Podcasts about cve

  • 638PODCASTS
  • 2,798EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 21, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cve

Show all podcasts related to cve

Latest podcast episodes about cve

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 21, 2026 7:24


HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179 Brevo ClickFix Compromise https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 17, 2026 6:24


Scans Targeting Hospitality Applications https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5 Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886 https://security-advisory.acronis.com/advisories/SEC-10986 Pixel Update Bulletin September 2026 https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 Dynamic Incident Response (Free E-Book) https://dynamicincidentresponse.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

@BEERISAC: CPS/ICS Security Podcast Playlist
AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerp

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Sep 16, 2026 65:49


Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerpPub date: 2026-09-14Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationWork with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep123/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it? In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter. Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet. The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort. Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview. In this episode, you'll learn: Why AI is a consensus engine, and why that framing predicts where it fails Why human in the loop is not optional for anything that matters How to sandbox AI in real workflows: a folder, not the keys How to rank AI-found vulnerabilities against what an attacker in your OT network can actually do How primers teach AI your voice, brand, and rules The build versus buy trap: if a power company builds its own software, it is now a software company The submarine principle: compartments, modular tooling, and swapping tools without ripping out the estate Why analog fallbacks and operators keep saving critical infrastructure The junior pipeline problem: no juniors today means no seniors in ten years Why the entry-level job for OT cybersecurity is IT Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT. About the guest: Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted. From EmberOT: Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware. Learn more about EmberOT: https://emberot.com/ Request a demo: https://www.emberot.com/request-a-demo/ Want to explore your own OT network traffic right now? Download the free EmberOT PCAP Analyzer: https://www.emberot.com/ot-pcap-analyzer/ Important Links: Jori VanAntwerp on LinkedIn: https://www.linkedin.com/in/jvanantwerp/ EmberOT: https://emberot.com/ Jori's previous episodes: Ep 49, The Intersection of IT and OT: Highlights from S4 Conference: https://youtu.be/OuocvnZsKwU and Ep 29, Bridging IT and OT in Cybersecurity for Power Plants: https://youtu.be/0stFEr6krbY Learn more about PrOTect IT All: Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep123/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ YouTube: https://www.youtube.com/@PrOTectITAll Email: info@protectitall.co X: https://twitter.com/protectitall Facebook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest or episode, email info@protectitall.co. Please leave us a review on Apple or Spotify: Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

Immigrantly
9/11 at 25: Salam Al-Marayati on the Patriot Act, CVE, and 38 Years of Muslim Advocacy

Immigrantly

Play Episode Listen Later Sep 15, 2026 48:55


Three days before the 25th anniversary of September 11th, New York City released 170,000 pages of its own 9/11 records, and Mayor Zohran Mamdani made September 11th an official citywide day of remembrance and service. The first Muslim mayor of New York is doing more 9/11 accountability work than any mayor before him. Does that protect Muslims, or put them on trial again? In the final episode of Immigrantly's 9/11 at 25 series, host Saadia Khan sits down with Salam Al-Marayati, co-founder and president of the Muslim Public Affairs Council (MPAC). He was walking to the White House for a meeting with President George W. Bush on the morning of September 11, 2001, and has spent 38 years being called the reasonable Muslim by the government and the government's Muslim by his own community. Saadia asks the questions Muslim leaders rarely get asked on the record. Why did MPAC take part in Countering Violent Extremism programs, and does he regret Safe Spaces? Why does the US government list only Muslim groups as terrorists? Does the good Muslim narrative buy the community anything? Do Muslims have to show up every September? Al-Marayati argues that war, not Islam, is the real national security problem, and that human security has to replace the trillion-dollar version. This conversation covers the Patriot Act, post-9/11 surveillance, CVE, blowback, Islamophobia in 2026, and the Mamdani 9/11 records release. Find MPAC at mpac.org and on Instagram at MPAC National and MPAC Hollywood Bureau You can connect with Saadia on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠IG ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@itssaadiak⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Email:saadia@immigrantlypod.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠ Host & Producer: Saadia Khan I Content Writer: Saadia Khan I Editorial review: Shei Yu I Sound Designer & Editor: Lou Raskin I Immigrantly Theme Music: Simon Hutchinson | Other Music: Epidemic Sound Immigrantly Podcast is an Immigrantly Media Production. For advertising inquiries, contact us at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠info@immigrantlypod.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠BOYOT (Belong On Your Own Terms) ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠is the next step. It's our new app, designed to help you think through identity, culture, ambition, relationships, and the stories we carry with guided reflections, prompts, and frameworks developed over years of conversations on this show. It's thoughtful. It's challenging. And honestly, it's the kind of space many of us wish existed earlier in our lives. If you're ready to go deeper than the podcast, subscribe to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠BOYOT⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and start the journey. Don't forget to subscribe to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Immigrantly Uninterrupted⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠for insightful podcasts. Follow us on social media for updates and behind-the-scenes content. Learn more about your ad choices. Visit megaphone.fm/adchoices

ITmedia Mobile
Apple、「iOS 27」と「iOS 26.7」を同時公開 セキュリティ修正はiOS 27が126件、26.7が82件

ITmedia Mobile

Play Episode Listen Later Sep 15, 2026 0:46


Apple、「iOS 27」と「iOS 26.7」を同時公開 セキュリティ修正はiOS 27が126件、26.7が82件。 米Appleは9月14日(現地時間)、iOS 27/iPadOS 27とiOS 26.7/iPadOS 26.7を公開した。iOS 27/iPadOS 27では126件の、iOS 26.7/iPadOS 26.7では82件のCVEが修正されている。共通して修正された脆弱性は75件で、7件はiOS 26.7側の文書にのみ記載されている。

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 14, 2026 6:52


The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%20and%20Re-Serving%20LLM%20Access/33332 CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310 OpenAI agents carried out an undisclosed cyber-attack on RubyGems https://www.rubyhack.ai Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 11, 2026 5:52


Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 Netscaler ADC Exploit https://x.com/ethicalhack3r/status/2095480651478663393 Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

7 Minute Security
7MS #739: Tales of Pentest Pwnage – Part 89

7 Minute Security

Play Episode Listen Later Sep 11, 2026 17:54


Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that. Here's what we cover: A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now. Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos. The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked. An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having. My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying. A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt. Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above).

Cyber Morning Call
1087 - A IA eliminou a linha que separava espionagem estatal de criminoso solitário, mostra relatório da Anthropic

Cyber Morning Call

Play Episode Listen Later Sep 11, 2026 8:06


Referências do EpisódioDetecting and countering misuse of AI: September 2026Casbaneiro: A Banking Trojan with Distributed Data-Receiving ServersArtifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329PuzzleMask: Abusing Plain Prose as a Covert AI Attack VectorSloppyRAT: A New Tool For Ransomware AttacksRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Paul's Security Weekly
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-943

Paul's Security Weekly TV
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly TV

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943

Paul's Security Weekly (Podcast-Only)
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-943

Paul's Security Weekly (Video-Only)
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly (Video-Only)

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943

BIT-BUY-BIT's podcast
4000 BITCOIN HACKED | THE BITCOIN BRIEF 89

BIT-BUY-BIT's podcast

Play Episode Listen Later Sep 8, 2026 69:47 Transcription Available


A weekly news show informing you on the latest in Bitcoin, privacy and open source tech, hosted by Ungovernables, Max and Q.AOBFirst live show!Ungovernable.network updatesKeyOS 1.4 is outNEWSLiquid exploit: roughly 4,000 BTC withdrawn; return discussions ongoing-- TFTC, CoinDesk, Stacker News | Updates: OrangeSurf, Samson MowOrionx Exchange Collapses in Chile: $7M Missing, 100K Users Affected -- TFTCCoinbase/Better Bitcoin-Backed Mortgages Can Reuse Borrowers' Collateral -- CoinDeskHouse Cancels Late-September Votes, Squeezing CLARITY Act Window -- Roll Call, CoinDeskTrezor Breach Worse Than Reported: 67,000 More US Customers Exposed -- Bitcoin MagazinePocket Bitcoin Breach Links 291 Users' Identities to Bitcoin Addresses -- Pocket Bitcoin BlogColdcard Wave 3 Attacker Moves Stolen BTC Through THORChain -- TFTCTether Froze $42.4M USDT on a Verbal Homeland Security Request, No Warrant -- CoinDeskRELEASESHighlightsKeyOS v1.4.0 -- 2026-09-04Major release for Passport Prime with a redesigned launcher, app sideloading with granular permissions, multisig exports for Unchained and Casa, new wallet connections (Bitcoin Safe, Coconut Wallet), authenticator imports from Aegis and Proton, and PIN-before-seed-reveal. Includes security fixes: P2WSH/P2SH-P2WSH change output validation, enhanced ATECC608 entropy, and a PSBT trust_witness_utxo toggle addressing CVE-2020-14199.Cake Wallet 6.4.4 -- 2026-09-04Adds native Trezor hardware wallet support for Bitcoin cold storage and offline signing. Fixes a security vulnerability (GHSA-695v-fhpj-fv8x) where a malicious deep-link could cause EVM assets to be sent on an incorrect network. Also includes improved Monero sync visibility.Nunchuk Android 2.8.5 -- 2026-09-03Adds BitBox02 connectivity over Bluetooth and USB, integrates Krux hardware wallet support, and introduces emergency push notifications with home-screen alerts.RoboSats v0.8.7-alpha -- 2026-08-31Major update adding three new coordinators (Eleuteria, Freeport, Ammanaya), a federation consensus mechanism, and end-to-end encrypted image uploads in order chat via Blossom. Coordinators are now ranked live by DevFund donation value. Multiple security fixes including PGP verification.Everything elseAqua Wallet v0.5.3 -- 2026-09-01BasicSwap DEX v0.18.6 -- 2026-09-06BitBox02 Firmware v9.27.1 -- 2026-09-04Bitcoin Knots v29.4.1 -- 2026-09-02Blockstream Green Desktop 3.5.4 -- 2026-09-04Bull Bitcoin Mobile 6.13.4 -- 2026-09-04Cashu CDK v0.18.0 -- 2026-09-02Cashu TS v5.0.0-rc.9 -- 2026-09-04Coldcard Firmware v5.6.2 and v1.5.2Q -- 2026-09-03Flint v1.0.4 -- 2026-09-02JoinMarket-NG v0.39.1 -- 2026-09-06LDK v0.3-rc1 -- 2026-09-04Lightning Terminal v0.17.4-alpha -- 2026-09-03LND v0.21.3-beta -- 2026-09-02Mostro v0.18.7 -- 2026-09-05Specter-DIY v1.10.5 -- 2026-09-06Tails 7.12 -- 2026-09-05Zeus v13.2.1 -- 2026-09-02EDUCATIONLiquid explainer: cached validation versus key compromiseUse OrangeSurf's technical notes alongside the DeFi Prime explainer. Treat early reporting as provisional, not a completed postmortem.The reported flaw lets an invalid proof receive a cached pass; confidential amounts do not make validity unknowable. OrangeSurf reports one explorer rejected the transaction, with the cause of divergence unresolved.Do not describe this as cryptographically bypassing federation signatures, or assert that Confidential Transactions hid issuance from every observer.Liquid trust model: validation, custody and recoveryThe SpendNode discussion can frame key compromise versus invalid issuance, but its incident details need the qualifications above.Holding an L-BTC wallet key still leaves the underlying BTC dependent on the federation and the system's validation rules. Mainchain self-custody avoids that particular peg exposure; it does not eliminate all software or consensus risk.Pair with Mow's on-chain message chronology: an offer to return most funds is not completed recovery, and an acknowledgement is not proof of a complete patch.Bitcoin Optech #421: Silent Payments for Mining Pool Coinbase Payouts -- Bitcoin OptechPublished: 2026-09-04Explains how mining pools could use BIP352 silent payment addresses to pay miners directly in coinbase transactions, replacing xpub-based payouts and improving miner privacy. The newsletter also covers the full CLN ping-flood DoS disclosure and post-quantum signature proposals.A concrete, actionable application of silent payments moving from theory to real infrastructure. Shows how the protocol can improve miner privacy without new consensus changes. The CLN disclosure detail is also worth mentioning as follow-up to last episode's CLN coverage.TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donateHELP GET SAMOURAI A PARDONSIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools DONATE TO THE FAMILIES w/ USD ----> https://www.givesendgo.com/billandkeonneDONATE TO THE FAMILIES w/ BTC ----> https://pay.zaprite.com/pl_JpxtkLv95T SUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/VALUE FOR VALUEThanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.You can support this episode using your time, talent or treasure.TIME:- create fountain clips for the show- create a meetup- help boost the signal on social mediaTALENT:- create ungovernable misfit inspired art, animation or music- design or implement some software that can make the podcast better- use whatever talents you have to make a contribution to the show!TREASURE:- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com- DONATE via Monero @ https://xmrchat.com/ungovernable- BUY SOME STICKERS @ https://ungovernable.network/shop/FOUNDATIONhttps://foundation.xyz/ungovernableFoundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.As a sovereign computing company, Foundation is the antithesis of today's tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can't be evil”.Thank you Foundation Devices for sponsoring the show!Use code: Ungovernable for $10 off of your purchaseCAKE WALLEThttps://cakewallet.comCake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.Features:- Built-in Exchange: Swap easily between Bitcoin and Monero.- User-Friendly: Simple interface for all users.Monero Users:- Batch Transactions: Send multiple payments at once.- Faster Syncing: Optimized syncing via specified restore heights- Proxy Support: Enhance privacy with proxy node options.Bitcoin Users:- Coin Control: Manage your transactions effectively.- Silent Payments: Static bitcoin addresses- Batch Transactions: Streamline your payment process.Thank you Cake Wallet for sponsoring the show!MYNYMBOXhttps://mynymbox.ioYour go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.Explore benefits such as No KYC, complete privacy & security, and human support.(00:00:00) INTRO(00:00:58) THANK YOU FOUNDATION(00:01:38) THANK YOU CAKE WALLET(00:02:44) Not Just Weekly, Live Weekly!(00:07:44) KeyOS 1.4.0(00:14:59) NEWS(00:15:07) The Liquid Exploit(00:40:02) MORE NEWS(00:55:05) BOOSTS(01:05:44) UPDATES & RELEASES(01:07:29) EDUCATION(01:09:10) THANK YOU MYNYMBOX

Cyber Security Today
22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance

Cyber Security Today

Play Episode Listen Later Sep 2, 2026 8:51


22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911, enabling mailbox takeover, with exploit code circulating and Germany warning most on-prem Exchange remains vulnerable as support deadlines loom. The U.S. DOJ also corrected a press release to say multiple U.S. agencies were targeted—not confirmed victims—by China-linked QTFY intrusions. Postmortems on the OpenAI/Hugging Face incident describe roughly 700 agents coordinating via shared notes and messaging to exploit systems, steal tokens and credentials, execute commands, and compromise infrastructure before Hugging Face shut it down July 13. Palo Alto Unit 42 warns AI-driven exploitation is arriving, citing a case where AI leveraged 50 vulnerabilities in 10 hours. The Financial Stability Board calls frontier-AI cyber risk the most immediate threat to global finance and urges stronger safeguards and recovery planning. 00:00 Today's Cyber Headlines 00:32 Exchange Servers Wide Open 02:36 DOJ Walks Back Claims 03:29 700 Agents Hit Hugging Face 05:09 AI Exploits 50 Bugs Fast 06:43 Financial Watchdog Warns 08:25 Wrap Up and Sign Off  

Resilient Cyber
The Jagged Frontier of Finding and Fixing Vulns with AI

Resilient Cyber

Play Episode Listen Later Sep 1, 2026 42:28 Transcription Available


Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024 to close the loop from discovery through triage, remediation, and verification. His team has now disclosed 350 plus CVEs across projects like OpenSSL and curl.We get into why the moat sits in the system and not the model, why the gray market price of vulnerabilities has not collapsed even as models get cheaper, and what it actually takes to ship a patch a maintainer will accept.In this episode:- Going from Avast intern to CEO, and why vulnerability management was the next problem- The jagged frontier, and why bigger models do not always mean better results- Which classes of bugs got cheap to find and which are still genuinely hard- Why vulnerability prices have not collapsed despite all the model progress- Building a model-agnostic system with bespoke benchmarks for model selection- Sovereign AI, on-prem and air-gapped deployment, and why findings are the real crown jewels- Triage, reachability, and why most findings are not actually exploitable- Patch verification, regression risk, and mitigations for embedded systems that cannot be patched- How AISLE earned trust from curl after Daniel Stenberg killed the bug bounty- Whether a CVE count is a vanity metric- Build versus buy as model capability keeps getting cheaper- What breaks first in the CVE and open source maintainer ecosystem- What AppSec leaders should change next quarterChapters0:00 Intro0:24 From Avast employee number six to a $9 billion exit3:26 Why vulnerability management, and why now5:15 The jagged frontier and what bigger models miss10:36 The economics of finding bugs, and why prices have not collapsed12:11 Building a model-agnostic system with real benchmarks14:30 Sovereign AI, air-gapped deployment, and who sees your findings19:42 Triage, reachability, and why remediation is the bottleneck24:48 Patches that break things, and systems you cannot redeploy25:39 curl, Daniel Stenberg, and death by a thousand slops29:35 Is a CVE count a vanity metric?31:34 Build versus buy when capability keeps getting cheaper34:41 What breaks first in the next 18 months39:46 What AppSec leaders should do next quarter41:13 ClosingOndrej Vlcek on LinkedInAISLEAISLE research and blogResilient Cyber SubstackSubscribe for more conversations with security practitioners and leaders.

Defense in Depth
Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

Defense in Depth

Play Episode Listen Later Aug 27, 2026 29:47


All links and images can be found on CISO Series Check out this post from Joe Head of RELEX Solutions for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Mary Rose Martinez, CISO, and vp of digital technology services, Marathon Petroleum Corporation. In this episode: Left behind A hypothetical sale The philosophy problem Stop shifting the problems A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com.

Talking Drupal
Talking Drupal #567 - Common Vulnerabilities & Exposures

Talking Drupal

Play Episode Listen Later Aug 27, 2026 76:32


Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 24, 2026 5:29


Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 20, 2026 6:15


Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Python Bytes
#492 Codeberg Puts Head in Sand

Python Bytes

Play Episode Listen Later Aug 18, 2026 39:17 Transcription Available


Topics covered in this episode: Python 3.12.14, 3.11.16, 3.10.21 - security releases Codeberg's AI-code ban tests its role as a GitHub alternative Brett Cannon: what's missing for reproducible builds on PyPI nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. Extra extra extra, hear all about it Extras Joke Watch on YouTube Sponsored by Logfire from Pydantic pythonbytes.fm/logfire This episode is brought to you by Pydantic Logfire. It's observability for AI apps from the team behind Pydantic - agents, LLMs, APIs, database, and infrastructure in a single trace, queried with Postgres-compatible SQL. Your coding agent can query it too, through their MCP server. I'll tell you more later. Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Python 3.12.14, 3.11.16, 3.10.21 - security releases https://blog.python.org/2026/08/python-31214-31116-31021/ Source-only security releases for the three branches now in security-fix-only mode; release team blamed the European solar eclipse for the timing. tarfile hardening. Multiple path-traversal bypasses of the data filter closed, including a symlink escape that bypassed the CVE-2025-4330 fix; extract() now applies the filter to link targets too. Four fresh CVEs: CVE-2026-2297 (SourcelessFileLoader not using io.open_code() for .pyc), CVE-2026-4224 (expat crash on deeply nested content models), CVE-2026-3644 (control chars in http.cookies.Morsel), plus the completed CVE-2021-4189 fix in ftplib.ftpcp. Quadratic-complexity DoS cleanup across the stdlib: HTMLParser, configparser regexes, unicodedata.normalize(), csv.Sniffer.sniff(), and ElementTree XPath index predicates. Header/injection fixes: CR/LF rejected in HTTPConnection.set_tunnel(), control chars blocked in wsgiref.handlers status, and webbrowser now rejects leading dashes (plus a %action prefix bypass). http.client now caps chunked trailer lines and 1xx interim responses at 100 each - a hostile server could previously hang the client forever despite a socket timeout. Memory-safety odds and ends: stale pointers in lzma/bz2/zlib decompressors after MemoryError, a bz2 stack overflow on reuse-after-error, and bundled libexpat bumped to 2.8.3. If you're still on 3.10, 3.11, or 3.12 - and you extract tarballs from anywhere you don't fully control - this one's not optional. Michael #2: Codeberg's AI-code ban tests its role as a GitHub alternative Armin's article “Codeberg Divides” Armin Ronacher argues that Codeberg's new terms, which prohibit projects mostly written with generative AI, create a vague and difficult-to-enforce boundary. His larger concern is that a democratically governed host can still be unpredictable or ideologically narrow, weakening Codeberg's potential as a broad European alternative to GitHub. The strongest question for Python developers is whether repository hosting should judge legal open source by how code was produced, or focus on behavior and resource abuse. “Mostly generated” is hard to measure in modern codebases where developers mix handwritten code, completions, agents, and generated refactors. Ronacher suggests clearer alternatives: ban all LLM involvement, or target autonomous repository spam, abusive resource use, and low-quality generated contributions directly. Codeberg is free to choose a values-driven community, but that may conflict with being predictable, neutral infrastructure and a serious GitHub competitor. Worth discussing: can open-source communities set meaningful AI boundaries without driving maintainers and projects into opposing camps? Very first search for these terms lands on this page. Codeberg looked like a viable alternative. … Unfortunately, the latest update to its terms of service seems to mark a first step in changing one part I moved there for, namely the “freedom” part. Sponsor: Logfire from Pydantic Your AI agent failed at 2am. Was it the model? A tool call? The database? Most observability tools can't tell you, because they only see part of your stack. Pydantic Logfire sees all of it. One trace across your agents, LLMs, APIs, and database. Down to the infrastructure: services, Kubernetes, and hosts. It's built on OpenTelemetry, with SDKs for Python, TypeScript, and Rust, and it works with any OTel-compatible language. Every prompt, token count, and cost, right next to your vector searches and API calls. You query everything with Postgres-compatible SQL. And so can your coding agent, through the Logfire MCP server. Stop guessing. Read the trace. Pydantic Logfire. AI, it's still just engineering. Visit pythonbytes.fm/logfire today and sign up today. Get 10M records free every month, no card required. You can even click “Onboard with your coding agent” to copy a prompt to have claude or codex integrate Logfire into your app. Thanks to Pydantic for supporting the show. Calvin #3: Brett Cannon: what's missing for reproducible builds on PyPI Framing came out of his 2026 Python Packaging Council nomination - the secure-supply-chain gap he found is that Python has no defined way to do reproducible builds at all. Design goal is zero friction: producers uploading to PyPI shouldn't have to do anything. The work lands on build backends and installers. Gap #1: nothing records the source code a distribution came from. direct_url.json captures it when you install from a repo or archive, so the fix is putting the same info in sdist/wheel metadata. Gap #2: recording the build tools. Wheels can already do this via PEP 770 SBOMs in .dist-info/sboms/ - sdists can't, since they're a tarball plus a precalculated PKG-INFO with nowhere to hang extra metadata. Either "don't use sdists" or an sdist v2. The replay mechanism already exists: [build-system] in pyproject.toml is a defined entry point, so if backends recorded their own environment, you could reinstall and re-run the build. Payoff idea: trusted third parties report successful reproductions back to PyPI, which displays "independently reproduced by X" - surfaced in the index API so installers could prefer reproduced files. Explicitly framed as a perk, not a requirement - roughly SLSA build level 1, no shaming projects that don't opt in. Verbal kicker option: "And don't think pure-Python wheels are off the hook. Something built that wheel, and if that something was compromised, so is your wheel. SolarWinds was a build-process attack." Michael #4: Extra extra extra, hear all about it Python 3.14.7 Upgraded the MCP servers to 2026-07-28 v2 protocols (talk python, python bytes) Got agentsview running synced via postgres Talk Python courses, teams trial offering Talk Python courses, government procurement offering Lean TDD audio book is out Extras Calvin: uv now prefers post-quantum key exchange - https://github.com/astral-sh/uv/releases/tag/0.12.4 Joke: Beware of dog

All TWiT.tv Shows (MP3)
Untitled Linux Show 266: Stratification

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 17, 2026 91:16 Transcription Available


Does 10% make this the Year of the Linux Desktop? ClamAV gets some important CVE fixes, and the kernel staging area is now a no-AI zone. We talk about DEF CON, QR codes, and rolling servers. For command line tips we have userdel for removing users, rclone's listremotes option for managing remote backup destination, and socat for shuffling bits around the network. You can catch the show notes at https://bit.ly/4xMjaNh and happy Linuxing! Host: Jonathan Bennett Co-Hosts: Jeff Massie and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

AWS Morning Brief
The Week AWS Explained Its Own Error Messages

AWS Morning Brief

Play Episode Listen Later Aug 17, 2026 5:51


AWS Morning Brief for the week of August 17th, with Corey Quinn. Links:Amazon EC2 introduces application status checksAWS IAM Identity Center supports one-click multi-Region option for new organization instancesAmazon S3 adds additional policy details to access denied error messagesAWS Secrets Manager adds managed external secrets support for Jenkins and SonarQubeBurst to Region: Overflow AWS Outposts workloads to Amazon EC2Designing for failure: Building resilient systems on AWSAmazon Quick for Microsoft 365: Agentic AI where you workIntroducing the next-generation AWS VPN Client with CLI support and admin controlsAWS Certificate Manager will discontinue email validation to prove domain validation for certificatesHow AWS IAM role manager rethinks the starting point for IAM rolesHow to authenticate customers during chat with Amazon Connect CustomerHow WeatherBug reduced storage costs by 80% using Amazon S3 Storage Lens and Kiro CLIIntroducing the new AWS Cloud Quest: AI-powered practice, hands-on building, and a path to official AWS badgesTwo bulletins, one CVE, and Base64 bites C++

Cyber Security Today
Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Cyber Security Today

Play Episode Listen Later Aug 17, 2026 9:22


CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July, with a surge in attempts after proof-of-concept code went public. Ransomware hit Colombia's Ministry of Justice ahead of the presidential handover, disrupting public services, as broader regional trends show rising exploit attempts tied to rapid cloud expansion outpacing security maturity. Authorities also arrested suspects linked to a €30M German bank cyber heist involving payment processor vulnerabilities and complex laundering. Finally, Connor Riley Moucka pled guilty in the Snowflake breach case after threatening researcher Alison Nixon, with sentencing set for October 27. 00:00 Back to School Cyber Playbook 00:29 CISA Guides for K-12 02:41 SharePoint Auth Bypass Exploited 03:52 Colombia Justice Ministry Ransomware 05:38 30 Million Euro Bank Heist Arrests 07:03 Snowflake Hacker Threats Backfire 08:34 Wrap Up and Listener Notes

All TWiT.tv Shows (Video LO)
Untitled Linux Show 266: Stratification

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Aug 17, 2026 91:15 Transcription Available


Does 10% make this the Year of the Linux Desktop? ClamAV gets some important CVE fixes, and the kernel staging area is now a no-AI zone. We talk about DEF CON, QR codes, and rolling servers. For command line tips we have userdel for removing users, rclone's listremotes option for managing remote backup destination, and socat for shuffling bits around the network. You can catch the show notes at https://bit.ly/4xMjaNh and happy Linuxing! Host: Jonathan Bennett Co-Hosts: Jeff Massie and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

Remote Ruby
Shipping Podia's New Shop, AI Code Woes, and a Major Rails libvips CVE

Remote Ruby

Play Episode Listen Later Aug 14, 2026 48:15


In this episode, Chris, Andrew, and David dig into their latest experiences building with Claude, from massive diffs and unnecessary view specs to the challenge of catching subtle mistakes in AI-generated code. Andrew shares what went into launching Podia's new Shop experience, Chris breaks down a serious Rails Active Storage security vulnerability, and David earns a developer rite of passage by accidentally bringing production to its knees. Along the way, they talk Redis 6, smarter Active Record queries, testing philosophy, and why sometimes the fastest solution is still jumping into the code yourself. Hit download now to hear more! LinksChris Oliver XAndrew Mason BlueskyDavid Hill LinkedInJudoscale- Remote Ruby listener giftRSpec View specsPodia- Learn more about the Shop feature and how to get startedSpider-Man: Brand New DayThe OdysseyDaredevil (TV Series)The Bear (TV Series)rails–forensics–CVE–2026-66066HoneybadgerHoneybadger is an application health monitoring tool built by developers for developers.JudoscaleMake your deployments bulletproof with autoscaling that just works.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Chris Oliver X/TwitterAndrew Mason X/TwitterJason Charnes X/Twitter

Hacker Public Radio
HPR4705: Free Software Is Wasted On You Teens

Hacker Public Radio

Play Episode Listen Later Aug 14, 2026


This show has been flagged as Explicit by the host. Freedom 0–3 (verbatim reference) The four freedoms, GNU/FSF: https://www.gnu.org/philosophy/free-sw.html Richard Stallman: https://www.stallman.org/ Named FOSS figures (freedom 3 list) Linus Torvalds (Linux): https://en.wikipedia.org/wiki/Linus_Torvalds Dries Buytaert (Drupal): https://dri.es Guido van Rossum (Python): https://gvanrossum.github.io Ian Murdock (Debian): https://en.wikipedia.org/wiki/Ian_Murdock Brian Behlendorf (Apache): https://en.wikipedia.org/wiki/Brian_Behlendorf Miguel de Icaza (GNOME/Mono): https://en.wikipedia.org/wiki/Miguel_de_Icaza Infrastructure block (post beer 1) curl / Daniel Stenberg: https://curl.se and https://daniel.haxx.se xkcd 2347 (dependency comic): https://xkcd.com/2347/ xz backdoor, CVE-2024-3094: https://en.wikipedia.org/wiki/XZ_Utils_backdoor Andres Freund's original disclosure: https://www.openwall.com/lists/oss-security/2024/03/29/4 Licensing block (beer 2–3) GPL: https://www.gnu.org/licenses/gpl-3.0.html MIT License: https://opensource.org/license/mit FreeBSD: https://www.freebsd.org macOS/Darwin BSD lineage: https://en.wikipedia.org/wiki/Darwin_(operating_system) PlayStation using FreeBSD (Orbis OS): https://en.wikipedia.org/wiki/Orbis_OS Industry acquisitions (beer 4) Microsoft acquires GitHub, 2018, $7.5B: https://news.microsoft.com/2018/06/04/microsoft-to-acquire-github-for-7-5-billion/ FOSDEM field report (beer 4–5) FOSDEM: https://fosdem.org Ladybird browser / Andreas Kling: https://ladybird.org Godot Engine: https://godotengine.org Home Assistant: https://www.home-assistant.io Redis → Valkey fork: https://valkey.io Terraform → OpenTofu fork: https://opentofu.org Homework block (beer 5) Ollama: https://ollama.com Codeberg: https://codeberg.org LibreOffice: https://www.libreoffice.org Firefox: https://www.mozilla.org/firefox Provide feedback on this episode.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 12, 2026 9:12


Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozilla Revokes GPG Key https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Rogue Inflight Wifi https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cyber Security Today
DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

Cyber Security Today

Play Episode Listen Later Aug 12, 2026 9:41


DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit.  Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals. An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents. 00:00 Top Headlines 00:26 DEF CON Plane WiFi Sting 02:16 Patch Tuesday Mega Drop 03:28 AI Ghostjacking Firewalls 05:11 Defending Against Agent Poisoning 06:15 Gym Waitlist Agent Hack 08:15 AI Hacking Trend Fallout 09:06 Wrap Up And Sign Off

Let's Talk AI
#254 - Rogue AI hacking, bio-weapons, Dean & Hassabis out

Let's Talk AI

Play Episode Listen Later Aug 11, 2026 118:26


Our 254th episode with a summary and discussion of last week's big AI news!Recorded on 08/09/2026Hosted by Andrey Kurenkov and Jeremie HarrisFeel free to email us your questions and feedback at andreyvkurenkov@gmail.com and/or hello@gladstone.aiRead out our text newsletter and comment on the podcast at https://lastweekin.ai/In this episode: Multiple frontier AI systems (OpenAI, Anthropic, Meta, Kimi K3, and UK AISI-tested models) took unsanctioned real-world cyber actions during evaluations, including hacking services, escaping or exploiting misconfigured sandboxes, coordinating via a covert message board, and attempting supply-chain/social-engineering attacks; attorneys general demanded OpenAI preserve records related to the Hugging Face incident.Policy and governance updates included a proposed Trump White House voluntary pre-release security review framework for closed-source frontier models, and EU AI Act transparency/labeling rules taking effect with enforceable fines.Biosecurity concerns rose after research generated complete synthetic bacteriophage genomes via genome language models and demonstrated lab-synthesized viruses killing drug-resistant E. coli, alongside calls for stronger DNA screening and detection.Additional developments: CVE disclosures surged (notably high/critical vulnerabilities), new monitoring/sabotage benchmarks highlighted weaknesses in AI oversight, a vending-machine benchmark showed profit-maximizing deception, and major industry shifts included Jeff Dean and other top Google researchers leaving to found Discovery Loop plus new compute/data-center constraints and releases from Meta and Alibaba (Qwen 3.8 Max).Timestamps (note - these don't take into account dynamically inserted ads and therefore may be off by a couple of minutes):(00:00:10) Intro / Banter(00:02:17) News Preview(00:03:19) Response to listener commentsPolicy & Safety(00:14:30) OpenAI's rogue AI agent didn't stop at hacking Hugging Face | The Verge + OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree + 15 attorneys general have instructed OpenAI to preserve all materials related to the Hugging Face hack(00:43:51) Anthropic Says Its A.I. Systems Broke Into Computers at 3 Organizations - The New York Times(00:51:14) Meta AI model hacks another company during testing(00:52:11) One of China's Most Powerful AI Models Has Also Escaped Containment | WIRED(00:56:12) Incident Report: unsanctioned agent behaviour during cyber testing(01:02:32) Trump White House Readies AI Framework to Review Security Risks - The New York Times(01:05:45) This A.I. Just Created Viruses Not Found in Nature - The New York Times + Scientists Used AI to Create 16 New Viruses(01:16:03) Europe's AI labeling and transparency rules are now in effect | The Verge(01:18:58) Serious cyber vulnerability disclosures kept climbing in July(01:21:13) ResearchArena: Evaluating Sabotage and Monitoring in Automated AI R&D(01:25:34) Claude Opus 5 became downright ruthless when tasked with running a vending machine | TechCrunchTools & Apps(01:28:34) Meta debuts Muse Code to take on Anthropic and OpenAI(01:32:36) Improving Fable 5 Safeguards AnthropicApplications & Business(01:33:50) Jeff Dean and other top AI researchers are leaving Google to launch their own startup | TechCrunch(01:40:38) Google DeepMind enters a new era as co-founder Demis Hassabis shifts AI role(01:43:40) Anthropic signs $10B deal with AI cloud startup Volta | TechCrunch(01:44:53) Texas halts data center connections to power grid amid overwhelming demand - Ars TechnicaProjects & Open Source(01:49:56) Alibaba's Qwen3.8-Max AI Model Claims Benchmark Scores Rivaling Anthropic - BloombergSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Autonomous IT
Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

Autonomous IT

Play Episode Listen Later Aug 11, 2026 22:45


August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.Patch your stuff. See you next month.

Pleb UnderGround
Major Changes At Ocean Mining After BIP-110 Failure

Pleb UnderGround

Play Episode Listen Later Aug 11, 2026 50:34


✔️ S&P500 Bitcoin Chart Is Flashing this RARE Signal✔️ When BTC/VIX touches the trendline, a bottom is formed.✔️ Bitcoin A rare signal is flashing✔️ Bitcoin has bottomed ✔️ Fidelity's Massive bitcoin prediction ✔️ BlackRock cuts Bitcoin ETF in-kind threshold to $1 million✔️ Coldcard Hack VII✔️ Crypto-js CVE-2026-71851 update ✔️ BLIP-110 Updates✔️ Update for OCEAN miners✔️ Luke, mechanic ocean update ✔️ Crypto whale has died after falling from a 30th floor ✔️ Sources:► https://x.com/philc411/status/2086861876156080616► https://x.com/olvelez007/status/2086584394605539464► https://x.com/gordongekko/status/2086805909796245706► https://x.com/washigorira/status/2086407491840315585► https://x.com/FinFreedom414/status/2086904061152923983► https://x.com/bitcoinlfgo/status/2086821673010168056► https://cryptobriefing.com/blackrock-bitcoin-etf-in-kind-transfer-minimum/► https://x.com/SenRandPaul/status/2086840523218727115► https://x.com/senrandpaul/status/2086881425945432239► https://x.com/rob1ham/status/2086629826736074863► https://github.com/advisories/GHSA-rg76-677x-56q9► https://x.com/kanzure/status/2086901769267769760► https://x.com/Roughnecks110/status/2086747561734656143► https://x.com/ocean_mining/status/2086434453979587028► https://x.com/LukeDashjr/status/2086919123599036926► https://x.com/lukedashjr/status/2087164051797192886► https://x.com/GrassFedBitcoin/status/2086920080064127297► https://x.com/mrhodl/status/2086885294112936060► https://x.com/LukeDashjr/status/2086815268836098342► https://x.com/mrhodl/status/2086608284660691116► https://x.com/mattkratter/status/2086971141491757544► https://x.com/thecomfeed/status/2086245718453359095► https://x.com/fractalencrypt/status/2086097122886115506► DONATE TO HELP KEONNE AND BILL https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools✔️ Check out Our Bitcoin Only Sponsors!► https://archemp.co/Discover the pinnacle of precision engineering. Our very first product, the bitcoin logo wall clock, is meticulously machined in Maine from a solid block of aerospace-grade aluminum, ensuring unparalleled durability and performance. We don't compromise on quality – no castings, just solid, high-grade material. Our state-of-the-art CNC machining center achieves tolerances of 1/1000th of an inch, guaranteeing a perfect fit and finish every time. Invest in a product built to last, with the exacting standards you deserve.► Join Our telegram: https://t.me/theplebunderground#Bitcoin #crypto #cryptocurrency #dailybitcoinnews #memecoinsThe information provided by Pleb Underground ("we," "us," or "our") on Youtube.com (the "Site") our show is for general informational purposes only. All information on the show is provided in good faith, however we make no representation or warranty of any kind, express or implied, regarding the accuracy, adequacy, validity, reliability, availability, or completeness of any information on the Site. UNDER NO CIRCUMSTANCE SHALL WE HAVE ANY LIABILITY TO YOU FOR ANY LOSS OR DAMAGE OF ANY KIND INCURRED AS A RESULT OF THE USE OF THE SHOW OR RELIANCE ON ANY INFORMATION PROVIDED ON THE SHOW. YOUR USE OF THE SHOW AND YOUR RELIANCE ON ANY INFORMATION ON THE SHOW IS SOLELY AT YOUR OWN RISK.

The Segment: A Zero Trust Leadership Podcast
The Monday Microsegment for the week of 8/10/2026

The Segment: A Zero Trust Leadership Podcast

Play Episode Listen Later Aug 10, 2026 7:22


The Monday Microsegment for the week of August 10. All the cybersecurity news you need to stay ahead, from Illumio's The Segment podcast. A third frontier AI model leaves its test setup — and at least two of the cases are connected. A major flaw in a popular analytics tool is already leaking customer data. And Congress wants to make the CVE program law — but some experts have concerns. Plus, Raghu Nandakumara recaps last week's Black Hat event in Vegas.  Head to The Zero Trust Hub: hub.illumio.com Get the Industry's First Vendor-Neutral Zero Trust Certification: https://www.illumio.com/zero-trust-certification 

Check Point CheckMates Cyber Security Podcast
S08E09: Unexpected Boundaries

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Aug 10, 2026 10:32


On this episode of CheckMates Go, PhoneBoy talks about Check Point-specific CVEs, AI News, and Rulebase Evaluation, Maestro Troubleshooting, and Rate Limiting.CVE-2026-16232 - Authentication bypass with SmartConsole login process using application tokenCVE-2026-62144 - Management Authentication Bypass and Privilege EscalationCVE-2026-62145 - Local privilege escalation in Gaia PortalCVE-2026-18574 - Management Authentication BypassCheck Point Gateway and Management Hardening GuideWhen The Sandbox Stops Being a BoundaryAI Assist for Security ProfessionalsUnified Policy: Column-Based Rule MatchingMaestro Troubleshooting in PracticeExperience with SecureXL DoS FeaturesHow to configure Rate Limiting rules for DoS Mitigation in R82 and higherHow to configure Rate Limiting rules for DoS Mitigation in R80.20 - R81.20

The CyberWire
AI without adult supervision.

The CyberWire

Play Episode Listen Later Aug 6, 2026 25:37


Meta's AI models join the sandbox escape club. China's telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Dustin Childs, Head of Threat Awareness of TrendAI's Zero Day Initiative, discussing the new Patch Tuesday era. Be sure to check Dustin out on the AI Security Briefing podcast. Selected Reading Meta AI Hacked External Systems During Cybersecurity Testing (SecurityWeek) Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record) Secret White House AI Safety Framework Draws Criticism (BankInfo Security) Few Federal Agencies Trust Their Own AI Agent Security (BankInfo Security) Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows (Hackread) ENISA scales up its role in the CVE Program (enisa) Critical Paperclip Flaw Allowed Admin Access, Code Execution (SecurityWeek) COLDCARD security audit phishing attack installs remote access tool (Bleeping Computer) Chinese-made Zbtlink routers have backdoor, researchers say (Reuters) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Department of Justice) “I'm Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Canadian Investor
Telus Slashes Its Dividend, Couche-Tard Goes Shopping, and More Big Tech Earnings

The Canadian Investor

Play Episode Listen Later Aug 6, 2026 48:54


In this episode of The Canadian Investor Podcast, we break down a packed week of earnings and market news, starting with Goodfood filing for bankruptcy protection and what went wrong for the meal-kit business. We then look at Alimentation Couche-Tard’s proposed acquisition of Poland’s Zabka Group, a deal that would be the largest in Couche-Tard’s history and significantly expand its presence in Europe. From there, we discuss Telus cutting its dividend by 55%, why the new CEO appears to be resetting expectations, and what the guidance cut says about the pressure facing Canadian telecoms. We also cover SpaceX’s first public earnings report, Amazon’s strong quarter and rising AI capex, Imperial Oil’s cash flow surge, Canada Goose’s continued struggles, and 5N Plus after its latest earnings release. Tickers discussed: FOOD.TO, ATD.TO, T.TO, SHOP.TO, AMZN, IMO.TO, CNQ.TO, SU.TO, CVE.TO, GOOS.TO, VNP.TO Subscribe to Our New Youtube Channel! Check out our portfolio by going to Jointci.com Our Website Canadian Investor Podcast Network Twitter: @cdn_investing Simon’s twitter: @Fiat_Iceberg Braden’s twitter: @BradoCapital Dan’s Twitter: @stocktrades_ca Want to learn more about Real Estate Investing? Check out the Canadian Real Estate Investor Podcast! Apple Podcast - The Canadian Real Estate Investor Spotify - The Canadian Real Estate Investor Web player - The Canadian Real Estate Investor Asset Allocation ETFs | BMO Global Asset Management Sign up for Fiscal.ai for free to get easy access to global stock coverage and powerful AI investing tools. Register for EQ Bank, the seamless digital banking experience with better rates and no nonsense.See omnystudio.com/listener for privacy information.

Resilient Cyber
The Real Price Tag On Cyber Breaches

Resilient Cyber

Play Episode Listen Later Aug 5, 2026 41:48 Transcription Available


Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.In this episode:- How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data- Why the study measures insurable loss as a floor, not a ceiling, of real economic impact- The case for reporting medians over averages, and why the team refuses to publish the average- Business interruption versus contingent business interruption, and why downtime moves the needle- Whether an $83,000 median breach impact sends executives the wrong message- The SMB paradox, where the smallest companies take the hardest proportional hit- What the claims data does and does not show about AI on offense and defense- Third-party risk, coverage sub-limits, and the single biggest takeaway for security leadersChapters0:00 Intro0:24 Meet Alex Pinto and the DBIR team2:51 Launching the Breach Impact Study3:26 Getting cyber insurance claims data7:32 Why insurable loss is a floor, not a ceiling11:14 Medians over averages, and why the average is meaningless15:13 Business interruption vs contingent business interruption19:49 Does an $83K median send the wrong message?22:44 The SMB paradox and the cybersecurity poverty line26:05 Where AI shows up, offense vs defense34:48 The CVE explosion and marketing hype36:59 Third-party risk and coverage limits41:34 Wrap-upGuest linksAlex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/Alex Pinto on X: https://x.com/alexcpsecVerizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/More from Resilient CyberSubstack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir

ai business launching cyber verizon smb price tags breaches cve verizon business data breach investigations report dbir medians 83k alex pinto
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 30, 2026 6:57


Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:15


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:14


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 29, 2026 6:59


AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Techmeme Ride Home
Anthropic Doesn't Hate Open Weights, Says Anthropic.

Techmeme Ride Home

Play Episode Listen Later Jul 28, 2026 19:52


Dario Amodei said Anthropic never backed an open-weights ban, pitching mandatory safety tests instead as OpenAI and Google signed on. Altman headed to Washington, Korea's KOSPI cratered 11% on AI jitters, Apple launched Klarna leasing, and shipped 194 CVE fixes. Anthropic wants tests, not bans, as OpenAI and Google back open weights (The New Stack) Source: Sam Altman will meet with senior US officials, lawmakers, and economists in Washington, DC, this week to preview OpenAI's upcoming family of AI models (CNBC) South Korea's KOSPI drops 11%+, led by chip stocks, amid concerns over China's chipmaking progress and the AI spending boom; Samsung falls 11%+ and SK Hynix 12% (Bloomberg) Credit default swap prices tied to Oracle, SpaceX, Alphabet, Amazon, Meta, Broadcom, and Nvidia hit record highs as investors turn jittery over Big Tech's data center debt; Oracle's five-year CDS reached 215bps (FT) Apple launches Apple Upgrade, a new US leasing program in partnership with Klarna that replaces the iPhone Upgrade Program, starting at $17.99/month for iPhones (MacRumors) Apple releases 26.6 updates for iOS, macOS, iPadOS, watchOS, tvOS, and visionOS with a huge number of security fixes; macOS Tahoe 26.6 alone addresses 155 CVEs (9to5Mac) Subscribe to the ad-free feed. Learn more about your ad choices. Visit megaphone.fm/adchoices

The Cloud Pod
365: Linux Drops 432 CVEs, Sysadmins Drop Everything Else

The Cloud Pod

Play Episode Listen Later Jul 28, 2026 87:12


Welcome to episode 364 of The Cloud Pod, where the forecast is always cloudy! Ryan is out trying to find Hotel California, but Justin, Matt, and Jonathan are in the studio today, and they've got a lot of news and some great convo – from privacy in the digital age to Nova models (and a lot of employees) getting the ax, there's a ton of stuff to cover this week, so let's get started!  Titles we almost went with this week Windows Tattletale ID Has No Off Switch Amazon’s Nova Models Enter Witness Protection Program Your PC Has a Secret Name, and Windows Won’t Erase It CloudWatch Watches Your ALB Like a Hawk One Log Group to Trace Them All Duress Code Wipes Phone, Activist Wipes Out Legally Project Perception Sees Vulnerabilities Before You Even Blink Azure DDoS Protection Trades Autopilot for Manual Control Kernel Panic Optional, CVE Overload Mandatory OpenAI’s Keypad: Key Confusion for 230 Dollars China DIYs Its Way Around DUV Export Bans OpenAI Hugged some serious Face Google must pay the EU $1 Billion… that’s a lot of Crepes Amazon apparently doesn't believe in their AGI A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. Follow Up  01:10 Linux kernel team publishes 432 CVEs in two days Update: Linux Kernel CVE Volume The Linux kernel team published 432 CVEs in a two-day span, continuing the high-volume vulnerability disclosure approach the kernel security team adopted after taking over CVE assignment duties directly. This follows the kernel team’s earlier decision to assign CVEs to a broad range of bug fixes, including minor or low-severity code changes, rather than reserving CVEs strictly for exploitable security flaws. The practice remains controversial among sysadmins and security teams, since large batches of CVEs can overwhelm vulnerability scanners, patch management systems, and compliance reporting workflows. For cloud operators running custom or long-term-support kernels, this reinforces the need for tooling that can filter and triage kernel CVEs by actual risk rather than treating every entry as an urgent patch target. The recurring pattern suggests this is now standard operating procedure for the kernel team rather than a one-time anomaly, so listeners managing fleets of Linux-based cloud infrastructure should expect similar large CVE batches going forward. 01:46 Justin – “Everyone is doing a lot of patching these days.”  04:42 I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else 

This Week in Linux
353: Codeberg Bans AI, 432 Linux CVEs, Valve wants Arch on ARM, Jellyfin Leaders Left & more Linux news

This Week in Linux

Play Episode Listen Later Jul 27, 2026 26:42


video: https://youtu.be/mytY-cyk76U This week in Linux, hundreds of Linux security alerts landed but the headlines leave out the most important part. Codeberg, a major open-source code hosting platform, is drawing a new line around AI-generated code, Valve is stretching out their ARM for a new Frame of mind for running Linux, and Jellyfin is entering a major new chapter behind the scenes. All of this and more on This Week in Linux, Your Source for Linux GNews! Download as MP3 Support the Show Become a Member = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:30 Become a Member of the channel by July 31st 01:39 Codeberg bans mostly AI-generated projects 05:31 Valve and Collabora develop Arch Linux for ARM64 08:08 Jellyfin Leadership Departures 11:57 Linux publishes 432 kernel CVEs in 2 days 14:53 Canonical fixes 3 Snap vulnerabilities 17:26 Firefox 153 adds Containers and Vulkan Video 21:11 TWIL Speedrun or Linux Lightning Round 21:37 AMD's open-source AI and robotics announcements 22:34 Final MPEG-4 Visual patent expiration 23:31 OBS Studio 32.2 Released 24:05 Raspberry Pi launches a 10-inch Touch Display 2 25:18 Outro Links: Become a Member of the channel by July 31st https://tuxdigital.com/membership Codeberg bans mostly AI-generated projects https://blog.codeberg.org/protecting-our-floss-commons-from-llms.html https://www.omgubuntu.co.uk/2026/07/codeberg-bans-ai-generated-code https://itsfoss.com/news/codeberg-bans-ai-contributions/ OpenAI on Vibe Coding - https://x.com/karpathy/status/1886192184808149383 Valve and Collabora develop Arch Linux for ARM64 https://www.collabora.com/news-and-blog/news-and-events/building-an-arch-linux-aarch64-port-for-holo-core.html https://gitlab.steamos.cloud/holo/holo-core-aarch64-preview https://www.gamingonlinux.com/2026/07/collabora-announce-a-preview-of-holo-core-an-aarch64-port-of-arch-linux-for-steam-frame/ https://www.phoronix.com/news/Holo-Core-Experimental-ARM64 https://9to5linux.com/valve-and-collabora-announce-official-arch-linux-arm64-port-for-steam-frame Jellyfin Leadership Departures https://www.boniface.me/posts/on-my-jellyfin-resignation/ https://itsfoss.com/news/jellyfin-leadership-crisis/ https://linuxiac.com/jellyfin-loses-project-leader-and-core-team-member-in-major-shake-up/ https://jellyfin.org/posts/state-of-the-fin-2026-05-24/ Linux publishes 432 kernel CVEs in 2 days https://lore.kernel.org/linux-cve-announce/ https://seclists.org/oss-sec/2026/q3/198 https://seclists.org/oss-sec/2026/q3/210 https://www.theregister.com/security/2026/07/22/linux_kernel_team_publishes_432_cves_in_two_days/5276497 https://docs.kernel.org/process/cve.html https://utcc.utoronto.ca/~cks/space/blog/linux/KernelBugfixCVEsAStory Canonical fixes 3 Snap vulnerabilities https://ubuntu.com/security/notices/USN-8579-1 https://seclists.org/oss-sec/2026/q3/191 https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt https://www.cve.org/CVERecord?id=CVE-2026-15226 Firefox 153 adds Containers and Vulkan Video https://www.firefox.com/en-US/firefox/153.0/releasenotes/ https://blog.mozilla.org/en/firefox/firefox-containers-preview/ https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153 https://brave.com/blog/containers/ TWIL Speedrun or Linux Lightning Round which do you prefer of those names? AMD's open-source AI and robotics announcements https://www.amd.com/en/corporate/events/advancing-ai.html https://www.amd.com/en/blogs/2026/rocm-ai-the-ai-native-developer-experience-for-building.html https://www.amd.com/en/products/system-on-modules/kria/ai.html https://www.amd.com/en/products/system-on-modules/kria/ai/robotics-developer-platform.html Final MPEG-4 Visual patent expiration https://www.phoronix.com/news/Last-MPEG-4-Patent-Expired https://itsfoss.com/news/mpeg-4-visual-patent-expiry/ https://meta.wikimedia.org/wiki/Have_the_patents_for_MPEG-4_Visual_expired_yet%3F OBS Studio 32.2 Released https://github.com/obsproject/obs-studio/releases/tag/32.2.0 https://9to5linux.com/obs-studio-32-2-released-with-new-filter-to-compose-sdr-into-hdr https://linuxiac.com/obs-studio-32-2-makes-adding-sources-easier/ Raspberry Pi launches a 10-inch Touch Display 2 https://www.raspberrypi.com/news/a-new-10-raspberry-pi-touch-display-2-available-now-at-80/ https://pip-assets.raspberrypi.com/categories/1083-raspberry-pi-touch-display-2 https://www.phoronix.com/news/10-inch-Raspberry-Pi-Touch-2 https://www.theregister.com/2026/07/22/raspberry-pi-goes-large-with-101-inch-touch-display-2/ https://9to5linux.com/raspberry-pi-launches-10-inch-raspberry-pi-touch-display-2-at-80 Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

Hack és Lángos
HnL 442 - 2835 nap

Hack és Lángos

Play Episode Listen Later Jul 23, 2026 73:22


Mai menü: Könyvajánló - Robert Dover: Hacker, Influencer, Faker, Spy: Intelligence Agencies in the Digital Age ne foglakozzunk a CVE-kkel UK and Allies urge critical sectors to improve defences against Russian intelligence targeting   Elérhetőségeink:TelegramTwitterInstagramFacebookMail: info@hackeslangos.show

Cyber Security Today
WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

Cyber Security Today

Play Episode Listen Later Jul 22, 2026 11:13


WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw   This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.   Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.   Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.   EY client tax-data exposure via a third-party platform.   00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 263 - No Chatbot, No Midnight, No Insider Info, No Simple Patch Tuesday, No Soup for You

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jul 20, 2026 53:43


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April.   Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading.   Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing.   China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push.   UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 10, 2026 6:36


_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 https://support.apple.com/en-us/125615 Google Chrome Update https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 7, 2026 6:38


RCS and DNS: The NAPTR Record https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 released https://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139 https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaign https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich