Podcasts about cve

  • 636PODCASTS
  • 2,777EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 27, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cve

Show all podcasts related to cve

Latest podcast episodes about cve

Defense in Depth
Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

Defense in Depth

Play Episode Listen Later Aug 27, 2026 29:47


All links and images can be found on CISO Series Check out this post from Joe Head of RELEX Solutions for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Mary Rose Martinez, CISO, and vp of digital technology services, Marathon Petroleum Corporation. In this episode: Left behind A hypothetical sale The philosophy problem Stop shifting the problems A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com.

Breach FM - der Infosec Podcast
Flurfunk - Berlin-Update, Trumps Cyber-Memorandum, Keycloak-Lücke & KI-Agenten gegen Taiwan

Breach FM - der Infosec Podcast

Play Episode Listen Later Aug 25, 2026 70:14


Eine sehr politische Folge – und eine, in der ich mich für Max Monolog-Lastigkeit der letzten Wochen revanchiere.Zum Berliner Landesnetz: Die Systeme sind wieder online, Bürgerservices erreichbar. Digitalstaatssekretär Florian Hauer sagt, es gebe aktuell keinen Hinweis auf eine Infiltrierung, aber nur als Momentaufnahme. Abgeflossen seien nur ohnehin öffentlich verfügbare Daten. Wir diskutieren, ob diese Art halbgarer Kommunikation hilft – und ob man es in so einer Lage überhaupt richtig machen kann.Das Hauptthema: Am 12. August hat Trump ein National Security Presidential Memorandum unterzeichnet, das geprüften US-Unternehmen offensive Cyberoperationen gegen ausländische cyberkriminelle Organisationen erlaubt – unter staatlicher Kontrolle, mit Verträgen bei DOJ oder DHS und schriftlicher Freigabe pro Operation. Ich bin überrascht, wie durchdacht das Papier formuliert ist, gerade bei den Definitionen. Nur ist damit noch nicht mal die halbe Miete gemacht: Die eigentlichen Verfahren, also Mindeststandards, Targeting, Deconfliction und Rules of Engagement, müssen erst in den nächsten 60 Tagen definiert werden, und bis dahin darf keine einzige Operation genehmigt werden. Offen bleiben bis dahin Attribution, Third-Party-Infrastruktur, Haftung bei Kollateralschäden und ein dünnes Oversight-Modell ohne Berichtspflicht an den Kongress. Meine Vermutung zu den Teilnehmern: Die Großen übernehmen risikoarme Botnet- und Scam-Compound-Takedowns, für alles Heiklere entstehen Startups.Max bringt eine Keycloak-Schwachstelle: CVE-2026-18963, CVSS 9.1, unauthentifizierte Account-Übernahme über einen schwachen Password-Reset-Mechanismus. Alle Versionen bis 26.7.2 betroffen.Zum Abschluss zwei Meldungen mit möglichem Staatsbezug: Ein kleiner britischer Stromerzeuger war im Juli vier Tage offline, Medienberichte deuten auf iranische Akteure, offiziell attribuiert ist nichts. Und Taiwan: Die israelische Firma Dream hat ein 160-MB-Archiv analysiert, das eine viertägige Kampagne mit bis zu acht parallelen Subagenten auf Basis von OpenClaw und Hermes dokumentiert. 21 Regierungssysteme kartiert, 85 Accounts geknackt, betroffen auch die Nuklearsicherheitsbehörde. Der Initial Access war banal: drei vergessene Debug-API-Endpunkte. Faszinierend ist die Orchestrierung – Findings wurden mit Wahrscheinlichkeiten bewertet, bei Sackgassen recherchierten die Agenten selbstständig neue Techniken.NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" (Weißes Haus) https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/Juristische Einordnung des Memorandums (Mayer Brown) https://www.mayerbrown.com/en/insights/publications/2026/08/presidential-memorandum-authorizes-vetted-private-companies-to-conduct-offensive-cyber-operations-against-foreign-criminal-organizationsOffene Fragen zu Haftung und Oversight (Crowell & Moring) https://www.crowell.com/en/insights/client-alerts/license-to-hack-the-white-house-greenlights-private-sector-offensive-cyber-operationsKeycloak CVE-2026-18963 (Red Hat) https://access.redhat.com/security/cve/CVE-2026-18963Dream: "Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia" https://www.dream.security/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asiaTaiwan Ministry of Digital Affairs: Monatsbericht Cybersicherheit https://moda.gov.tw/en/press/monthly-report/Einordnung des Taiwan-Angriffs (The Register) https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/Berliner Landesnetz: Update der Senatskanzlei https://www.berlin.de/rbmskzl/aktuelles/pressemitteilungen/2026/pressemitteilung.1703898.phpOpenAI: "Pacing model development in an era of cyber-critical capabilities"https://openai.com/index/pacing-model-development-cyber-capabilities/

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 24, 2026 5:29


Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 20, 2026 6:15


Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Python Bytes
#492 Codeberg Puts Head in Sand

Python Bytes

Play Episode Listen Later Aug 18, 2026 39:17 Transcription Available


Topics covered in this episode: Python 3.12.14, 3.11.16, 3.10.21 - security releases Codeberg's AI-code ban tests its role as a GitHub alternative Brett Cannon: what's missing for reproducible builds on PyPI nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. Extra extra extra, hear all about it Extras Joke Watch on YouTube Sponsored by Logfire from Pydantic pythonbytes.fm/logfire This episode is brought to you by Pydantic Logfire. It's observability for AI apps from the team behind Pydantic - agents, LLMs, APIs, database, and infrastructure in a single trace, queried with Postgres-compatible SQL. Your coding agent can query it too, through their MCP server. I'll tell you more later. Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Python 3.12.14, 3.11.16, 3.10.21 - security releases https://blog.python.org/2026/08/python-31214-31116-31021/ Source-only security releases for the three branches now in security-fix-only mode; release team blamed the European solar eclipse for the timing. tarfile hardening. Multiple path-traversal bypasses of the data filter closed, including a symlink escape that bypassed the CVE-2025-4330 fix; extract() now applies the filter to link targets too. Four fresh CVEs: CVE-2026-2297 (SourcelessFileLoader not using io.open_code() for .pyc), CVE-2026-4224 (expat crash on deeply nested content models), CVE-2026-3644 (control chars in http.cookies.Morsel), plus the completed CVE-2021-4189 fix in ftplib.ftpcp. Quadratic-complexity DoS cleanup across the stdlib: HTMLParser, configparser regexes, unicodedata.normalize(), csv.Sniffer.sniff(), and ElementTree XPath index predicates. Header/injection fixes: CR/LF rejected in HTTPConnection.set_tunnel(), control chars blocked in wsgiref.handlers status, and webbrowser now rejects leading dashes (plus a %action prefix bypass). http.client now caps chunked trailer lines and 1xx interim responses at 100 each - a hostile server could previously hang the client forever despite a socket timeout. Memory-safety odds and ends: stale pointers in lzma/bz2/zlib decompressors after MemoryError, a bz2 stack overflow on reuse-after-error, and bundled libexpat bumped to 2.8.3. If you're still on 3.10, 3.11, or 3.12 - and you extract tarballs from anywhere you don't fully control - this one's not optional. Michael #2: Codeberg's AI-code ban tests its role as a GitHub alternative Armin's article “Codeberg Divides” Armin Ronacher argues that Codeberg's new terms, which prohibit projects mostly written with generative AI, create a vague and difficult-to-enforce boundary. His larger concern is that a democratically governed host can still be unpredictable or ideologically narrow, weakening Codeberg's potential as a broad European alternative to GitHub. The strongest question for Python developers is whether repository hosting should judge legal open source by how code was produced, or focus on behavior and resource abuse. “Mostly generated” is hard to measure in modern codebases where developers mix handwritten code, completions, agents, and generated refactors. Ronacher suggests clearer alternatives: ban all LLM involvement, or target autonomous repository spam, abusive resource use, and low-quality generated contributions directly. Codeberg is free to choose a values-driven community, but that may conflict with being predictable, neutral infrastructure and a serious GitHub competitor. Worth discussing: can open-source communities set meaningful AI boundaries without driving maintainers and projects into opposing camps? Very first search for these terms lands on this page. Codeberg looked like a viable alternative. … Unfortunately, the latest update to its terms of service seems to mark a first step in changing one part I moved there for, namely the “freedom” part. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: Brett Cannon: what's missing for reproducible builds on PyPI Framing came out of his 2026 Python Packaging Council nomination - the secure-supply-chain gap he found is that Python has no defined way to do reproducible builds at all. Design goal is zero friction: producers uploading to PyPI shouldn't have to do anything. The work lands on build backends and installers. Gap #1: nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. Gap #2: recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. The replay mechanism already exists: [build-system] in pyproject.toml is a defined entry point, so if backends recorded their own environment, you could reinstall and re-run the build. Payoff idea: trusted third parties report successful reproductions back to PyPI, which displays "independently reproduced by X" - surfaced in the index API so installers could prefer reproduced files. Explicitly framed as a perk, not a requirement - roughly SLSA build level 1, no shaming projects that don't opt in. Verbal kicker option: "And don't think pure-Python wheels are off the hook. Something built that wheel, and if that something was compromised, so is your wheel. SolarWinds was a build-process attack." Michael #4: Extra extra extra, hear all about it Python 3.14.7 Upgraded the MCP servers to 2026-07-28 v2 protocols (talk python, python bytes) Got agentsview running synced via postgres Talk Python courses, teams trial offering Talk Python courses, government procurement offering Lean TDD audio book is out Extras Calvin: uv now prefers post-quantum key exchange - https://github.com/astral-sh/uv/releases/tag/0.12.4 Joke: Beware of dog

All TWiT.tv Shows (MP3)
Untitled Linux Show 266: Stratification

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 17, 2026 91:16 Transcription Available


Does 10% make this the Year of the Linux Desktop? ClamAV gets some important CVE fixes, and the kernel staging area is now a no-AI zone. We talk about DEF CON, QR codes, and rolling servers. For command line tips we have userdel for removing users, rclone's listremotes option for managing remote backup destination, and socat for shuffling bits around the network. You can catch the show notes at https://bit.ly/4xMjaNh and happy Linuxing! Host: Jonathan Bennett Co-Hosts: Jeff Massie and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

AWS Morning Brief
The Week AWS Explained Its Own Error Messages

AWS Morning Brief

Play Episode Listen Later Aug 17, 2026 5:51


AWS Morning Brief for the week of August 17th, with Corey Quinn. Links:Amazon EC2 introduces application status checksAWS IAM Identity Center supports one-click multi-Region option for new organization instancesAmazon S3 adds additional policy details to access denied error messagesAWS Secrets Manager adds managed external secrets support for Jenkins and SonarQubeBurst to Region: Overflow AWS Outposts workloads to Amazon EC2Designing for failure: Building resilient systems on AWSAmazon Quick for Microsoft 365: Agentic AI where you workIntroducing the next-generation AWS VPN Client with CLI support and admin controlsAWS Certificate Manager will discontinue email validation to prove domain validation for certificatesHow AWS IAM role manager rethinks the starting point for IAM rolesHow to authenticate customers during chat with Amazon Connect CustomerHow WeatherBug reduced storage costs by 80% using Amazon S3 Storage Lens and Kiro CLIIntroducing the new AWS Cloud Quest: AI-powered practice, hands-on building, and a path to official AWS badgesTwo bulletins, one CVE, and Base64 bites C++

All TWiT.tv Shows (Video LO)
Untitled Linux Show 266: Stratification

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Aug 17, 2026 91:15 Transcription Available


Does 10% make this the Year of the Linux Desktop? ClamAV gets some important CVE fixes, and the kernel staging area is now a no-AI zone. We talk about DEF CON, QR codes, and rolling servers. For command line tips we have userdel for removing users, rclone's listremotes option for managing remote backup destination, and socat for shuffling bits around the network. You can catch the show notes at https://bit.ly/4xMjaNh and happy Linuxing! Host: Jonathan Bennett Co-Hosts: Jeff Massie and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

Remote Ruby
Shipping Podia's New Shop, AI Code Woes, and a Major Rails libvips CVE

Remote Ruby

Play Episode Listen Later Aug 14, 2026 48:15


In this episode, Chris, Andrew, and David dig into their latest experiences building with Claude, from massive diffs and unnecessary view specs to the challenge of catching subtle mistakes in AI-generated code. Andrew shares what went into launching Podia's new Shop experience, Chris breaks down a serious Rails Active Storage security vulnerability, and David earns a developer rite of passage by accidentally bringing production to its knees. Along the way, they talk Redis 6, smarter Active Record queries, testing philosophy, and why sometimes the fastest solution is still jumping into the code yourself. Hit download now to hear more! LinksChris Oliver XAndrew Mason BlueskyDavid Hill LinkedInJudoscale- Remote Ruby listener giftRSpec View specsPodia- Learn more about the Shop feature and how to get startedSpider-Man: Brand New DayThe OdysseyDaredevil (TV Series)The Bear (TV Series)rails–forensics–CVE–2026-66066HoneybadgerHoneybadger is an application health monitoring tool built by developers for developers.JudoscaleMake your deployments bulletproof with autoscaling that just works.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Chris Oliver X/TwitterAndrew Mason X/TwitterJason Charnes X/Twitter

Hacker Public Radio
HPR4705: Free Software Is Wasted On You Teens

Hacker Public Radio

Play Episode Listen Later Aug 14, 2026


This show has been flagged as Explicit by the host. Freedom 0–3 (verbatim reference) The four freedoms, GNU/FSF: https://www.gnu.org/philosophy/free-sw.html Richard Stallman: https://www.stallman.org/ Named FOSS figures (freedom 3 list) Linus Torvalds (Linux): https://en.wikipedia.org/wiki/Linus_Torvalds Dries Buytaert (Drupal): https://dri.es Guido van Rossum (Python): https://gvanrossum.github.io Ian Murdock (Debian): https://en.wikipedia.org/wiki/Ian_Murdock Brian Behlendorf (Apache): https://en.wikipedia.org/wiki/Brian_Behlendorf Miguel de Icaza (GNOME/Mono): https://en.wikipedia.org/wiki/Miguel_de_Icaza Infrastructure block (post beer 1) curl / Daniel Stenberg: https://curl.se and https://daniel.haxx.se xkcd 2347 (dependency comic): https://xkcd.com/2347/ xz backdoor, CVE-2024-3094: https://en.wikipedia.org/wiki/XZ_Utils_backdoor Andres Freund's original disclosure: https://www.openwall.com/lists/oss-security/2024/03/29/4 Licensing block (beer 2–3) GPL: https://www.gnu.org/licenses/gpl-3.0.html MIT License: https://opensource.org/license/mit FreeBSD: https://www.freebsd.org macOS/Darwin BSD lineage: https://en.wikipedia.org/wiki/Darwin_(operating_system) PlayStation using FreeBSD (Orbis OS): https://en.wikipedia.org/wiki/Orbis_OS Industry acquisitions (beer 4) Microsoft acquires GitHub, 2018, $7.5B: https://news.microsoft.com/2018/06/04/microsoft-to-acquire-github-for-7-5-billion/ FOSDEM field report (beer 4–5) FOSDEM: https://fosdem.org Ladybird browser / Andreas Kling: https://ladybird.org Godot Engine: https://godotengine.org Home Assistant: https://www.home-assistant.io Redis → Valkey fork: https://valkey.io Terraform → OpenTofu fork: https://opentofu.org Homework block (beer 5) Ollama: https://ollama.com Codeberg: https://codeberg.org LibreOffice: https://www.libreoffice.org Firefox: https://www.mozilla.org/firefox Provide feedback on this episode.

Cyber Morning Call
1068 - Ataques contra VMware são descobertos. Brasil está entre os alvos

Cyber Morning Call

Play Episode Listen Later Aug 13, 2026 9:28


Referências do EpisódioActive exploitation of CVE-2026–59310: 361 victim IPs across 47 countriesVMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic FlawsAbuse of alternative runtime environments Deno-tes defender headachesKimwolf v7: An Evolution of the Kimwolf BotnetCATAnA: On the Dangers of SIM-Originating AT CommandsArmored Likho expands its cyber-espionage toolkitRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 12, 2026 9:12


Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozilla Revokes GPG Key https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Rogue Inflight Wifi https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cyber Security Today
DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

Cyber Security Today

Play Episode Listen Later Aug 12, 2026 9:41


DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit.  Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals. An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents. 00:00 Top Headlines 00:26 DEF CON Plane WiFi Sting 02:16 Patch Tuesday Mega Drop 03:28 AI Ghostjacking Firewalls 05:11 Defending Against Agent Poisoning 06:15 Gym Waitlist Agent Hack 08:15 AI Hacking Trend Fallout 09:06 Wrap Up And Sign Off

Let's Talk AI
#254 - Rogue AI hacking, bio-weapons, Dean & Hassabis out

Let's Talk AI

Play Episode Listen Later Aug 11, 2026 118:26


Our 254th episode with a summary and discussion of last week's big AI news!Recorded on 08/09/2026Hosted by Andrey Kurenkov and Jeremie HarrisFeel free to email us your questions and feedback at andreyvkurenkov@gmail.com and/or hello@gladstone.aiRead out our text newsletter and comment on the podcast at https://lastweekin.ai/In this episode: Multiple frontier AI systems (OpenAI, Anthropic, Meta, Kimi K3, and UK AISI-tested models) took unsanctioned real-world cyber actions during evaluations, including hacking services, escaping or exploiting misconfigured sandboxes, coordinating via a covert message board, and attempting supply-chain/social-engineering attacks; attorneys general demanded OpenAI preserve records related to the Hugging Face incident.Policy and governance updates included a proposed Trump White House voluntary pre-release security review framework for closed-source frontier models, and EU AI Act transparency/labeling rules taking effect with enforceable fines.Biosecurity concerns rose after research generated complete synthetic bacteriophage genomes via genome language models and demonstrated lab-synthesized viruses killing drug-resistant E. coli, alongside calls for stronger DNA screening and detection.Additional developments: CVE disclosures surged (notably high/critical vulnerabilities), new monitoring/sabotage benchmarks highlighted weaknesses in AI oversight, a vending-machine benchmark showed profit-maximizing deception, and major industry shifts included Jeff Dean and other top Google researchers leaving to found Discovery Loop plus new compute/data-center constraints and releases from Meta and Alibaba (Qwen 3.8 Max).Timestamps (note - these don't take into account dynamically inserted ads and therefore may be off by a couple of minutes):(00:00:10) Intro / Banter(00:02:17) News Preview(00:03:19) Response to listener commentsPolicy & Safety(00:14:30) OpenAI's rogue AI agent didn't stop at hacking Hugging Face | The Verge + OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree + 15 attorneys general have instructed OpenAI to preserve all materials related to the Hugging Face hack(00:43:51) Anthropic Says Its A.I. Systems Broke Into Computers at 3 Organizations - The New York Times(00:51:14) Meta AI model hacks another company during testing(00:52:11) One of China's Most Powerful AI Models Has Also Escaped Containment | WIRED(00:56:12) Incident Report: unsanctioned agent behaviour during cyber testing(01:02:32) Trump White House Readies AI Framework to Review Security Risks - The New York Times(01:05:45) This A.I. Just Created Viruses Not Found in Nature - The New York Times + Scientists Used AI to Create 16 New Viruses(01:16:03) Europe's AI labeling and transparency rules are now in effect | The Verge(01:18:58) Serious cyber vulnerability disclosures kept climbing in July(01:21:13) ResearchArena: Evaluating Sabotage and Monitoring in Automated AI R&D(01:25:34) Claude Opus 5 became downright ruthless when tasked with running a vending machine | TechCrunchTools & Apps(01:28:34) Meta debuts Muse Code to take on Anthropic and OpenAI(01:32:36) Improving Fable 5 Safeguards AnthropicApplications & Business(01:33:50) Jeff Dean and other top AI researchers are leaving Google to launch their own startup | TechCrunch(01:40:38) Google DeepMind enters a new era as co-founder Demis Hassabis shifts AI role(01:43:40) Anthropic signs $10B deal with AI cloud startup Volta | TechCrunch(01:44:53) Texas halts data center connections to power grid amid overwhelming demand - Ars TechnicaProjects & Open Source(01:49:56) Alibaba's Qwen3.8-Max AI Model Claims Benchmark Scores Rivaling Anthropic - BloombergSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Autonomous IT
Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

Autonomous IT

Play Episode Listen Later Aug 11, 2026 22:45


August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.Patch your stuff. See you next month.

Pleb UnderGround
Major Changes At Ocean Mining After BIP-110 Failure

Pleb UnderGround

Play Episode Listen Later Aug 11, 2026 50:34


✔️ S&P500 Bitcoin Chart Is Flashing this RARE Signal✔️ When BTC/VIX touches the trendline, a bottom is formed.✔️ Bitcoin A rare signal is flashing✔️ Bitcoin has bottomed ✔️ Fidelity's Massive bitcoin prediction ✔️ BlackRock cuts Bitcoin ETF in-kind threshold to $1 million✔️ Coldcard Hack VII✔️ Crypto-js CVE-2026-71851 update ✔️ BLIP-110 Updates✔️ Update for OCEAN miners✔️ Luke, mechanic ocean update ✔️ Crypto whale has died after falling from a 30th floor ✔️ Sources:► https://x.com/philc411/status/2086861876156080616► https://x.com/olvelez007/status/2086584394605539464► https://x.com/gordongekko/status/2086805909796245706► https://x.com/washigorira/status/2086407491840315585► https://x.com/FinFreedom414/status/2086904061152923983► https://x.com/bitcoinlfgo/status/2086821673010168056► https://cryptobriefing.com/blackrock-bitcoin-etf-in-kind-transfer-minimum/► https://x.com/SenRandPaul/status/2086840523218727115► https://x.com/senrandpaul/status/2086881425945432239► https://x.com/rob1ham/status/2086629826736074863► https://github.com/advisories/GHSA-rg76-677x-56q9► https://x.com/kanzure/status/2086901769267769760► https://x.com/Roughnecks110/status/2086747561734656143► https://x.com/ocean_mining/status/2086434453979587028► https://x.com/LukeDashjr/status/2086919123599036926► https://x.com/lukedashjr/status/2087164051797192886► https://x.com/GrassFedBitcoin/status/2086920080064127297► https://x.com/mrhodl/status/2086885294112936060► https://x.com/LukeDashjr/status/2086815268836098342► https://x.com/mrhodl/status/2086608284660691116► https://x.com/mattkratter/status/2086971141491757544► https://x.com/thecomfeed/status/2086245718453359095► https://x.com/fractalencrypt/status/2086097122886115506► DONATE TO HELP KEONNE AND BILL https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools✔️ Check out Our Bitcoin Only Sponsors!► https://archemp.co/Discover the pinnacle of precision engineering. Our very first product, the bitcoin logo wall clock, is meticulously machined in Maine from a solid block of aerospace-grade aluminum, ensuring unparalleled durability and performance. We don't compromise on quality – no castings, just solid, high-grade material. Our state-of-the-art CNC machining center achieves tolerances of 1/1000th of an inch, guaranteeing a perfect fit and finish every time. Invest in a product built to last, with the exacting standards you deserve.► Join Our telegram: https://t.me/theplebunderground#Bitcoin #crypto #cryptocurrency #dailybitcoinnews #memecoinsThe information provided by Pleb Underground ("we," "us," or "our") on Youtube.com (the "Site") our show is for general informational purposes only. All information on the show is provided in good faith, however we make no representation or warranty of any kind, express or implied, regarding the accuracy, adequacy, validity, reliability, availability, or completeness of any information on the Site. UNDER NO CIRCUMSTANCE SHALL WE HAVE ANY LIABILITY TO YOU FOR ANY LOSS OR DAMAGE OF ANY KIND INCURRED AS A RESULT OF THE USE OF THE SHOW OR RELIANCE ON ANY INFORMATION PROVIDED ON THE SHOW. YOUR USE OF THE SHOW AND YOUR RELIANCE ON ANY INFORMATION ON THE SHOW IS SOLELY AT YOUR OWN RISK.

The Segment: A Zero Trust Leadership Podcast
The Monday Microsegment for the week of 8/10/2026

The Segment: A Zero Trust Leadership Podcast

Play Episode Listen Later Aug 10, 2026 7:22


The Monday Microsegment for the week of August 10. All the cybersecurity news you need to stay ahead, from Illumio's The Segment podcast. A third frontier AI model leaves its test setup — and at least two of the cases are connected. A major flaw in a popular analytics tool is already leaking customer data. And Congress wants to make the CVE program law — but some experts have concerns. Plus, Raghu Nandakumara recaps last week's Black Hat event in Vegas.  Head to The Zero Trust Hub: hub.illumio.com Get the Industry's First Vendor-Neutral Zero Trust Certification: https://www.illumio.com/zero-trust-certification 

Check Point CheckMates Cyber Security Podcast
S08E09: Unexpected Boundaries

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Aug 10, 2026 10:32


On this episode of CheckMates Go, PhoneBoy talks about Check Point-specific CVEs, AI News, and Rulebase Evaluation, Maestro Troubleshooting, and Rate Limiting.CVE-2026-16232 - Authentication bypass with SmartConsole login process using application tokenCVE-2026-62144 - Management Authentication Bypass and Privilege EscalationCVE-2026-62145 - Local privilege escalation in Gaia PortalCVE-2026-18574 - Management Authentication BypassCheck Point Gateway and Management Hardening GuideWhen The Sandbox Stops Being a BoundaryAI Assist for Security ProfessionalsUnified Policy: Column-Based Rule MatchingMaestro Troubleshooting in PracticeExperience with SecureXL DoS FeaturesHow to configure Rate Limiting rules for DoS Mitigation in R82 and higherHow to configure Rate Limiting rules for DoS Mitigation in R80.20 - R81.20

PolySécure Podcast
Actu - 09 août 2026 - Parce que... c'est l'épisode 0x32A!

PolySécure Podcast

Play Episode Listen Later Aug 10, 2026 52:11


Parce que… c'est l'épisode 0x32A! Shameless plug 19 septembre 2026 - Montréal Canada - - Bsides Montréal 2026 22 septembre 2026 - Belgique - - BE-Cyber 24 au 25 septembre 2026 - Belgique - - BruCON 1er au 3 octobre 2026 - Krakow, Pologne - - AligatorCon 13 et 14 novembre 2026 - Worldwide - - DEATHCon 16 au 19 novembre - Rennes, France - Pôle d'Excellence Cyber (PEC) - European Cyber Week 2026 1 au 3 décembre 2026 - Ottawa, Canada - Forward Global - Forum inCYBER Canada Notes IA ou Ghost in the shell Sandbox pour les nuls Black Hat USA 2026: The ‘Breaking' News: The OpenAI–Hugging Face Incident Anthropic's AI used fake identities, malware in rogue attack on GitHub project AISI, OpenAI report more ‘unsanctioned' model hacks Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers Anthropic: Security Gaps, Not Model Issues Led to Claude Attacks Incident Report: unsanctioned agent behaviour during cyber testing Third-party cyber evaluations involving OpenAI models An AI model from Meta also hacked another company during testing Now we have a timeline of the OpenAI accidental attack against Hugging Face Comment: Now we have a timeline of the OpenAI accidental attack against Hugging Face AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project OK, Well, Rogue AI Agents Are Hacking Again On jase là OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree OpenAI Trained Its Models For Months While Those Models Were Coordinating Exploits Via Message Boards OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack Prompt to fail Bypassing AI guardrails is so easy a script kiddie can do it Prompt injection isn't the bug, AI agent frameworks are Slow guardrails OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities OpenAI pledges to add Astra security as Anthropic loosens Fable's leash Human AI helps Microsoft bug hunters chase a record $20M payday Humans in the loop miss a third of dangerous AI coding agent requests AI struggles to patch vulns without adult supervision The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy LLM-Assisted Detection and Repair of Hardware Security Vulnerabilities in Verilog Designs LLMs won't break symmetric crypto AI is ‘both the weapon and the target' in latest wave of cyberattacks AI slop pollutes the CVE pipeline with fake vulns Cloudflare has mostly ditched third party security tools, suggests not trying that at home ‘Asimov was right' about rules for robots, says ex-US Cyber Director La guerre, la guerre, c'est pas une raison pour se faire mal! En eau brouille Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks US company's AI lets Ukraine's cheap kamikaze drones track targets on their own Souveraineté ou vive le numérique libre! Senators warn Trump's AI interventions could drive users to Chinese models Pluralistic: Post-American compute for a post-American Internet (04 Aug 2026) Privacy ou cachez ces informations que je ne saurais voir What the Flock Southold is being wired into Suffolk County's open-air prison ‘DO NOT MENTION ALPR USAGE': How Cops Are Trying to Hide Their Use of Flock Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool More Police Officers Fired, Investigated, or Arrested for Misusing Flock Camera Systems Texas Police Used 83,000+ Flock Cameras to Hunt Down A Woman Who Had An Abortion I am the law The SCREEN Act is a Christian Nationalist Nightmare Judge rules Meta caused “public nuisance” and must fund mental health treatment EU Age Verification Project Mandates Hardware-Bound Attestation Why the Answers to Hateful Content Online are Hiding in the Platforms' Own Rules Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data Hack the planet! Senators demand crackdown on wildfire “prediction market” bets Thousands of servers can be backdoored by exploiting buggy motherboard controllers IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents Web Security is Too Hard Russia's SVR borks public Wi-Fis for digital surveillance Ransomware attacks spike as world distracted by AI Pluralistic: Google is a scammer's paradise (05 Aug 2026) Blue ou tout ce qui améliore notre posture Micro-Segmentation Anomaly Detection in Zero-Trust Software-Defined Network Fabrics Bugtraq is back - Bugtraq - SecurityFocus Mailing Lists Divers ou parce que j'ai aucune idée où les placer Sensitive Info Goes Into ‘No Reply' Emails Constantly. This Guy Sees It All Collaborateurs Nicolas-Loïc Fortin Crédits Montage par Intrasecure inc Locaux réels par Intrasecure inc

The CyberWire
AI without adult supervision.

The CyberWire

Play Episode Listen Later Aug 6, 2026 25:37


Meta's AI models join the sandbox escape club. China's telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I'm Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Canadian Investor
Telus Slashes Its Dividend, Couche-Tard Goes Shopping, and More Big Tech Earnings

The Canadian Investor

Play Episode Listen Later Aug 6, 2026 48:54


In this episode of The Canadian Investor Podcast, we break down a packed week of earnings and market news, starting with Goodfood filing for bankruptcy protection and what went wrong for the meal-kit business. We then look at Alimentation Couche-Tard’s proposed acquisition of Poland’s Zabka Group, a deal that would be the largest in Couche-Tard’s history and significantly expand its presence in Europe. From there, we discuss Telus cutting its dividend by 55%, why the new CEO appears to be resetting expectations, and what the guidance cut says about the pressure facing Canadian telecoms. We also cover SpaceX’s first public earnings report, Amazon’s strong quarter and rising AI capex, Imperial Oil’s cash flow surge, Canada Goose’s continued struggles, and 5N Plus after its latest earnings release. Tickers discussed: FOOD.TO, ATD.TO, T.TO, SHOP.TO, AMZN, IMO.TO, CNQ.TO, SU.TO, CVE.TO, GOOS.TO, VNP.TO Subscribe to Our New Youtube Channel! Check out our portfolio by going to Jointci.com Our Website Canadian Investor Podcast Network Twitter: @cdn_investing Simon’s twitter: @Fiat_Iceberg Braden’s twitter: @BradoCapital Dan’s Twitter: @stocktrades_ca Want to learn more about Real Estate Investing? Check out the Canadian Real Estate Investor Podcast! Apple Podcast - The Canadian Real Estate Investor Spotify - The Canadian Real Estate Investor Web player - The Canadian Real Estate Investor Asset Allocation ETFs | BMO Global Asset Management Sign up for Fiscal.ai for free to get easy access to global stock coverage and powerful AI investing tools. Register for EQ Bank, the seamless digital banking experience with better rates and no nonsense.See omnystudio.com/listener for privacy information.

Resilient Cyber
The Real Price Tag On Cyber Breaches

Resilient Cyber

Play Episode Listen Later Aug 5, 2026 41:48 Transcription Available


Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.In this episode:- How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data- Why the study measures insurable loss as a floor, not a ceiling, of real economic impact- The case for reporting medians over averages, and why the team refuses to publish the average- Business interruption versus contingent business interruption, and why downtime moves the needle- Whether an $83,000 median breach impact sends executives the wrong message- The SMB paradox, where the smallest companies take the hardest proportional hit- What the claims data does and does not show about AI on offense and defense- Third-party risk, coverage sub-limits, and the single biggest takeaway for security leadersChapters0:00 Intro0:24 Meet Alex Pinto and the DBIR team2:51 Launching the Breach Impact Study3:26 Getting cyber insurance claims data7:32 Why insurable loss is a floor, not a ceiling11:14 Medians over averages, and why the average is meaningless15:13 Business interruption vs contingent business interruption19:49 Does an $83K median send the wrong message?22:44 The SMB paradox and the cybersecurity poverty line26:05 Where AI shows up, offense vs defense34:48 The CVE explosion and marketing hype36:59 Third-party risk and coverage limits41:34 Wrap-upGuest linksAlex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/Alex Pinto on X: https://x.com/alexcpsecVerizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/More from Resilient CyberSubstack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir

ai business launching cyber verizon smb price tags breaches cve verizon business data breach investigations report dbir medians 83k alex pinto
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 30, 2026 6:57


Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:14


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:15


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 29, 2026 6:59


AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Techmeme Ride Home
Anthropic Doesn't Hate Open Weights, Says Anthropic.

Techmeme Ride Home

Play Episode Listen Later Jul 28, 2026 19:52


Dario Amodei said Anthropic never backed an open-weights ban, pitching mandatory safety tests instead as OpenAI and Google signed on. Altman headed to Washington, Korea's KOSPI cratered 11% on AI jitters, Apple launched Klarna leasing, and shipped 194 CVE fixes. Anthropic wants tests, not bans, as OpenAI and Google back open weights (The New Stack) Source: Sam Altman will meet with senior US officials, lawmakers, and economists in Washington, DC, this week to preview OpenAI's upcoming family of AI models (CNBC) South Korea's KOSPI drops 11%+, led by chip stocks, amid concerns over China's chipmaking progress and the AI spending boom; Samsung falls 11%+ and SK Hynix 12% (Bloomberg) Credit default swap prices tied to Oracle, SpaceX, Alphabet, Amazon, Meta, Broadcom, and Nvidia hit record highs as investors turn jittery over Big Tech's data center debt; Oracle's five-year CDS reached 215bps (FT) Apple launches Apple Upgrade, a new US leasing program in partnership with Klarna that replaces the iPhone Upgrade Program, starting at $17.99/month for iPhones (MacRumors) Apple releases 26.6 updates for iOS, macOS, iPadOS, watchOS, tvOS, and visionOS with a huge number of security fixes; macOS Tahoe 26.6 alone addresses 155 CVEs (9to5Mac) Subscribe to the ad-free feed. Learn more about your ad choices. Visit megaphone.fm/adchoices

The Cloud Pod
365: Linux Drops 432 CVEs, Sysadmins Drop Everything Else

The Cloud Pod

Play Episode Listen Later Jul 28, 2026 87:12


Welcome to episode 364 of The Cloud Pod, where the forecast is always cloudy! Ryan is out trying to find Hotel California, but Justin, Matt, and Jonathan are in the studio today, and they've got a lot of news and some great convo – from privacy in the digital age to Nova models (and a lot of employees) getting the ax, there's a ton of stuff to cover this week, so let's get started!  Titles we almost went with this week Windows Tattletale ID Has No Off Switch Amazon’s Nova Models Enter Witness Protection Program Your PC Has a Secret Name, and Windows Won’t Erase It CloudWatch Watches Your ALB Like a Hawk One Log Group to Trace Them All Duress Code Wipes Phone, Activist Wipes Out Legally Project Perception Sees Vulnerabilities Before You Even Blink Azure DDoS Protection Trades Autopilot for Manual Control Kernel Panic Optional, CVE Overload Mandatory OpenAI’s Keypad: Key Confusion for 230 Dollars China DIYs Its Way Around DUV Export Bans OpenAI Hugged some serious Face Google must pay the EU $1 Billion… that’s a lot of Crepes Amazon apparently doesn't believe in their AGI A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. Follow Up  01:10 Linux kernel team publishes 432 CVEs in two days Update: Linux Kernel CVE Volume The Linux kernel team published 432 CVEs in a two-day span, continuing the high-volume vulnerability disclosure approach the kernel security team adopted after taking over CVE assignment duties directly. This follows the kernel team’s earlier decision to assign CVEs to a broad range of bug fixes, including minor or low-severity code changes, rather than reserving CVEs strictly for exploitable security flaws. The practice remains controversial among sysadmins and security teams, since large batches of CVEs can overwhelm vulnerability scanners, patch management systems, and compliance reporting workflows. For cloud operators running custom or long-term-support kernels, this reinforces the need for tooling that can filter and triage kernel CVEs by actual risk rather than treating every entry as an urgent patch target. The recurring pattern suggests this is now standard operating procedure for the kernel team rather than a one-time anomaly, so listeners managing fleets of Linux-based cloud infrastructure should expect similar large CVE batches going forward. 01:46 Justin – “Everyone is doing a lot of patching these days.”  04:42 I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else 

This Week in Linux
353: Codeberg Bans AI, 432 Linux CVEs, Valve wants Arch on ARM, Jellyfin Leaders Left & more Linux news

This Week in Linux

Play Episode Listen Later Jul 27, 2026 26:42


video: https://youtu.be/mytY-cyk76U This week in Linux, hundreds of Linux security alerts landed but the headlines leave out the most important part. Codeberg, a major open-source code hosting platform, is drawing a new line around AI-generated code, Valve is stretching out their ARM for a new Frame of mind for running Linux, and Jellyfin is entering a major new chapter behind the scenes. All of this and more on This Week in Linux, Your Source for Linux GNews! Download as MP3 Support the Show Become a Member = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:30 Become a Member of the channel by July 31st 01:39 Codeberg bans mostly AI-generated projects 05:31 Valve and Collabora develop Arch Linux for ARM64 08:08 Jellyfin Leadership Departures 11:57 Linux publishes 432 kernel CVEs in 2 days 14:53 Canonical fixes 3 Snap vulnerabilities 17:26 Firefox 153 adds Containers and Vulkan Video 21:11 TWIL Speedrun or Linux Lightning Round 21:37 AMD's open-source AI and robotics announcements 22:34 Final MPEG-4 Visual patent expiration 23:31 OBS Studio 32.2 Released 24:05 Raspberry Pi launches a 10-inch Touch Display 2 25:18 Outro Links: Become a Member of the channel by July 31st https://tuxdigital.com/membership Codeberg bans mostly AI-generated projects https://blog.codeberg.org/protecting-our-floss-commons-from-llms.html https://www.omgubuntu.co.uk/2026/07/codeberg-bans-ai-generated-code https://itsfoss.com/news/codeberg-bans-ai-contributions/ OpenAI on Vibe Coding - https://x.com/karpathy/status/1886192184808149383 Valve and Collabora develop Arch Linux for ARM64 https://www.collabora.com/news-and-blog/news-and-events/building-an-arch-linux-aarch64-port-for-holo-core.html https://gitlab.steamos.cloud/holo/holo-core-aarch64-preview https://www.gamingonlinux.com/2026/07/collabora-announce-a-preview-of-holo-core-an-aarch64-port-of-arch-linux-for-steam-frame/ https://www.phoronix.com/news/Holo-Core-Experimental-ARM64 https://9to5linux.com/valve-and-collabora-announce-official-arch-linux-arm64-port-for-steam-frame Jellyfin Leadership Departures https://www.boniface.me/posts/on-my-jellyfin-resignation/ https://itsfoss.com/news/jellyfin-leadership-crisis/ https://linuxiac.com/jellyfin-loses-project-leader-and-core-team-member-in-major-shake-up/ https://jellyfin.org/posts/state-of-the-fin-2026-05-24/ Linux publishes 432 kernel CVEs in 2 days https://lore.kernel.org/linux-cve-announce/ https://seclists.org/oss-sec/2026/q3/198 https://seclists.org/oss-sec/2026/q3/210 https://www.theregister.com/security/2026/07/22/linux_kernel_team_publishes_432_cves_in_two_days/5276497 https://docs.kernel.org/process/cve.html https://utcc.utoronto.ca/~cks/space/blog/linux/KernelBugfixCVEsAStory Canonical fixes 3 Snap vulnerabilities https://ubuntu.com/security/notices/USN-8579-1 https://seclists.org/oss-sec/2026/q3/191 https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt https://www.cve.org/CVERecord?id=CVE-2026-15226 Firefox 153 adds Containers and Vulkan Video https://www.firefox.com/en-US/firefox/153.0/releasenotes/ https://blog.mozilla.org/en/firefox/firefox-containers-preview/ https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153 https://brave.com/blog/containers/ TWIL Speedrun or Linux Lightning Round which do you prefer of those names? AMD's open-source AI and robotics announcements https://www.amd.com/en/corporate/events/advancing-ai.html https://www.amd.com/en/blogs/2026/rocm-ai-the-ai-native-developer-experience-for-building.html https://www.amd.com/en/products/system-on-modules/kria/ai.html https://www.amd.com/en/products/system-on-modules/kria/ai/robotics-developer-platform.html Final MPEG-4 Visual patent expiration https://www.phoronix.com/news/Last-MPEG-4-Patent-Expired https://itsfoss.com/news/mpeg-4-visual-patent-expiry/ https://meta.wikimedia.org/wiki/Have_the_patents_for_MPEG-4_Visual_expired_yet%3F OBS Studio 32.2 Released https://github.com/obsproject/obs-studio/releases/tag/32.2.0 https://9to5linux.com/obs-studio-32-2-released-with-new-filter-to-compose-sdr-into-hdr https://linuxiac.com/obs-studio-32-2-makes-adding-sources-easier/ Raspberry Pi launches a 10-inch Touch Display 2 https://www.raspberrypi.com/news/a-new-10-raspberry-pi-touch-display-2-available-now-at-80/ https://pip-assets.raspberrypi.com/categories/1083-raspberry-pi-touch-display-2 https://www.phoronix.com/news/10-inch-Raspberry-Pi-Touch-2 https://www.theregister.com/2026/07/22/raspberry-pi-goes-large-with-101-inch-touch-display-2/ https://9to5linux.com/raspberry-pi-launches-10-inch-raspberry-pi-touch-display-2-at-80 Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

Hack és Lángos
HnL 442 - 2835 nap

Hack és Lángos

Play Episode Listen Later Jul 23, 2026 73:22


Mai menü: Könyvajánló - Robert Dover: Hacker, Influencer, Faker, Spy: Intelligence Agencies in the Digital Age ne foglakozzunk a CVE-kkel UK and Allies urge critical sectors to improve defences against Russian intelligence targeting   Elérhetőségeink:TelegramTwitterInstagramFacebookMail: info@hackeslangos.show

Cyber Security Today
WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

Cyber Security Today

Play Episode Listen Later Jul 22, 2026 11:13


WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw   This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.   Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.   Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.   EY client tax-data exposure via a third-party platform.   00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off

Passwort - der Podcast von heise security
Die IETF knirscht, Cisco knirscht und die Rikscha auch

Passwort - der Podcast von heise security

Play Episode Listen Later Jul 22, 2026 110:20 Transcription Available


Im Podcast geht es mal wieder um einen bunten Strauß an Themen der vergangengen Wochen, angefangen mit einer sehr unangenehmen aber auch wichtige Diskussion zur zukünftigen Absicherung von TLS. Weiter geht es mit LLMs, die angeblich autonom Ransomware ausliefern, und Cisco, die keine einzelnen CVEs mehr ausliefern. Außerdem besprechen die Hosts elektrische Infrastruktur, die man fernsteuern und insbesondere aus der Ferne abschalten kann – leider kann das jeder der mag.

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 263 - No Chatbot, No Midnight, No Insider Info, No Simple Patch Tuesday, No Soup for You

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jul 20, 2026 53:43


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April.   Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading.   Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing.   China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push.   UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/

Autonomous IT
Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

Autonomous IT

Play Episode Listen Later Jul 14, 2026 29:06


570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the networkAn RDP bug you can shut down with a single setting, no patch requiredA SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner accessA 9.9 Hyper-V escape that lets one compromised VM take the whole hostA BitLocker bypass (6.1) worth knowing if you manage laptops in the fieldPlus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.

Absolute AppSec
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

Absolute AppSec

Play Episode Listen Later Jul 14, 2026


In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture Management (ASPM) consolidation. Cameron strongly advocates for utilizing ASPM as a distinct, single pane of glass dashboard to deduplicate vulnerabilities and streamline executive reporting by product suite. However, the hosts contrast this ideal against the messy reality of organizations dealing with a "Frankenstein" mix of loosely bootstrapped open-source scanning tools and competing vendor plugins. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. Cameron and Kurt stress the necessity of shifting away from abstract CVSS scores toward custom, runtime-informed risk appetites and impact analysis—prioritizing the hardening of high-risk corporate assets over low-reachability internal flaws. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. Ultimately, the panel laments that AppSec teams are effectively functioning as corporate incident responders because Security Operations Center (SOC) analysts lack product-level insight. The episode concludes with a review of automated agent statistics and a fun look ahead to the future emergence of meta OWASP top-ten risk lists.

Cyber Security Today
ShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishing

Cyber Security Today

Play Episode Listen Later Jul 13, 2026 10:25


ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint   Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected.   Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17.   Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender.   ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint.   Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 10, 2026 6:36


_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 https://support.apple.com/en-us/125615 Google Chrome Update https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Cybersecurity Defenders Podcast
Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 9, 2026 34:26


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.Stories covered:• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlChapters:0:00 Intro & catching up4:31 Google Dialogflow CX "Rogue Agent" flaw11:03 EvilTokens & "ghost phishing"17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 1024:56 HalluSquatting: weaponizing AI hallucinations33:16 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #phishing

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 7, 2026 6:38


RCS and DNS: The NAPTR Record https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 released https://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139 https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaign https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Blue Security
Claude Fable, SharePoint RCE, and CISA's KEV list

Blue Security

Play Episode Listen Later Jul 7, 2026 22:08


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience, and a critical SharePoint vulnerability that has caught CISA's attention. They delve into the implications of these topics for security professionals and the importance of staying updated on actively exploited vulnerabilities.----------------------------------------------------YouTube Video Link: ⁠⁠https://youtu.be/3VbR22krL-w----------------------------------------------------Documentation: https://www.bleepingcomputer.com/news/artificial-intelligence/claude-fable-relaunch-disappoints-users-with-nerfed-performance/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659https://www.cisa.gov/known-exploited-vulnerabilities-catalog----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Error Code
EP 89: How AI Is Breaking OT Cybersecurity

Error Code

Play Episode Listen Later Jul 7, 2026 39:22


AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerp, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters.

Cyber Security Today
AI-Run Ransomware, New Oracle Critical Flaw, NetNut busted

Cyber Security Today

Play Episode Listen Later Jul 6, 2026 14:26


AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator   This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key.   It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240.   A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices.   Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day.   00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off

Resilient Cyber
Why Finding Vulnerabilities Was Never the Hard Part

Resilient Cyber

Play Episode Listen Later Jul 5, 2026 36:39


Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.Why this conversation mattersEric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.Key takeawaysAttackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable's findings are non-CVE, a third of your findings can carry two-thirds of your risk.Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.Notable quotes“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.“you're on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.

The Cybersecurity Defenders Podcast
Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 3, 2026 33:53


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.htmlChapters:0:00 Intro & catching up1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)9:18 CISA advisory: billboard & highway sign controllers13:46 Cursor "DuneSlide" prompt-injection sandbox escape20:34 Claude Fable 5 export controls lifted28:17 Data centers, nuclear déjà vu & the AI race33:39 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #promptinjection

AWS Morning Brief
Open Governance for MySQL Plot Twist

AWS Morning Brief

Play Episode Listen Later Jun 29, 2026 6:19


AWS Morning Brief for the week of June 29th, with Corey Quinn. Links:Amazon CloudWatch launches OTel Container Insights for Amazon EKSAmazon GuardDuty AI-powered investigations accelerate threat response (Preview)Amazon Route 53 Global Resolver now supports sharing DNS Views between AWS AccountsAutomate AWS Invoice Retrieval with New Programmatic APIsRun isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMsUpgrading Lambda function runtimes at scale with AWS Transform customHuntington Bank: Redacting sensitive data from 400M+ documents with AWSOpen Governance for MySQL: A Step Forward for the CommunityHow AWS and a local community organization built a developer engagement model that worksModernizing border control with digital arrival cards on AWS CloudPrevent data exfiltration: AWS egress controls for cloud workloadsRestrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPsA new way to keep your AWS Certification current CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

The CyberWire
Klue me in on the breach.

The CyberWire

Play Episode Listen Later Jun 24, 2026 28:16


LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here. Selected Reading Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch) Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch) Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs)  DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  (Zafran)  23 ClawHub Plugins Squat Official Org Scopes (Manifold Security)  Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr)  Indian auto giant Bajaj Auto hit by ransomware incident (The Record)  U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times) Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek) US adds sanctions against accused Cambodian scammers Prince Group (Reuters) Ushering in the Next Frontier of Quantum Innovation (The White House)  Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED)  Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 24, 2026 6:48


CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 22, 2026 6:06


eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090 NGINX ngx_http_v3_module vulnerability CVE-2026-42530 https://my.f5.com/manage/s/article/K000161616 Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The CyberWire
The court calls Google's bluff.

The CyberWire

Play Episode Listen Later Jun 11, 2026 31:20


Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain attacks evolve. And a massive data breach triggers a record fine in South Korea. Our guest is Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done. AI analyzes the FIFA World cup, one cliché at a time.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done across humans, automation, and AI agents. You can read more from Ping Identity here. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers (The Decoder) White House Reins In AI-Testing Unit as National-Security Concerns Grow (Wall Street Journal) Anthropic Releases ‘Safe' Version of Its Mythos A.I. Technology (The New York Times) PRC-linked influence operations are targeting AI debates in the US (OpenAI) Technical Analysis of MLTBackdoor (ThreatLabz) CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry (Rapid7) Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels (Socket) Veeam Patches Critical RCE Vulnerability in Backup & Replication published: yesterday (Beyond Machines) ‘Amazon.com of South Korea' Is Fined a Record $409 Million (The New York Times) The 2026 big soccer tournament, in clichés. (Sinch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices