Podcasts about ddos

Cyber attack disrupting service by overloading the provider of the service

  • 1,511PODCASTS
  • 4,207EPISODES
  • 46mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Jul 30, 2026LATEST
ddos

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about ddos

Show all podcasts related to ddos

Latest podcast episodes about ddos

The Tech Trailblazers Startup Podcast
Founders on Fire: Rethinking Cybersecurity with Steve Brodie & Goldilock

The Tech Trailblazers Startup Podcast

Play Episode Listen Later Jul 30, 2026 26:29


In this episode of the Founders on Fire series by the Tech Trailblazers Awards, host Rose Ross sits down with Steve Brodie from Goldilock—a Security Trailblazer Gold winner.Steve shares the story behind Goldilock, a UK-based cybersecurity company founded to revolutionise operational resilience and risk reduction by enabling complete, remote disconnection from the internet at the physical layer.In this episode, we cover:Beyond the "Kill Switch": Why Goldilock rebranded its flagship technology to Firebreak and how proactive defence differs from reactive emergency response.Hardware Enforcement: How physical layer security acts as both the first and last line of defence alongside traditional software-focused setups.Cross-Sector Security: The role of hardware controls across IT, IoT, OT, and Critical National Infrastructure (CNI) amidst changing legislative landscapes like the UK Cybersecurity Bill.Emergency & Autonomous Use Cases: How physical disconnection protects systems from ransomware, DDoS attacks, and AI-driven threats while keeping essential functions running.

Cyber Security Today
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens

Cyber Security Today

Play Episode Listen Later Jul 29, 2026 12:56


Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began. Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps. Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance. Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft. 00:00 Introduction and Headlines 00:30 South Carolina Hospital Ransomware Attack 02:07 Healthcare Ransomware Crisis 03:25 IoT Botnet Uses Blockchain 05:40 Shared AI Chats Exposed 08:00 AI Agent Infiltrates Thailand Ministry 10:45 Swiss Train Maker Refuses Ransom 12:31 Closing Remarks

Technology for Business
Web Application Firewalls Explained

Technology for Business

Play Episode Listen Later Jul 29, 2026 47:15


This week we are joined by Michael Collins, Principal Consulting Solutions Architect at Barracuda, to explain what a web application firewall (WAF) is and how it differs from a network firewall. Along with Nate, CIT's Director of Cybersecurity, we explore how WAFs help defend websites, web apps, and APIs against threats like injection, bot attacks, brute force attempts, and DDoS, especially as AI “vibe coding” leads to insecure public-facing applications. The episode covers choosing basic vs enterprise-grade WAF protection based on business criticality and sensitive data, tuning to reduce false positives using detect vs block modes and staged deployment, visibility into daily attacks, geofencing and IP blocking, and how WAFs support compliance efforts like PCI and HIPAA as part of a broader security strategy.00:27 What Is a WAF03:58 Defining Web Apps07:41 APIs and Vibe Coding Risks11:12 Choosing the Right WAF14:31 Tuning and False Positives20:52 Onboarding Detect to Block28:06 Compliance and Regulations31:48 Visibility and Geofencing38:13 DDoS Story and Wrap Up42:54 Testing and Deployment Options46:35 Final Thanks and CTACheck out more from Barracuda

The Starting Zone: The World of Warcraft Podcast!
Episode #746: The Season One Checklist!

The Starting Zone: The World of Warcraft Podcast!

Play Episode Listen Later Jul 27, 2026 88:50


Welcome to The Starting Zone Podcast, The World of Warcraft Podcast for New and Experienced Players! This week Spencer Downey and Jason Lucas discuss the Season One Achievements going away, the Gameplay Incident, Hotfixes and everything going on around Azeroth! Episode #746: The Season One Checklist! What's New this Week in World of Warcraft! Weekly Event - Arena Skirmish Bonus Event TURBULENT TIMEWAYS WEEK 4 - Burning Crusade Timewalking PvP Brawl - Gravity Lapse Mythic+ Affixes: Devour Trial of Style - August 1st to 8th Darkmoon Faire - August 2nd to 8th Don't miss it Weekly Checklist World Boss - Nexus-Captain Leth'ir (Naigtal) Special Assignment World Quests Weekly from SIlvermoon, outside the Bank Dungeon weekly from Halduron World Events Saltheril's Soiree in Eversong Woods Abundance in all zones, with a rotating Abundant Harvest zone Legends of the Haranir in Harandor Stormarion Assault in Voidstorm Important Posts July's Trading Post Ignites a True-Blue Celebration [Updated 7/22] Join the Final Surge for Decor Duels The Clock is Ticking on Midnight Season 1 Achievements and Rewards Restorations of Hardcore Characters Lost to DDoS on July 21 Prohibited Gameplay Incident and Response Midnight: Curse of Ula'tek PTR Development Notes Hotfixes and much more! You can find us on Discord at The Starting Zone or email us at TheStartingZone@Gmail.com Have you heard about our Patreon? It's a great way to support the show and goes towards making more content for you! Check it out here: https://www.patreon.com/thestartingzone Looking for to grab some great TSZ merch? Look no further than here! We've got the shirts, hoodies, mugs, pillows even stickers you want!

legends discord achievements checklist world of warcraft ticking ddos azeroth soiree silver moon hotfixes jason lucas final surge starting zone tsz spencer downey
Speak Out Stand Out by Green Communications
Winn Schwartau: Critical Ignoring For Digital Life

Speak Out Stand Out by Green Communications

Play Episode Listen Later Jul 27, 2026 33:54 Transcription Available


Your kid is going to see the internet, even if you try to block it forever, so we bring in a voice who has been studying the digital world from the beginning. Cybersecurity expert, author, and futurist Winn Schwartau joins us to answer the question parents ask most: “How can I protect my kids online?” His response is blunt and strangely reassuring: you can't, not completely. What you can do is get serious about tools, involvement, and a simple security mindset that works everywhere from banks to families: detect and react.We unpack what healthy digital habits actually look like at home, starting with screen time limits and why the type of screen matters as much as the number of hours. We talk about social media addiction, the like button as a reward loop, and why hundreds of online “friends” can warp teen identity and fuel insecurity. Wynne also explains research suggesting kids raised on constant tech may be wired differently, and why real human connection still takes time and effort.Then we go deeper into misinformation, attention economics, and Winn's upcoming concept of “critical ignoring,” a practical way to fight information overload before it becomes a brain-level DDoS attack. You'll hear simple filters like “I don't care” and “I don't have time,” why “do your own research” is often a red flag, and how to approach source verification with “trust nothing, verify twice.” If you're looking for online safety tips for parents, media literacy for teens, and digital wellbeing strategies that don't rely on fear, this conversation delivers.Connect with WinnCheck out the book The Art & Science of Metawar: How to Coexist With AI-Driven Reality Distortion, Disinformation, & Addiction in the Metaverse. You can also contact Winn on Instagram.If this helps, subscribe, share with a parent friend, and leave a review so more families can find the show.Welcome to Speak Out Stand Out — the show where we build confidence in our future, one voice at a time. I'm your host, Elizabeth Green.I grew up shy, so I know firsthand how life-changing it can be when someone helps you find your voice. Now, I get to help kids and teens do exactly that — and this podcast is a place to share those tools with you.Each week, I talk with experts and inspiring guests about simple, practical and tangible ways to help the young people in Thanks for listing! Be sure to check out the show notes for additional resources including a free public speaking lesson and 52 fun practice prompts.  And if you enjoyed what you heard today, please give us a follow. Thanks for Listening to Speak Out, Stand OutLike what you hear? We would love if you would rate and review our podcast so it can reach more families. Also - grab our free mini lesson on impromptu speaking here. This is ideal for kids ages 6+.Interested in checking out our Public Speaking & Debate courses? Find more here!

The Bitcoin Matrix
Bitcoin Secures $1 Trillion and Has No Security Team | Luke de Wolf

The Bitcoin Matrix

Play Episode Listen Later Jul 25, 2026 160:57


"Bitcoin secures over a trillion dollars in value. It has no security team." Luke de Wolf is a cybersecurity professional and author of Defending Bitcoin. Luke spent his career defending critical infrastructure, the control systems behind power grids and gas pipelines. His claim: Bitcoin is the world's first decentralized critical infrastructure, and it should be defended with the same risk-management frameworks that protect the physical world. A trillion-dollar network with no security team. And Luke is a former BIP-110 skeptic who flipped to supporting it making him a moderate who pisses off both sides. We get into the CIA triad and why availability is the whole game, people as the weakest link and the Stuxnet lesson, the real cost of running a node over time, spam as a DDoS and the hidden tax on Bitcoin, the two CVEs behind inscriptions, and the full BIP-110 fight. We discuss why he flipped, the game theory of activation, soft fork vs hard fork, the intolerant minority, and whether BIP-110 even has a failed state. This is the defender's case for Bitcoin, and the fight is happening right now. Subscribe so you never miss an episode.

The CyberWire
A nightmare on Windows street.

The CyberWire

Play Episode Listen Later Jul 17, 2026 25:49


Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada's surveillance bill faces U.S. scrutiny. Meta's Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espionage campaign hits Bangladesh's military. The Hewlett Foundation commits $100 million to emerging tech security. And U.S. prosecutors dismantle an alleged cyber-enabled money laundering network. Our guest is Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS readiness and the identity security challenges facing public safety agencies. Leaked source code reveals an AI mixtape. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Nick Stohlman, Vice President of CJIS Strategy at Imprivata, talking about CJIS, Criminal Justice Information Services, readiness and the identity security challenges facing public safety agencies. Selected Reading New Windows LegacyHive zero-day gives hackers admin privileges (Bleeping Computer) The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat (Infosecurity Magazine) CISA urges immediate action on actively exploited Fortinet flaws (Bleeping Computer) Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record) Meta Oversight Board finds top AI models less likely to criticize repressive regimes (Reuters) Commerce faces rising AI bot activity, escalating DDoS attacks, and new fraud tactics (Akamai) From Biography to Backdoor: Tracking a DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel (Cyderes) Hewlett Foundation Announces New $100 Million Emerging Technology and Security Initiative (Hewlett Foundation) US charges two over laundering $43 million from investment fraud (Bleeping Computer) Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
The AI lock comes off.

The CyberWire

Play Episode Listen Later Jul 1, 2026 30:53


The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Buongiorno da Edo
I protocolli più stupidi della storia (e l'addio al podcast) - Buongiorno 328

Buongiorno da Edo

Play Episode Listen Later Jun 30, 2026 25:56


Chiudiamo questo podcast in bellezza con una puntata speciale e defaticante: vi racconto i 10 protocolli più stupidi della storia di Internet. Scopriremo che oltre ai geni che hanno creato la rete, ci sono stati anche ingegneri che si divertivano a trasmettere la 220V su IP, e altri che inventavano disastri di sicurezza clamorosi... per poter organizzare le partite di pallavolo.Ci prendiamo una lunga pausa. Ciao!Fonti e approfondimenti:- Tutti gli RFC citati in puntata: - RFC 1149 (IPoAC): https://www.rfc-editor.org/rfc/rfc1149 - RFC 2549 (IPoAC with QoS): https://www.rfc-editor.org/rfc/rfc2549 - RFC 2324 (HTCPCP): https://www.rfc-editor.org/rfc/rfc2324 - RFC 9110 (Save 418): https://www.rfc-editor.org/rfc/rfc9110 - RFC 3251 (Electricity over IP): https://www.rfc-editor.org/rfc/rfc3251 - RFC 1606 (IPv9): https://www.rfc-editor.org/rfc/rfc1606 - RFC 1437 (MIME Teleport): https://www.rfc-editor.org/rfc/rfc1437 - RFC 7511 (Scenic Routing): https://www.rfc-editor.org/rfc/rfc7511 - RFC 742 / RFC 1288 (Finger): https://www.rfc-editor.org/rfc/rfc742 - RFC 864 (Chargen): https://www.rfc-editor.org/rfc/rfc864- Implementazione IPoAC (Bergen Linux User Group): https://en.wikipedia.org/wiki/IP_over_Avian_Carriers#Real-life_implementation- Winston il piccione batte l'ADSL di Telkom: https://www.reuters.com/article/idUSTRE5893PB/- Storia di Les Earnest e del protocollo Finger: https://en.wikipedia.org/wiki/Finger_protocol- Allarme CISA sull'amplificazione DDoS tramite Chargen: https://www.cisa.gov/news-events/alerts/2014/01/17/udp-based-amplification-attacksLa mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it00:00 Intro05:13 I 7 protocolli nati per scherzo17:06 I 3 protocolli reali... ma terribili23:12 Outro e Addio#storia #protocolli #rfc #internet #addio

Podlodka Podcast
Podlodka #483 – Captcha

Podlodka Podcast

Play Episode Listen Later Jun 29, 2026 75:46


CAPTCHA давно перестала быть историей про светофоры, пешеходные переходы и кривые буквы. Сегодня это скорее часть антибот-защиты: система оценивает риск, смотрит на сигналы поведения и решает, можно ли пропустить пользователя сразу или лучше проверить внимательнее. В этом выпуске говорим с Русланом Сабиргалиевым из Smart Captcha и антибот-защиты от Яндекса не только про UX-боль, но и про экономику атак: зачем боты вообще приходят, сколько это может стоить сервису и почему иногда проще усложнить жизнь атакующим, чем пытаться идеально отличить человека от машины. Разбираем, как работают современные капчи, что такое невидимые проверки и risk scoring, какие сигналы может учитывать система, где заканчивается обычная капча и начинается антифрод. Отдельно обсуждаем false positive: что делать, когда нормального пользователя система внезапно считает подозрительным. Ещё поговорили про хороших ботов, AI-агентов, DDoS, защиту логина, форм, SMS и API, а также про доступность, ведь капча, которая защищает сервис, но ломает сценарий реальному пользователю, тоже становится проблемой, просто с другой стороны.     Партнер эпизода — Контур. Команда из 12 000 сотрудников развивает экосистему продуктов для бизнеса, от онлайн-бухгалтерии до сервиса видеоконференций. Вы наверняка знаете некоторые из них: Толк, Диадок, Эльбу и другие. Присоединяйтесь, если вас драйвят сложные задачи и возможность избавлять миллионы людей от рутины: https://clck.ru/3UCKWB Послушать новый подкаст Контура «От нуля до единицы. История российского IT»: https://kontur-it-story.mave.digital/ Реклама 16+, АО «ПФ «СКБ Контур», ОГРН 1026605606620. 620144, Екатеринбург, ул. Народной Воли, 19А. Erid:2SDnjcK3izE     Также ждем вас, ваши лайки, репосты и комменты в мессенджерах и соцсетях!
 Telegram-чат: https://t.me/podlodka Telegram-канал: https://t.me/podlodkanews Twitter-аккаунт: https://twitter.com/PodcastPodlodka Ведущие в выпуске: Андрей Смирнов, Аня Симонова

Defence Connect Podcast
CYBER UNCUT: Beware AI and influencers, NSW Rural Fire Service hacked, and say goodbye to the Essential Eight!

Defence Connect Podcast

Play Episode Listen Later Jun 29, 2026 33:01


This week, Cyber Uncut looks at important tax time advice, a string of Aussie hacks that have exposed sensitive personal information, and the Australian Signals Directorate's decision to retire the Essential Eight. CPA Australia has a warning this tax time, and that is to be very aware of taking tax advice from AI chatbots and financial influencers. An AI hallucination could cost you real money, so this is something to pay attention to! It's been a terrible week for data breaches in Australia, with the NSW Rural Fire Service warning its members of a data breach, and a ransomware actor dumping teacher and student data from the Reynella East College breach onto the dark web. Right now, cyber criminals are no doubt combing through the data, making this breach one that parents should pay attention to. Finally, the ASD has said that, as good as the Essential Eight is, it's no longer fit for purpose in the AI age. Find out what's going to replace it, and then stay tuned for an update on the alleged distributed denial-of-service (DDoS) attack that took down a One Nation website a couple of weeks ago. Just another week in cyber security. Enjoy, The Cyber Uncut team

Cyber Security Uncut
Beware AI and influencers, NSW Rural Fire Service hacked, and say goodbye to the Essential Eight!

Cyber Security Uncut

Play Episode Listen Later Jun 26, 2026 33:01


This week, Cyber Uncut looks at important tax time advice, a string of Aussie hacks that have exposed sensitive personal information, and the Australian Signals Directorate's decision to retire the Essential Eight. CPA Australia has a warning this tax time, and that is to be very aware of taking tax advice from AI chatbots and financial influencers. An AI hallucination could cost you real money, so this is something to pay attention to! It's been a terrible week for data breaches in Australia, with the NSW Rural Fire Service warning its members of a data breach, and a ransomware actor dumping teacher and student data from the Reynella East College breach onto the dark web. Right now, cyber criminals are no doubt combing through the data, making this breach one that parents should pay attention to. Finally, the ASD has said that, as good as the Essential Eight is, it's no longer fit for purpose in the AI age. Find out what's going to replace it, and then stay tuned for an update on the alleged distributed denial-of-service (DDoS) attack that took down a One Nation website a couple of weeks ago. Just another week in cyber security. Enjoy, The Cyber Uncut team

The Tech Blog Writer Podcast
The API Security Crisis Exposed By Akamai's State Of The Internet Report

The Tech Blog Writer Podcast

Play Episode Listen Later Jun 23, 2026 31:55


How prepared are businesses for a new wave of attacks targeting the apps, APIs, and AI systems now powering digital growth? In this episode, I speak with Richard Meeus from Akamai Technologies about the latest findings from Akamai's State of the Internet report, with a focus on apps, APIs, and DDoS activity across EMEA. Richard explains why APIs have become such an attractive target for attackers, especially as AI adoption accelerates. We discuss the sharp rise in API abuse, the growing use of automation to industrialize attacks, and why many organizations still lack visibility into the APIs exposing sensitive data. We also examine the rise in layer 7 DDoS attacks, how attackers are combining multiple techniques to distract defenders, and why sectors such as retail and manufacturing are facing growing pressure. Richard also shares his view on the geopolitical forces shaping DDoS activity and why hacktivist groups continue to use these attacks as a public statement. Another major theme is the security risk around AI chatbots. As more organizations deploy chatbots to improve customer service, Richard explains how overly helpful AI systems can expose data, respond to prompt injection attempts, or create new blind spots if the right controls are missing. But this conversation is not all about risk. Richard also explains why AI can help defenders strengthen visibility, improve testing, analyze logs faster, and support more proactive security strategies. So, as businesses race to adopt AI and modern digital services, are they paying enough attention to the APIs and infrastructure sitting underneath it all? Share your thoughts.

Choses à Savoir TECH
« HTTP/2 Bomb », le hack ultime qui effraie tout internet ?

Choses à Savoir TECH

Play Episode Listen Later Jun 22, 2026 2:33


Les attaques par déni de service, ou DDoS, font partie des méthodes les plus connues de la cybersécurité offensive. Leur principe est simple : envoyer tellement de requêtes vers un site ou un service en ligne que ses serveurs finissent par saturer. Résultat, la page ne répond plus, l'application tombe, et les utilisateurs légitimes ne peuvent plus accéder au service.Traditionnellement, ce type d'attaque nécessite un botnet, c'est-à-dire un vaste réseau de machines compromises : ordinateurs, routeurs, caméras connectées ou objets mal protégés. Mais des chercheurs de la société californienne Calif viennent de documenter une méthode beaucoup plus inquiétante : une attaque DDoS capable de fonctionner depuis un seul ordinateur. Cette technique, baptisée « HTTP/2 Bomb », doit être présentée lors de la conférence Real World AI Security, organisée à Stanford du 23 au 25 juin. Les chercheurs expliquent avoir utilisé Codex, l'IA d'OpenAI, pour les aider à détecter cette faille.Le cœur du problème vient de HTTP/2, une version moderne du protocole qui permet à un navigateur et à un serveur web de communiquer. HTTP/2 a été conçu pour accélérer les sites, notamment grâce à la compression des en-têtes et à l'envoi de plusieurs requêtes sur une même connexion. Mais ces optimisations peuvent être détournées. L'attaque exploite notamment HPACK, le système chargé de compresser certaines informations échangées entre le client et le serveur. En manipulant ce mécanisme, un attaquant peut forcer le serveur à reconstruire en mémoire de très grandes quantités de données pour un trafic en apparence limité. La seconde étape consiste à empêcher cette mémoire d'être libérée rapidement, en jouant sur les mécanismes de contrôle du flux.Selon Calif, un simple ordinateur connecté à 100 Mbps peut ainsi épuiser des dizaines de gigaoctets de mémoire vive en quelques secondes. Lors des tests, un serveur Envoy est tombé en une dizaine de secondes, Apache a saturé 32 Go de mémoire en 18 secondes, tandis que nginx et Microsoft IIS ont cédé en moins d'une minute. La menace est sérieuse, mais pas universelle. Tous les serveurs ne sont pas vulnérables, et certains correctifs existent déjà. En attendant, les experts recommandent de limiter strictement les en-têtes, de passer par des CDN ou proxys inverses, et de désactiver HTTP/2 lorsque c'est possible. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.

David Bombal
#583: Shadow AI: What every network engineer must know

David Bombal

Play Episode Listen Later Jun 16, 2026 31:05


Big thank you to Radware for sponsoring this video In this interview, David Bombal sits down with Randy Wood, Head of North American Business at Radware, to break down the massive shift occurring in enterprise cybersecurity. They discuss why the rise of Agentic AI is a "1994 internet moment times a thousand," creating an environment where autonomous AI agents are rapidly outgrowing traditional security guardrails. Randy explains the critical connection between AI and API security, revealing how undiscovered "Shadow AI" tools and thousands of hidden enterprise API vulnerabilities leave organizations completely exposed to highly sophisticated, AI-driven DDoS attacks and flawless localized phishing campaigns. Learn how network engineers and security professionals can protect confidential data by pivoting from rigid rules to analyzing behavioral intent before execution, ensuring your network is ready for an autonomous tech stack. Visit radware.com for more deep-dive technical resources. // Randy Wood's SOCIAL // LinkedIn: / rwoodiii // Website REFERENCE // https://www.radware.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:31 - Intro 01:21 - The Reality of AI Today 03:50 - Customer's Concerns About AI 07:12 - Deployment of AI Agents in Enterprise 08:08 - AI Used to Attack Enterprise 09:01 - AI as a Problem and a Solution 13:43 - Agentic Security with Radware 16:51 - Lack of Architecture and Policy 18:06 - The Impact of Claude Mythos 20:03 - How Do Attackers use AI? 22:25 - API Vulnerability and Security 24:38 - Most Common Attacks 26:13 - The Future of AI 28:00 - Advice for the Youth 30:33 - Where to Learn More Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #api #mythos

Packet Pushers - Full Podcast Feed
NB579: Datadog Unleashes Autonomous Agents; SpaceX Launches IPO

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jun 15, 2026 50:49


Take a Network Break! Our Red Alert covers critical vulnerabilities in Ivanti Sentry, including OS command injection and authentication bypass, for which patches are now available. On the news front, we dig into Arista's new 1.6Tbps rack-scale portfolio for AI infrastructure and Nokia's Deepfield Genome Shield, designed to proactively stop DDoS from residential proxy botnets. We... Read more »

Packet Pushers - Network Break
NB579: Datadog Unleashes Autonomous Agents; SpaceX Launches IPO

Packet Pushers - Network Break

Play Episode Listen Later Jun 15, 2026 50:49


Take a Network Break! Our Red Alert covers critical vulnerabilities in Ivanti Sentry, including OS command injection and authentication bypass, for which patches are now available. On the news front, we dig into Arista's new 1.6Tbps rack-scale portfolio for AI infrastructure and Nokia's Deepfield Genome Shield, designed to proactively stop DDoS from residential proxy botnets. We... Read more »

Packet Pushers - Fat Pipe
NB579: Datadog Unleashes Autonomous Agents; SpaceX Launches IPO

Packet Pushers - Fat Pipe

Play Episode Listen Later Jun 15, 2026 50:49


Take a Network Break! Our Red Alert covers critical vulnerabilities in Ivanti Sentry, including OS command injection and authentication bypass, for which patches are now available. On the news front, we dig into Arista's new 1.6Tbps rack-scale portfolio for AI infrastructure and Nokia's Deepfield Genome Shield, designed to proactively stop DDoS from residential proxy botnets. We... Read more »

Vintage Anime Club Podcast
Episode 234 - Interrupted Transformation (Digimon Adventure Movies 1 & 2)

Vintage Anime Club Podcast

Play Episode Listen Later Jun 12, 2026 99:04


After a brief break, we're back on our isekai bandwagon with some digital monsters! That's right, we're covering the two Mamoru Hosoda Digimon Adventure movies, though they are more like short films than feature length movies. Join Dennis, Garrett, Ed, and Karen for Digimon Adventure Movie 1: Prologue & Digimon Adventure Movie 2: Our War Game. Talking points include the inevitable Summer Wars comparison, kaiju battles set to Bolero, the whistle system, silly kid arguments, breaking one of the unbreakable anime rules, and the power of a DDoS attack.  0:00:00 - Intro & The Watchlist 0:13:31 - Some Anime News 0:24:35 - Production Notes & Our Digimon History 0:38:18 - Bolero: The AMV (Digimon Adventure Movie 1) 0:49:07 - Our Summer Wars Game (Digimon Adventure Movie 2) 1:10:43 - Voices, Final Thoughts, & Kanpai You can support the show by donating to our Ko-Fi through the link below or purchasing Digimon The Movies 1-3 Collection on Blu-ray through our Amazon affiliate link: https://amzn.to/4v4zKqp Dennis: @ichnob | Ed: @ippennokuinashi | Garrett: @blkriku | Karen: @ryacosplay  Linktr.ee | Ko-Fi | RSS

KuppingerCole Analysts
Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs

KuppingerCole Analysts

Play Episode Listen Later Jun 12, 2026 16:51


Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance tool. Key Topics: ✅ What CDNs are and why they're no longer optional for competitive organizations✅ How CDN and DDoS mitigation differ — and where they overlap✅ Cache busting, HTTP floods, Slowloris and other real-world attack vectors✅ Why "security-first CDN" is fundamentally different from "CDN with security bolted on"✅ What CISOs and infrastructure leaders should look for when evaluating CDN solutions✅ How to measure CDN value from day one: round trip time and time to render A CDN without security is just a bigger target — find out why building security in from the ground up changes everything.

AWS Morning Brief
OpenAI on Bedrock and Other Strange Bedfellows

AWS Morning Brief

Play Episode Listen Later Jun 8, 2026 7:25


AWS Morning Brief for the week of June 8th, with Corey Quinn. Links:AWS Interconnect - multicloud now offers a free 500 Mbps tierOracle Database@AWS is now available in twenty AWS RegionsAmazon Cognito now supports multi-Region replicationAmazon EKS and Amazon EKS Distro now supports Kubernetes version 1.36Amazon SES now supports tenant-level suppression listsAWS Compute Optimizer now supports 32-day lookback for EBS volume and ECS service rightsizing recommendationsAWS Cost and Usage Report 2.0 now supports Athena and Redshift integrationAmazon ElastiCache for Valkey now supports durabilityUnderstanding how backups work in Amazon AuroraOpenAI models and Codex on Amazon Bedrock are now generally availableHow Bedrock Streaming optimizes its AWS costsFrom Monolith to Multi-Account: Pinterest's AWS Organization Transformation JourneyGain visibility into DDoS attacks with flow logs in AWS Shield AdvancedIdentify unused AWS KMS keys and prevent accidental key deletionsCVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsCVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer

Hacker And The Fed
A Single Email Took Down a Major Food Supplier

Hacker And The Fed

Play Episode Listen Later Jun 4, 2026 45:27


Chris and Hector break down a phishing attack that exposed employee data at a major food supplier, Microsoft's escalating fight with a security researcher publishing zero days, and the eye watering cost of enterprise AI adoption. They also discuss insider trading on prediction markets, the takedown of a massive DDoS botnet, and why basic security failures continue to create outsized consequences. Join our Patreon for weekly bonus episodes: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

Cyberhelden
Cyberhelden 75 - DigiD, residential proxies en AI die aanvallen niet magisch maakt

Cyberhelden

Play Episode Listen Later Jun 4, 2026 47:28


Ronald, Marco en Jelle zijn terug met DigiD, device-code-phishing, residential proxies en de vraag of AI cyberaanvallers echt onhoudbaar maakt. Eerst kort: Marco repareert tijdens een nachtwacht Home Assistant-data met Claude, Jelle bouwt met AI een lesdashboard, en Ronald rijdt in Kaapstad een fox hunt met antennes op de auto. Daarna DigiD. Staatssecretaris Willemijn Aerdts blokkeert de Amerikaanse overname van Solvinity door Kyndryl. Ronald legt uit waarom dit via de Wet ongewenste zeggenschap telecommunicatie loopt, waarom dat juridisch anders is dan VIFO, en waarom Nederland hiermee feitelijk zegt: Amerikaanse jurisdictie en CLOUD Act-risico's zijn voor DigiD te groot. Marco bespreekt RSI, recursive self-improvement, als nieuwe AI-hypeterm. Het idee: AI die zijn eigen training verbetert. De nuchtere conclusie blijft: losse stappen automatiseren lukt steeds beter, maar richting houden, controleren of iets klopt en echt autonoom onderzoek doen blijft lastig. Jelle pakt Kali365: phishing via Microsoft 365 device-code-flows. Het slachtoffer logt in op de echte Microsoft-site, maar autoriseert het apparaat van de aanvaller. Domeinchecken is dus niet genoeg als de context rond de login vergiftigd is. Het eerste hoofdverhaal: ASocks en residential proxies. Politie en NCSC verstoren een botnet met minstens 17 miljoen besmette apparaten, aangestuurd via ongeveer 200 servers in Nederland. Marco vat het scherp samen: het botnet is de infrastructuur, de residential proxy is het product. Aanvallers kopen verkeer vanaf normale thuisverbindingen in plaats van herkenbare datacenters of Tor-exitnodes. Daardoor lijken phishing, credential stuffing, DDoS en brute-force-pogingen op gewoon verkeer van echte gebruikers. Open vraag: zijn de apparaten echt opgeschoond, of vooral de aansturing geraakt? Jelle sluit af met Lennart Maschmeyers paper Deception and Detection. Maschmeyer stelt dat AI aanval en verdediging helpt, maar verdedigers structureel meer kunnen winnen: verdediging draait veel om detectie en patroonherkenning, aanval verderop in de kill chain om misleiding, context en gecontroleerde effecten. De drie zijn kritisch op zijn dwell-time-argument, maar herkennen de kern: je wilt geen autonome agent die in een vijandelijk netwerk creatief gaat improviseren. Tegelijk maakt AI aanvallers wel sneller als copiloot, codegenerator, parser van scanoutput en phishinghulp. Vooral lagere en middelmatige actoren kunnen daarmee sneller opschalen. *Bronnen* DigiD / Solvinity - NOS: https://nos.nl/artikel/2615885-staatssecretaris-verbiedt-amerikaanse-overname-solvinity-bedrijf-achter-digid - Wet OZT: https://wetten.overheid.nl/BWBR0045423 - Wet VIFO: https://wetten.overheid.nl/BWBR0046686 RSI - TechCrunch: https://techcrunch.com/2026/05/28/rsi-is-the-new-agi-and-its-just-as-hard-to-pin-down/ Kali365 - FBI IC3: https://www.ic3.gov/PSA/2026/PSA260521 - BleepingComputer: https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/ ASocks / residential proxies - Politie: https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html - NCSC expertblog: https://www.ncsc.nl/expertblogs/residential-proxies-en-hun-grote-impact-op-de-digitale-veiligheid-in-nederland - NCSC nieuws: https://www.ncsc.nl/nieuws/gezamenlijke-actie-politie-en-ncsc-legt-groot-botnetwerk-plat - Security.nl: https://www.security.nl/posting/938396/Proxy-botnet+van+17+miljoen+apparaten+na+actie+politie+en+NCSC+offline?channel=rss Maschmeyer / AI - CV Maschmeyer: https://www.lennartmaschmeyer.com/CV_Lennart_Maschmeyer.pdf - Paper: https://doi.org/10.1162/isec.a.398 - M-Trends 2025: https://cloud.google.com/security/resources/m-trends

Cyber Security Today
AI Vulnerability Explosion, Kim Wolf Botnet Arrest, Ghost CMS Hack, Iran Cyber Espionage

Cyber Security Today

Play Episode Listen Later May 25, 2026 13:14


Is AI about to trigger a cybersecurity vulnerability explosion? In this episode of Cybersecurity Today, David Shipley examines what some researchers are calling the early signs of a "vulnerability apocalypse" as Anthropic's Claude-powered Project Glasswing identifies thousands of potential software flaws at machine speed. The episode breaks down the real numbers behind the hype: over 10,000 candidate vulnerabilities flagged, 1,726 confirmed high or critical findings, 97 patched issues, and the growing concern that AI-driven bug hunting could overwhelm already stretched security teams. One example: a critical WolfSSL certificate forgery vulnerability (CVE-2026-5194, CVSS 9.1). Also in this episode: Canadian authorities arrest Ottawa suspect Jacob Butler, also known as "Dort," allegedly linked to the Kim Wolf botnet operation blamed for nearly 30 terabits-per-second distributed denial-of-service (DDoS) attacks and more than 25,000 incidents. We also cover active exploitation of a Ghost CMS SQL injection vulnerability (CVE-2026-26980), with attackers reportedly compromising hundreds of websites using ClickFix malware lures, including high-profile targets. And finally, an Iran-linked cyber espionage campaign dubbed "Screening Serpents" uses highly personalised fake recruitment approaches to target aerospace, defence, and telecom professionals with new remote access malware. If you work in cybersecurity, infrastructure, or IT leadership, this is one to watch. 00:00 Vunpocalypse Headlines 00:28 AI Finds Vulnerabilities 01:32 False Positives and Costs 02:39 WolfSSL Critical CVE 03:51 Patch Volume Pressure 04:28 Kim Wolf Botnet Arrest 05:13 Botnet Scale and Swatting 06:48 International Takedowns 07:41 Ghost CMS Mass Exploits 09:07 ClickFix Infection Chain 10:25 How to Remediate Ghost 10:39 Iran Spear Phishing Ops 12:51 Closing and Sign Off #Cybersecurity #CyberSecurityToday #AIsecurity #GhostCMS #DDoS #CyberEspionage #Anthropic #ClaudeAI #IranCyberThreat #InfoSec

2.5 Admins
2.5 Admins 300: IPvWot?

2.5 Admins

Play Episode Listen Later May 21, 2026 28:24


Why a proposal for an alternative to IPv6 is unlikely to be viable, Microsoft really doesn’t want you to run Exchange Server on-prem, Google will finally stop being a proper search engine, setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare. Plugs Support us on patreon and get an ad-free RSS feed with some early episodes Tuning ZFS for Databases Webinar: May 27th at 11am EDT: Database Performance on ZFS with Tom Lawrence News/discussion Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6 Exchange Server zero-day vulnerability can be triggered by opening a malicious email Google Search as you know it is over Free consulting We were asked about setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare. See our contact page for ways to get in touch.

Late Night Linux All Episodes
2.5 Admins 300: IPvWot?

Late Night Linux All Episodes

Play Episode Listen Later May 21, 2026 28:24


Why a proposal for an alternative to IPv6 is unlikely to be viable, Microsoft really doesn’t want you to run Exchange Server on-prem, Google will finally stop being a proper search engine, setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare. Plugs Support us on patreon and get an ad-free RSS feed with some early episodes Tuning ZFS for Databases Webinar: May 27th at 11am EDT: Database Performance on ZFS with Tom Lawrence News/discussion Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6 Exchange Server zero-day vulnerability can be triggered by opening a malicious email Google Search as you know it is over Free consulting We were asked about setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare. See our contact page for ways to get in touch.

euroradiofm
Алена Прыходзька, Павел Лібер. DDoS-атакі ці ігнор выбарцаў: ад чаго залежаў вынік выбараў у КР

euroradiofm

Play Episode Listen Later May 21, 2026 47:14


Выбары ў Каардынацыйную раду скончыліся. Прагаласавала ўсяго 2113 чалавек. Цяпер хтосьці называе гэтыя выбары правальнымі, хтосьці — скандальнымі, а для некага яны былі вельмі цяжкімі. І ў дадзеным выпадку я не пра кандыдатаў і спісы, якія бралі ўдзел у выбарчым працэсе, а пра тых, хто гэтыя выбары тэхнічна і арганізацыйна забяспечваў — Выбарчую камісію і арганізатараў пляцоўкі для электроннага галасавання. Бо, па словах Паўла Лібера, у выглядзе DDoS-атак на платформу прыйшло больш як 24 мільярды (!) запытаў і 68 Tb трафіка. Што стала асноўнай прычынай праблем падчас галасавання і наколькі нечаканым стаў узровень атак на платформу для галасавання на выбарах у Каардынацыйную раду? Ці сапраўды падрыхтоўка да выбараў пачалася запозна, і ці была магчымасць пашырыць спіс дакументаў, па якіх людзі маглі галасаваць? Як праходзіла верыфікацыя галасоў і ці існуе пагроза зліву базы галасавання? На гэтыя ды іншыя пытанні ў эфіры Еўрарадыё адказваюць кіраўніца Выбарчай камісіі на выбарах у Каардынацыйную раду Алена Прыходзька і распрацоўшчык праграмы для галасавання Павел Лібер

Adversary Universe Podcast
Adversaries Follow the Money: The CrowdStrike 2026 Financial Services Threat Landscape Report

Adversary Universe Podcast

Play Episode Listen Later May 18, 2026 30:52


The CrowdStrike 2026 Financial Services Threat Landscape report is now live! Adam and Cristian are here to break down the trends and techniques affecting an industry that has become a major target for adversaries. Financial services is the fourth most-targeted industry as of Q1 2026 and accounts for 12% of all observed adversary activity. eCrime adversaries target the industry for financial gain. MUTANT SPIDER, the most active eCrime threat in the past 12 months, is tied to several intrusions in which they sell access to ransomware groups. The Democratic People's Republic of Korea set its sights on cryptocurrency and fintech entities to steal funds for its military programs. While financial gain may seem the obvious goal in targeting financial services, it's not the only one. Nation-state adversaries in China, Iran, and Russia launched operations against the sector for intelligence collection. Hacktivists conducted DDoS campaigns and data breach operations, primarily driven by ideological conflicts. Even if you don't work in the financial services sector, you most likely work with it — consumer banks, credit card companies, insurers, payment processors, and related businesses are all part of everyday business and personal life. Tune in to hear which adversaries are targeting them and why, which regions are in the crosshairs, and how companies should defend themselves. And stick around to hear about Adam's foray into ice cream cakes.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 350: Investigation Types Made Simple - CISSP Training (Replay)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later May 18, 2026 44:49 Transcription Available


Send us Fan MailDefault passwords are the kind of problem everyone “knows” about and yet they still open doors for attackers every day. We start with a quick reality check on router security and why factory settings, legacy gear, and unmanaged IoT and OT devices can turn a simple misconfiguration into redirect attacks, man-in-the-middle exposure, DDoS headaches, or silent monitoring. If you're studying for the CISSP or defending a real network, you'll walk away with a clearer sense of what to fix first and how to roll changes out without creating change-management chaos.Then we shift into CISSP Domain 1.6: understanding requirements for investigation types. We break down administrative, criminal, civil, and regulatory investigations and why the burden of proof changes everything. We talk through why HR and legal need to be involved early, when law enforcement is (and is not) helpful, and how sloppy evidence handling can get key artifacts thrown out. We also cover e-discovery and legal holds, using the Electronic Discovery Reference Model (EDRM) to make the process easier to remember and apply.To close, we get practical about evidence: admissibility, chain of custody, and the forensics basics that protect data integrity, including media, memory, network, software, and embedded device analysis, plus the value of write blockers and disciplined documentation. If you want to pass the CISSP and operate like a calm, credible security professional during an incident, this is the mindset. Subscribe for weekly CISSP-focused training, share this with a teammate, and leave a review with the investigation topic you want us to tackle next.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Camada 8
#76 - Como a Academia Melhora os Provedores de Internet com Pedro Botelho

Camada 8

Play Episode Listen Later May 13, 2026 52:59


No episódio de maio do Camada 8, convidamos Pedro de Botelho Marcos, professor Drº. na FURG (Universidade Federal do Rio Grande), para uma conversa sobre como a pesquisa aplicada em redes e medições da Internet pode ajudar a resolver problemas reais da operação e aproximar academia e mercado.O professor Pedro fala sobre como a aproximação com a comunidade de operadores de rede ajudou a direcionar suas pesquisas para problemas reais, especialmente em medições da Internet, interconexão e peering, IXs, engenharia de tráfego, segurança no roteamento (RPKI e ASPA) e mitigação de DDoS. Ele também comenta sobre ferramentas e plataformas usadas para medições da Internet, como RIPE Atlas, looking glasses, além de compartilhar experiências no desenvolvimento de soluções por meio da colaboração entre academia e mercado, e muito mais.Dê o play e confira agora mesmo o novo episódio do quadro Roteamento de Ideias do Camada 8!Participantes:Antonio Marcos Moreiras (Host) - Gerente de projetos e desenvolvimento no NIC.br https://www.linkedin.com/in/moreirasEduardo Barasal Morales (Host) - Coordenador da área de formação de sistemas autônomos do Ceptro.br no NIC.br https://www.linkedin.com/in/eduardo-barasal-moralesPedro de Botelho Marcos (Convidado) - Professor Drº. na FURG (Universidade Federal do Rio Grande) https://www.linkedin.com/in/pedrobmarcos/Links citados:Semana de Infraestrutura da Internet no Brasil: https://semanainfra.nic.br/Live Intra Rede: https://intrarede.nic.br/Curso BCOP Presencial: https://cursoseventos.nic.br/curso/curso-bcop/Curso BCOP EaD: https://cursoseventos.nic.br/curso/curso-bcop-ead/Programa Acelera NET: https://cursoseventos.nic.br/curso/programa-acelera-net/RIPE Atlas: https://atlas.ripe.net/IX.br - Looking Glass: https://lg.ix.br/Alice - Looking Glass: https://github.com/alice-lg/alice-lgSemana de Capacitação 11 - Looking Glass: https://www.youtube.com/live/kAlyyVD1Bv8?si=bSqGmCbnFbVRFPutPEERING Testbed: https://peering.ee.columbia.edu/Agenda de cursos do Ceptro|NIC.br: https://ceptro.br/cursos-eventosRedes Sociais:https://www.youtube.com/nicbrvideos/https://x.com/comuNICbr/https://www.telegram.me/nicbr/https://www.linkedin.com/company/nic-br/https://www.instagram.com/nicbr/https://www.facebook.com/nic.br/https://www.flickr.com/NICbr/Contato:Equipe Ceptro.brcursosceptro@nic.brDireção e áudio:Equipe Ceptro.brEquipe de Comunicação do NIC.brEdição completa por Rádiofobia Podcast e Multimídia: https://radiofobia.com.br/Veja também:https://nic.br/https://ceptro.br/

euroradiofm
Выбары ў КР — сарваныя? Эфір з Прыходзька і Ліберам

euroradiofm

Play Episode Listen Later May 12, 2026 37:41


11 траўня беларусы мусілі пачаць галасаваць на выбарах у Каардынацыйную раду 4-га склікання. Але гэтага пакуль не адбылося. Спачатку — праз дадатковую праверку кампаніі-верыфікатара Sumsub, якую напярэдадні абвінавацілі нібыта ў супрацы з расійскімі спецслужбамі. Затым — праз масіраваную DDoS-атаку, якая вядзецца ад вечара панядзелка і не дае магчымасці прагаласаваць. Колькі можа каштаваць такая атака, ці ёсць шанец яе адбіць, якія рызыкі нясуць выбарцы, якой будзе сёлетняя яўка на выбарах у протапарламент у выгнанні? Размаўляем пра гэта з кіраўніцай ЦВК Аленай Прыходзька і распрацоўшчыкам праграмы для галасавання Паўлам Ліберам.

Crazy Wisdom
Episode #546: Beyond Postgres and Node.js: What Happens When Your Database Runs Your Code

Crazy Wisdom

Play Episode Listen Later May 11, 2026 56:42


In this episode of the Crazy Wisdom Podcast, host Stewart Alsop sits down with Tyler Cloutier, founder of Clockwork Labs and creator of SpaceTimeDB. They explore how SpaceTimeDB functions as more than just a database—it's essentially a distributed operating system that merges server logic with data storage, enabling real-time applications and time-travel capabilities. The conversation ranges from the technical architecture of databases and operating systems to the philosophy of distributed systems, touching on everything from Unix and Linux to how SpaceTimeDB could revolutionize AI-generated software deployment. Tyler explains how their system reduces the complexity of building real-time applications, makes deployment simpler for both humans and AI agents, and why games like their MMORPG BitCraft Online drove them to create this new infrastructure. They also discuss the future of the internet, the role of bots in gaming, and how SpaceTimeDB fits into the broader landscape of cloud computing alongside tools like Cloudflare, Vercel, and Docker. For more information, visit spacetimedb.com or check out Clockwork Labs on GitHub and Twitter.Timestamps00:00 Stewart introduces Tyler Cloutier, founder of Clockwork Labs, discussing the origin of SpaceTimeDB's name inspired by Einstein's theory and its time travel capabilities that store all operations indefinitely05:00 Tyler explains SpaceTimeDB as more of an operating system than a database, using tables instead of file systems while running code in a sandboxed environment with full atomic properties10:00 Discussion of how SpaceTimeDB replaces both Node.js and Postgres by merging web server and database functionality, eliminating separate deployment concerns15:00 Tyler explains JavaScript execution through Chrome's V8 engine and JIT compiling, leading to Node.js creation for server-side JavaScript development20:00 Explanation of stateless web servers versus stateful game servers, and why games require in-memory state management for real-time performance25:00 Tyler introduces reducers and real-time subscriptions, questioning why more applications aren't real-time when state changes should update immediately30:00 Discussion of Facebook as essentially a text-based MMO, comparing social media architecture to game server requirements and the need for unified systems35:00 Tyler explains ACID properties in databases: atomic, consistent, isolated, and durable, using game item trading examples40:00 Comparing SpaceTimeDB to smart contract systems without cryptocurrency or global consensus, positioning it as a smart database with centralized trust45:00 Tyler reveals SpaceTimeDB uses 43% fewer tokens than Postgres for AI-generated applications, making it valuable for vibe coding platforms50:00 Conversation shifts to bots in games and proof-of-human concepts, with Tyler proposing biometric systems and discussing potential in-person gaming applications55:00 Closing discussion about tracking AI-driven traffic through UTM parameters and finding SpaceTimeDB at spacetimedb.comKey Insights1. SpaceTimeDB is fundamentally a database that runs application code directly inside it, combining what traditionally required separate systems like Postgres and Node.js. Users compile their application logic into WebAssembly or JavaScript and upload it to run within the database itself. This architecture provides high performance because the entire server backend operates inside the database environment. The system also features time travel capabilities, storing every operation and change to data persistently and indefinitely, allowing users to set application state back to any earlier point in time. This makes SpaceTimeDB more accurately described as an operating system rather than just a database, where the abstraction is that everything is a table rather than a file.2. The inspiration for SpaceTimeDB came from building BitCraft Online, an MMORPG where all players exist in a single persistent world and rebuild civilization together. Traditional MMO backends required complex custom solutions to handle real-time state, with game servers storing state in memory and periodically writing to databases. This complexity existed because games cannot afford the latency of constantly delegating to distant databases like traditional web applications can. SpaceTimeDB solved this by making the database fast enough to handle real-time requirements directly, eliminating the need for separate game servers. This same performance advantage that benefits games also applies to web applications, which is why SpaceTimeDB evolved from a game-specific tool to a general-purpose platform.3. SpaceTimeDB functions as a distributed operating system where each database acts like a process in an actor model system, similar to Erlang or Scala Akka. Databases can send messages to other databases and be spawned across a cluster for horizontal scaling. This represents an overlay operating system running on top of Linux rather than competing with it, providing a distributed abstraction across many machines while Linux handles device drivers and hardware support. The vision is for the cloud to function as a single enormous computer running one operating system, where developers simply publish their programs without managing separate services, deployment, routing, networking, or persistence infrastructure.4. The real-time capabilities of SpaceTimeDB address a fundamental limitation in how most web applications work today. Traditional web servers are stateless, delegating all state to databases and accepting network round-trip latency for each request, which is why users often must refresh pages to see updates. SpaceTimeDB allows queries to be subscribed to, maintaining open connections that stream changes whenever query results update. This makes applications like Discord, Facebook, or banking systems naturally real-time without requiring page refreshes. The historical accident that more things are not real-time represents a problem SpaceTimeDB solves by unifying the web world with the game world's real-time requirements.5. SpaceTimeDB implements ACID properties—Atomic, Consistent, Isolated, and Durable—ensuring database operations are reliable and safe. Atomic means operations either fully happen or not at all, preventing issues like item duplication in games when trading between players. Consistent means declared invariants like unique usernames are always enforced. Isolated means concurrent operations do not interfere with each other. Durable means changes persist even if computers restart, with varying levels from in-memory on one machine to disk storage across multiple geographic locations. These properties are managed through reducers, functions inspired by React Redux that fold changes into application state incrementally.6. For AI and large language models, SpaceTimeDB offers significant advantages in building and deploying applications. Testing showed that creating applications with SpaceTimeDB uses 43% fewer tokens compared to Postgres implementations, costs less, has fewer bugs, and is easier to extend. This matters because the primary cost for vibe coding platforms is tokens. As more software gets written in the next twelve months than ever before, there is insufficient focus on infrastructure required to run all this AI-generated software. SpaceTimeDB positions itself as ideal for LLMs to target because of its simplified deployment model where developers just publish code and the system handles everything behind the scenes.7. SpaceTimeDB can be understood as a smart contract system without cryptocurrency or global decentralized consensus. Like blockchain smart contracts, it executes code with atomic, consistent, isolated, and durable properties, but avoids the expense and slowness of requiring all computers worldwide to agree on everything. Instead, it offers centralized trust where users trust Clockwork Labs not to modify deployed contracts, rather than the trustless but extremely costly blockchain approach. This makes it functionally similar to Cloudflare's durable objects but with full relational database capabilities. The system exists before the networking layer where Cloudflare operates, handling deployment, server, and database functions while Cloudflare could provide DDoS protection in front of it.

Cyber Security Today
QR Phishing Explodes, Ubuntu Under Attack, CISA Warns Critical Infrastructure Prepare for Isolation

Cyber Security Today

Play Episode Listen Later May 6, 2026 19:36


QR-code phishing is no longer a niche attack. Microsoft says QR phishing attacks jumped from 7.6 million in January to 18.7 million in March 2026 — a 146% increase in just three months. In this episode of Cybersecurity Today, David Shipley explains why QR-based attacks are bypassing traditional corporate defences and why security teams need to rethink phishing awareness immediately. We also cover a critical new Apache HTTP Server vulnerability with both denial-of-service and potential remote code execution impacts, a sustained DDoS and extortion campaign targeting Ubuntu developer Canonical, and a remarkable case in Taiwan where a university student allegedly used software-defined radio gear to trigger emergency braking on four high-speed trains. Finally, CISA's new "CI Fortify" guidance urges critical infrastructure operators to prepare for scenarios where they may need to disconnect from the internet and continue operating manually during a geopolitical cyber crisis. Cybersecurity Today would like to thank Material Security for supporting this podcast.  Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365.  Contact them at  material[dot]security  Stories include: • Microsoft reports QR phishing attacks surged 146% in Q1 2026 • Apache HTTP Server CVE-2026-23918 urgent patch warning • Ubuntu developer Canonical hit by ongoing DDoS and extortion campaign • Taiwanese student allegedly halts high-speed trains with fake emergency radio signal • CISA tells critical infrastructure operators to prepare for isolation and manual operations Chapters: 00:00 Intro 01:02 QR phishing explodes in Q1 2026 06:15 Critical Apache HTTP Server flaw patched 09:15 Ubuntu maintainer Canonical hit by extortion DDoS attack 14:25 Taiwanese student wirelessly halts high-speed trains 20:32 CISA warns critical infrastructure to prepare for isolation 26:10 Closing thoughts

All TWiT.tv Shows (MP3)
Untitled Linux Show 253: Patch Out the Fun

All TWiT.tv Shows (MP3)

Play Episode Listen Later May 3, 2026 95:16 Transcription Available


Ubuntu has announced their AI future, and it's ... not actually terrible. CopyFail has us all patching, though thankfully it's not an "Internet-melter". There's a DDoS on FOSS infrastructure, a new directory in your home folder, and finally good news on the HDMI 2.1 front. For tips we talk toofan for typing practice, why copy and paste needs "shift", and a quicker primer on getting the most out of bash history. You can find the show notes at https://bit.ly/4cZ2jOj and enjoy! Host: Jonathan Bennett Co-Hosts: Rob Campbell and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: bitwarden.com/twit

All TWiT.tv Shows (Video LO)
Untitled Linux Show 253: Patch Out the Fun

All TWiT.tv Shows (Video LO)

Play Episode Listen Later May 3, 2026 95:16 Transcription Available


Ubuntu has announced their AI future, and it's ... not actually terrible. CopyFail has us all patching, though thankfully it's not an "Internet-melter". There's a DDoS on FOSS infrastructure, a new directory in your home folder, and finally good news on the HDMI 2.1 front. For tips we talk toofan for typing practice, why copy and paste needs "shift", and a quicker primer on getting the most out of bash history. You can find the show notes at https://bit.ly/4cZ2jOj and enjoy! Host: Jonathan Bennett Co-Hosts: Rob Campbell and Ken McDonald Download or subscribe to Untitled Linux Show at https://twit.tv/shows/untitled-linux-show Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: bitwarden.com/twit

The NeoLiberal Round
We Are Raising Funds to Help Ramon With Surgery

The NeoLiberal Round

Play Episode Listen Later May 2, 2026 6:57


Ramon Henry needs our help so that he can complete a life-saving procedure to prevent a brain bleed (aneurism). He has had two aneurism stemming from a damaged blood vessel and we are raising funds to acquire the material needed from the USA so that the surgeons can repair the damaged blood vessel and he can return home and continue his work as an IT Tech genius.Ramon is the IT VP at The Neoliberal and has helped us with setting up out Websites and domains and runs our IT services. He is currently in the hospital in Jamaica awaiting surgery.We have set up a GoFundMe Page where we are raiding US$10,000.00 ($1.5 Million Jamaican Dollars). We need more than that but the immediate need is $10,000.00 USD and we have already raised $2500 USD towards the amount needed. In this episode we share our need and also provide the excerpt of a Podcast episode where Ramon discussed how to prevent DDOS attack and how to enhance our cyber security.You can donate to the fund at: https://gofund.me/8365e9eb5Email us at info@theneoliberal.com and renaldocmckenzie@gmail.comCall us at 445-260-9198Visit us at https://theneoliberal.com and https://renaldocmckenzie.com or https://store.theneoliberal.comFollow us on Twitter: theneoliberalco or Facebook: theneoliberalcorporation.This is a production of Renaldo McKenzie and The Neoliberal Corporation.

The Journal.
The College Student Who Defeated the World's Biggest Cyberweapon

The Journal.

Play Episode Listen Later May 1, 2026 37:24


Last year, a massive cyberweapon terrorized the internet. It launched thousands of DDoS attacks, threatening tens of millions of people around the world. The weapon came to be known as Kimwolf. WSJ's Robert McMillan reports that cybersecurity experts were stumped. Kimwolf's attacks seemed to be launched from millions of internet-connected devices like TV boxes, cameras and picture frames. Eventually, the experts got help from an unlikely ally: a 22-year-old college senior named Benjamin Brundage. Jessica Mendoza talks to Ben about how he might have saved the internet. To check if your network is secretly connected to a residential proxy network, here are a few tips. Further Listening: - Cybersecurity Braces for AI ‘Bugmaggedon' - ‘Hack Me If You Can' from The Journal Sign up for WSJ's free What's News newsletter. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
Think before you deploy the agent.

The CyberWire

Play Episode Listen Later May 1, 2026 30:21


Five Eyes agencies issue agentic AI guidance. A federal database leaks Social Security numbers. A stealthy worm poisons open source packages. OT firms are sidelined from frontier cyber models. The FBI warns of a surge in cyber-enabled cargo theft. Officials flag likely election interference as security programs face cuts. Researchers uncover a covert Python backdoor. Ubuntu's site takes Iranian-linked DDoS fire. Cyber pros are sentenced in a ransomware case. Our guest is Andrew Carr, Global Head of Threat Management at Booz Allen, discussing how AI is accelerating cyberattacks. OpenAI joins the invitation-only club. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices we are joined by ⁠Andrew Carr⁠, Global Head of Threat Management at ⁠Booz Allen Hamilton⁠, discussing how AI is accelerating cyberattacks and reshaping cybersecurity defenses. If you enjoyed this conversation be sure to check out the full interview here. Selected Reading Careful Adoption of Agentic AI Services (CISA)  Careful adoption of agentic AI services (Cyber.gov.au) Medicare portal exposed health providers' Social Security numbers (The Washington Post) Open-source registries hit by 'Mini Shai-Hulud' supply chain attacks (Developer) OT Cybersecurity Frozen Out by Frontier Labs (OTToday) FBI Warns of Surge in Hacker-Enabled Cargo Theft (SecurityWeek) Breach Roundup: US Cyber Command Flags Election Threats (Gov Infosecurity) Sophisticated Deep#Door Backdoor Enables Espionage, Disruption (SecurityWeek) Pro-Iran group turns Ubuntu DDoS into shakedown (The Register) Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison (United States Department of Justice) OpenAI locks GPT-5.5-Cyber behind velvet rope (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Risky Business
Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs

Risky Business

Play Episode Listen Later Apr 22, 2026 60:33


On this week's show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week's cybersecurity news, including: Vercel got owned, and there's a few infostealer and compromised employee dots to connect Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs? The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing And DDos attacks hit a couple of smaller-player socials This week's episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments. This episode is also available on Youtube. Show notes Vercel April 2026 Security incident Vercel breach linked to infostealer infection at Context.ai Vercel confirms breach as hackers claim to be selling stolen data Matt Johansen: “This is not a good look” | X NIST limits vulnerability analysis as CVE backlog swells | Cybersecurity Dive CISA Cyber on X Ransomware attack continues to disrupt healthcare in London nearly two years later | The Record from Recorded Future News Lawmakers ponder terrorism designations, homicide charges over hospital ransomware attacks | CyberScoop In defeat for Trump, House extends electronic spying program for just 10 days | The Record from Recorded Future News Crypto infrastructure company blames $290 million theft on North Korean hackers | The Record from Recorded Future News US-sanctioned currency exchange says $15 million heist done by "unfriendly states" - Ars Technica Hackers are abusing unpatched Windows security flaws to hack into organizations | TechCrunch Mozilla Used Anthropic's Mythos to Find and Fix 271 Bugs in Firefox | WIRED NSA using Anthropic's Mythos despite Defense Department blacklist Beyond the breach: inside a cargo theft actor's post-compromise playbook | Proofpoint US Beware scam messages offering ships safe transit through Hormuz Strait, says security firm | The Straits Times New Jersey men given lengthy sentences for running North Korean laptop farms | The Record from Recorded Future News Turns Out We're Not Alone - Volodymyr Styran US joins nearly two dozen other countries in striking back against DDoS-for-hire platforms | Cybersecurity Dive Bluesky blames app outage on ‘sophisticated' DDoS attack | The Record from Recorded Future News Mastodon says its flagship server was hit by a DDoS attack | TechCrunch An IT expert explained under what conditions using a VPN can cause a smartphone to explode

Cyber Security Headlines
Vercel breach, ZionSiphon targets water infrastructure, Bluesky DDoS

Cyber Security Headlines

Play Episode Listen Later Apr 21, 2026 7:39


Vercel confirms breach, stolen data for sale ZionSiphon targets water infrastructure Bluesky blames outage on DDoS Get the show notes here: https://cisoseries.com/cybersecurity-news-vercel-breach-zionsiphon-targets-water-infrastructure-bluesky-ddos/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

Cybercrime Magazine Podcast
Cybercrime News For Apr. 20, 2026. Europol Operation Targets 75,000+ DDoS Users. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Apr 20, 2026 2:24


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Ozone Nightmare
The Decentralization Myth

Ozone Nightmare

Play Episode Listen Later Apr 20, 2026 5:01


Today on the 5: You may have seen something about Bluesky having an outage last week due to a reported DDoS attack. This led many to criticize the problem of having a service that isn't decentralized. While those critiques are valid, the idea of decentralization is itself a myth in the world we currently live in.

The CyberWire
Temporary fix for Section 702.

The CyberWire

Play Episode Listen Later Apr 17, 2026 35:35


The House extends Section 702, for now. Mythos raises fresh cyber risk concerns. CISA warns of reduced capacity. ZionSiphon targets Israeli water systems. Operation PowerOFF hits DDoS-for-hire networks. CISA flags an actively exploited ActiveMQ flaw. WordPress plugin supply chain attacks spread. China tests deep-sea cable-cutting tech. Our guest is Arvind Nithrakashyap, CTO and Co-Founder of Rubrik, discussing AI as the next frontier. Tim Starks from CyberScoop takes us Inside the FBI's recent router takedown. A DraftKings data dealer meets his downfall.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, ⁠Daily Briefing⁠, and you'll never miss a beat. And be sure to follow CyberWire Daily on ⁠LinkedIn⁠. Industry Voices On today's Industry Voices segment, we are joined by ⁠Arvind Nithrakashyap⁠, CTO and Co-Founder of ⁠Rubrik⁠, discussing AI as the next frontier. If you enjoyed this conversation, check out the full interview here.  CyberWire Guest Today we have ⁠Tim Starks⁠ from ⁠CyberScoop⁠ discussing Inside the FBI's router takedown that cut off APT28's ‘tremendous access'.  Selected Reading ⁠House extends surveillance powers for 10 days⁠ (NPR) ⁠White House Works to Give US Agencies Anthropic Mythos AI⁠ (Bloomberg) ⁠Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction' Followed⁠ (SecurityWeek) ⁠How Anthropic Discovered Mythos AI Was Too Dangerous For Release⁠ (Bloomberg) ⁠CISA Warns of 'Detrimental Capacity Impacts' Amid Shutdown⁠ (BankInfo Security) ⁠New ZionSiphon Malware Discovered Targeting Israeli Water Systems⁠ (Hackread) ⁠Europol-supported global operation targets over 75 000 users engaged in DDoS attacks⁠ (Europol) ⁠CISA flags Apache ActiveMQ flaw as actively exploited in attacks⁠ (Bleeping Computer) ⁠30+ WordPress plugins bought on Flippa and backdoored in supply chain attack⁠ (TNW) ⁠New undersea cable cutter risks Internet's backbone⁠ (Ars Technica) ⁠Man gets 30 months for selling thousands of hacked DraftKings accounts⁠ (Bleeping Computer) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our ⁠brief listener survey⁠. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at ⁠sponsor.thecyberwire.com⁠. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
Hackers ignore the ceasefire.

The CyberWire

Play Episode Listen Later Apr 9, 2026 28:24


Iran-linked hackers signal cyberattacks will continue despite the cease-fire. Microsoft restores access after suspending open-source developer accounts. John Deere settles its right-to-repair fight. A suspected Adobe Reader zero-day surfaces. Palo Alto Networks and SonicWall patch high-severity flaws. New macOS malware targets crypto wallets. A threat cluster abuses live chat to bypass MFA. CISA orders urgent Ivanti patching. Researchers track a stealthy DDoS-for-hire botnet. Our guest is Edgard Capdevielle, CEO of Nozomi Networks, sharing insights on threats posed by nation-states and AI on OT security. macOS has a 49 day time limit.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Edgard Capdevielle, CEO of Nozomi Networks, sharing insights on threats posed by nation-states and AI on OT security. If you enjoyed this conversation, check out the full interview here. Selected Reading Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long (SecurityWeek) Microsoft suspends dev accounts for high-profile open source projects (Bleeping Computer) John Deere to Pay $99 Million in Monumental Right-to-Repair Settlement (The Drive) Adobe Reader Zero-Day Exploited for Months: Researcher (SecurityWeek) Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities (SecurityWeek) New macOS Malware notnullOSX Targets Crypto Wallets Over $10K (Hackread) Google Warns of New Threat Group Targeting BPOs and Helpdesks (Infosecurity Magazine) Masjesu Rising: The Commercial IoT Botnet Built for Stealth, DDoS, and IoT Evasion (Trellix) CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday (Bleeping Computer) We Found a Ticking Time Bomb in macOS TCP Networking - It Detonates After Exactly 49 Days (Photon Blog) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Today
Electric Vehicles and EV Security - Steve Visconti CEO of Xiid Corporation with David Shipley

Cyber Security Today

Play Episode Listen Later Apr 3, 2026 26:38


EV Charging Infrastructure Security: How Hackers Could Disrupt Chargers, Networks, and the Grid Cybersecurity Today  would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst In this holiday weekend edition of Cybersecurity Today, Jim Love introduces David Shipley's interview with Steve Visconti, CEO of Xiid Corporation, about cybersecurity risks in electric vehicle (EV) charging infrastructure. Visconti explains Xiid's software-based security layer for IP networks, aimed at critical infrastructure across enterprise, public sector, and DOD environments, and its growing focus on OT/IoT such as EV charging systems. The discussion highlights how EV chargers connect vehicles, homes, back-office billing/control systems, cloud services, and potentially vehicle-to-grid power flows, creating large-scale attack surfaces that could enable disruption, DDoS activity, or broader grid instability. Visconti argues for "unreachability" architectures that close ports and remove static exposure while allowing only registered users and machine-to-machine access. The interview also touches on concerns about vulnerabilities leading to fires, supply-chain risks, and policy debates such as government-accessible vehicle kill switches. 00:00 Holiday Weekend Intro 01:46 Meet Steve Visconti 04:16 EV Charging Symposium 06:40 Vehicle to Grid Risks 09:16 Fires and Attack Vectors 12:14 Making Chargers Unreachable 14:37 Car as the Threat 19:05 Awareness and DDoS Reality 23:09 Government Kill Switch Debate 24:49 Wrap Up and Sponsor Thanks

Torsion Talk Podcast
6 Cybersecurity Threats Every Garage Door & Home Service Business Must Know Right Now

Torsion Talk Podcast

Play Episode Listen Later Mar 31, 2026 23:41


In this episode of Torsion Talk, Ryan Lucia breaks down six of the biggest cybersecurity threats hitting garage door and home service businesses right now. From Google Business Profile hijacking and phishing emails to SIM swapping, ransomware, shared passwords, and DDoS attacks, this episode is a must-listen for contractors who want to protect their leads, customer data, phone numbers, and business systems before it's too late.Ryan explains why small businesses are prime targets for hackers and scammers, especially in the home service space where owners and teams often run everything from their phones without dedicated IT support. He walks through real-world scenarios that are happening right now, including stolen Google Business Profiles, compromised lead inboxes, phishing attacks disguised as banks or vendors, and even situations where customers think they are calling your company but are actually routed somewhere else.This episode also covers one of the most overlooked risks in modern business: weak password habits, shared logins, former employees retaining access, and the dangers of relying on text-message verification instead of stronger authentication tools. Ryan breaks down how SIM swapping works, why it can be devastating for a business owner, and what simple steps you can take immediately to protect your accounts.More importantly, Ryan gives practical guidance on what to do next. He explains why every business should be using authenticator apps, password managers, user-specific logins, access audits, software updates, offline backups, and basic phishing education for their staff. He also shares a real example involving a compromised phone that led to a fake garage door service call, proving just how sophisticated these attacks have become.If you own a garage door company, HVAC business, plumbing company, electrical company, or any home service business, this episode could save you from major financial loss, downtime, and stress. Cybersecurity is no longer optional. Your business is a tech company whether you like it or not, and protecting it starts with awareness, better habits, and action today.Find Ryan at:⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://garagedooru.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://aaronoverheaddoors.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://markinuity.com/⁠Check out our sponsors!Sommer USA - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠http://sommer-usa.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Surewinder - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://surewinder.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Stealth Hardware - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://quietmydoor.com/⁠

The CyberWire
Millions of devices still up for grabs.

The CyberWire

Play Episode Listen Later Mar 20, 2026 34:14


Feds take down major IoT botnets. The FBI seizes hacktivist infrastructure. A data breach hits Kaplan, while a hacker claims access to millions of law enforcement tips. Fake Zoom calls deliver malware. A crypto “security” tool turns out to be spyware. A critical AI framework flaw gets exploited in hours. An insider extortion case ends in conviction. And a streaming scam pulls in over $10 million. A look back at ten years of Cyberwire podcasts. Intern Kevin gets ready for RSAC. A cyberattack leaves breathalyzers offline.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. Celebrating CyberWire Daily Maria Varmazis leads a conversation with Peter Kilpe and Dave Bittner reflecting on the origins of the CyberWire Daily podcast as part of the 10th anniversary series, sharing behind-the-scenes insights and how it all got started. CyberWire Guest Today we are joined by Intern Kevin—also known as Kevin Magee—as he gets ready for RSA Conference 2026 next week. Selected Reading Feds disrupt IoT botnets behind record-breaking DDoS attacks (The Register) FBI seizes Handala data leak site after Stryker cyberattack (Bleeping Computer) Kaplan North America Reports Data Breach Impacting Nearly 195,000 Individuals (Beyond Machines) Hacker says they compromised millions of confidential police tips held by US company (Reuters) Fake interactive Zoom call leads to malicious ScreenConnect download | news (SC Media) Crypto Scam "ShieldGuard" Dismantled After Malware Discovery (Infosecurity Magazine) Hackers Exploit Critical Langflow Bug in Just 20 Hours (Infosecurity Magazine) Ex-data analyst stole company data in $2.5M extortion scheme (Bleeping Computer) Musician admits to $10M streaming royalty fraud using AI bots (Bleeping Computer) Cyberattack leaves Maine drivers with breathalyzer test systems unable to start vehicles (WGME) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Citadel Dispatch
CD193: FIPS - FIXING THE INTERNET

Citadel Dispatch

Play Episode Listen Later Mar 6, 2026 57:48 Transcription Available


FIPS is an open source mesh networking project that enables devices to connect directly to each other without relying on any central servers or infrastructure. Today's internet depends on companies and governments that can monitor, censor, or shut down communication at will. FIPS solves this by giving every node a cryptographic identity and encrypting all traffic automatically, so no one in the middle can see or block what you're doing. Nodes discover each other and route messages through the mesh on their own, and regular apps like browsers and SSH clients work on top of it without any special setup.Arjen on Nostr: https://primal.net/p/npub1hw6amg8p24ne08c9gdq8hhpqx0t0pwanpae9z25crn7m9uy7yarse465grJonathan on Nostr: https://primal.net/p/npub19wavu4f7l6l43h24jyskn7fvzy37kcfp67aqjtmv2qgy4lp34nhsda8p6k FIPS Repo: https://gitworkshop.dev/npub1y0gja7r4re0wyelmvdqa03qmjs62rwvcd8szzt4nf4t2hd43969qj000ly/relay.ngit.dev/fips Tollgate: https://tollgate.meSovereign Engineering: https://sovereignengineering.io/ EPISODE: 193BLOCK: 939631PRICE: 1465 sats per dollar(02:03) Introducing FIPS and the goal of a middleman free internet(04:16) Why static IPs fail for hosting and how FIPS reframes identity(05:51) Decoupling transport and routing: protocol-agnostic design(06:50) Peer discovery across Wi‑Fi, Bluetooth, and local broadcast(07:43) Future global routing ideas and decentralized discovery(09:05) Local mesh handshakes, Noise encryption, and Bloom filters(11:02) Community meshes, resilience, and mixed transports(11:42) Starlink and bridging meshes over the wider internet(13:21) Use case: protest resilience and reconnecting to the world(14:08) Origins: conferences, Sovereign Engineering, and NoDNS(16:04) From NoDNS to FIPS: faster updates, remaining gaps(17:10) Economics: sats for peering and incentive-aware routing(18:00) Abuse, DDoS surfaces, and defenses via npubs and rate limits(19:45) Learning from mesh hype cycles and bootstrapping adoption(22:32) Lowering app friction: make existing apps work over FIPS(25:12) DNS trick: IPv6 mapping and transparent transport(27:08) Backwards compatibility as a must-have for scale(28:08) Rethinking data flow with Nostr streams and local hosting(30:12) Offline-to-online spectrum and graceful reconciliation(31:10) Status update: early servers, testers, and bandwidth limits(32:20) Physical constraints: MTU, Bluetooth, LoRa(36:00) Reality checks: pitfalls, past meshes, and expectations(38:12) New primitives: Nostr, Blossom, eCash; Jonathan's role(40:37) Identity concerns, key rotation, and operational practices(46:10) Hosting sensitive services: hot keys(48:09) Self-hosting privately, Tor comparisons, and latency(49:37) Observation, Tollgate incentives, and community privacy(50:40) Tollgate legal concerns and community norms(53:21) Call to action, testing FIPS, and packaging plans(55:10) Closing thoughtsmore info on the show: https://citadeldispatch.comlearn more about me: https://odell.xyz

The CyberWire
The basics broke telecom.

The CyberWire

Play Episode Listen Later Feb 23, 2026 31:28


A senior FBI cyber official warns Salt Typhoon remains an ongoing threat. Data protection authorities issue a joint statement raising serious concerns about AI image creation. A Japanese semiconductor equipment maker confirms a ransomware attack. New number formats seek to reduce AI overhead. A low-skilled Russian-speaking threat actor compromised more than 600 Fortinet FortiGate firewalls. Spanish authorities have arrested four alleged members of Anonymous. CISA tags a pair of Roundcube Webmail flaws. Cybersecurity stocks fell sharply on news of a new security feature in Claude AI. Monday business breakdown. Brandon Karpf, friend of the show discussing sovereignty in space and cyber. Digital disruption drains drumsticks. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Dave sits down with Brandon Karpf, friend of the show, and Maria Varmazis, host of T-Minus, as they are discussing sovereignty in space and cyber. Selected Reading FBI: Threats from Salt Typhoon are ‘still very much ongoing' (CyberScoop) Joint Statement on AI-Generated Imagery and the Protection of Privacy (International Enforcement Cooperation Working Group (IEWG)) Japanese chip-testing toolmaker Advantest suffers ransomware attack (Help Net Security) AI's Math Tricks Don't Work for Scientific Computing (IEEE) Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls (Infosecurity Magazine) Suspected Anonymous members cuffed in Spain over DDoS attack (The Register) CISA: Recently patched RoundCube flaws now exploited in attacks (Bleeping Computer) Anthropic Unveils 'Claude Code Security,' Sending Cyber Stocks Lower (Bloomberg) RSAC Innovation Sandbox finalists secure $5 million each. (N2K Pro Business Briefing) Cyber attack takes major chicken processor Hazeldenes offline leaving businesses without meat (ABC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices