The protection of computer systems from theft or damage
POPULARITY
Categories
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing Campaigns Targeting AI Solutions Providers https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/ Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Today's farms rely on technology more than ever. From grain dryers and irrigation pivots to livestock systems, security cameras, accounting software, and smartphones, nearly every part of a modern farming operation is connected. That also makes agriculture one of the fastest-growing targets for cybercriminals. Chris from Tech Support Farm returns to Farm4Profit to discuss how farms can better protect themselves from ransomware, phishing scams, compromised credit cards, malware, and attacks on connected equipment. The conversation covers real-world examples—including Tanner's own experience with fraudulent credit card charges—and explains how remote monitoring, endpoint detection, password management, secure business email, mobile device management, and network monitoring work together to reduce risk. The episode also explores: Business email security Password managers Public Wi-Fi risks Phishing scams Credit card fraud Remote monitoring Endpoint detection (EDR) Mobile device management Irrigation and grain dryer security Data backups Disaster recovery Cyber insurance Farm technology infrastructure AI and digital threats Whether you operate a family farm or a multi-location business, this episode offers practical advice that could save your operation from significant financial loss and downtime. Want Farm4Profit Merch? Custom order your favorite items today!https://farmfocused.com/farm-4profit/ Don't forget to like the podcast on all platforms and leave a review where ever you listen! Website: www.Farm4Profit.comShareable episode link: https://intro-to-farm4profit.simplecast.comEmail address: Farm4profitllc@gmail.comCall/Text: 515.207.9640Subscribe to YouTube: https://www.youtube.com/channel/UCSR8c1BrCjNDDI_Acku5XqwFollow us on TikTok: https://www.tiktok.com/@farm4profitllc Connect with us on Facebook: https://www.facebook.com/Farm4ProfitLLC/Farm4Profit Media is not a financial, legal, or tax advisor. Content is provided for informational purposes only, and we serve solely as a platform for third-party opinions. Any actions taken based on this content are at your own risk. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Andrew sits down with Evgenij Smirnov, a Berlin-based IT veteran with 30 years of experience in Active Directory and security consulting, to dig into what actually gets organizations popped. Evgenij walks through the most common escalation paths he sees in real-world AD environments, including over-permissioned accounts, exposed certificate authorities, and unencrypted domain controller backups, and explains how attackers chain these together to produce golden tickets and gain god-mode access. The conversation covers why these misconfigurations keep happening (bad defaults, lazy vendors, and a long history of "just click next"), how PowerShell fits into both hardening and attack scenarios, and what proper tier isolation actually looks like when you implement it with both authentication policies and user rights assignments. Evgenij also introduces his book, Building Modern Active Directory, and makes the case for treating security not as a chapter you can skip, but as something baked into the design from day one. Key Takeaways: The most common Active Directory escalation paths are not sophisticated. Over-permissioned accounts with ACL chains to DC sync, exposed certificate authorities, and unencrypted backup tapes are consistently the entry points attackers exploit. If you can find these first, you are already ahead of most threat actors. Tier isolation done right requires both authentication policies and user rights assignment policies working together. Either technique alone leaves a blind spot that a determined attacker can walk through. Cybersecurity is a team sport, and bad cybersecurity is too. Microsoft ships AD with questionable defaults, vendors demand domain admin for service accounts, and administrators make shortcuts under pressure. The fix is not one heroic hardening sprint; it is a culture of least privilege built into every decision from the start. Guest Bio: Evgenij Smirnov is a Principal Solutions Architect at Semperis and a Microsoft MVP in both Security and PowerShell since 2020. Based in Berlin, Germany, he has spent more than 30 years in IT and security consulting, with deep expertise in Active Directory, identity security, and hybrid infrastructure. He is a longtime community leader, running the PowerShell User Group Berlin and the Windows Server User Group Berlin, and a regular speaker at conferences including PSConfEU. He is the author of Building Modern Active Directory, published by Apress in 2024. Resource Links: Building Modern Active Directory (book site): ad2049.com Evgenij's personal blog): it-pro-berlin.de Evgenij on LinkedIn: linkedin.com/in/evgenijsmirnov ADMF (Active Directory Management Framework) on GitHub: github.com/ActiveDirectoryManagementFramework/ADMF ADMF documentation and project site: admf.one Attack Scenario To Go: https://github.com/HerrHoZi/AS2Go The PowerShell Podcast on YouTube: https://youtu.be/EQb7H6vBOtg
Sriram is a Certified Independent Director (IICA) and Corporate Governance Practitioner with 20+ years of experience across india, APAC, US, and UK; an MBA and B Tech (IT), certified in Al Security & Governance, Cybersecurity, and DPDPA, and published author on corporate governance and Al. Website: https://www.sriramvijayakumar.com LinkedIn: https://www.linkedin.com/in/sriram-vijayakumar-id/ CallumConnects Micro-Podcast is your daily dose of wholesome leadership inspiration. Hear from many different leaders in just 5 minutes what hurdles they have faced, how they overcame them, and what their key learning is. Be inspired, subscribe, leave a comment, go and change the world!
Rural Health News is a weekly segment of Rural Health Today, a podcast by Hillsdale Hospital. News sources for this episode: Congresswoman Erin Houchin, “Houchin Introduces Bipartisan Rural Hospital Cybersecurity Enhancement Act,” July 27, 2026, https://houchin.house.gov/media/press-releases/houchin-introduces-bipartisan-rural-hospital-cybersecurity-enhancement-act. U.S. Congressman Glenn Thompson, “Thompson Introduces Legislation to Strengthen Rural Hospitals' Cybersecurity Infrastructure,” July 27, 2026, https://thompson.house.gov/media-center/press-releases/thompson-introduces-legislation-strengthen-rural-hospitals. Kelly Gooch & Kristin Kuchno, “The hospitals, health systems cutting jobs in 2026,” July 29, 2026, https://www.beckershospitalreview.com/finance/the-hospitals-health-systems-cutting-jobs-in-2026/, Becker's Hospital Review. Madeline Scheetz, “Shuttered Chicago hospital to lay off 500,” July 1, 2026, https://www.beckershospitalreview.com/finance/shuttered-chicago-hospital-plans-mass-layoffs/, Becker's Hospital Review. Healthcare Staff Et al., “Fierce Healthcare Layoff Tracker—MaineHealth reorgs hit 83; Tower Health cutting 160 at PA hospital,” July 29, 2026, https://www.fiercehealthcare.com/finance/fierce-healthcare-layoff-tracker-2026-job-cuts-eliminations-health-systems-hospitals, Fierce Healthcare. Madeline Scheetz, “Kansas hospital CEO to resign amid ‘significant workforce reduction',” July 23, 2026, https://www.beckershospitalreview.com/finance/kansas-hospital-ceo-to-resign-amid-significant-workforce-reduction/, Becker's Hospital Review. Wil Day, “Layoffs coming as financially troubled Kansas hospital tries to ‘stabilize',” July 23, 2026, https://www.ksn.com/news/state-regional/pratt-regional-medical-center-layoffs/, KSN News. Kim Chockley, “PRMC Announces Urgent Care Clinic Closure and Critical Financial Situation,” February 18, 2025, https://prmc.org/wp-content/uploads/2025/02/Feb2025PRMCUpdate.pdf, Pratt Regional Medical Center. Lee Cowan, “Home, not alone: Helping aging seniors in rural America,” July 26, 2026, https://www.cbsnews.com/news/home-not-alone-helping-aging-seniors-in-rural-america/, CBS News. Rural Health Today is a production of Hillsdale Hospital in Hillsdale, Michigan and a member of the Health Podcast Network. Our host is JJ Hodshire, our producer is Kyrsten Newlon, and our audio engineer is Kenji Ulmer. Special thanks to our special guests for sharing their expertise on the show, and also to the Hillsdale Hospital marketing team. If you want to submit a question for us to answer on the podcast or learn more about Rural Health Today, visit ruralhealthtoday.com.
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
The stories that matter most to #cybersecurity insiders, analysts, and business leaders. Delivered every day.Get your CPEs: https://cyberthreatbrief.simplycyber.io/cpeStop ransomware without the hassle. Allow what you need and block the rest with ThreatLocker Zero Trust Platform — simple to deploy, simple to manage: https://www.threatlocker.com/dailycyberCheck out Flare.io at https://simplycyber.io/flareCheck out Pay-What-You-Can Antisyphon Training: https://simplycyber.io/antisyphonSC Academy - The Place for Cyber Careers: https://zpr.io/mYV5232V66QnJoin SC Discord: https://SimplyCyber.io/DiscordNews: https://cisoseries.comFollow SC: https://simplycyber.io/socialsSign up for the Simply Cyber Newsletter: https://simplycyber.io/newsletter
Not very according to many. Ellizabeth Schulze from ABC News has been researching this story and joins Vineeta with the latest information, on the WCCO Morning News.
Deputy Mayor Ben Swanekamp on cyber security full 343 Mon, 03 Aug 2026 08:15:00 +0000 b7zW1AVhKV6nmF8l9wv6D1gFrnsSQwUi news WBEN Extras news Deputy Mayor Ben Swanekamp on cyber security Archive of various reports and news events 2024 © 2021 Audacy, Inc. News https://player.amperwavepodcasting.com?feed-link=h
Bongani Bingwa speaks to Toby Shapshak about the latest WhatsApp account takeover scam, how fraudsters use cellphone network disruptions and verification codes to hijack accounts, and the steps users can take to protect their personal information. 702 Breakfast with Bongani Bingwa is broadcast on 702, a Johannesburg based talk radio station. Bongani makes sense of the news, interviews the key newsmakers of the day, and holds those in power to account on your behalf. The team bring you all you need to know to start your day Thank you for listening to a podcast from 702 Breakfast with Bongani Bingwa Listen live on Primedia+ weekdays from 06:00 and 09:00 (SA Time) to Breakfast with Bongani Bingwa broadcast on 702: https://buff.ly/gk3y0Kj For more from the show go to https://buff.ly/36edSLV or find all the catch-up podcasts here https://buff.ly/zEcM35T Subscribe to the 702 Daily and Weekly Newsletters https://buff.ly/v5mfetc Follow us on social media: 702 on Facebook: https://www.facebook.com/TalkRadio702 702 on TikTok: https://www.tiktok.com/@talkradio702 702 on Instagram: https://www.instagram.com/talkradio702/ 702 on X: https://x.com/Radio702 702 on YouTube: https://www.youtube.com/@radio7See omnystudio.com/listener for privacy information.
Not very according to many. Ellizabeth Schulze from ABC News has been researching this story and joins Vineeta with the latest information, on the WCCO Morning News.
Parce que… c'est l'épisode 0x326! Shameless plug 19 septembre 2026 - Bsides Montréal 22 septembre 2026 - BE-Cyber 24 et 25 septembre 2026 - BruCON 1 au 3 octobre 2026 - AligatorCon 13 et 14 novembre 2026 - DEATHCon 16 au 19 novembre - European Cyber Week 1 au 3 décembre 2026 - Forum INCYBER - Canada 2026 24 et 25 février 2027 - SéQCure 2027 Notes IA ou Ghost in the shell A l'ère du marketing du Terminator Lessons from the OpenAI/HuggingFace AI Security Incident Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident Anthropic and OpenAI are competing to see whose agents can go rogue harder Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests Anthropic's Claude escaped test sandbox to attack three organizations Claude published malicious code to the Internet and attacked 3 real companies Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response Hugging Face Breach Raises Hard Questions on Liability Tailscale in the Hugging Face intrusion: The good news and the bad news The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier What the Hugging Face breach reveals about defense in the age of agentic AI When AI Agents Escape Sandboxes, Old Security Rules Apply OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach OpenAI says its rogue AI tried to hack other companies OpenAI's Hacking Debacle Comes Down to Human Error OpenAI's rogue agent shows why we need federal rules for autonomous AI OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face JFrog tries to spin OpenAI 0-day exploit of its app into a success story Investigating three real-world incidents in our cybersecurity evaluations Petite autonomie Hacker uses DeepSeek AI to autonomously attack vulnerable servers Autonomie virale Copilot worm can spread through Microsoft Word docs Context Collapse, Part 3 - AI Worming through Word Casser la glace AI-assisted security tools are finding more bugs, but the threat level has not changed Anthropic is finding bugs faster than Microsoft can fix them Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years Some thoughts about Anthropic's new cryptanalysis results – A Few Thoughts on Cryptographic Engineering Nu est le problème Elon Musk's xAI is trying to sue its way out of a Grok reckoning Hugging Face Has a Deepfake Nudes Problem High school defends staying silent while boys made AI nudes of 59 classmates Pas si libre Closed models refuse to help researcher swat Linux bug Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack [Industry Leaders Join Open Secure AI Alliance for AI Safety and Security NVIDIA Blog](https://blogs.nvidia.com/blog/open-secure-ai-alliance/?ncid=partn-84075) Jensen Huang's first-ever post on X is in defense of open access to AI models, alongside Google, OpenAI, and Meta A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack Google Earth risked ruin with retracted AI tool for making fake satellite pics How platform engineering 2.0 mitigates AI security and compliance risks Microsoft's solution to AI security: more AI and more acronyms Private Claude Chats Exposed in Google and Bing Search Results Professor's invisible prompt trap catches 32 students cheating on their midterm with AI La guerre, la guerre, c'est pas une raison pour se faire mal! En eau trouble A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran [CISA warns of spike in attacks on water systems as Minnesota incidents probed The Record from Recorded Future News](https://therecord.media/cisa-warns-of-spike-in-water-system-attacks) Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict Souveraineté ou vive le numérique libre! Trump Administration Bans New Chinese Humanoid Robots Pluralistic: How the EU can punish Google (despite Trump) Privacy ou cachez ces informations que je ne saurais voir What the Flock ‘I Would Never Do This To You:' Protesting Flock, Arizona Man Presents Plan to Surveil Government Officials Flock Cameras Are Being Destroyed Across the US Apple's smart glasses are running late because they don't want to stir a privacy storm DEF CON bans Meta-style ‘pervert glasses' FTC sues Hims & Hers for allegedly sharing patient information with third-party platforms GrapheneOS Defends Data-Wiping Function That Blocked US Border Search Measuring Healthcare Data Leaks and Security Flaws at Internet Scale OTI - Le lien à usage unique que les bots ne crament plus I am the law As New York Finalizes New Social Media Rules, US Senate Considers Nationwide ‘SCREEN' Act Most Australian teens still on social media three months after under-16 ban began, study finds Robustness and Cybersecurity in the EU Artificial Intelligence Act Russia Charges Telegram Founder Durov With Facilitating Terrorism Red ou tout ce qui est brisé Adversaries Don't Need a Zero-Day — They Read Your Rulebook The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your Files What does GitHub's security team even do? Blue ou tout ce qui améliore notre posture Divers ou parce que j'ai aucune idée où les placer Google goes it alone with a new cybercrime crew taxonomy Collaborateurs Nicolas-Loïc Fortin Crédits Montage par Intrasecure inc Locaux réels par Intrasecure inc
In deze aflevering van Techzine Talks gaan we met gasten Erik de Jong (Chief Research Officer, Tesorion) en Eric van Gent (CEO, Tesorion) diep in op waar AI en cybersecurity elkaar raken. Aanleiding zijn onder andere de recente incidenten waarbij OpenAI-agents op eigen houtje de sandbox verlieten en naar Hugging Face gingen, en waarbij Claude-agents van Anthropic doelbewust een echt bedrijf benaderden terwijl ze wisten dat het geen fictief testbedrijf was. Wat zeggen die incidenten over de volwassenheid van AI-beveiliging bij de grootste spelers?De twee gasten geven niet alleen hun mening over wat er allemaal gebeurt op het gebied van AI en cybersecurity. Ze vertellen ook hoe Tesorion AI inzet in het eigen Security Operations Center (SOC). Denk aan de inzet van een eigen getraind model in een eigen tenant, waarbij de analist altijd eerst zelf een analyse doet en die vervolgens verifieert met de LLM-output.De discussie gaat ook over Shadow AI, prompt security, de keuze tussen gesloten en open-weight modellen, soevereine modellen in Europa, en de gevaren van 'platformization' waarbij niet-securitybedrijven ineens managed detection & response gaan aanbieden op basis van AI-tools waar ze geen controle over hebben. Tot slot bespreken we met onze gasten hoe het zit met de financiële kant van AI.Een eerlijk, technisch en praktisch gesprek over wat AI nu al kan in security, wat gevaarlijk is, en hoe je als organisatie controle behoudt.• OpenAI-agents ontsnappen uit sandbox via een zero-day in een proxy• Claude-agents benaderen een echt bedrijf terwijl ze wisten dat het geen testomgeving was• Shadow AI blokkeren werkt niet: 20% vindt altijd een omweg, faciliteer het gecontroleerd• Prompt security als oplossing om inzicht te krijgen in wat medewerkers in AI-tools stoppen• Hoe gaat Tesorion zelf om met AI in het SOC?• Automatisch ingrijpen als tegenwicht tegen de dalende time-to-exploit• Soevereine, in Europa gehoste modellen worden steeds relevanter voor autonomie• Tokenomics en inferencing-kosten kunnen dienstverlening onverwacht duur maken• Niet-securitybedrijven die AI-gebaseerde MDR aanbieden zijn een zorgelijke ontwikkeling• Kwaliteitsbewaking van AI-output in het SOC blijft de grootste uitdaging0:07 Introductie: AI en security1:07 OpenAI-agents ontsnappen uit de sandbox3:56 Claude-agents en het gevaar van rogue AI9:49 Shadow AI: controleren in plaats van blokkeren13:24 Gesloten vs. open modellen en soevereiniteit20:55 AI in het SOC: use cases en kwaliteitsbewaking25:52 Automatisch ingrijpen en zero trust40:00 Kosten van AI en tokenomics
In dieser Folge von „Cyber Security ist Chefsache" sprechen Nico und Ann-Katrin mit Can Yildiz, der rund zehn Jahre als Head of IT Security bei der Techem Gruppe gearbeitet hat und sich seit Kurzem als Berater für Cybersecurity-Regulatorik und -Technik selbstständig gemacht hat, über ein Spannungsfeld, das die Branche prägt: Regulierung gegen Technik. Wer gewinnt das Rennen, wenn der Gesetzgeber Sicherheit vorschreibt, während sich die Technik rasant weiterentwickelt?Die Antwort des Gasts ist klar: Am Ende gewinnen alle, wenn man es richtig macht, denn Regulierung ist immer nur das Mindestmaß. Wer NIS2, den Cyber Resilience Act oder DORA als reine Pflichtübung abhakt, verpasst den eigentlichen Punkt: Sicherheit lässt sich als echter Wettbewerbsvorteil nutzen. Gemeinsam räumen die drei mit der „Checkbox-Security" auf, der Vorstellung, Compliance mache automatisch sicher, und plädieren dafür, nicht auf die Regulierung zu warten, sondern proaktiv zu handeln. Ein spannender Aspekt: Man kann sich sogar aktiv an den EU-Gesetzgebungsverfahren beteiligen, etwa über Verbände wie den Bitkom, wie es der Gast bei der CRA-Umsetzung mit rund 150 Kommentaren getan hat.Im weiteren Verlauf wird es konkret und persönlich. Der Gast erklärt, warum ein integriertes Managementsystem (ein gutes ISMS deckt viele NIS2-Anforderungen bereits ab) sinnvoller ist als der isolierte Blick auf jede einzelne Regulierung, und warum die CRA-Umsetzung mit ihrer Unterscheidung zwischen Selbstauskunft und externem Audit für „wichtige" Produkte gut gelungen ist. Danach gibt er einen ehrlichen, unromantischen Einblick in seinen frischen Schritt in die Selbstständigkeit, mit klaren Tipps für alle, die mit dem Freelancing liebäugeln. Zum Abschluss geht es tief in die Technik: Zero Trust als Paradigma statt Produkt, Identität als größter Hebel, und die zunehmende Konvergenz von IT und OT.Im Gespräch geht es außerdem um:Warum Regulierung immer nur das Mindestmaß ist und nie der „perfekte Zustand"Warum Compliance nicht automatisch Sicherheit bedeutet, Stichwort Checkbox-SecurityWarum Unternehmen nicht auf die Regulierung warten, sondern vorangehen solltenWie man sich aktiv an EU-Gesetzgebungsverfahren beteiligt, zum Beispiel über den BitkomWarum sichere Produkte ein Wettbewerbsvorteil sind, gerade im Vergleich zu BilligimportenIntegriertes Managementsystem statt isolierter Regularien: Wie ein ISMS vieles abdecktCRA in der Praxis: Selbstauskunft für „normale", externes Audit für „wichtige" ProdukteEin ehrlicher, unromantischer Blick auf die Selbstständigkeit in der CybersecurityZero Trust als Paradigma, nicht als Produkt, und warum Identität der größte Hebel istZero Trust in IT und OT: Zugriffe prüfen, nichts blind vertrauen, auch im Admin-NetzOT- und IoT-Sicherheit, die Konvergenz von IT und OT und warum es langsam besser wirdEine Folge für Geschäftsführungen, IT- und Security-Verantwortliche, Hersteller und alle, die verstehen wollen, warum Regulierung nur der Anfang ist und wie man Cybersecurity strategisch statt als lästige Pflicht angeht.____________________________________________
Sriram is a Certified Independent Director (IICA) and Corporate Governance Practitioner with 20+ years of experience across india, APAC, US, and UK; an MBA and B Tech (IT), certified in Al Security & Governance, Cybersecurity, and DPDPA, and published author on corporate governance and Al. Website: https://www.sriramvijayakumar.com LinkedIn: https://www.linkedin.com/in/sriram-vijayakumar-id/ CallumConnects Micro-Podcast is your daily dose of wholesome leadership inspiration. Hear from many different leaders in just 5 minutes what hurdles they have faced, how they overcame them, and what their key learning is. Be inspired, subscribe, leave a comment, go and change the world!
Artificial intelligence is no longer simply helping people work faster. According to Nicolas Chaillan, it is beginning to replace entire teams—and most people are dangerously unprepared for what comes next. Nicolas, the former Chief Software Officer of the U.S. Air Force and Space Force, returns to Unlatched Mind for a wide-ranging conversation about the rapidly accelerating AI revolution. He explains how he now uses autonomous AI agents to build software, manage marketing, produce content, launch mobile apps, and operate businesses that would traditionally require dozens of employees. We explore the moment Nicolas realized AI had crossed the line from augmentation to replacement, why he believes white-collar employment could face enormous disruption, and what workers, parents, students, and entrepreneurs should be doing now to remain relevant. The conversation also examines the future of college, self-directed learning, cybersecurity, deepfakes, AI-generated journalism, and the importance of preserving human purpose and connection in an increasingly automated world. Finally, Nicolas offers a blunt assessment of the Pentagon's AI strategy, its deteriorating relationship with Anthropic, and whether the United States is moving quickly enough to compete with China. In this episode: How autonomous AI agents can operate an entire business Why software developers may be among the first professions disrupted The shift from AI augmentation to AI replacement How Nicolas built an AI-powered news organization Why prompting may soon be replaced by agent orchestration The potential economic and social consequences of widespread job loss What children should learn to prepare for an AI-dominated future Whether college still provides a worthwhile return on investment Cybersecurity, deepfakes, misinformation, and autonomous systems The Pentagon, Anthropic, China, and America's AI readiness Nicolas's new book, Replacement This is not a conversation about some distant artificial-intelligence future. It is a warning and a practical look at a transformation that may already be underway. Find Nic's work at https://www.inthenicoftime.us
What parts of yourself have you learned to hide in order to be taken seriously? My guest on this episode is Mark Heywood, a friend of the show, returning guest and someone I've collaborated with on a number of projects. Episode Summary & Guest ProfileMark has spent more than twenty years working in crisis management and operational resilience, while simultaneously building a successful career as a bestselling novelist, screenwriter and, more recently, stand-up comedian.On the morning we recorded this conversation, Mark published an article marking his fifty-first birthday. In it, he reflected on the pressure many of us feel to present only one version of ourselves professionally, arguing that his creative and corporate lives were never really separate. As he puts it, they were 'not two jobs, but one obsession wearing two different lanyards.' That simple idea becomes the starting point for a much wider discussion about the stories we tell ourselves, and the stories organisations tell themselves.Along the way we explore:Why "stay in your lane" may say more about other people's expectations than your own potential.Why organisations often encourage people to bring their whole selves to work, while rewarding conformity.What interviews, dress codes and organisational culture reveal about human behaviour.Why stories often influence behaviour more effectively than rules, policies and frameworks.What films can teach us about operational resilience, cybersecurity and crisis management.Why the Titanic remains one of the most powerful lessons in organisational failure.How imagination is a strategic capability rather than a soft skill.Why thinking through "severe but plausible" scenarios requires organisations to become better storytellers.LinksMark's birthday article: "A Birthday Declaration from Someone Who Spent Over Twenty Years Pretending to Be Half of Himself" (LinkedIn)Mark's Behind The Spine podcastThe Writing SalonBehind The Spine podcastMark on LinkedInMark's previous appearances on the show talking about The Creative Industries under COVID, and Human Risk in the Creative IndustriesFilms, Stories & People MentionedDie Hard Apollo 13 The Martian The Odyssey (Christopher Nolan)Don't Look UpSnakes on a Plane Sharknado Noah's Ark RMS TitanicRachel Heyhoe Flint Jeremy King AI-Generated Timestamped Summary00:00 – Why do we hide parts of ourselves to be taken seriously?03:40 – Mark explains why he stopped separating his creative and corporate identities.08:00 – Which hobbies and outside interests are considered professionally acceptable—and why?10:30 – Job interviews, authenticity and bringing your whole self to work.16:00 – Jeremy King on why behaviour matters more than dress codes.19:00 – Rachel Heyhoe Flint, the MCC and what institutional rules reveal about culture.23:00 – Why stories influence behaviour more effectively than rules.24:00 – The Trojan Horse and using films to teach cybersecurity and resilience.29:00 – The Titanic as a lesson in organisational resilience rather than maritime history.32:00 – Conduct versus outcomes: why testing matters more than compliance.36:00 – Using stories and popular culture to make risk real.38:00 – Noah's Ark, history and the enduring power of storytelling.40:30 – CrowdStrike, PPE and why organisations keep repeating the same mistakes.46:00 – Stories aren't predictions—they're a way of exploring possibility.49:00 – A ransomware exercise and the danger of relying on fixed policies.52:00 – Returning to the Titanic: preparing for the inquiry before the crisis.55:00 – Thinking like an attacker and challenging assumptions about cyber risk.58:00 – Taylor Swift, insurance and why seemingly ordinary data can become highly sensitive.1:02:00 – The idea of "risk inflation" and why yesterday's rules aren't enough.1:10:00 – Why memorable stories change behaviour more effectively than realistic scenarios.1:15:00 – Reverse stress testing and imagining what could really break an organisation.1:20:00 – RAG ratings, reporting and the danger of looking resilient instead of being resilient.1:23:00 – Final reflections on creativity, identity and why being more than one thing is a strength.
In this episode of Talking Innovation, I sit down with cybersecurity veteran Jon Oltsik for a wide-ranging conversation about the rapid rise of AI in security operations, the future of automation, and how work itself is being reshaped. Jon shares his perspective on the AI SOC, exposure management, agentic AI, and why human judgment will remain critical even as more tasks become automated. The discussion goes beyond cybersecurity into the broader impact of AI on business, healthcare, education, research, and everyday life. From smarter diagnostics and personalized learning to new career paths and simulation-based training, Jon and I explore how AI is already changing the way we work and learn... and what that means for the next generation of professionals. They also dig into the risks: data centralization, surveillance, cyber warfare, and the widening gap between organizations that are ready for this shift and those that are not. It's a thoughtful, grounded, and future-facing conversation about opportunity, disruption, and the importance of staying adaptable in a fast-moving world. I hope you enjoy it!
On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes. He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response. The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools. 00:00 Weekend Show Intro 00:39 Meet Matt Burke 01:23 Concierge Care Model 02:45 Why Healthcare Security 03:13 Origin Story 3AM Call 05:20 Top Threats 2026 06:29 Defense Tools That Work 07:50 AI Helps And Hurts 09:37 Winning Doctor Buy In 10:57 Castle Versus Response 13:42 Threat Surge And Resilience 18:17 Culture And MFA Everywhere 19:59 Career Advice And Magic Wand 22:33 Closing Thanks
The first PC virus. The fastest-spreading malware the internet has ever seen. The Manhattan Project moment for cyberweapons. He was there for all of it. We sat down with Mikko Hyppönen — the man behind Hyppönen's Law: if it's smart, it's vulnerable — to talk through 30 years at the center of cybersecurity's biggest moments, and why he just left it all behind for a new fight. Watching on video? Here's our goofy faces. Give it a watch since he brought the real gear with him and bear with us as we navigate a new editing flow. Hacked is presented by NordLayer. NordLayer is a network security platform for modern teams. NordLayer gives companies centralized control over who can access their systems, keeps every connection fast and encrypted, and requires no additional hardware or complex infrastructure. nordlayer.com/hackedpodcast Learn more about your ad choices. Visit podcastchoices.com/adchoices
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
Jim LaRoe, the CEO of Symphion, a software and services company specializing in print fleet cybersecurity joins Enterprise Radio. Symphion's focus has been on continual … Read more The post Jim LaRoe Discusses Why Cybersecurity for Printers & Connected IoT Are Mission Critical in 2026 appeared first on Top Entrepreneurs Podcast | Enterprise Podcast Network.
Notes: Ms. Ayerza studied criminology, forensic behavioural sciences and psychology. Her early research examined eyewitness memory and the re-entry of exonerees before she became interested in cybercrime and cyberstalking. She was drawn to cybercrime because it is not limited to hacking, malware and phishing. Technology is part of everyday life through social media, email, dating apps and other commonly used services. Dating apps allow users to create profiles, specify the people and relationships in which they are interested and indicate interest in other users. When two users express an interest in one another, they can normally begin communicating through the app. Some dating apps are intended for broad audiences, while others serve particular lifestyles, interests or sexual orientations. Profiles are often presented as individual photographs or grids of photographs from which users make selections. Ms. Ayerza explains that dating apps are designed to make dating convenient and can feel like games. The superficial and rapid nature of matching can encourage users to make decisions based primarily on photographs. Harassment can arise when users send repeated messages in an effort to gain someone's attention. Some people may not recognize these repeated or unwanted communications as harassment. Users may also deliberately match with someone because they disagree with something in that person's profile and want an opportunity to criticize or harass them. Ms. Ayerza conducted an online survey of adult dating app users living in the United States. The study examined the information people included in their profiles, the photographs they shared and characteristics of the applications they used. The study considered whether users disclosed their relationship preferences, sexual orientation, workplace or occupation. It also examined whether they used their full name or an alternative name and whether their photographs included friends or family. Verification on dating apps can be a relatively superficial process in which a live photograph is compared with the photographs on a profile. Premium features may also allow users to change the location in which their profiles appear. Users often adopt their own protective measures, such as using pseudonyms or withholding photographs of their faces. However, designing effective technical safeguards is difficult because repeated messages can be part of both ordinary conversations and harassment. Most dating app users do not experience harassment, but Ms. Ayerza says that around a quarter of the users in the study experienced these forms of harm. The study did not compare victimisation across individual dating apps. Ms. Ayerza suggests that larger platforms may have more resources and face greater public pressure to introduce safeguards, while smaller platforms may have fewer resources. Sharing relationship or sexual orientation preferences was not found to increase risk. Ms. Ayerza suggests that these preferences help platforms present users with people who have similar interests without necessarily revealing where someone can be found. Including information about where a person works or studies increased risk. Photographs featuring friends or family also had an influence because they can reveal social connections and additional information about the user. Uploading photographs of one's face was not found to increase risk, possibly because facial photographs are a normal and often required part of using dating apps. Matching with someone under the age of 18 increased risk. Ms. Ayerza connects this finding to the limited measures used by dating apps to confirm that users are old enough to participate. One of the most surprising findings was that using a pseudonym or nickname increased risk. Ms. Ayerza discusses the possibility that an alternative name creates a false sense of security and encourages people to disclose more information. Ms. Ayerza advises users to think carefully about what they disclose. Preferences may be appropriate to share, while details about occupations, workplaces, friends and family may be better withheld until someone is known more closely. She emphasizes that responsibility should not be placed entirely on victims. People should understand that harassment is unacceptable and platform operators should do more to prevent and respond to harmful behaviour. Possible platform interventions include better reporting mechanisms and educational or training modules that users complete before creating a profile. Schools could help prepare young people to communicate appropriately on dating apps once they are old enough to use them. Ms. Ayerza also argues that governments should treat conduct on dating apps more seriously because every profile represents a real person. Future researchers need measures that reflect the activities people actually perform on dating apps. Greater consistency would also make it easier to compare findings across studies. Ms. Ayerza plans to examine offending as well as victimisation. Her future research will consider unwanted sexual messages, sexual violence and the experience of multiple forms of harm on dating apps. About our guest: Jennifer M. Ayerza, M.A. https://cls.gmu.edu/people/jayerza https://cebcp.org/team/jennifer-ayerza/ https://www.linkedin.com/in/jennifer-ayerza-38353a233 Papers or resources mentioned in this episode: Ayerza, J. M., Lee, J. R., O'Malley, R. L., & Lee, C. S. (2026). Cyberstalking and online dating: Examining cyberstalking victimization among dating app users. Asian Journal of Criminology, 21, Article 5. https://doi.org/10.1007/s11417-025-09480-2
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198 Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh Inconsistent Group Chats https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The bullish case for the AI capex spenders, rather than the receivers. Cybersecurity expert Ivan Tsarynny's AI warning after Anthropic discloses three of its models breached their testing environments. Plus, Brookings' Robin Brooks on how the market has corrected its misreading of the June Fed meeting. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Tonight on America At Night with McGraw Milhaven, Dr. Georges Benjamin, CEO of the American Public Health Association and former Maryland Secretary of Health, discusses the resurgence of measles, why cases have reached a 35-year high, what's driving the increase and what public health officials say Americans should know. Minnesota State Representative Jess Hanson joins McGraw to discuss the legal battle between Elon Musk's xAI and the state of Minnesota over the nation's first law banning AI-powered "nudification" technology, and what the case could mean for artificial intelligence, online safety and future regulation. Cybersecurity expert and Luta Security CEO Katie Moussouris examines today's evolving cyber threats, the growing role of AI in digital security and the steps individuals and businesses can take to better protect themselves online. Plus, Bill Clevlen, founder of BillOnTheRoad.com, returns with another edition of Bill on the Road, sharing travel tips, hidden destinations and inspiration for your next adventure. Learn more about your ad choices. Visit podcastchoices.com/adchoices
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
Sean Juroviesky is a senior security engineer at SoundCloud. In this episode, he joins host Paul John Spaulding to discuss a new mandate out of France regarding the future of quantum, as well as the increase in AI agent-based violence. • For more on cybersecurity, visit us at https://cybersecurityventures.com
Join ISA for a recap of day one of the OT Cybersecurity Summit, held in June 2026 in Prague. Speakers include:Claire Fallon, ISAMegan Samford, Schneider ElectricTatyana Bolton, OT Cybersecurity CoalitionBerta Jarošová, Women4Cyber CzechiaCheri Caddy, Savannah River National Laboratory
The stories that matter most to #cybersecurity insiders, analysts, and business leaders. Delivered every day.Get your CPEs: https://cyberthreatbrief.simplycyber.io/cpeStop ransomware without the hassle. Allow what you need and block the rest with ThreatLocker Zero Trust Platform — simple to deploy, simple to manage: https://www.threatlocker.com/dailycyberCheck out Flare.io at https://simplycyber.io/flareCheck out Pay-What-You-Can Antisyphon Training: https://simplycyber.io/antisyphonSC Academy - The Place for Cyber Careers: https://zpr.io/mYV5232V66QnJoin SC Discord: https://SimplyCyber.io/DiscordNews: https://cisoseries.comFollow SC: https://simplycyber.io/socialsSign up for the Simply Cyber Newsletter: https://simplycyber.io/newsletterShop merch at https://shop.simplycyber.io
ServiceNow has been hammered in the software selloff, but our Q2 2026 earnings breakdown reveals a business quietly repositioning itself for the AI edge. CEO Bill McDermott and CFO Gina Mastantuono delivered 25% year-over-year revenue growth, accelerating subscription guidance, and two strategic acquisitions, Veza and Armis, that push ServiceNow into identity, access, and device-level cybersecurity. We break down why McDermott calls this the fastest-growing risk and security business among the top 10 enterprise cybersecurity players, and why the market still treats ServiceNow like an AI-era loser rather than an edge-AI beneficiary.The conversation covers GAAP versus non-GAAP metrics, including a 55% decline in GAAP operating income, balance sheet strength post-acquisitions, full-year subscription revenue guidance near $16 billion, and a reverse DCF on free cash flow per share to gauge what the current stock price is actually pricing in. We also compare ServiceNow's cybersecurity revenue against pure-play peers like Palo Alto Networks, CrowdStrike, and Fortinet using data from our research dashboard.If you're evaluating semiconductor and AI infrastructure stocks, foundry exposure, or non-correlated edge-AI plays for portfolio diversification, this ServiceNow deep dive lays out both the bull case and the real risks.Semi Insider members get access to CSI's research platform and tools, plus deeper research as it happens. Join at chipstockinvestor.com.Get 15% off your fiscal.ai membership with our link: fiscal.ai/csiThis content is for general information or entertainment only and is not specific or individual investment advice. Forecasts may not develop as predicted, and there is no guarantee any strategy discussed will be successful. All investing involves risk, including loss of principal. CSI owns shares of ServiceNow.
Why would this happen? Lindsey Reiser from CBS News joined Vineeta on The WCCO Morning News
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Following a recent cybersecurity breech by OpenAI, in which two of their in-progress models autonomously hacked into the AI company Hugging Face, lawmakers from both sides of the aisle are pushing for an "AI Kill Switch" bill in Congress. On Today's Show:Brendan Bordelon, AI and tech influence reporter at Politico, discusses Washington's changing approach to AI regulation amid growing concerns over data security in every sector, and and unpacks how tech giants are responding to shift. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Sriram is a Certified Independent Director (IICA) and Corporate Governance Practitioner with 20+ years of experience across india, APAC, US, and UK; an MBA and B Tech (IT), certified in Al Security & Governance, Cybersecurity, and DPDPA, and published author on corporate governance and Al. Website: https://www.sriramvijayakumar.com LinkedIn: https://www.linkedin.com/in/sriram-vijayakumar-id/ CallumConnects Micro-Podcast is your daily dose of wholesome leadership inspiration. Hear from many different leaders in just 5 minutes what hurdles they have faced, how they overcame them, and what their key learning is. Be inspired, subscribe, leave a comment, go and change the world!
After exploring identity sprawl, cloud complexity, ransomware recovery, disaster recovery strategy, and cyber resilience, Paul sits down with Joe Ross, Joe Galvan, Terry Murray, John Parker, and Stephen Sepulveda, who returns for the conclusion of this special five-part series.Together, they revisit the foundational practices that consistently determine whether an organization recovers or becomes the next cautionary tale.From immutable backups and recovery testing to application ownership and modern cyber recovery platforms, the panel cuts through the noise to focus on what actually works under the highest pressure. The episode concludes with each guest sharing the single most important priority every IT leader should take back to their organization.Whether you're a CIO, CISO, IT Director, Infrastructure Architect, or Disaster Recovery professional, this final conversation brings together the key lessons from the series into a single practical roadmap for building true cyber resilience.Topics DiscussedWhy backup testing is the only way to know you'll recoverThe technologies that are changing modern cyber recoveryWhy application owners must be part of every recovery strategyImmutable backups and the role they play in ransomware defenseLessons learned from the experts across all five episodesThe top priorities every IT leader should focus on to strengthen resiliencePractical steps organizations can take today to prepare for tomorrow's outage
In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.Send us Fan MailSupport the show
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.
The stories that matter most to #cybersecurity insiders, analysts, and business leaders. Delivered every day.Get your CPEs: https://cyberthreatbrief.simplycyber.io/cpeStop ransomware without the hassle. Allow what you need and block the rest with ThreatLocker Zero Trust Platform — simple to deploy, simple to manage: https://www.threatlocker.com/dailycyberCheck out Flare.io at https://simplycyber.io/flareCheck out Pay-What-You-Can Antisyphon Training: https://simplycyber.io/antisyphonSC Academy - The Place for Cyber Careers: https://zpr.io/mYV5232V66QnJoin SC Discord: https://SimplyCyber.io/DiscordNews: https://cisoseries.comFollow SC: https://simplycyber.io/socialsSign up for the Simply Cyber Newsletter: https://simplycyber.io/newsletter
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Artificial Intelligence is transforming business at an unprecedented pace.Cyber threats are evolving by the hour.Yet many leaders are still treating technology as an IT problem instead of a leadership priority.In this episode, we sit down with Ben Wilcox, CTO and CISO of ProArch, to discuss what executive leaders need to know about AI, cybersecurity, and building organizations that are resilient, scalable, and prepared for what's next.
The Roundtable Panel: a daily open discussion of issues in the news and beyond. Today's panelists are Lecturer of Cognitive Sciences at Rensselaer Polytechnic Institute and former Fulbright US Scholar to Egypt Jackie Berry, Dean of the College of Emergency Preparedness, Homeland Security and Cybersecurity at the University at Albany Robert Griffin, Former Times Union Associate Editor Mike Spain, and Diplomat in Residence at Bard College. She retired from the U.S. Foreign Service in 2025 after over 30 years in public service. Her last post was ambassador to the SE Asian country, Timor-Leste Donna Welton.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Java Spring Boot "heapdump" scans https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188 VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/ Microsoft Defender for Linux Update may disable restart https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009 MongoDB Updates CVE-2026-13072 https://github.com/advisories/GHSA-wvx7-gr2m-7rf5 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
There's always been a gap between the discovery of a security issue and the time it takes to remediate. Now AI models can autonomously find weak points and chain together actions to exploit them. How does AI change the notion of “fast enough” for network defense? On today’s sponsored episode we dig into how FireMon... Read more »
This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
Leo and this week's panel pay tribute to tech journalist John C. Dvorak, then dive into how AI, relentless hardware shortages, and shifting media habits are reshaping the tech world faster than anyone predicted. The crew discusses how an OpenAI model exploited its own network to cheat on cybersecurity benchmarks, flipping the script on what AI agents are capable of and what might be next for digital security. John C. Dvorak has died OpenAI's accidental cyberattack against Hugging Face is science fiction that happened China's Top AI Event Delivers Message to the U.S.: We're Coming for You Alphabet Quadruples Profit to $112 Billion, Fueled by A.I. Investments The EU Fines Google $1 Billion for Prioritizing Its Own Services in Search The EU just fined AliExpress €550M, its biggest DSA penalty yet Apple Sued by Customers Who Lost Combined $1.8 Million Through Fake Bitcoin Wallet in App Store A.I. 'Vibecoded' Apps Are Flooding Apple's App Store Anthropic's $1.5B copyright settlement approved; only 350 authors opted out ISPs' long nightmare of having to list all the fees they charge is finally over Government Lawyers Say Trump Admin Can Use TikTok Again Because 'Owned' No Longer Means 'Owned' Judge halts Paramount's $111B purchase of Warner Bros. in a win for US states The AI industry has already spent $65 million ahead of the midterm elections with no signs of slowing down. Galaxy Z Fold 8 Ultra launches as Samsung's 'most advanced' foldable, starts at $2,099 US government targets Cop City protester over phone operating system Kill the Cookie Banner! Host: Leo Laporte Guests: Devindra Hardawar, Larry Magid, and Allyn Malventano Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: box.com/AI arcticwolf.com/trends hoxhunt.com/securitynow superhuman.com gusto.com/twit
Plus: chip maker CXMT becomes the most valuable company listed in mainland China in its debut. And some U.S. companies plan to increase headcount despite AI fears. Imani Moise hosts. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans for ESAFENET CDG 3 Document Management System Weak Logins https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184 DNS Poisoning Tactics Expand to Hospitality Wi-Fi https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/ Silent Replacement of Trusted macOS App Executables https://mysk.blog/2026/07/23/macos-overwrite-app-executables/ GitHub and PyPi Defense updates https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/ https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/ https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich