN-central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577N-able Says Attackers Take Over N-central Servers After Initial Fix Proves IncompleteCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftAdobe fixed a maximum-severity vulnerability flaw in Campaign ClassicSecurity update available for Adobe Campaign Classic | APSB26-114Série de posts da Galaxy Research sobre ataque contra carteiras da ColdcardThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET VersionToy Ghouls' new toy: the GenieLocker ransomwareRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 30, 2026 6:57


Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:14


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

Cyber Morning Call
1058 - Cisco confirma ataques reais explorando senha fixa em firewalls corporativos

Cyber Morning Call

Play Episode Listen Later Jul 30, 2026 8:57


Referências do EpisódioCisco Secure Firewall Management Center Software Static Credential VulnerabilityCisco warns of FMC static credential flaw exploited in zero-day attacksVMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code ExecutionInside Astaroth's New Spambot ComponentStable Channel Update for Desktop - Wednesday, July 29, 2026KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't EnoughCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Coordinated “cyberattack” on Minnesota water utilities: What you need to knowClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 29, 2026 6:59


AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Techmeme Ride Home
Anthropic Doesn't Hate Open Weights, Says Anthropic.

Techmeme Ride Home

Play Episode Listen Later Jul 28, 2026 19:52


Dario Amodei said Anthropic never backed an open-weights ban, pitching mandatory safety tests instead as OpenAI and Google signed on. Altman headed to Washington, Korea's KOSPI cratered 11% on AI jitters, Apple launched Klarna leasing, and shipped 194 CVE fixes. Anthropic wants tests, not bans, as OpenAI and Google back open weights (The New Stack) Source: Sam Altman will meet with senior US officials, lawmakers, and economists in Washington, DC, this week to preview OpenAI's upcoming family of AI models (CNBC) South Korea's KOSPI drops 11%+, led by chip stocks, amid concerns over China's chipmaking progress and the AI spending boom; Samsung falls 11%+ and SK Hynix 12% (Bloomberg) Credit default swap prices tied to Oracle, SpaceX, Alphabet, Amazon, Meta, Broadcom, and Nvidia hit record highs as investors turn jittery over Big Tech's data center debt; Oracle's five-year CDS reached 215bps (FT) Apple launches Apple Upgrade, a new US leasing program in partnership with Klarna that replaces the iPhone Upgrade Program, starting at $17.99/month for iPhones (MacRumors) Apple releases 26.6 updates for iOS, macOS, iPadOS, watchOS, tvOS, and visionOS with a huge number of security fixes; macOS Tahoe 26.6 alone addresses 155 CVEs (9to5Mac) Subscribe to the ad-free feed. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Morning Call
1056 - CISA inclui no KEV falha que burla patch de persistência no FortiOS

Cyber Morning Call

Play Episode Listen Later Jul 28, 2026 6:38


Referências do EpisódioCISA Adds Two Known Exploited Vulnerabilities to CatalogCVE-2025-68686 - SSL-VPN Symlink Persistence Patch BypassCVE-2026-16812 - Arista VeloCloud Orchestrator On-Prem OS Command Injection VulnerabilityMirage Kitten targets Middle East and Africa region with new malwareExpanding the Castle: New Campaigns, New Tooling, and the NeedleStealer ConnectionHelpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC BackdoorBreaking the Sandbox Again: Bypassing n8n's CVE-2026-27577 PatchApple security releasesRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca GarciaX6LO8GntgGb95egmmOCZ

This Week in Linux
353: Codeberg Bans AI, 432 Linux CVEs, Valve wants Arch on ARM, Jellyfin Leaders Left & more Linux news

This Week in Linux

Play Episode Listen Later Jul 27, 2026 26:42


video: https://youtu.be/mytY-cyk76U This week in Linux, hundreds of Linux security alerts landed but the headlines leave out the most important part. Codeberg, a major open-source code hosting platform, is drawing a new line around AI-generated code, Valve is stretching out their ARM for a new Frame of mind for running Linux, and Jellyfin is entering a major new chapter behind the scenes. All of this and more on This Week in Linux, Your Source for Linux GNews! Download as MP3 Support the Show Become a Member = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:30 Become a Member of the channel by July 31st 01:39 Codeberg bans mostly AI-generated projects 05:31 Valve and Collabora develop Arch Linux for ARM64 08:08 Jellyfin Leadership Departures 11:57 Linux publishes 432 kernel CVEs in 2 days 14:53 Canonical fixes 3 Snap vulnerabilities 17:26 Firefox 153 adds Containers and Vulkan Video 21:11 TWIL Speedrun or Linux Lightning Round 21:37 AMD's open-source AI and robotics announcements 22:34 Final MPEG-4 Visual patent expiration 23:31 OBS Studio 32.2 Released 24:05 Raspberry Pi launches a 10-inch Touch Display 2 25:18 Outro Links: Become a Member of the channel by July 31st https://tuxdigital.com/membership Codeberg bans mostly AI-generated projects https://blog.codeberg.org/protecting-our-floss-commons-from-llms.html https://www.omgubuntu.co.uk/2026/07/codeberg-bans-ai-generated-code https://itsfoss.com/news/codeberg-bans-ai-contributions/ OpenAI on Vibe Coding - https://x.com/karpathy/status/1886192184808149383 Valve and Collabora develop Arch Linux for ARM64 https://www.collabora.com/news-and-blog/news-and-events/building-an-arch-linux-aarch64-port-for-holo-core.html https://gitlab.steamos.cloud/holo/holo-core-aarch64-preview https://www.gamingonlinux.com/2026/07/collabora-announce-a-preview-of-holo-core-an-aarch64-port-of-arch-linux-for-steam-frame/ https://www.phoronix.com/news/Holo-Core-Experimental-ARM64 https://9to5linux.com/valve-and-collabora-announce-official-arch-linux-arm64-port-for-steam-frame Jellyfin Leadership Departures https://www.boniface.me/posts/on-my-jellyfin-resignation/ https://itsfoss.com/news/jellyfin-leadership-crisis/ https://linuxiac.com/jellyfin-loses-project-leader-and-core-team-member-in-major-shake-up/ https://jellyfin.org/posts/state-of-the-fin-2026-05-24/ Linux publishes 432 kernel CVEs in 2 days https://lore.kernel.org/linux-cve-announce/ https://seclists.org/oss-sec/2026/q3/198 https://seclists.org/oss-sec/2026/q3/210 https://www.theregister.com/security/2026/07/22/linux_kernel_team_publishes_432_cves_in_two_days/5276497 https://docs.kernel.org/process/cve.html https://utcc.utoronto.ca/~cks/space/blog/linux/KernelBugfixCVEsAStory Canonical fixes 3 Snap vulnerabilities https://ubuntu.com/security/notices/USN-8579-1 https://seclists.org/oss-sec/2026/q3/191 https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt https://www.cve.org/CVERecord?id=CVE-2026-15226 Firefox 153 adds Containers and Vulkan Video https://www.firefox.com/en-US/firefox/153.0/releasenotes/ https://blog.mozilla.org/en/firefox/firefox-containers-preview/ https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153 https://brave.com/blog/containers/ TWIL Speedrun or Linux Lightning Round which do you prefer of those names? AMD's open-source AI and robotics announcements https://www.amd.com/en/corporate/events/advancing-ai.html https://www.amd.com/en/blogs/2026/rocm-ai-the-ai-native-developer-experience-for-building.html https://www.amd.com/en/products/system-on-modules/kria/ai.html https://www.amd.com/en/products/system-on-modules/kria/ai/robotics-developer-platform.html Final MPEG-4 Visual patent expiration https://www.phoronix.com/news/Last-MPEG-4-Patent-Expired https://itsfoss.com/news/mpeg-4-visual-patent-expiry/ https://meta.wikimedia.org/wiki/Have_the_patents_for_MPEG-4_Visual_expired_yet%3F OBS Studio 32.2 Released https://github.com/obsproject/obs-studio/releases/tag/32.2.0 https://9to5linux.com/obs-studio-32-2-released-with-new-filter-to-compose-sdr-into-hdr https://linuxiac.com/obs-studio-32-2-makes-adding-sources-easier/ Raspberry Pi launches a 10-inch Touch Display 2 https://www.raspberrypi.com/news/a-new-10-raspberry-pi-touch-display-2-available-now-at-80/ https://pip-assets.raspberrypi.com/categories/1083-raspberry-pi-touch-display-2 https://www.phoronix.com/news/10-inch-Raspberry-Pi-Touch-2 https://www.theregister.com/2026/07/22/raspberry-pi-goes-large-with-101-inch-touch-display-2/ https://9to5linux.com/raspberry-pi-launches-10-inch-raspberry-pi-touch-display-2-at-80 Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

Hack és Lángos
HnL 442 - 2835 nap

Hack és Lángos

Play Episode Listen Later Jul 23, 2026 73:22


Mai menü: Könyvajánló - Robert Dover: Hacker, Influencer, Faker, Spy: Intelligence Agencies in the Digital Age ne foglakozzunk a CVE-kkel UK and Allies urge critical sectors to improve defences against Russian intelligence targeting   Elérhetőségeink:TelegramTwitterInstagramFacebookMail: info@hackeslangos.show

ScanNetSecurity 最新セキュリティ情報
WordPress 6.9 以降で 2 件の脆弱性の組み合わせで遠隔コード実行の可能性

ScanNetSecurity 最新セキュリティ情報

Play Episode Listen Later Jul 23, 2026 0:19


独立行政法人情報処理推進機構(IPA)は7月22日、WordPressの脆弱性(CVE-2026-60137、CVE-2026-63030:wp2shell)について発表した。影響を受けるシステムは以下の通り。

Cyber Security Today
WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

Cyber Security Today

Play Episode Listen Later Jul 22, 2026 11:13


WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw   This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.   Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.   Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.   EY client tax-data exposure via a third-party platform.   00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off

Cyber Morning Call
1052 - Extorsão via BitLocker usa impressoras para entregar nota de resgate

Cyber Morning Call

Play Episode Listen Later Jul 22, 2026 6:19


Referências do EpisódioA new extortion cocktail: office printers, small ransoms, and BitLockerSolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28307)SolarWinds Serv-U Remote Code Execution Vulnerability (CVE-2026-28311)SolarWinds Serv-U Broken Access Control Vulnerability (CVE-2026-28321)Oracle Critical Patch Update Advisory - July 2026OpenAI admits it was the source of the agent swarm that attacked Hugging FacePublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Cyber Morning Call
1051 - Falha crítica na ServiceNow AI Platform está sob exploração ativa

Cyber Morning Call

Play Episode Listen Later Jul 21, 2026 4:12


Referências do EpisódioCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionCVE-2026-6875 - Sandbox Escape in ServiceNow AI PlatformCookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin RansomwareExploitation in the Wild of wp2shellRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 263 - No Chatbot, No Midnight, No Insider Info, No Simple Patch Tuesday, No Soup for You

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jul 20, 2026 53:43


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April.   Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading.   Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing.   China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push.   UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/

Autonomous IT
Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

Autonomous IT

Play Episode Listen Later Jul 14, 2026 29:06


570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the networkAn RDP bug you can shut down with a single setting, no patch requiredA SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner accessA 9.9 Hyper-V escape that lets one compromised VM take the whole hostA BitLocker bypass (6.1) worth knowing if you manage laptops in the fieldPlus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.

Absolute AppSec
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

Absolute AppSec

Play Episode Listen Later Jul 14, 2026


In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture Management (ASPM) consolidation. Cameron strongly advocates for utilizing ASPM as a distinct, single pane of glass dashboard to deduplicate vulnerabilities and streamline executive reporting by product suite. However, the hosts contrast this ideal against the messy reality of organizations dealing with a "Frankenstein" mix of loosely bootstrapped open-source scanning tools and competing vendor plugins. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. Cameron and Kurt stress the necessity of shifting away from abstract CVSS scores toward custom, runtime-informed risk appetites and impact analysis—prioritizing the hardening of high-risk corporate assets over low-reachability internal flaws. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. Ultimately, the panel laments that AppSec teams are effectively functioning as corporate incident responders because Security Operations Center (SOC) analysts lack product-level insight. The episode concludes with a review of automated agent statistics and a fun look ahead to the future emergence of meta OWASP top-ten risk lists.

Cyber Security Today
ShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishing

Cyber Security Today

Play Episode Listen Later Jul 13, 2026 10:25


ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint   Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected.   Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17.   Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender.   ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint.   Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 10, 2026 6:36


_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 https://support.apple.com/en-us/125615 Google Chrome Update https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Cybersecurity Defenders Podcast
Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 9, 2026 34:26


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.Stories covered:• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlChapters:0:00 Intro & catching up4:31 Google Dialogflow CX "Rogue Agent" flaw11:03 EvilTokens & "ghost phishing"17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 1024:56 HalluSquatting: weaponizing AI hallucinations33:16 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #phishing

@BEERISAC: CPS/ICS Security Podcast Playlist
EP 89: How AI Is Breaking OT Cybersecurity

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Jul 9, 2026 39:22


Podcast: Error Code (LS 27 · TOP 10% what is this?)Episode: EP 89: How AI Is Breaking OT CybersecurityPub date: 2026-07-07Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationAI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerpt, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters. The podcast and artwork embedded on this page are from Robert Vamosi, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 7, 2026 6:38


RCS and DNS: The NAPTR Record https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 released https://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139 https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaign https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Blue Security
Claude Fable, SharePoint RCE, and CISA's KEV list

Blue Security

Play Episode Listen Later Jul 7, 2026 22:08


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience, and a critical SharePoint vulnerability that has caught CISA's attention. They delve into the implications of these topics for security professionals and the importance of staying updated on actively exploited vulnerabilities.----------------------------------------------------YouTube Video Link: ⁠⁠https://youtu.be/3VbR22krL-w----------------------------------------------------Documentation: https://www.bleepingcomputer.com/news/artificial-intelligence/claude-fable-relaunch-disappoints-users-with-nerfed-performance/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659https://www.cisa.gov/known-exploited-vulnerabilities-catalog----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Error Code
EP 89: How AI Is Breaking OT Cybersecurity

Error Code

Play Episode Listen Later Jul 7, 2026 39:22


AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerp, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters.

Cyber Security Today
AI-Run Ransomware, New Oracle Critical Flaw, NetNut busted

Cyber Security Today

Play Episode Listen Later Jul 6, 2026 14:26


AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator   This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key.   It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240.   A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices.   Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day.   00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off

Resilient Cyber
Why Finding Vulnerabilities Was Never the Hard Part

Resilient Cyber

Play Episode Listen Later Jul 5, 2026 36:39


Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.Why this conversation mattersEric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.Key takeawaysAttackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable's findings are non-CVE, a third of your findings can carry two-thirds of your risk.Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.Notable quotes“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.“you're on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.

The Cybersecurity Defenders Podcast
Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 3, 2026 33:53


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.htmlChapters:0:00 Intro & catching up1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)9:18 CISA advisory: billboard & highway sign controllers13:46 Cursor "DuneSlide" prompt-injection sandbox escape20:34 Claude Fable 5 export controls lifted28:17 Data centers, nuclear déjà vu & the AI race33:39 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #promptinjection

AWS Morning Brief
Open Governance for MySQL Plot Twist

AWS Morning Brief

Play Episode Listen Later Jun 29, 2026 6:19


AWS Morning Brief for the week of June 29th, with Corey Quinn. Links:Amazon CloudWatch launches OTel Container Insights for Amazon EKSAmazon GuardDuty AI-powered investigations accelerate threat response (Preview)Amazon Route 53 Global Resolver now supports sharing DNS Views between AWS AccountsAutomate AWS Invoice Retrieval with New Programmatic APIsRun isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMsUpgrading Lambda function runtimes at scale with AWS Transform customHuntington Bank: Redacting sensitive data from 400M+ documents with AWSOpen Governance for MySQL: A Step Forward for the CommunityHow AWS and a local community organization built a developer engagement model that worksModernizing border control with digital arrival cards on AWS CloudPrevent data exfiltration: AWS egress controls for cloud workloadsRestrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPsA new way to keep your AWS Certification current CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Microsoft Mechanics Podcast
Secure containers from code to runtime | Microsoft Defender

Microsoft Mechanics Podcast

Play Episode Listen Later Jun 29, 2026 9:34


Secure containerized apps end-to-end using Microsoft Defender for Cloud. Correlate cross-cloud attacks into a single incident, catch runtime threats that image scanning misses, and block vulnerable images before they reach production. Investigate container hijacking, isolate compromised pods with Security Copilot-guided remediation, and close the loop from SOC to dev by pushing CVE fixes to GitHub and syncing resolution back to Defender. Matt McSpirit, Microsoft Azure expert, shares how to detect, investigate, and remediate container threats in one connected workflow. ► QUICK LINKS: 00:00 - Secure containers in Microsoft Defender 01:02 - Cross-cloud incident 03:07- Runtime detection 04:10 - Investigate and build context 04:49 - Security Copilot incident report & containment 06:03 - Prevention 07:34 - Recommendations and take action 09:04 - Wrap up ► Link References Get started at https://aka.ms/DefenderCloudSecurity ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics

CISSP Cyber Training Podcast - CISSP Training Program
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 29, 2026 43:08 Transcription Available


Send us Fan MailA vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That's the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it's not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what's inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Resilient Cyber
Rain Versus Flood, Making Sense of the 2026 CVE Surge

Resilient Cyber

Play Episode Listen Later Jun 27, 2026 24:59


CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat.DescriptionJerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST mid-year vulnerability forecast that just put 2026 on pace for nearly 70,000 CVEs. He joins Resilient Cyber to separate the scary headline number from what actually matters for defenders. We get into why GitHub now publishes one in five CVEs, the rain versus flood distinction that explains why exploitable risk is flat even as raw volume explodes, what the NVD collapse means now that the CNAs have to step up, and how teams should really be triaging with EPSS and the CISA KEV catalog.Key takeawaysCVEs are on pace for nearly 70,000 in 2026, up more than 40 percent year over year. Much of the surge traces back to a single source, with GitHub now publishing one in five CVEs after scaling up its advisory team.The three drivers behind the surge are very different forces. AI-assisted discovery that nobody can definitively flag, a 449 percent jump in GitHub security advisories, and VulnCheck acting as a CNA of last resort all get lumped into one scary number.Rain versus flood is the frame that matters. Raw CVE volume is climbing fast, but once you filter for CISA KEV and EPSS the actionable, exploitable risk has stayed essentially flat.Most of the new findings are old human debt, not a new AI threat. The OWASP Top 10 has barely changed in 25 years, and tooling can now find those same mistakes at scale across mostly open source code.The AI moment is useful cover to finally patch. Jerry argues teams are using the AI hype cycle to win the time and resources to fix long-known issues, which is a genuinely good outcome.The NVD was the dam that fell. It was never fair to expect one small organization to enrich every CVE, so responsibility now shifts back to the CNAs and the large vendors that leaned on it for years.Treat CVE data as a product you pay for. Jerry's advice is to use procurement leverage, since demanding better CVE records before you renew a contract is one of the few real forcing functions available.What gets exploited has not really changed. VPN concentrators and the same old vulnerability classes still dominate, and the NSA's annual top 10 exploited bugs are reliably old, with no sign yet of AI driving widespread attacks.Asset inventory is still the real bottleneck. You cannot triage what you cannot see, and most organizations still cannot say with confidence whether they even run the software a given pile of CVEs affects.AI-accelerated exploitation is coming, but not as mass exploits. The bigger shift is a tireless attacker that loops on your network for days until it finds a way in, which is exactly what agents are best at.GuestJerry Gamblin, creator of CVE.ICU and founder of RogoLabs. Resources mentionedFIRST 2026 mid-year vulnerability forecastSubscribewww.resilientcyber.io

The CyberWire
Klue me in on the breach.

The CyberWire

Play Episode Listen Later Jun 24, 2026 28:16


LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here. Selected Reading Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch) Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch) Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs)  DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  (Zafran)  23 ClawHub Plugins Squat Official Org Scopes (Manifold Security)  Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr)  Indian auto giant Bajaj Auto hit by ransomware incident (The Record)  U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times) Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek) US adds sanctions against accused Cambodian scammers Prince Group (Reuters) Ushering in the Next Frontier of Quantum Innovation (The White House)  Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED)  Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 24, 2026 6:48


CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Social Chemist
Into the Manosphere: The Patriarchy, Sexism, and Gender-Based Terrorism w/ Dr. Cynthia Miller-Ibriss

The Social Chemist

Play Episode Listen Later Jun 24, 2026 52:51


Send us Fan MailOn today's episode, I am joined by Dr. Cynthia Miller-Ibriss, a Professor in the School of Public Affairs and in the School of Education at the American University in Washington, DC, where she is also the founding director and chief vision officer in the Polarization and Extremism Research and Innovation Lab (PERIL). She is the author of "Man-Up: The New Misogyny & the Rise of Violent Extremism," a book that covers the five strategies misogyny groups use to intimidate and oppress women and the LGBTQAI+ community, and strategies we can use to mitigate male-motivated violence.  InstagramThe Social Chemist (@socialchemistig) • Instagram photos and videosThreadThe Social Chemist (@socialchemistig) on ThreadsDr. Cynthia Miller-Ibriss's books Books | CynthiaMillerIdrissDr. Cynthia Miller-Ibriss's Social Media / PERIL Dr. Cynthia Miller-Idriss (@milleridriss) / XCynthia Miller-Idriss - PERIL ResearchRecommended Social Chemist EpisodesThe Black Pill Radicalization Process of the Incel Community w/ Robert Green

SBS Russian - SBS на русском языке
As women linked to ISIS return, how does Countering Violent Extremism (CVE) work in Australia? - SBS Examines. Как Австралия противодействует насильственному экстремизму?

SBS Russian - SBS на русском языке

Play Episode Listen Later Jun 24, 2026 11:38


The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - Возвращение из Сирии 32 женщин и детей, связанных с группировкой «Исламское государство», вызвало опасения по поводу общественной безопасности и обсуждение обязательных мероприятий по противодействию насильственному экстремизму (CVE) для лиц из групп риска.Больше историй, интервью и новостей от SBS Russian доступно здесь.Слушайте программу на русском языке SBS по понедельникам, четвергам и субботам в 12 часов дня.Читайте нас в Facebook и подпишитесь на наши подкасты по этой ссылке.Смотрите прямые трансляции Чемпионата мира по футболу FIFA 2026™ бесплатно на SBS On Demand.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 22, 2026 6:06


eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090 NGINX ngx_http_v3_module vulnerability CVE-2026-42530 https://my.f5.com/manage/s/article/K000161616 Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Resilient Cyber
AI Industrialized the Vuln Lifecycle and Broke the System of Record

Resilient Cyber

Play Episode Listen Later Jun 15, 2026 40:43


VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 12, 2026 6:39


More Bitlocker Issues: GreatXML https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Oracle Security Alert Advisory - CVE-2026-35273 https://www.oracle.com/security-alerts/alert-cve-2026-35273.html https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ How Deceptive Installers Are Targeting macOS Users https://www.huntress.com/blog/deceptive-installers-macos-infostealers My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

7 Minute Security
7MS #726: Baby's First Hermes

7 Minute Security

Play Episode Listen Later Jun 12, 2026 22:03


Hello friends! I've been on a bit of an AI agent journey lately, and today I'm sharing my experience ditching OpenClaw and going all-in on Hermes — a self-hosted AI agent built by Nous Research. A Network Chuck video sold me on it, I wiped my Mac Mini (again), and baby's first Hermes adventure began! Here's what we get into today: Why I left OpenClaw — After getting the Mac Mini set up, OpenClaw left me feeling pretty meh: burning through API requests, random mid-conversation shutdowns, and a marketplace where the top listings were flagged as "potentially malicious." Hard pass. Network Chuck's five reasons Hermes rocks — His video summarized why Hermes stands out: (1) Nous Research has serious open source model cred predating OpenClaw, (2) more flexible persistent memory via markdown files + optional Honcho integration for building a profile of you over time, (3) a mission around humanistic and democratic AI, (4) a self-improvement loop where it writes its own skills after figuring things out, and (5) it just doesn't break — it feels like a product, not a project. The install — I used Claude to build a Mac Mini install guide from the Network Chuck transcript, and had Hermes up and running in about 15 minutes (one small Ollama hiccup aside). The install wizard lets you choose cloud models like Claude or ChatGPT, or go fully local with something like Gemma — I'm planning a hybrid setup with two Telegram bots. First real-world use: sitting in a truck running errands — With Hermes running on the Mac Mini and connected via Telegram, I asked it what it could do. It suggested Uptime Kuma for LAN monitoring — weirdly well-timed since I'd just been thinking about flaky IoT devices. I said "go install it," and it did — narrating its own troubleshooting out loud the whole time like a little robot intern. Remote access and Home Assistant — Had it install Home Assistant for smarthome control too, with plans to wire up TwinGate for remote access (it had a TailScale skill ready to fire in about two seconds, but I'm trying to keep VPN services consolidated). Daily digest via email — Hooked Hermes into a dedicated Gmail account and set up a 6 a.m. cron job that sends me a personalized morning digest: weather for my watched locations, recent breach/CVE news from select sites, and a summary of my favorite pentesting-focused Mastodon accounts. Needs tuning, but the first digest landed this morning and it's really good! The privacy angle — The real long-term win I see here is a hybrid model: feed raw, unsanitized pentest data to a local private model, let it analyze and sanitize, then hand off the clean version to a cloud model for deeper insight. Best of both worlds without the data exposure anxiety. Check out the Network Chuck video that started it all, and as always, if you're doing cool AI + security stuff, I'd love to hear about it. Find our pentesting services and training at 7MinSec.com, pentesting tips and scripts at 7MinSec.wiki, and if you want to support the show, head over to 7MinSec.club.

SBS Persian - اس بی اس فارسی
As women linked to ISIS return, how does Countering Violent Extremism (CVE) work in Australia? - با بازگشت زنان مرتبط با داعش، مبارزه با افراط گرایی خشونت آمیز (CVE) در استرالیا چگونه کا

SBS Persian - اس بی اس فارسی

Play Episode Listen Later Jun 12, 2026 8:24


The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - بازگشت ۳۲ زن و کودک از سوریه که با گروه خودخوانده داعش مرتبط هستند، باعث ایجاد نگرانی در مورد امنیت جامعه و بحث در مورد فعالیت های اجباری مبارزه با افراط گرایی خشونت آمیز (CVE) برای افراد در معرض خطر شده است.

women australia syria islamic state cve countering violent extremism cve
SBS Korean - SBS 한국어 프로그램
As women linked to ISIS return, how does Countering Violent Extremism (CVE) work in Australia? - SBS Examines: 호주의 '폭력적 극단주의 예방(CVE)' 프로그램은 어떻게 작동할까요?

SBS Korean - SBS 한국어 프로그램

Play Episode Listen Later Jun 12, 2026 10:09


The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - 자칭 ‘이슬람국가(IS)'와 연관된 시리아 출신 여성과 어린이 32명이 귀국함에 따라 지역사회 안전에 대한 우려가 제기되고 있습니다. 위험군 대상자에 대한 ‘폭력적 극단주의 예방(CVE)' 의무 프로그램 시행을 둘러싼 논의가 진행되고 있습니다.

women australia syria islamic state cve countering violent extremism cve
The CyberWire
The court calls Google's bluff.

The CyberWire

Play Episode Listen Later Jun 11, 2026 31:20


Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain attacks evolve. And a massive data breach triggers a record fine in South Korea. Our guest is Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done. AI analyzes the FIFA World cup, one cliché at a time.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done across humans, automation, and AI agents. You can read more from Ping Identity here. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers (The Decoder) White House Reins In AI-Testing Unit as National-Security Concerns Grow (Wall Street Journal) Anthropic Releases ‘Safe' Version of Its Mythos A.I. Technology (The New York Times) PRC-linked influence operations are targeting AI debates in the US (OpenAI) Technical Analysis of MLTBackdoor (ThreatLabz) CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry (Rapid7) Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels (Socket) Veeam Patches Critical RCE Vulnerability in Backup & Replication published: yesterday (Beyond Machines) ‘Amazon.com of South Korea' Is Fined a Record $409 Million (The New York Times) The 2026 big soccer tournament, in clichés. (Sinch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Today
AI Worms, Hacks, and Insurance Shifts

Cyber Security Today

Play Episode Listen Later Jun 10, 2026 9:39


Instagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, with only MFA-protected accounts resisting. Step Security details a new Miasma-derived worm wave called Hades that targets config files for 14 AI coding tools, can inject instructions to hijack assistants, lies to AI security tools, and includes a "dead man switch" wipe if stolen GitHub tokens are revoked; Microsoft also removed some GitHub repos after 73 open-source projects were compromised to inject an info stealer. University of Toronto and Vector Institute researchers demonstrated an AI worm using a free local model that spread across a simulated network via known flaws and misconfigurations. Google issued an emergency Chrome patch for actively exploited CVE-2026-11645 in V8, and insurers are tightening claims scrutiny and increasingly excluding AI-related liabilities. 00:00 Instagram AI Hack Fallout 01:36 AI Worm Hades Evolves 02:55 Microsoft Repo Compromise 03:54 Lab Built AI Worm Demo 05:27 Emergency Chrome Zero Day 07:07 Cyber Insurance Tightens Up 08:02 AI Liability Coverage Shrinks 09:16 Wrap Up and Sign Off

The CyberWire
Meta's recovery plan needed recovery.

The CyberWire

Play Episode Listen Later Jun 8, 2026 28:39


Meta exposes 20,000 Instagram accounts through a support tool bug. CISA warns of active attacks on SolarWinds Serv-U. WordPress sites face takeover through a widely used plugin. A new Gafgyt variant broadens its reach. Pink extortionists steal cloud data with vishing and legitimate tools. Plus, allegations against IBM and AT&T, a dark web drug dealer gets 26 years, and the Monday business brief. Tim Starks from CyberScoop discusses the ongoing debate over staffing and budget cuts at CISA. NATO lets Ukraine play the bad guy.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Tim Starks from CyberScoop, who is discussing the ongoing debate over staffing and budget cuts at CISA, the political battles surrounding the agency's future, and what the Trump administration's plans could mean for U.S. cybersecurity efforts. Selected Reading Meta AI Bug Exposes Over 20,000 Instagram Accounts (Infosecurity Magazine) NSO Group back in Meta's crosshairs after alleged WhatsApp targeting (The Register) CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) (Help Net Security) Everest Forms Vulnerability Exploited to Hack WordPress Sites (SecurityWeek) C0XMO botnet spreads via DD-WRT router flaw, kills rival malware (Bleeping Computer) New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams (Hackread) Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks (GovInfo Security)  California man sentenced to over 26 years for dark web drug trafficking (SC Media) AI observability platform Coralogix raises $200 million in a Series F round. (N2K Pro Business Briefing)   Nato narrowly beats Russia-style enemy in cyber attack simulation (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.   Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 1st, 2026: Bitskrieg; Gogs Unpatched Vuln; Oracle Critical Updates; PAN-OS Exploited;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 1, 2026 4:58


Announcing Bitskrieg https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html Vulnerability in Gogs https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/ Oracle Critical Security Patch Update Advisory - May 2026 https://www.oracle.com/security-alerts/cspumay2026.html GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257 https://security.paloaltonetworks.com/CVE-2026-0257

Python Bytes
#482 Mr. Beast's episode

Python Bytes

Play Episode Listen Later Jun 1, 2026 24:01 Transcription Available


Topics covered in this episode: CVE-2026-48710: A Maintainer's Perspective daily-stars-explorer Markdown to pdf with pandoc and typst postman2pytest Extras Joke Watch on YouTube About the show Brian #1: CVE-2026-48710: A Maintainer's Perspective Marcelo Trylesinski suggested by Lee Luocks Short version: users of Starlette: upgrade to Starlette 1.0.1 security professionals: we can't treat open source projects like corporations This top link is a Starlette security advisory with the title Missing Host header validation poisons request.url.path, bypassing path-based security checks The CVE apparently caused some negative press targeting starlette. However, “the vulnerability came from the application pattern and the deployment, never from something Starlette intended.” A quote from an OSTIF article: “This bug is a classic “responsibility gap” where if this maintainer didn't patch, thousands of exposed projects would have to individually secure their projects. In doing this work, they've voluntarily taken on the responsibility to protect the ecosystem from long-term systemic harm. As with all open source projects, they owed us nothing and could have left this to be everyone else's problem and took the extraordinary steps of helping the ecosystem.” Both X40 D-Sec and Ars Technica expected immediate fixes and responses from Starlette. That's not good. We can do better. Michael #2: daily-stars-explorer Explore the full history of any GitHub repository.

Security Now (MP3)
SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

Security Now (MP3)

Play Episode Listen Later May 27, 2026 164:01 Transcription Available


Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its source code exfiltrated Russia is using very old Western software Why to get a no-charge AI chatbot account New Sci-Fi on Netflix What we learn from Mozilla's use of Mythos Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com doppel.com cyberhoot.com/securitynow trustedtech.team/securitynow365 XBOW.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 27, 2026 6:14


Possible ACR Stealer From Page Impersonating Claude https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018 Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Multiple Vulnerabilities in Angular Language Service VS Code Extension https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 22, 2026 6:35


Selective HTTP Proxying in Linux https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002 Megalodon: Mass GitHub Repo Backdooring via CI Workflows https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/ MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 https://x.com/fabian_bader/status/2057198207243804881 Cisco Secure Workload Unauthorized API Access Vulnerability CVE-2026-20223 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 21, 2026 5:39


GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001