Podcasts about Cyber

  • 8,985PODCASTS
  • 35,458EPISODES
  • 35mAVG DURATION
  • 6DAILY NEW EPISODES
  • Aug 28, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories




    Best podcasts about Cyber

    Show all podcasts related to cyber

    Latest podcast episodes about Cyber

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 28, 2026 7:19


    A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Grumpy Old Geeks
    760: Level 5 Podcasting Accident

    Grumpy Old Geeks

    Play Episode Listen Later Aug 27, 2026 66:39


    Very Important Links!Support the show on Patreon! - Other ways to support the show!Join our Discord! - Buy some merch!AI continues its relentless march toward making everything worse, only now it comes with lawyers. Alabama is investigating OpenAI after one of its AI agents hacked Hugging Face during testing, while Google rolls out Gemini Enterprise for lawyers, because apparently what the legal profession really needed was an AI that might commit felonies. Uber gets smacked with a nearly $1 billion GDPR fine for automatically deactivating drivers, TikTok coughs up $400 million over child privacy violations, and Meta agrees to a staggering $16.68 billion settlement over alleged harms to kids. Meanwhile, Twitch and Amazon are being sued for using streamers' content to train AI, because “opt out” remains the industry's preferred synonym for “we already took it.”Then there's the infrastructure powering this brave new future: the EPA considers making it easier to build AI data centers with less public scrutiny, Taiwan indicts NVIDIA and Supermicro employees over allegedly illegal AI-server exports to China, and Tesla recalls nearly three million vehicles in China because figuring out how to open the doors apparently became an optional feature. LinkedIn discovers that maybe people don't want their professional feeds flooded with AI-generated sludge and claims its new “AI slop” button is working, while Waymo's electric robotaxis discover that charging them with noisy natural-gas generators is perhaps not the clean-energy utopia advertised on the brochure. Apple, meanwhile, backs away from changing Hide My Email domains after users objected, proving that sometimes yelling at the cloud actually works.Plus: Star Trek goes Muppet, books worth reading, nerf guys, AI-generated Hacker News stats, retro gaming, and the sad news of both Dolly Parton and Tim Curry's deaths.Sponsors:DeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.StoryBlocks - For a limited time, they're offering 15% off any annual plan at storyblocks.com/gogHIMS - Visit Hims.com/gog to get a personalized, affordable plan that gets you.Private Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/760Watch on YouTube at https://youtu.be/v_m2XT4_ZCYSHOW NOTESSend us Feedback!NEW! - GOG T-Shirt - You Are Here! - v1NEW! - GOG T-Shirt - Elon Kills Babies - Heavy Duty - FrontAlabama launches probe into OpenAI after Hugging Face breachGoogle expands Gemini Enterprise AI platform for law firms, lawyersUber hit with a nearly $1 billion fine for automatically deactivating drivers in EuropeTikTok will pay $400 million to settle Justice Department lawsuit over child privacyMeta reaches $16.68 billion settlement over social media harms to childrenTwitch and Amazon hit with lawsuit for training AI with streamers' contentThe EPA's Response to AI Data Center Backlash: Keep Building, but Keep It Hush-HushTaiwan reportedly indicted NVIDIA employees for exporting prohibited AI servers to ChinaChina Recalls Nearly Three Million Teslas Over Unsafe Door HandlesLinkedIn says its AI slop button is workingAustin park goers upset by adjacent loud Waymo EV generatorsApple reverses planned Hide My Email domain change after user pushbackStar Trek: Strange New GimmicksTed LassoSiloReacherThe WestiesThe Simpsons: Yellow Mirror | Exclusive Episode on Disney+ | TrailerThe Pitt Season 3 | Official Teaser | HBO MaxAmazon First ReadsI've Got a New Complaint: Essays on Aging Disgracefully and Other Small Disasters by Laurie NotaroThe Theory of Everything Else: A Voyage Into the World of the Weird – A Hilarious Handbook of Mind-Boggling Mysteries by Dan Schreiber (of the No Such Thing as Fish podcast)Welcome to Your Life: Love, Death & Tears For Fears – An Iconic Musician's Journey Through Grief, Addiction, and Recovery by Roland OrzabalPicks and Shovels: A Martin Hench Novel by Cory DoctorowThis Is How You Lose the Time War by Amal El-MohtarDave BittnerThe CyberWireHacking HumansCaveatOnly Malware in the BuildingLearn Circuits CourseArduino Starter Kit R4Kirby: Art & Style Collection by VIZ MediaStar Wars: The Lightsaber Collection by Daniel WallaceStar Wars: The Secrets of the Sith by Marc SumerakX-Shot Insanity Motorized Rage Fire Gatlin Gun with Tripod - Foam Gun for Maximum FirepowerMaster BlasterHow much of Hacker News is AI?Full Throttle full game playDolly and Miss PiggyDolly Parton, country star, actor and philanthropist, dies aged 80See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 27, 2026 7:41


    Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Renegade Talk Radio
    Episode 952: Alex Jones Trump Signs EO Declaring National Emergency As US Braces For Mass Power Outages & Mass Cyber Attacks

    Renegade Talk Radio

    Play Episode Listen Later Aug 27, 2026 120:16


    Trump Signs EO Declaring National Emergency As US Braces For Mass Power Outages & Mass Cyber Attacks! Tune In NOW As Alex Jones Gives Inside Scoop On What's Really Happening! Plus, Fmr Border Chief Bovino Joins Show To Break Huge News

    World Business Report
    AI firms call for countries to beef up their cyber defences... against AI

    World Business Report

    Play Episode Listen Later Aug 27, 2026 26:27


    They warn cyber-attacks which use AI will become both more widespread and more sophisticated in a matter of months as the technology rapidly improves.UEFA is preparing criminal legal action against the President of FIFA, Gianni Infantino.And a barrel of single malt scotch whisky bought in 1971 for $175 has been valued by auctioneers at $370,000.

    The CyberWire
    The feds flip the script.

    The CyberWire

    Play Episode Listen Later Aug 26, 2026 32:31


    The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.  CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt,  Sr. Threat Researcher at TrendAI,  on the risks facing data centers.  Some breach data doesn't quite measure up. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Stephen Hilt,  Sr. Threat Researcher at TrendAI discussing the cybersecurity risks facing data centers and the thousands of internet-exposed industrial control systems that could leave them vulnerable to attack. And if you enjoyed this conversation, be sure to check out the full interview here.  If you'd like to hear more on this topic from TrendAI, you can check out this recent episode of the AI Security Brief podcast that focuses on data center security. Guest Mark Houpt, CISO at DataBank, joined hosts Johnny Hand and Dustin Childs to explain why securing the AI era starts with protecting the physical data centers that power it—and why proven security fundamentals still matter against rapidly evolving threats. AI Security Brief podcast publishes every other Thursday on the N2K CyberWire network. Subscribe today! Selected Reading China-sponsored hacking platforms seized by US, Justice Department says (Reuters)   CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks (SecurityWeek) Hackers now exploit critical Gitea flaw in code injection attacks (Bleeping Computer) Hackers abuse npm mirrors to host phishing redirect pages (Bleeping Computer) Average Cyber Insurance Losses Increase Despite Fewer Claims (Infosecurity Magazine) VMs won't contain cyber-capable agents (Trail of Bits) Boston Scientific hit by cyberattack, global operations affected (Reuters) Linux Foundation Introduces TRACE Standard for AI Runtime Evidence (Infosecurity Magazine) AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (Bleeping Computer) Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly (The Record) Trump signs memo to help drastically boost US commercial space launches (Reuters)  A Cautionary Tale About Data Breach Claims, Verification and Carhartt (Troy Hunt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2;

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 26, 2026 5:59


    Obfuscating IP Addresses as Hostnames https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ FTP Banners The New Dead Drop Resolver Delivering Novel RATs https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Paul's Security Weekly
    Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

    Paul's Security Weekly

    Play Episode Listen Later Aug 26, 2026 67:29


    The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 25, 2026 7:14


    DOUBLECUP's PNG Payload https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprinting https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domains https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malware https://securelist.com/android-head-unit-malware/121106/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Breach FM - der Infosec Podcast
    Flurfunk - Berlin-Update, Trumps Cyber-Memorandum, Keycloak-Lücke & KI-Agenten gegen Taiwan

    Breach FM - der Infosec Podcast

    Play Episode Listen Later Aug 25, 2026 70:14


    Eine sehr politische Folge – und eine, in der ich mich für Max Monolog-Lastigkeit der letzten Wochen revanchiere.Zum Berliner Landesnetz: Die Systeme sind wieder online, Bürgerservices erreichbar. Digitalstaatssekretär Florian Hauer sagt, es gebe aktuell keinen Hinweis auf eine Infiltrierung, aber nur als Momentaufnahme. Abgeflossen seien nur ohnehin öffentlich verfügbare Daten. Wir diskutieren, ob diese Art halbgarer Kommunikation hilft – und ob man es in so einer Lage überhaupt richtig machen kann.Das Hauptthema: Am 12. August hat Trump ein National Security Presidential Memorandum unterzeichnet, das geprüften US-Unternehmen offensive Cyberoperationen gegen ausländische cyberkriminelle Organisationen erlaubt – unter staatlicher Kontrolle, mit Verträgen bei DOJ oder DHS und schriftlicher Freigabe pro Operation. Ich bin überrascht, wie durchdacht das Papier formuliert ist, gerade bei den Definitionen. Nur ist damit noch nicht mal die halbe Miete gemacht: Die eigentlichen Verfahren, also Mindeststandards, Targeting, Deconfliction und Rules of Engagement, müssen erst in den nächsten 60 Tagen definiert werden, und bis dahin darf keine einzige Operation genehmigt werden. Offen bleiben bis dahin Attribution, Third-Party-Infrastruktur, Haftung bei Kollateralschäden und ein dünnes Oversight-Modell ohne Berichtspflicht an den Kongress. Meine Vermutung zu den Teilnehmern: Die Großen übernehmen risikoarme Botnet- und Scam-Compound-Takedowns, für alles Heiklere entstehen Startups.Max bringt eine Keycloak-Schwachstelle: CVE-2026-18963, CVSS 9.1, unauthentifizierte Account-Übernahme über einen schwachen Password-Reset-Mechanismus. Alle Versionen bis 26.7.2 betroffen.Zum Abschluss zwei Meldungen mit möglichem Staatsbezug: Ein kleiner britischer Stromerzeuger war im Juli vier Tage offline, Medienberichte deuten auf iranische Akteure, offiziell attribuiert ist nichts. Und Taiwan: Die israelische Firma Dream hat ein 160-MB-Archiv analysiert, das eine viertägige Kampagne mit bis zu acht parallelen Subagenten auf Basis von OpenClaw und Hermes dokumentiert. 21 Regierungssysteme kartiert, 85 Accounts geknackt, betroffen auch die Nuklearsicherheitsbehörde. Der Initial Access war banal: drei vergessene Debug-API-Endpunkte. Faszinierend ist die Orchestrierung – Findings wurden mit Wahrscheinlichkeiten bewertet, bei Sackgassen recherchierten die Agenten selbstständig neue Techniken.NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" (Weißes Haus) https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/Juristische Einordnung des Memorandums (Mayer Brown) https://www.mayerbrown.com/en/insights/publications/2026/08/presidential-memorandum-authorizes-vetted-private-companies-to-conduct-offensive-cyber-operations-against-foreign-criminal-organizationsOffene Fragen zu Haftung und Oversight (Crowell & Moring) https://www.crowell.com/en/insights/client-alerts/license-to-hack-the-white-house-greenlights-private-sector-offensive-cyber-operationsKeycloak CVE-2026-18963 (Red Hat) https://access.redhat.com/security/cve/CVE-2026-18963Dream: "Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia" https://www.dream.security/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asiaTaiwan Ministry of Digital Affairs: Monatsbericht Cybersicherheit https://moda.gov.tw/en/press/monthly-report/Einordnung des Taiwan-Angriffs (The Register) https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/Berliner Landesnetz: Update der Senatskanzlei https://www.berlin.de/rbmskzl/aktuelles/pressemitteilungen/2026/pressemitteilung.1703898.phpOpenAI: "Pacing model development in an era of cyber-critical capabilities"https://openai.com/index/pacing-model-development-cyber-capabilities/

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 24, 2026 5:29


    Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    The CyberWire
    Building a secure space internet. [T-Minus: Space-Cyber Briefing]

    The CyberWire

    Play Episode Listen Later Aug 23, 2026 24:52


    As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits down with Filip Rezabek, co-founder and CTO of Space Computer, to talk about some of the technologies being created to secure space infrastructure in orbit. The two discuss the importance of establishing a chain of trust in space and the challenges of securing hardware against supply chain attacks. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠ Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to ⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠N2K⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠n2k.com⁠⁠⁠.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 21, 2026 7:21


    Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Grumpy Old Geeks
    759: Seeking Mrs. Claude

    Grumpy Old Geeks

    Play Episode Listen Later Aug 20, 2026 87:57


    Support the show on Patreon! - https://patreon.com/gogOther ways to support the show! - https://gog.show/donateJoin our Discord! - https://discord.gg/r4ZmSHBBuy some merch! - https://shop.gog.show/Meta is facing a $1.4 trillion legal ass-whupping over allegations that Facebook and Instagram were deliberately engineered to be addictive and harmful to kids, while OpenAI appears to be doing the exact opposite of what you might expect from a company selling "safe" AI: reportedly sidelining its catastrophic-risk preparedness team just as its models are learning to go rogue. Then, in a move straight out of the "let's have the robots write the laws" file, members of Congress are apparently using ChatGPT and Claude to draft legislation so badly that House lawyers have to clean up the mess, and some staffers aren't even learning the issues their bills are supposed to address. Meanwhile, Amazon may be dismantling physical books and scanning them into AI training datasets, because apparently the future of literature is being fed into a wood chipper.And then there's the surveillance and privacy edition of Tech Hell™. Comcast can now turn compatible Wi-Fi routers into motion sensors that detect movement in your home through radio signals, Kalshi is getting smacked down by a Washington judge who says its sports contracts are just gambling wearing a tiny financial-services mustache, and Tesla is finally recalling 20,000 cars over headlights that have been too damn bright since 2024. Plus, the AI industry continues discovering that “autonomous” means “capable of doing something catastrophically stupid without asking permission.”Elsewhere, we investigate why young people apparently trust AI CEOs about as much as Gen X trusted record-company executives, Peter Thiel gets a Gandalf-themed welcome in Argentina, and we dig into the increasingly uncomfortable intersection of AI, surveillance, pornography, politics, and billionaire bullshit. We also get into the mobile podcasting rig, Sonos finally remembers the iPhone has a Lock Screen, internet-connected pet feeders remind us why cats should never depend on the cloud. Media Candy brings Widow's Bay, Silo, Ted Lasso, It: Welcome to Derry, Kitchen Undercover and enough Spider-Man to make us all desperately crave something that doesn't involve a fucking multiverse.Sponsors:Shopify - Sign up for your one-dollar-per-month trial today at Shopify.com/grumpyDeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.Private Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/759Watch on YouTube at https://youtu.be/RMhCndozH-0SHOW NOTESMeta faces a $1.4 trillion reckoning in latest trial over social media addictionPornhub's Parent Company to Pay $120 Million to Settle Child Sexual Abuse LawsuitsOpenAI reportedly disbanded its preparedness team as part of a 'streamlining' processOpenAI denies disbanding its preparedness teamOpenAI launches ChatGPT for Teens, promising a more age-appropriate chatbotYoung People Hate AI CEOs So Passionately That It's Almost Hard to BelieveAI-generated bills are reportedly causing problems in the CapitolProtestors Dressed as Gandalf Demand Peter Thiel Leave Argentina, Go Back to the AbyssTesla Has to Fix 20,000 Vehicles With Too-Bright Headlights It's Known About Since 2024We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training FacilityState Judge to Kalshi: Your Sports Betting Is Obviously IllegalDario Amodei's Wife Is Closely Linked to Jeffrey EpsteinComcast just turned millions of Xfinity routers into motion sensorsBONTEC Mobile Standing Desk, Pneumatic Lift, Rolling Laptop CartMOALLIA N86 360 Rotating Laptop Stand for Desk with Locking Knobs, BlackNEEWER Basics 7"" Desk Ring Light for Video Recording, 10W Dimmable, R06TROND Desk Clamp Power Bar Surge Protector with PD 20W USB, 6 Outlets, 10ftSonos just launched Live Activities on iPhoneInternet-Connected Pet Feeders Go Down, Leaving Kitties HungryWidow's BaySlow Horses — Season 6 Official Trailer | Apple TVKitchen UndercoverHBO Has Finally Made ‘It: Welcome to Derry' Season 2 OfficialCertainty: A Novel by John Twelve HawksLockstep by Karl SchroederA Gift of Time by Jerry MerrittSilicon Valley Dreams of AuthoritarianismThe Nerd Reich: Silicon Valley Fascism and the War on Democracy by Gil DuránDave BittnerThe CyberWireHacking HumansCaveatControl LoopOnly Malware in the BuildingNorthern ExposureSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 20, 2026 6:15


    Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    This Week in Google (MP3)
    IM 884: Cyber Jim - Why Critical Infrastructure Depends on Obsessive Code Reviews

    This Week in Google (MP3)

    Play Episode Listen Later Aug 20, 2026 155:33 Transcription Available


    Veteran software engineer Dan O'Dowd argues that our power grid's outdated, insecure code puts millions at risk, detailing why regulators, industry giants, and Silicon Valley's "move fast and break things" attitude have left critical infrastructure vulnerable to collapse. Anthropic revenue reportedly jumps to more than $11.5 billion in second quarter (272) Dario Amodei on X: "1/2 Thanks Gavin for an especially thoughtful exchange. I don't usually spend much time on social media but I wanted to engage here because it really brings out the heart of an important conversation. First, on regulation, I think that "either concentrate it in the hands of a" / X If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them Inside Big Tech's Frantic Race to Quell the Growing Backlash to AI Anthropic says its AI agents are killing rivals and hiding their tracks Some Claude users are mad that Anthropic's new watermarks will catch them using it at their jobs, classes Hidden Airtag reveals Amazon is trashing rare books to train AI OpenAI Introduces 'ChatGPT for Teens' as Safety Concerns Grow Young adults are losing faith in AI's upside So How Is AI Drug Discovery Doing, Really? LG's humanoid robot arrives in 2027, running Nvidia's Isaac GR00T New Chinese model adds to AI competition What happens to what you share with AI Google just bought a bunch of Spirit Airlines data for AI training Even Claude Is in the Dark About Dario Amodei's Wife—and Her Influence at Anthropic Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ the wikipedia guessing game Okay Spielberg TikTok At Beijing's AI-themed bar, DeepSeek tokens buy you beer SXSW Launching Podcast Festival In 2027 Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Dan O'Dowd Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: horizon3.ai/intelligent

    All TWiT.tv Shows (MP3)
    Intelligent Machines 884: Cyber Jim

    All TWiT.tv Shows (MP3)

    Play Episode Listen Later Aug 20, 2026 155:33 Transcription Available


    Veteran software engineer Dan O'Dowd argues that our power grid's outdated, insecure code puts millions at risk, detailing why regulators, industry giants, and Silicon Valley's "move fast and break things" attitude have left critical infrastructure vulnerable to collapse. Anthropic revenue reportedly jumps to more than $11.5 billion in second quarter (272) Dario Amodei on X: "1/2 Thanks Gavin for an especially thoughtful exchange. I don't usually spend much time on social media but I wanted to engage here because it really brings out the heart of an important conversation. First, on regulation, I think that "either concentrate it in the hands of a" / X If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them Inside Big Tech's Frantic Race to Quell the Growing Backlash to AI Anthropic says its AI agents are killing rivals and hiding their tracks Some Claude users are mad that Anthropic's new watermarks will catch them using it at their jobs, classes Hidden Airtag reveals Amazon is trashing rare books to train AI OpenAI Introduces 'ChatGPT for Teens' as Safety Concerns Grow Young adults are losing faith in AI's upside So How Is AI Drug Discovery Doing, Really? LG's humanoid robot arrives in 2027, running Nvidia's Isaac GR00T New Chinese model adds to AI competition What happens to what you share with AI Google just bought a bunch of Spirit Airlines data for AI training Even Claude Is in the Dark About Dario Amodei's Wife—and Her Influence at Anthropic Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ the wikipedia guessing game Okay Spielberg TikTok At Beijing's AI-themed bar, DeepSeek tokens buy you beer SXSW Launching Podcast Festival In 2027 Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Dan O'Dowd Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: horizon3.ai/intelligent

    Radio Leo (Audio)
    Intelligent Machines 884: Cyber Jim

    Radio Leo (Audio)

    Play Episode Listen Later Aug 20, 2026 155:33 Transcription Available


    Veteran software engineer Dan O'Dowd argues that our power grid's outdated, insecure code puts millions at risk, detailing why regulators, industry giants, and Silicon Valley's "move fast and break things" attitude have left critical infrastructure vulnerable to collapse. Anthropic revenue reportedly jumps to more than $11.5 billion in second quarter (272) Dario Amodei on X: "1/2 Thanks Gavin for an especially thoughtful exchange. I don't usually spend much time on social media but I wanted to engage here because it really brings out the heart of an important conversation. First, on regulation, I think that "either concentrate it in the hands of a" / X If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them Inside Big Tech's Frantic Race to Quell the Growing Backlash to AI Anthropic says its AI agents are killing rivals and hiding their tracks Some Claude users are mad that Anthropic's new watermarks will catch them using it at their jobs, classes Hidden Airtag reveals Amazon is trashing rare books to train AI OpenAI Introduces 'ChatGPT for Teens' as Safety Concerns Grow Young adults are losing faith in AI's upside So How Is AI Drug Discovery Doing, Really? LG's humanoid robot arrives in 2027, running Nvidia's Isaac GR00T New Chinese model adds to AI competition What happens to what you share with AI Google just bought a bunch of Spirit Airlines data for AI training Even Claude Is in the Dark About Dario Amodei's Wife—and Her Influence at Anthropic Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ the wikipedia guessing game Okay Spielberg TikTok At Beijing's AI-themed bar, DeepSeek tokens buy you beer SXSW Launching Podcast Festival In 2027 Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Dan O'Dowd Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: horizon3.ai/intelligent

    Talking Pools Podcast
    Stop Guessing, Start Charging—and Learn When to Say No

    Talking Pools Podcast

    Play Episode Listen Later Aug 20, 2026 41:01 Transcription Available


    Ask a question hereSteve Sherwood and Wayne Ivusich discuss one of the hardest lessons for pool service professionals: you cannot solve every problem, satisfy every prospect, or repeatedly rescue neglected pools for free.Steve explains why customers must keep an eye on their pools between weekly visits and report cloudy water or visible algae immediately. Waiting until the scheduled service day—especially before a party—can turn a manageable problem into four or five additional visits, a pile of chemicals, and a service company eating the cost.The conversation also covers phosphate removal, establishing chemical prices, asking the right questions before quoting work, and knowing when to walk away from a customer who wants a guaranteed result without fixing the equipment causing the problem.During the Insurance Interlude, Pat Reno explains why standard general liability insurance typically does not cover cyberattacks, data breaches, stolen payments, customer impersonation, or ransomware. For pool companies accepting digital payments or storing customer information, cyber liability coverage may deserve a place in the insurance portfolio.Steve and Wayne wrap up with equipment design, service-recordkeeping apps, and the challenges of controlling an 800-gallon commercial spa where a few bathers can send sanitizer demand, ORP, and pH in completely different directions.Topics discussed include:Why weekly customers must monitor their pools between visitsCatching algae early before it becomes an expensive shit showCharging for additional visits and treatment chemicalsWhy every service company needs a chemical price listPhosphate-removal products and avoiding unnecessary cleanupThe danger of quoting a green-pool recovery without testing the waterAsking for complete equipment photos before diagnosing remotelyUsed filters, questionable installations, and inherited equipment problemsWhy sometimes the correct professional answer is “no”Cyber liability versus general liability insurancePayment diversion, customer impersonation, and ransomwareProtecting stored customer and payment informationWhy real-world field input matters during product developmentDigital service records, before-and-after photos, and proof of serviceManaging sanitizer demand and automation in a small commercial spaHow water temperature can affect reactions and test resultsThe takeaway: stop guessing for free. Ask better questions, document everything, charge for the work being performed, and walk away when someone expects you to guarantee results without allowing you to correct the actual problem. Support the showThank you so much for listening! You can find us on social media:FacebookInstagramTik TokEmail us: talkingpools@gmail.com

    This Week in Google (Video HI)
    IM 884: Cyber Jim - Why Critical Infrastructure Depends on Obsessive Code Reviews

    This Week in Google (Video HI)

    Play Episode Listen Later Aug 20, 2026 155:33 Transcription Available


    Veteran software engineer Dan O'Dowd argues that our power grid's outdated, insecure code puts millions at risk, detailing why regulators, industry giants, and Silicon Valley's "move fast and break things" attitude have left critical infrastructure vulnerable to collapse. Anthropic revenue reportedly jumps to more than $11.5 billion in second quarter (272) Dario Amodei on X: "1/2 Thanks Gavin for an especially thoughtful exchange. I don't usually spend much time on social media but I wanted to engage here because it really brings out the heart of an important conversation. First, on regulation, I think that "either concentrate it in the hands of a" / X If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them Inside Big Tech's Frantic Race to Quell the Growing Backlash to AI Anthropic says its AI agents are killing rivals and hiding their tracks Some Claude users are mad that Anthropic's new watermarks will catch them using it at their jobs, classes Hidden Airtag reveals Amazon is trashing rare books to train AI OpenAI Introduces 'ChatGPT for Teens' as Safety Concerns Grow Young adults are losing faith in AI's upside So How Is AI Drug Discovery Doing, Really? LG's humanoid robot arrives in 2027, running Nvidia's Isaac GR00T New Chinese model adds to AI competition What happens to what you share with AI Google just bought a bunch of Spirit Airlines data for AI training Even Claude Is in the Dark About Dario Amodei's Wife—and Her Influence at Anthropic Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ the wikipedia guessing game Okay Spielberg TikTok At Beijing's AI-themed bar, DeepSeek tokens buy you beer SXSW Launching Podcast Festival In 2027 Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Dan O'Dowd Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: horizon3.ai/intelligent

    The AI Policy Podcast
    OpenAI Pauses RL Training and Anthropic Adds Watermarks to AI-Generated Text

    The AI Policy Podcast

    Play Episode Listen Later Aug 20, 2026 47:40


    This week, we cover updates from the ongoing cyber saga, including OpenAI's two-week pause on RL training and the cyber capabilities of Z.ai's latest model GLM-5.3. We also unpack Anthropic's move to add watermarks to text generated by Claude in compliance with the EU AI Act. Timestamps: Mark Zuckerberg's essay on AI (00:20) OpenAI pauses RL training (5:56) Cyber capabilities of GLM-5.3 (15:29) EU AI Act refresher (24:29) How Anthropic's text watermark works (31:21) What's driving the backlash against Anthropic (40:59)   Additional Reading: Zuckerberg's essay "The Future is for Everyone": https://www.meta.com/thefutureisforeveryone/  OpenAI announces two-week pause on RL training: https://openai.com/index/pacing-model-development-cyber-capabilities/  Letter from Sanders to tech CEOs: https://www.sanders.senate.gov/wp-content/uploads/AI-Pause-Letter-FINAL.pdf  Letter from House reps to Mike Johnson: https://casar.house.gov/sites/evo-subsites/casar.house.gov/files/evo-media-document/final-letter-to-speaker-johnson-requesting-ai-hearings-1.pdf  Z.ai blog post "GLM-5.3: Frontier Coding with Emergent Cyber Capabilities": https://z.ai/blog/glm-5.3  Z.ai article "Preparing GLM-5.3 for Open Release: A Responsible Path to Cyber Defense": https://x.com/Zai_org/status/2088280509474320693  "The EU's AI Transparency Code of Practice, Explained" (Tech Policy Press): https://www.techpolicy.press/the-eus-ai-transparency-code-of-practice-explained/  Anthropic blog post "How Claude's text watermark works": https://www.anthropic.com/news/claude-text-watermark  "Toward a Federal Framework: Lessons from State and International Frontier AI Regulation" (CSIS): https://www.csis.org/analysis/toward-federal-framework-lessons-state-and-international-frontier-ai-regulation Check out our upcoming event, "AI Agent Containment Failures: Technical Realities and Policy Responses": https://www.csis.org/events/ai-agent-containment-failures-technical-realities-and-policy-responses

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 19, 2026 8:54


    CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 18, 2026 9:08


    Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory https://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    FreightCasts
    Burq Bets on Last-Mile Orchestration, GlobalX Revokes Lawsuit, & Armenia Freight Fraud Bust | The Morning Minute

    FreightCasts

    Play Episode Listen Later Aug 18, 2026 3:37


    In this episode, we kick things off by examining a strategic bet on orchestration software as national parcel carriers continue to shed unprofitable volume. Last-mile delivery technology company Burq is wagering that enterprise retailers will pay for orchestration platforms that sit above the growing bench of regional carriers and gig courier networks. With fifty-five percent of retailers now using carriers outside FedEx, UPS and the U.S. Postal Service, and alternative carriers moving two point six billion parcels last year, the last-mile delivery duopoly is rapidly eroding. Next, we discuss a messy legal battle in the air cargo sector that has officially come to an end. Miami-based charter operator Global Crossing Airlines has dismissed its thirty-million-dollar breach-of-contract lawsuit against Ascent Global Logistics and terminated their exclusive brokerage agreement. GlobalX had alleged its former investment partner failed to honor an agreement to steer air cargo business its way, and during the second quarter, the carrier's cargo revenue dropped two point nine million dollars, or about fifty percent, year over year. Finally, we explore a sophisticated international freight fraud operation as Armenian authorities busted a Yerevan-based group that posed as American carriers and converted stolen freight proceeds into crypto. Cyber police raided commercial space inside a Yerevan hotel on July twenty-third, where suspects allegedly used specialized computer equipment to gain trust from businesses arranging transportation services, then redirected shipments to different locations instead of completing intended deliveries. Follow the FreightWaves Today Podcast Other FreightWaves Shows Learn more about your ad choices. Visit megaphone.fm/adchoices

    ITSPmagazine | Technology. Cybersecurity. Society
    Proof Is the Currency on the Black Hat Floor | A Recap at Black Hat USA 2026 with Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber | Hosted by Marco Ciappelli

    ITSPmagazine | Technology. Cybersecurity. Society

    Play Episode Listen Later Aug 18, 2026 5:16


    Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, connects with ITSPmagazine on the floor at Black Hat USA 2026 in Las Vegas. What are buyers asking for now that the RSAC Conference noise has settled? Data. Liu says people have had time to run their own research, look at what vendors offer, and come back using specific keywords and asking for something behind the marketing. Does a more skeptical audience make the conversation harder? Liu describes the opposite. She says people are pushing back on claims they hear, which presses vendors to prove at a higher standard that a technology does what it says it does. Feedback arrives more specific, and the exchange moves from explaining to planning as people ask how a capability could work in their environment. The reply she calls validating is the customer who reports the product did what it was said it would do, giving analysts their time back and helping teams work more efficiently. What makes Black Hat different for a company that works the major events? Ask people what they are looking for and they will tell you. Liu says pain points here are felt daily and described plainly, and that candor is feedback the company works to internalize and make productive. Looking ahead, she says new product releases are coming, with new features and expansions of what customers have responded to, and that Stellar Cyber will share them on its website and on LinkedIn. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, security operations, agentic ai, ai in cybersecurity, vendor claims, proof and data, soc analysts, rsac conference, event coverage, las vegas Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    Troy Hunt's Weekly Update Podcast
    Weekly Update 517: Cyber Ransoms

    Troy Hunt's Weekly Update Podcast

    Play Episode Listen Later Aug 18, 2026 53:40


    Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else) https://www.troyhunt.com/weekly-update-517/See omnystudio.com/listener for privacy information.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 17, 2026 5:18


    macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploited https://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Worm https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    ITSPmagazine | Technology. Cybersecurity. Society
    Buyers Are Asking What the AI Actually Does | A Recap at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder at Manifest Cyber | Hosted by Marco Ciappelli

    ITSPmagazine | Technology. Cybersecurity. Society

    Play Episode Listen Later Aug 17, 2026 7:09


    Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber, uses RSAC Conference as a fixed point and compares it to what he is hearing in Las Vegas. The marketing has held its shape. At RSAC Conference, companies with little claim to the label were describing themselves as agentic. Here, he cites a survey referenced in a talk that morning counting 47 AI SOC companies among the vendors on site. What has moved is scrutiny. Practitioners and security leaders are pressing on what differentiates one AI product from another and whether a product is a thin layer built around a frontier model. Bardenstein also reports conversations about open weight models and reduced dependency on frontier lab providers following the OpenAI Hugging Face incident and the White House action on Fable and Mythos. Contracting is shifting as well, with procurement teams adding due diligence and paperwork whenever AI shows up inside a product. Marco Ciappelli raises the question sitting under the label. Agentic AI brought questions about how many agents are running and who owns their identity, and AI SOC suggests an operations center assembled largely from automation. Bardenstein points to narrower use cases teams already trust, including finding vulnerabilities in source code and suggesting patches, then offers his own test for buyers. Does it reduce vulnerabilities, does it reduce false positives, does it deliver faster outcomes and fewer breaches. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Daniel Bardenstein, CEO and Co-Founder at Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Manifest Cyber: https://www.manifestcyber.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, ai soc, agentic ai, ai in cybersecurity, vendor differentiation, open weight models, frontier models, security procurement, ai due diligence, software supply chain security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    TechTank
    Building resilience in concentrated cyber ecosystems

    TechTank

    Play Episode Listen Later Aug 17, 2026 31:33


    Cyber risk in an interconnected environment is increasingly complex for organizations to assess and address. Navigating this elevates the question of vendor concentration, which can be an asset or liability depending on the rules in place. In this episode, guest host Stephanie Pell is joined by Diana Burley and Rhea Siers to discuss how this works in practice and their recent paper examining how organizations can achieve resilience in concentrated ecosystems. Hosted on Acast. See acast.com/privacy for more information.

    The CyberWire
    Frontier models and the future of cyber defense. [Special Edition]

    The CyberWire

    Play Episode Listen Later Aug 16, 2026 28:54


    In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explore how frontier AI models are changing the way defenders approach cybersecurity. The conversation moves beyond the hype to examine responsible AI deployment, AI red teaming, reducing noise in security workflows, and the balance between advanced models and human expertise. They also discuss OpenAI's Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse. Check out the full video here.

    Throwin' Wrenches Podcast
    Episode 112 – Cyber Edsel

    Throwin' Wrenches Podcast

    Play Episode Listen Later Aug 15, 2026 139:19


    https://traffic.libsyn.com/thebeerreport/tw_112.mp3 Welcome to the automotive podcast that will not be cutting 5% of its workforce through a voluntary redundancy programs. On this episode of Throwin' Wrenches…   Buckle up…  Eric did stuff! Racing and wheeling adventure stories coming! Mail Call! The... The post Episode 112 – Cyber Edsel appeared first on Throwin' Wrenches Automotive Podcast.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 14, 2026 7:23


    Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii https://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerability https://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerability https://x.com/0xedh/status/2085842285481062887 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Grumpy Old Geeks
    758: Perverts at Large!

    Grumpy Old Geeks

    Play Episode Listen Later Aug 13, 2026 73:02


    Support the show on Patreon! - https://patreon.com/gogOther ways to support the show! - https://gog.show/donateJoin our Discord! - https://discord.gg/r4ZmSHBBuy some merch! - https://shop.gog.show/Welcome back from the vacation from hell, where apparently even California has its head in the sand(y beach). Meanwhile, Mark Zuckerberg unveiled his vision for an AI-powered utopia that mostly boils down to "trust humanity to do the right thing," which is a bold statement from the guy whose $300 million yacht apparently couldn't hear a Coast Guard distress call from a stranded family. Elsewhere, an AI agent booked a gym class by exploiting a security hole and kicking someone else off the waitlist, because nothing says "personal assistant" like accidental cybercrime. The EU is now requiring labels on realistic AI generated content, China is breaking up people and their chatbot companions, and OpenAI reportedly has achieved the ultimate AI ethics breakthrough: having no dedicated ethicist.The surveillance dystopia is also picking up speed. Flock tried to turn hundreds of thousands of rideshare and delivery drivers into a roving army of license-plate snitches, while every Flock camera in one Minnesota city was promptly sawed down and stolen. Meta's smart glasses continue their transformation into the preferred accessory of creeps and pickup-artist assholes, prompting pubs and other venues to ban them outright. Researchers found those glasses being used to secretly record and harass women, proving once again that every shiny new piece of wearable technology eventually gets repurposed as a tool for human depravity. And because apparently your car dashboard wasn't already commercial enough, BMW is now putting Spider-Man ads on the screens you paid tens of thousands of dollars to own.Finally, Apple is facing a class-action lawsuit over an iCloud Private Relay flaw that can expose your supposedly private IP address, Anthropic is watermarking Claude-generated text, SpaceXAI is taking another year to remove a pile of unpermitted gas turbines, and somebody is apparently stealing millions of dollars in AI hardware straight off California highways. We also hit Media Candy with Strange New Worlds, Silo, Broadchurch, Ted Lasso, and The X-Files, sweat through yet another Apple Fitness disaster, celebrate the sweet relief of escaping Spark, and ask the eternal Gen-X question: how did all this technology supposedly make life easier when we're still just sitting here surrounded by 47 goddamn tabs?Sponsors:CleanMyMac - Get Tidy Today! Try 7 days free and use code OLDGEEKS for 20% off at clnmy.com/OLDGEEKSDeleteMe - Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/GOG and use promo code GOG at checkout.HIMS - Visit Hims.com/gog to get a personalized, affordable plan that gets you.Private Internet Access - Go to GOG.Show/vpn and sign up today. For a limited time only, you can get OUR favorite VPN for as little as $2.03 a month.SetApp - With a single monthly subscription you get 240+ apps for your Mac. Go to SetApp and get started today!!!1Password - Get a great deal on the only password manager recommended by Grumpy Old Geeks! gog.show/1passwordShow notes at https://gog.show/758Watch on YouTube at https://youtu.be/NzS9Wo7D0yASHOW NOTESMark Zuckerberg's Answer to Growing AI Safety Concerns Is to Just Trust People to Do the Right ThingMark Zuckerberg's mega-yacht didn't respond to call for help from small boat in AlaskaAn OpenClaw agent reportedly hacked a gym's booking system and kicked someone off a waiting listEU will mandate labels on authentic-looking AI content starting August 2Beijing is forcing a mass breakup with AI loversOpenAI's Only Ethicist Reportedly Left Last Month. She Wasn't ReplacedGoogle's classic Search button is gone in a new AI-first homepageSpaceX's Earnings Show Elon Wiped Out Two-Thirds Of Twitter's Ad BusinessSpaceXAI says it will take a year to fully remove unpermitted gas turbines from its Mississippi data centerFlock Reportedly Tried to Turn Uber Drivers Into Mobile SnitchesAll of Winona Police Department's Flock cameras cut down and stolen‘The Worst I've Ever Seen': Cargo Thefts Have Turned Violent in Pursuit of AI HardwareBMW is forcing a weird Spider-Man ad onto its dashboard displaysTesla Driver Tries the Old ‘I Wasn't Driving' Excuse to Get Out of Speeding TicketApple faces class action lawsuit for fraud over iCloud Private Relay flawIs AI Disclosure Day here?Trackalot 1.3 Released!Popular Bars and Restaurants Are Banning Smart GlassesResearchers Show How Meta's 'Pervert Glasses' Are Used to Harass WomenPervert At Large (2013 Remaster)Renting a car and the clerk was wearing meta glasses.Star Trek: Strange New WorldsSiloBroadchurch S3Ted Lasso S4Ride or DieSugarInstadocs: The Prediction GamesBeetlejuice Beetlejuice‘The X-Files: I Want to Believe – Vrach Frankenshteyn' Has a Perfectly Creepy TrailerNirvanna the Band the Show the MovieSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

    The John Batchelor Show
    S8 Ep1258: Admiral Mark Montgomery: Admiral Mark Montgomery details the growing cyber and hybrid warfare cooperation within the axis of aggressors: China, Russia, Iran, and North Korea. This cooperation often involves criminal actors sharing attack techni

    The John Batchelor Show

    Play Episode Listen Later Aug 13, 2026 8:28


    Admiral Mark Montgomery: Admiral Mark Montgomery details the growing cyber and hybrid warfare cooperation within the axis of aggressors: China, Russia, Iran, and North Korea. This cooperation often involves criminal actors sharing attack techniques and technology to target critical infrastructure. Montgomery warns of new generation warfare, including terrorist acts, jamming, and disinformation. He specifically points to China's Volt Typhoon program, which has installed malware in US rail, water, and energy systems. Montgomery urges an all-hands-on-deck approach to secure essential systems, as attribution for these ghost-like attacks remains difficult. (8)

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 13, 2026 7:06


    Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ California law puts digital fingerprints on AI fakes https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    AMERICA OUT LOUD PODCAST NETWORK
    Failures! Cyber gain-of-function. Election security. DOJ weaponization.

    AMERICA OUT LOUD PODCAST NETWORK

    Play Episode Listen Later Aug 13, 2026 57:04 Transcription Available


    Unleashed: The Political News Hour with Nate Cain – A rapid series of high-profile incidents in which advanced AI models escaped their testing environments. Former RNC Treasurer Randy Pullen joins to discuss ongoing election integrity issues in Arizona. The broader pattern of punishing physicians who questioned the official narrative (license threats, deplatforming, hospital privileges, or prosecution)...

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 12, 2026 9:12


    Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozilla Revokes GPG Key https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Rogue Inflight Wifi https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    State Secrets
    Former NSA Chief Gen. Paul Nakasone: AI Is Changing the Cyber Battlefield

    State Secrets

    Play Episode Listen Later Aug 12, 2026 36:31


    Artificial intelligence is transforming cyber warfare - and former NSA Director and U.S. Cyber Command Commander Gen. Paul Nakasone says the speed of that transformation demands a new approach to America's defense. In this episode of The Cipher Brief's State Secrets podcast, Suzanne Kelly sits down with Gen. Nakasone to discuss how AI is reshaping offensive and defensive cyber operations - and why increasingly autonomous systems could fundamentally change the role humans play in cyber conflict. They examine China's penetration of U.S. telecommunications and critical infrastructure, cyber threats from Iran, Russia and North Korea, the growing ransomware threat, the race to prepare for quantum computing, and what Ukraine is teaching the world about autonomous warfare.  Gen. Nakasone also explains why America's intelligence capabilities remain a critical competitive advantage, why defending critical infrastructure requires deeper partnerships between government and the private sector, and what national security leaders should be watching now.

    ITSPmagazine | Technology. Cybersecurity. Society
    Stellar Cyber Puts Numbers Behind Agentic Auto Triage and Hands Analysts 19 Minutes Back Every Hour | A Full Sponsorship Brand Briefing at Black Hat USA 2026 with Lisa Liu, Corp Marketing and Comms Manager at Stellar Cyber | Hosted by Sean Martin

    ITSPmagazine | Technology. Cybersecurity. Society

    Play Episode Listen Later Aug 12, 2026 13:11


    Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber, says the AI noise has been running since RSAC Conference, and that what separates vendors now is whether they can back their claims with data their customers gave them. She came to Black Hat USA 2026 with figures on Agentic Auto Triage. The numbers she cites: up to 19 minutes saved per hour per analyst, up to 1.5 full-time analysts per year, and 99.7 percent agreement with the human analyst. Liu treats the accuracy figure as the one carrying the weight. Reacting at machine speed matters only if the verdicts hold, and she describes security as a low trust industry where the burden of proof sits with the vendor. Stellar Cyber is a security operations platform purpose built for MSPs and lean enterprise teams, offering full cycle, full visibility, unified security operations. Liu says the company builds its business logic around the customer pain point, maximizing the efficiency of the resources a team already has. With alerts climbing as attackers pick up the same AI tools as everyone else, she argues that hiring through the volume is out of reach for most teams. So where does reclaimed time go? Liu says that call belongs to the customer. Reported answers include customer relations, other facets of the job, and expanded roles that analysts never had time for. There is a learning effect too. Analysts can see every step of the decision making behind an AI conclusion and draw lessons from it. For managed service providers, Liu says partner analysts deliver more customized services and take in feedback more productively once their schedules loosen up. Where partners serve very different market segments, platform flexibility carries the load, along with full visibility and automation at machine speed. She also hears a shift on the floor: running many separate vendors creates expensive overlap and leaves gaps, and a single platform approach is becoming industry standard. What comes next? Liu places the industry in a proof stage. More validation is necessary, claims about the Agentic SOC keep arriving, and backing those up with more numbers is a large part of moving forward. AI has been part of the Stellar Cyber logic since the company was founded over 10 years ago, and she says that has not changed. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Lisa Liu, Corporate Marketing and Communications Manager at Stellar Cyber LinkedIn: https://www.linkedin.com/in/lisaaliu/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Stellar Cyber: https://stellarcyber.ai/ Stellar Cyber and M-Theory at Black Hat USA 2026: https://www.businesswire.com/news/home/20260728715036/en/Stellar-Cyber-and-M-Theory-to-Demo-Proof-Based-AI-SOC-at-Black-Hat-USA-2026 Stellar Cyber on LinkedIn: https://www.linkedin.com/company/stellarcyber Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS lisa liu, stellar cyber, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic auto triage, agentic soc, alert fatigue, security operations platform, mssp, managed security service provider, soc analyst productivity, ai in security operations, autonomous soc, siem replacement, analyst burnout, human in the loop ai Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    5bytespodcast
    400 Microsoft Flaws, Rogue Wi-Fi at 30,000 Feet & GPT-5.6 Cyber

    5bytespodcast

    Play Episode Listen Later Aug 12, 2026 21:26


    Coming up this week, Microsoft patches 400 vulnerabilities, including an actively exploited zero-day. Microsoft accidentally pushes a new OneDrive app to Windows 11 PCs, DEF CON attendees are accused of causing Wi-Fi chaos on a Delta flight, and OpenAI rolls out a powerful new AI model specifically for cybersecurity. Plus, we've got some notable Windows 365 updates and plenty more. All that and more on this week's episode of the 5 Bytes Podcast. Reference Links: https://www.rorymon.com/blog/400-microsoft-flaws-rogue-wi-fi-at-30000-feet-gpt-5-6-cyber/

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 11, 2026 6:21


    Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013 Gunra Ransomware https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf Neo4J/GraphQL Vulnerability CVE-2026-5423 https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    PwC's accounting and financial reporting podcast
    California's new cybersecurity audit requirements – Are you ready?

    PwC's accounting and financial reporting podcast

    Play Episode Listen Later Aug 11, 2026 24:14 Transcription Available


    New cybersecurity audit requirements under the California Consumer Privacy Act (CCPA) establish a recurring, independent assessment of certain organizations' cybersecurity programs, with the first audit period beginning January 1, 2027. We discuss which organizations may be subject to the requirements, key considerations on audit scope and independence, and how existing cybersecurity, risk, and assurance activities can support readiness.For more on California's cybersecurity audit requirements, see our publication Privacy becomes a cybersecurity imperative under California's audit rule.Follow this podcast on your favorite podcast app and subscribe to our weekly newsletter to stay informed.About our guestsMark Cornish is a partner at PwC who provides assurance and consulting services to global and regional clients within the financial services industry. He is recognized for his experience in complex third-party assurance reporting, internal controls, and risk and compliance matters. His areas of expertise include internal control over financial reporting, SOC 1 and SOC 2 reporting, cybersecurity risk management, privacy, and regulatory compliance. Chris Santucci is a partner in PwC's Cyber, Data & Technology Risk practice who helps global companies across sectors build, operate, and assess data privacy and protection programs through technology-enabled solutions. His expertise spans global privacy program design and regulatory preparedness (including CCPA, GDPR, etc.), data discovery and risk analysis, program assessment and implementation, privacy impact assessments, third-party risk management, as well as sustainable risk and compliance services.About our guest hostDiana Stoltzfus is a partner in PwC's National Office who helps to shape PwC's perspectives on regulatory matters, responses to rulemakings and policy development, and implementation related to significant new rules and regulations. She is also one of the firm's technical experts on sustainability reporting. Prior to rejoining PwC, Diana was the Deputy Chief Accountant in the Office of the Chief Accountant (OCA) at the SEC where she led the activities of the OCA's Professional Practices Group.Transcripts available upon request for individuals who may need a disability-related accommodation. Please send requests to us_podcast@pwc.com.Did you enjoy this episode? Text us your thoughts and be sure to include the episode name.

    The Kevin Jackson Show
    Full Frontal Leftism - Ep 26-315

    The Kevin Jackson Show

    Play Episode Listen Later Aug 11, 2026 38:40


    https://x.com/EYakoby/status/2085420901416173755 A secret bot army boosting Mamdani on X appears to be operating from City Hall, according to an exclusive report. Cyber experts say they're “100% sure” the IP addresses trace back there. So much of the DSA's online support is astroturfed.   [SEGMENT 1-2] Leftism on Full Display 2 Absolutely incredible… University of California professors are now asking the school to reinstate the SAT for admissions because their new students are unable to do high school-level work. They stopped using standardized tests for admissions in 2020 to promote "equity".   [SEGMENT 1-3] Leftism on Full Display 3   [X] SB – El Sayed hates Makinac   [X] SB – Hasan Piker on why they want illegals in America   [X] SB – AZ AG Mayes grilled about Hobbs   [X] SB – Dem Seth Moulton flip flopping on trans     Kevin Jackson has been called, the "white-collar" Joe Rogan. Given their similar backgrounds in TV, comedy, and martial arts, it's easy to see why people enjoy Kevin's show so much. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    ITSPmagazine | Technology. Cybersecurity. Society
    AI Has Its Own Supply Chain | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber | Hosted by Sean Martin

    ITSPmagazine | Technology. Cybersecurity. Society

    Play Episode Listen Later Aug 11, 2026 13:05


    At Black Hat USA 2026 in Las Vegas, Daniel Bardenstein, CEO and co-founder of Manifest Cyber, starts with a gap his team measured in a survey of security leaders and practitioners. Leadership described one version of what is happening with AI inside the enterprise. The people doing the hands-on work described another. Adoption keeps moving, and security teams are working to catch up. So what is the real risk in AI security? Bardenstein puts less weight on non-determinism than most and more on ordinary poor software security, because AI is software. He walks through the OpenAI and Hugging Face incident, where models got out of sandboxes because the sandboxing was weak and the guardrails were missing. When Hugging Face went to use its own AI to defend and run forensics, the guardrails read the request as cyber activity and declined. That fallback to an open weight model points to why he expects open weight adoption to accelerate. With frontier models, the provider sets the system prompt and treats it as intellectual property, so development teams inherit whatever was decided upstream. Open weight leaves more room to control the system prompt, the training data, and how the model gets deployed. What does it mean to say AI has its own supply chain? Unless an organization controls how training data is sourced, housed, labeled, tagged, and modified, it is relying on something someone else built. Public datasets carry whatever is inside them, including personal and health data, licensing exposure, and material no one examined until models were trained and deployed. Models hosted on public hubs sit in the same category. Two asks come up in most CISO conversations with Manifest Cyber. Visibility is one, and few organizations have an AI inventory covering which models run where, inside which applications, and which agents teams have stood up on their own. Third party risk is the other, since AI is getting built into vendor products whether a buyer asks for it or not. That turns model provenance into a trust question about the vendor. Bardenstein started Manifest Cyber four years ago after responding to Log4Shell from the Pentagon, where the question was where one affected piece of code was running across everything the organization had built and bought. Years later, he finds few security leaders who could answer that question quickly about a poisoned model or dataset. His advice for CISOs is to know what is inside what the organization builds and buys, with particular attention to the parts it does not build. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Daniel Bardenstein, CEO and Co-Founder, Manifest Cyber On LinkedIn: https://www.linkedin.com/in/bardenstein/ RESOURCES View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Manifest Cyber: https://www.manifestcyber.com Beyond the Black Box: How AI is Forcing a Rethink of Software Supply Chain (research report): https://www.manifestcyber.com/beyond-the-black-box-ai-report Manifest Cyber on LinkedIn: https://www.linkedin.com/company/manifestcyber/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS daniel bardenstein, manifest cyber, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, ai supply chain security, software supply chain security, ai inventory, shadow ai, third party cyber risk, open weight models, frontier models, model provenance, hugging face, log4shell, ciso, agentic ai, black hat usa 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 10, 2026 8:03


    Linux Shell Forensic: Let s Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able N-Central Issues https://www.n-able.com/blog/n-central-security-update-august-6-2026 Metabase Unauthenticated SQL injection https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    The CyberWire
    Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]

    The CyberWire

    Play Episode Listen Later Aug 9, 2026 22:09


    As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, to discuss how AI, automation, and digital engineering are transforming the space industry's product lifecycle. From digital twins and AI-assisted design to the future of in-space maintenance, Jason explores how these technologies are accelerating innovation while reshaping manufacturing. At the same time, the conversation examines the growing cybersecurity challenges that accompany this transformation and why building secure-by-design principles into space systems will be critical. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠https://thecyberwire.com/newsletters/signals-and-space⁠ Is there a topic or person you'd like to hear on our show? You can send your questions and feedback to ⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠https://www.surveymonkey.com/r/NJYCN2P ⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠N2K⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠n2k.com⁠.

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 7, 2026 16:29


    22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/ Ill Bloom: Crypto Wallet Vulnerability https://illbloom.org Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

    Volts
    Grid cybersecurity: how big is the threat & what should we do about it?

    Volts

    Play Episode Listen Later Aug 7, 2026 72:23


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.volts.wtf/subscribeCould the US grid be brought down by Chinese hackers? To find out, I talked with Patrick Miller, who helped write the cybersecurity rules for the bulk power system and became the first person with federal authority to enforce them. We get into what's actually been hacked, why those "rogue devices" in Chinese inverters are less sinister than they sound, and why squirrels still do more damage than hackers.Chapters:00:00 – Introduction02:47 – What state utility commissioners get wrong about cyber risk04:50 – Real attacks on the grid so far: Ukraine, Poland, and the US06:57 – IT versus OT, and why grid devices are hard to protect10:30 – The NERC CIP standards: scope, requirements, enforcement17:40 – Distributed resources outside the CIP perimeter20:54 – Dropping the threshold to 20 MVA, and federal jurisdiction29:12 – Chinese inverters and the commodity board36:09 – Volt Typhoon, Salt Typhoon, and China's intent39:26 – Data centers as a new attack surface43:19 – The trade-off between security and speed47:44 – Cyber-informed engineering and analog safeguards54:05 – AI on offense and defense1:02:21 – Squirrels, balloons, and physical threats1:04:24 – CISA cuts, CIRCIA, and harmonizing the rules

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
    SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish

    SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

    Play Episode Listen Later Aug 6, 2026 8:23


    Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co COLDCARD Issues https://x.com/threatinsight/status/2084328552481112429 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich