Podcasts about Malware

  • 1,811PODCASTS
  • 7,324EPISODES
  • 38mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 30, 2026LATEST
Malware

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Malware

Show all podcasts related to malware

Latest podcast episodes about Malware

ScanNetSecurity 最新セキュリティ情報
Microsoft Malware Protection Engine における任意の特権ファイルの書き込みが可能となるファイル操作での検証不備(Scan Tech Report)

ScanNetSecurity 最新セキュリティ情報

Play Episode Listen Later Sep 30, 2026 0:09


2026 年 5 月に修正された Microsoft Defender を構成するソフトウェアの脆弱性を悪用するエクスプロイトコードが公開されています。

Decipher Security Podcast
The Malware That Asks AI What to Do Next | Ryan Fetterman

Decipher Security Podcast

Play Episode Listen Later Sep 29, 2026 30:54


Ryan Fetterman from Cisco Talos sits down with Decipher's Lindsey O'Donnell-Welch to talk about ClosedQuorum, the first reported malware binary with an autonomous command-and-control. They talk about the wide range of ways threat actors are using AI, and useful detection strategies for AI-assisted attacks. LinksTalos analysis: https://blog.talosintelligence.com/th...

Security Squawk
FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware

Security Squawk

Play Episode Listen Later Sep 29, 2026 40:25


FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware Hackers Claim They Breached the FBI and Stole Data on Nearly Every Agent A criminal crew says it stole data on nearly every FBI agent and job applicant through the bureau's hiring system. The reported way in was the kind of business software your company might run. "We're too small to be a target" doesn't hold up. *The tools you trust are now the attacker's way in.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to track cyber news but can't afford to be blindsided by it. First, the FBI. The extortion group ShinyHunters claims it stole more than two terabytes of data on almost every agent and job applicant. The bureau has confirmed it's investigating. The reported way in was a flaw in Oracle's PeopleSoft HR software, the kind thousands of mid-size companies run. From there, the attackers reportedly jumped into the FBI's cloud. That flaw has been disclosed since June and used all year. Any company still running an unpatched box faces the same risk. Leaked HR and applicant data could give the next attacker a ready-made kit for targeting people and their families. Next, malware that brings its own AI. Researchers found a botnet called Carbonato that hijacks Docker servers left exposed to the internet. It installs an AI agent on the machine and lets that agent decide what to do next. The attackers didn't build the AI. They took an open-source tool and rewrote a single 39-line instruction file to turn it hostile. Running an adaptive attack now takes little more than editing a text file. Its number-one target is your AI keys. The crew uses stolen keys to run its own bootleg AI service, so a leak costs you data and funds the attacker. The way in wasn't a nation-state exploit. It was a server left open with no password. Finally, a defense supplier on a ransomware leak site. A group calling itself Storm posted Applied Composites, a California company that makes composite parts for aircraft, missiles, and satellites. There's no ransom number yet and no list of stolen files. Posting the name first puts pressure on the victim; details can follow if it stays quiet. A 500-to-1,000-person manufacturer deep in the defense supply chain is an attractive target: pressure to pay, without a Fortune 500 security budget. For a supplier, a leak-site listing isn't just downtime. It's a customer-trust and compliance event that can cost contracts. None of these started with a genius hack. Trusted software left unpatched, a server left open, a supplier left under-protected. The attackers walked through the door. • How ShinyHunters claims it breached the FBI and what data is at risk • Why the software running your HR and cloud is now the front line • Carbonato: the malware that installs its own AI agent to hack for it • Why stolen AI keys are the new top prize for attackers • How a small defense manufacturer ended up on a ransomware leak site • Why attackers target the small supplier to reach the big customer • What business owners should do before their name is the one on the list Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #FBI #ShinyHunters #Ransomware #DataBreach #AI #Docker #VendorRisk #SupplyChainSecurity #MSP #BusinessRisk

Cybercrime Magazine Podcast
CTRL, ALT, HACKED. The Xbox Reshuffle, Steam Attacked By Malware, & More.

Cybercrime Magazine Podcast

Play Episode Listen Later Sep 25, 2026 26:57


According to ars Technica, Xbox announced a radical restructuring of its internal studios that is seemingly designed to reduce that “independence” for the teams behind some of gaming's biggest franchises. In this episode, host Paul John Spaulding, Kyle Haglund, VP, Audio Engineering at Cybercrime Magazine, and Sam White, Video Producer at Cybercrime Magazine, discuss this story, alongside several others making news in the gaming industry recently, including Steam's recent hit by malware, and more. • For more on cybersecurity, visit us at https://cybersecurityventures.com

Cyber Security Headlines
ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware

Cyber Security Headlines

Play Episode Listen Later Sep 22, 2026 7:18


ShinyHunters hijacks Clop's own leak site Fake LastPass installers kill security tools Trusted npm release carries GHAPPIER malware Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries Get the show notes here: https://cisoseries.com/cybersecurity-news-september-22-2026/

Cyberhelden
Cyberhelden 84 - Een superspion voor je deur

Cyberhelden

Play Episode Listen Later Sep 21, 2026 47:56


Na 25 minuten AI-gebruik drie uur verplicht aandacht voor je partner. Zo kun je tokenlimieten ook bekijken, vindt Ronald. Zelf heeft hij andere technische problemen: de antennes uit de vorige aflevering hielden het maar twee minuten vol op zijn autodak. Toch derde geworden bij de foxhunt. Met een gewoon radiootje. Voor het hoofdverhaal hoeven we gelukkig niets op het dak te plakken. Die auto zit al vol sensoren. Je mag de kazerne op. Maar je auto ook? Camera's, microfoons, radar, soms lidar en een internetverbinding: een moderne auto heeft behoorlijk wat mee om de omgeving in kaart te brengen. Handig bij het parkeren. Ook interessant als je wilt weten wat er op een defensieterrein staat of wie bij de R&D-afdeling van ASML naar binnen loopt. Defensie onderzoekt of slimme auto's van kazernes en uit de omgeving moeten worden geweerd. We bespreken wie bij die sensoren en gegevens kan, wat een gerichte software-update mogelijk maakt en waarom een Europees logo weinig zegt over waar je auto gebouwd wordt. Inclusief de elektrische Mini van BMW en Great Wall Motor. Klinkt als een samenwerking waar we even over moeten praten. Maar zou een fabrikant zijn hele handel riskeren met een achterdeur? En geldt dit niet net zo goed voor Tesla? Daar zijn we niet in twee zinnen uit. China beperkte zelf al de toegang van Tesla's tot bepaalde overheidslocaties. Ook Polen, het Verenigd Koninkrijk en België komen voorbij. En als Defensie maatregelen neemt, waarom zouden andere ministeries en vitale bedrijven dan achterblijven? Heel naar voor de medewerker die net een nieuwe auto heeft gekocht. Ondertussen publiceert Anthropic hoe aanvallers Claude inzetten. Malware aanpassen zodra de antivirus aanslaat, gestolen sleutels uit Android-apps vissen en aanvallen draaien op andermans AI-budget. We bespreken wat er verandert als één operator met agents werk kan verzetten waarvoor eerder een team nodig was. En wat een AI-leverancier daardoor allemaal van die operaties meekrijgt. De vraag of wij zelf al in het rapport staan, wordt uiteraard ook gesteld. Verder: OpenAI claimt een wiskundige doorbraak rond Navier-Stokes, Iraanse aanvallers gebruiken zelfs een MRI-scan als lokmiddel om regimecritici malware te laten installeren, en Chinese typsoftware blijkt een ingang voor een China-gelinkte hackgroep. Je wilt Chinese tekens typen, maar krijgt via een verouderde browser in de themawinkel GRAYRABBIT binnen. Wie wil juist déze gebruikers hebben, en waarom? Bronnen: - Slimme auto's, Kamerbrief en TNO-onderzoek: https://open.overheid.nl/documenten/8b4abbc1-092d-43a9-83b6-1eb73bc65209/file - Sensoren en datastromen in auto's: https://fpf.org/wp-content/uploads/2024/09/FPF_connected_vehicl_v2_03_nosidebar-2.pdf - Reuters over Tesla-beperkingen in China: https://www.euronews.com/next/2021/05/21/uk-tesla-china - Anthropic, threat report september 2026: https://www.anthropic.com/threat-intelligence-report-september-2026 - OpenAI over Navier-Stokes: https://openai.com/index/navier-stokes-solution/ - NCSC over CHOSEN BRICK: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists - Gen Threat Labs over Sogou en GRAYRABBIT: https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou

David Bombal
#607: How Hackers Steal Your Accounts Even With 2FA Enabled

David Bombal

Play Episode Listen Later Sep 19, 2026 31:29


Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts. We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend's account can lead to an infection. Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks. In this interview: • Microsoft Defender's strengths and limitations • Free tools for investigating suspicious Windows activity • How infostealers and initial access brokers operate • Stolen session tokens and the limits of 2FA • Fake download sites, malicious ads and targeted phishing • Preparing recovery options before your accounts are compromised • Security and privacy trade-offs across Windows, Linux and macOS // Leo's SOCIAL // YouTube: / @pcsecuritychannel X: https://x.com/leotday Discord: / discord // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:35 - Intro 0:48 - Leo's Background & How Malware Has Evolved 03:27 - How to Detect Malware on Your Computer 05:21 - Best Sysinternals Tools for Malware Analysis 08:21 - Windows Device Tracking & Privacy Concerns 10:42 - Would you Recommend Windows in 2026? 11:59 - Privacy Laws & the Future of Tracking 12:50 - How Telemetry Helps Catch Cybercriminals 14:02 - ThreatLocker Sponsor 15:18 - How Hackers Actually Get Into Systems 16:42 - How to Protect Yourself From Getting Hacked 19:12 - Do You Really Need Antivirus? 21:35 - Security Advice for Home Users 25:59 - Why Smart People Still Get Hacked 26:59 - What Happens After Your Credentials Are Stolen 28:06 - Linux vs Mac vs Windows 29:40 - Is Windows Really Targeted More by Malware? 31:18 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #malware #bhusa2026 #microsoftdefender

Unspoken Security
How AI Is Rewriting the Rules of Offensive Security

Unspoken Security

Play Episode Listen Later Sep 18, 2026 53:28 Transcription Available


In this episode of Unspoken Security, host AJ Nash sits down with Snehal Antani, co-founder and CEO of Horizon3.ai and former first CTO of Joint Special Operations Command (JSOC), to dissect what AI is really doing to the economics of cyber attacks - and cyber defense. Snehal opens with a jaw-dropping data point: his team compromised a defense industrial base supplier and achieved full domain admin in 77 seconds. From there, the conversation moves into the surprising counter-strategy his team uncovered - that today's LLMs and agentic attackers are dramatically more gullible than human hackers, clicking on well-placed honey tokens up to 95% of the time.The two dig into why "train like you fight" - a principle Snehal absorbed at JSOC - is now essential for cyber teams, why compliance frameworks like CMMC are failing to produce real resilience, and why the future of cyber warfare is "AI versus AI with humans by exception." Snehal walks through Horizon3.ai's architectural bet on disposable models, persistent knowledge graphs, and constrained-action-space agents, and explains why the "haves and have-nots" of red teaming is finally being disrupted by autonomous pentesting that IT admins - not elite ethical hackers - can operate.The conversation closes with a candid look at the industry itself: the ChatGPT-driven sameness of vendor messaging, the Black Hat gimmick arms race, and Snehal's plea to return to technical authenticity. He ends with a deeply personal reflection on his late father - the electrical engineer who sabotaged toy robots so his six-year-old son would learn to troubleshoot them - and the weight of trying to pass that same gift on to his own kids.Send us Fan MailSupport the show

ENJOYYOURBIKE - Der Radsport & Triathlon Talk
205: Der „Asphalt" Killer! ENVE Melee V2 & iPhone Duo für Bikepacking?

ENJOYYOURBIKE - Der Radsport & Triathlon Talk

Play Episode Listen Later Sep 18, 2026 145:53 Transcription Available


Wir haben schon das neue ENVE Melee V2 2027 auf unserer "Couch"! Es bleibt so schön und zurückhaltend wie der Vorgänger, ist aber technisch viel mehr als nur ein Facelift. Krass, wieviel Neues und vor allem Schnelles in dem Rad steckt ohne die DNA des aktuellen Melees zu verlieren. Außerdem: COROS lässt unerwartet Karten auf die Pace 4! Aktuell ist die Beta-Phase und die ist schon voll, aber es wird nicht mehr lange dauern, dass die beliebteste COROS Uhr wohl noch beliebter wird. Nicht ganz ernst gemeint diskutieren wir außerdem darüber iPhone Duo für Bikepacking ;-) – Es löst irgendwie ein "Will-Haben" bei uns aus und gleichzeitig ist es ein "BRAUCHT MAN NICHT"-Ding. ------------------------------------------------------------ PICKLISTE & PARTNERSHOPS ------------------------------------------------------------ EYB Pickliste aller je gemachten Podcast-Picks: https://docs.google.com/document/d/1UjfitykkrWqKdWUTrYY0JBX-T4Qn8pdSm6RiWlM4j0M/edit?usp=sharing Unsere Partner-Shops: https://www.enjoyyourbike.com/neu/aktuelles/partner-shops/ ------------------------------------------------------------ NORDVPN (Werbung) ------------------------------------------------------------ Exklusiver Deal mit dem Promo-Code enjoyyourbike: 2-Jahres-Tarif + 4 Extra-Monate gratis! Nicht nur VPN – schützt auch vor Phishing, Betrug und Malware. Ein Konto schützt bis zu 10 Geräte. 30-Tage-Geld-zurück-Garantie. https://nordvpn.com/enjoyyourbike ------------------------------------------------------------ ALLE INFOS & LINKS ZUR SENDUNG ------------------------------------------------------------ COROS Pace 4 Pro – Karten kommen: https://coros.com/de/stories/coros-metrics/c/september-2026 iPhone Duo: https://www.apple.com/de/iphone-duo/ Ortlieb Tidura – neues Eigengewebe: https://de.ortlieb.com/collections/tidura ENVE Melee V2 2027: https://www.enjoyyourbike.com/detail/index/sArticle/30434/sCategory/2092177 Formel Reifenumfang: (622 + 2 × Reifenbreite × 0,85) × π = Reifenumfang in mm ------------------------------------------------------------ PICKS ------------------------------------------------------------ Brot Topping: https://www.spicebar.de/crunchy-brot-topping Other Means – Das Fahrradmagazin: https://othermeansmag.com/ ------------------------------------------------------------ INHALT ------------------------------------------------------------ 00:00:00 Intro 00:01:58 Reifenumfang – Ingo und André rechnen sich um Kopf und Kragen 00:10:43 COROS Pace 4 bekommt Karten – Pace 4 Pro Teaser 00:28:36 NordVPN (Werbung) 00:33:47 iPhone Duo – Arbeiten auf Reisen? 00:57:37 TPU mit Dichtmilch beim Pendeln 01:16:58 Ortlieb entwickelt eigenes Gewebe: Tidura 01:19:27 ENVE Melee V2 2027 – für viele der Tarmac-Killer! 01:45:28 Picks 01:56:31 Preshow: Dating Apps

Crying Out Cloud
AI-Powered Threat Actors, Poison Pills & Cyber Sabotage with John Hultquist

Crying Out Cloud

Play Episode Listen Later Sep 16, 2026 24:26


On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hultquist, Chief Analyst at Google Threat Intelligence Group (ex-Mandiant, ex-FireEye, founder of CYBERWARCON & SLEUTHCON).Drawing on over two decades of tracking state-sponsored adversaries like Sandworm, John cuts through the hype to explain what modern threat intelligence actually does: it keeps CISOs from burning millions of dollars on the wrong technology, spots adversary shifts before static IOCs exist, and bridges the gap between raw binary reverse-engineering and executive decision-making.In this episode, John unpacks how threat actors are weaponizing AI and bypassing commercial costs entirely and traces the real shift underway: adversaries embedding adversarial prompt-injection payloads inside malware to shut down automated SOC scanners.What's Inside:1. The economics of illicit AI: Underground access vs. hijacked enterprise compute2. Malware poison pills designed to neutralize automated LLM triage3. Why firmware and ICS layers are becoming primary targets for disruption4. Behavioral detection models when living-off-the-land means zero usable IOCs5. Lessons from tracking Sandworm and convincing leadership to act before the lights go out

Cyber Morning Call
1090 - Malware usa protocolo de internet das coisas para espionar empresas na Ásia e na América do Sul

Cyber Morning Call

Play Episode Listen Later Sep 16, 2026 4:49


Referências do EpisódioThe banana stand: brokering and managing infections across Asia using MQTTParaShells: Parallels Desktop Turns Appliance Install Into a Root ShellRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Ich glaube, es hackt!
Warum dein Fernseher mehr über dich weiß als deine Mutter

Ich glaube, es hackt!

Play Episode Listen Later Sep 15, 2026 58:14 Transcription Available


In dieser Folge geht's ums (fast) selbstfahrende Auto, einen Ex-Partner, der per App noch auf den Tesla seiner Ex zugreifen konnte, Rechenzentren aus echten Hirnzellen, spionierende Fernseher und einen Wurm, der sich per Telefonanruf verbreitet – plus jede Menge Apple- und iPod-Anekdoten zum Schluss. **Themen dieser Folge:** - QR-Code per Longpress öffnen: Rüdiger und Tobi werten die Reaktionen aus ihrer exklusiven WhatsApp-Gruppe aus - Autonomes Fahren: Rüdiger testet ein Auto, das auf der Autobahn komplett selbst fährt – und erinnert sich an seinen Stern-TV-Test von 2015 - Zukunftsvision: Fährt euer Auto bald selbst zum Supermarkt und lädt den Einkauf ein? - Tesla-Stalking-Fall aus Sydney: Ein verurteilter Ex-Partner konnte über eine geteilte App-Freigabe das Auto seiner Ex während der Fahrt auf 40 km/h drosseln – und die Betroffene konnte ihm den Zugriff nicht ohne seine Zustimmung entziehen - Biocomputer aus menschlichen Hirnzellen: Ein Startup baut Rechenzentren mit im Labor gezüchteten Neuronen statt Siliziumchips – Ziel ist Energieeffizienz, nicht Rechenleistung - Bundesweiter Warntag am 10. September: Wer hat den Alarm mitbekommen? - Tobis neues Google Pixel mit GrapheneOS – und der Fall aus den USA, in dem ein Reisender wegen einer versehentlich ausgelösten "Erase-PIN" wegen Vernichtung von Beweismitteln angezeigt wurde - Wie Handys im Gefängnis unentdeckt bleiben – und wie Inhaftierte früher über RTL-Teletext (Seite 673) Nachrichten von draußen empfangen konnten - "WeWorm": Ein Zero-Click-Wurm, der sich über Sprachanrufe in WeChat verbreitet und potenziell Milliarden Geräte hätte infizieren können - LG-Fernseher im Visier von Sicherheitsforschern: Raumgespräche, Netzwerk-Scans und Standortdaten landen offenbar bei LG – fürs Ad-Targeting - Ein US-Fernsehhersteller wird für 2,7 Milliarden Dollar verkauft – nicht wegen der Geräte, sondern wegen der gesammelten Nutzerdaten - Die Ukraine launcht "Trophy Lab": eine (halb-offene) Datenbank mit erbeuteten russischen Waffensystemen für Rüstungsentwickler - Apple Mail erinnert künftig aktiv an unbeantwortete Nachfragen – Rüdiger war not amused - Zum Ausklang: Karl Lagerfelds legendäre Sammlung von über 500 iPods, die neuen Apple EarPods und Rüdigers Pläne für ein Foldable iPhone -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast

Cyber Security Today
ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays

Cyber Security Today

Play Episode Listen Later Sep 14, 2026 11:36


Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving over 153 million U.S. driver's license scans and 1.1 million Canadian scans, contributing to more than 160 million North American license records stolen this year.  A report says state governments lack money, staffing, and training to defend critical infrastructure as Iran-linked attacks hit water utilities.  Researchers traced OpenAI agents uploading over 2,000 malicious RubyGems packages. Anthropic's threat report describes AI-enabled criminal and nation-state operations, including ShinyHunters and Russia's Midnight Blizzard.  Finally, a new DOT rule will classify cyberattack-related flight disruptions as "not controllable," reducing passenger compensation despite compliance requirements. 00:00 Headlines Preview 00:35 Florida DMV Breach 01:14 IDScan Mega Leak 02:52 States Lack Cyber Resources 04:31 OpenAI Agents Malware Flood 06:28 Anthropic AI Espionage 08:13 Regulate Weaponized AI 08:53 Airlines Compliance Trap 11:10 Wrap Up And Sign Off

Techzine Talks
"Control your own data": Hoe Klarrio grote organisaties uit de vendor lock-in houdt

Techzine Talks

Play Episode Listen Later Sep 14, 2026 44:55


In deze aflevering van Techzine Talks spreken we met Werner Vermeylen, CISO bij Klarrio. We hebben het over datgene waar Klarrio zich al lang mee bezighoudt, namelijk maatwerk dataplatformen. Uiteraard komen ook zaken zoals datasoevereiniteit en security aan bod, ook in gereguleerde omgevingen. Klarrio bouwt al tien jaar cloud-agnostische en open-source dataplatformen voor grote bedrijven in sectoren als halfgeleiders, telecom en energie. Een van de basisprincipes i bij dit alles is dat de klant zelf de volledige controle heeft en houdt.Vermeylen legt uit waarom grote bedrijven ondanks eigen IT-teams toch vastlopen bij het bouwen van dataplatformen. Klarrio heeft zich gedurende tien jaar onder andere gespecialiseerd in het uitvoeren van migraties zonder downtime (van DC/OS naar Kubernetes). Ook de rol van de CISO, NIS2, CRA en de groeiende druk vanuit regelgeving komen uitgebreid aan bod.Het gesprek gaat ook diep in op de impact van AI op datasecurity: exploittijden dalen hard, malware verstopt zich in open-source packages op GitHub. Tot slot gaan we in op de zoektocht naar soevereine defensieve AI-tooling met lokale LLM-modellen.Belangrijkse inzichten:• Klarrio bouwt geen product, maar volledig maatwerk dataplatformen op basis van open source en cloud-agnostisch design• Datasoevereiniteit gaat verder dan cloudkeuze: ook de architectuur, licenties en componenten bepalen echte controle• Zero-day exploittijden dalen hard, terwijl AI aanvallen sterk versnelt• Open source is niet automatisch soeverein: botnetwerken op GitHub plaatsen malware in populaire packages• Niets is 100% veilig: wie dat wel beweert, liegtHoofdstukken:1:11 - Wat doet Klarrio: custom dataplatformen2:09 - Doelgroep: grote bedrijven in gereguleerde sectoren3:48 - Controle over je eigen data: soevereiniteit als kernfilosofie8:13 - Architectuurkeuzes: van DC/OS naar Kubernetes13:32 - Use case: verkeersplatform voor de Nederlandse overheid16:27 - Projectoplevering en kennisoverdracht18:58 - De CISO-rol bij Klarrio: security by design22:58 - AI en de versnelling van zero-day exploits24:31 - Soevereine defensieve AI en lokale LLM-modellen29:03 - Malware in open source: GitHub-botnetwerken ontdekt32:21 - Kwetsbaarheidsbeheer: risico's analyseren en accepteren43:27 - Beslissingen nemen in onzekerheid

Cyber Security Headlines
NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malware

Cyber Security Headlines

Play Episode Listen Later Sep 11, 2026 7:42


Critical NetScaler vulnerability exploited in attacks AdaptHealth data breach impacts 4.1 million people MantaxOtax Android malware delivers ransomware and spyware together Get the show notes here: https://cisoseries.com/cybersecurity-news-netscaler-vulnerability-exploited-adapthealth-suffers-breach-new-android-malware/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

The Shared Security Show
Is Hotel WiFi Safe?

The Shared Security Show

Play Episode Listen Later Sep 7, 2026 14:33


Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft's CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware delivery.They cover what HTTPS and VPNs actually protect, why a lock icon does not prove a page is legitimate, the warning signs that should make travelers disconnect, and when a cellular hotspot is the better choice. Scott also shares an update on his Digital Legacy Tree book and tools.** Links mentioned on the show **Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/FBI hotel Wi‑Fi guidance https://watech.wa.gov/fbi-warns-cyber-risks-when-telecommuters-use-hotel-wi-fiFCC — Cybersecurity Tips for International Travelers https://www.fcc.gov/consumers/guides/cybersecurity-tips-international-travelersScott Wright — Digital Legacy Tree book and tools https://securityperspectives.com/digital-legacy-tools** Watch this episode on YouTube **https://youtu.be/TBqKfiGayfo** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

microsoft safe fbi hotels reddit wifi blue sky vpn mastodon phishing malware vpns faraday scott wright public wifi midnight blizzard captive portal travel security netsubscribe credential theft
Late Confirmation by CoinDesk
The Malware That Hijacked Crypto Payments for 8 Years | CoinDesk Daily

Late Confirmation by CoinDesk

Play Episode Listen Later Sep 3, 2026 1:53


The copy-paste hack that stole $150K. CrowdStrike and federal authorities dismantled Sality, a botnet that spent eight years swapping copied wallet addresses for the attacker's, so victims unknowingly sent crypto to a stranger. The fix is simple: check the first and last characters of any address after you paste it. CoinDesk's Jennifer Sanasie hosts "CoinDesk Daily." - This episode is brought to you by RealFi, a smarter stablecoin, backed by real-world assets. Find out more at⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ realfi.co⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. - This episode is brought to you by Grayscale, the world's largest digital asset-focused investment platform. Grayscale's mission is to make digital asset investing simple and open to every investor. Learn more at grayscale.com. - This episode was hosted by Jennifer Sanasie. “CoinDesk Daily” is produced by Jennifer Sanasie and edited by Victor Chen.

Hoje no TecMundo Podcast
A APPLE VAI MUDAR? + POLÍCIA BR USANDO IA PRA PEGAR BANDIDO

Hoje no TecMundo Podcast

Play Episode Listen Later Sep 2, 2026 21:56


John Ternus é o novo CEO da Apple e Tim Cook se despede;Meta, TikTok e YouTube retiram perfis de Renan Santos do ar; IA brasileira usada por policiais reduziu crimes em 27%;E muito mais!

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 1, 2026 6:27


The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Available https://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign; https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 31, 2026 5:43


Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ DLink Vulnerabliities https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513 Watchguard Patches https://psirt.watchguard.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The SupplyChainBrain Podcast
Protecting Against Malware in Open-Source Software Libraries

The SupplyChainBrain Podcast

Play Episode Listen Later Aug 28, 2026 24:19


How do we stop malware from infecting open-source software libraries?

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 27, 2026 7:41


Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

HeroicStories
How Do I Make Sure I Don’t Have Malware?

HeroicStories

Play Episode Listen Later Aug 27, 2026 4:34


The hard truth is that you can never fully prove your computer is malware free... but you can still stack the odds in your favor. I'll discuss why, the habits that keep you safer online, and what to do if something slips through.

HeroicStories
How Often Should I Scan My Computer for Malware?

HeroicStories

Play Episode Listen Later Aug 26, 2026 4:16


Find out when a manual scan makes sense, and how often you should run one for peace of mind.

TechTalk Cast
25/08/2026 – Brasil terá supercomputador bilionário para IA, GTA VI vira alvo de malware e +!

TechTalk Cast

Play Episode Listen Later Aug 25, 2026 7:02


Bom dia Tech! Tudo bem? Meu nome é Arthur Givigir e hoje é terça-feira, dia 25 de agosto de 2026 e trago para você as principais notícias de tecnologia, vamos lá?No episódio de hoje, o Brasil anunciou um pacote de R$ 2,3 bilhões para ampliar sua infraestrutura de inteligência artificial, incluindo a compra de um supercomputador que deverá ficar entre os dez maiores do mundo em capacidade de processamento para IA. Também falo sobre falsos downloads de GTA VI espalhando malware, uma falha chamada Zombie Card que consegue fazer cartões Visa expirados voltarem a realizar pagamentos, The Witcher 4 sendo confirmado para 2028 às vésperas da Gamescom e a Apple preparando um novo iMac com chip M6 ainda para este ano.Quer patrocinar ou fazer uma parceria com o Bom dia Tech? Mande um e-mail para contato@bomdia.teche vamos conversar!ApoioAmazon: Promoções KindleNotícias00:00: ☀️ Bom dia Tech!00:29: Brasil terá supercomputador entre os maiores do mundo para IA03:35: Falsos downloads de GTA VI estão espalhando malware05:57: Zombie Card faz cartões Visa expirados voltarem a funcionar08:40: The Witcher 4 é confirmado para 2028 antes da Gamescom10:48: Apple prepara novo iMac com chip M6 ainda para 202612:35: Inté a próxima!Produtos do EpisódioSmartphones JoviSamsung Galaxy FoldsNintendo Switch OLEDBundle Nintendo Switch OLED com Mario Kart 8PlayStation 5 SlimPlayStation DualSenseApple iPhone 16 (128 GB)Echo Show 5 (3ª geração)Echo Show 8 (3ª geração)Kindle ScribeComprando por esses links, o Bom dia Tech recebe uma pequena comissão e você ajuda no crescimento do podcast.Redes sociais:InstagramThreadsMastodonCapa:Capa: Gerada por IA

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 24, 2026 5:29


Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cyber Security Today
Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet

Cyber Security Today

Play Episode Listen Later Aug 24, 2026 8:50


Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen. Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys. Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun. 00:00 Top Stories Rundown  00:30 Entra ID Perfect 10 Patch 01:55 Defender Driver Weaponized 03:31 SickKids Hit Again 05:10 Leaked AWS Keys Still Live 06:48 Car Head Unit Botnet 08:25 Wrap Up And Sign Off

This Week in Linux
354: Linux 7.2, Linux Hits 10% Market Share, AUR Update, Fedora on Framework, KDE LTS, & more Linux news

This Week in Linux

Play Episode Listen Later Aug 24, 2026 31:34


video: https://youtu.be/lBJDyzkJbCI Linux 7.2 is here with a ton of new kernel improvements. Desktop Linux has crossed a major milestone for usage with more than 10% in North America and 7% globally. Arch Linux has announced some changes they are making to the way the AUR works because of the latest Malware attacks. Plus there's some big KDE news this week. KDE is bringing back LTS support with a much bigger "Bullet-Proof KDE" approach, and Framework has announced the next edition of the Framework Laptop 12 and it's coming with a preinstalled option of Fedora KDE. There is a LOT happening in the Linux world right now, and some of these stories get pretty wild. So here's Your Source for Linux GNews and see what's happened This Week in Linux. Download as MP3 Support the Show Become a Patron = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:52 Support the show (Become a Member) 01:43 Linux 7.2 Released 04:50 Linux crosses 10% in Desktop Market Share 10:53 Arch Linux changes how AUR Adoptions work after Malware waves 13:06 "Bullet-Proof KDE" brings LTS Support back to KDE 16:29 Framework Laptop 12 with Fedora Linux Preinstalled 19:39 NVIDIA, GOG, & Epic Games to compete with Valve on Linux Gaming Ecosystem 23:01 Steam Deck 1% lows improve by as much as 32% 25:27 Ubuntu Touch 24.04-2.0 Released 27:28 NVIDIA Becomes a Premier Sponsor of LVFS/Fwupd 28:48 FFmpeg 9.0 Released 29:56 Support the show 31:21 Outro Links: Linux 7.2 Released https://lwn.net/Articles/1089033/ https://kernelnewbies.org/Linux_7.2 https://www.phoronix.com/review/linux-72-features https://www.phoronix.com/news/Linux-7.2-Released Linux crosses 10% in Desktop Market Share https://gs.statcounter.com/os-market-share/desktop/north-america#monthly-202505-202606 https://radar.cloudflare.com/explorer?dataSet=http&groupBy=os&dt=2026-07-01_2026-07-31&loc=north-america&filters=deviceType%253DDESKTOP%252CbotClass%253DLIKELY_AUTOMATED https://store.steampowered.com/hwsurvey/ https://www.linux-magazine.com/Online/News/Linux-Surpasses-Double-Digit-Market-Share Arch Linux changes how AUR Adoptions work after Malware waves https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/thread/P5C7GZ4C3OJIH4EXJ62JAF6X6PY2BCQ4/ https://archlinux.org/news/active-aur-malicious-packages-incident/ https://lists.archlinux.org/hyperkitty/list/aur-general%40lists.archlinux.org/latest?count=200 https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/message/NNNGQYXYGBYGESV35AEQV2PLAVMMLW64/ "Bullet-Proof KDE" brings LTS Support back to KDE https://www.kubuntu.org/news/plasma-6.6-lts/ https://pointieststick.com/2026/08/ https://www.phoronix.com/news/KDE-Bullet-Proof-Software Framework Laptop 12 with Fedora Linux Preinstalled https://frame.work/blog/framework-laptop-12-now-with-core-series-3 https://frame.work/laptop12 https://youtu.be/459a7YBmBOE https://youtu.be/yE48_MN8Ng4 https://www.phoronix.com/news/Framework-Laptop-12-WCL NVIDIA, GOG, & Epic Games to compete with Valve on Linux Gaming Ecosystem https://blogs.nvidia.com/blog/geforce-now-thursday-linux-native-app/ https://www.gamingonlinux.com/2026/01/the-native-linux-app-for-nvidia-geforce-now-is-now-in-beta/ https://www.phoronix.com/review/nvidia-geforce-now-linux https://www.gamingonlinux.com/2026/07/gog-confirm-they-are-working-towards-gog-galaxy-on-linux/ https://www.gamingonlinux.com/2026/08/epic-games-store-will-get-a-linux-version-sometime-soon/ https://www.pcgamer.com/hardware/the-epic-games-launcher-will-be-available-on-linux-soon-says-dev-after-its-had-a-bit-of-work Steam Deck 1% lows improve by as much as 32% https://www.phoronix.com/news/AMD-P-State-Better-1p-Lows https://www.pcgamer.com/hardware/handheld-gaming-pcs/linux-kernel-patch-can-boost-the-steam-decks-1-percent-low-frame-rate-by-as-much-as-31-percent-in-early-testing/ Ubuntu Touch 24.04-2.0 Released https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-and-24-04-1-4-release-4007 NVIDIA Becomes a Premier Sponsor of LVFS/Fwupd https://www.linuxfoundation.org/press/linux-foundation-announces-key-industry-support-for-linux-vendor-firmware-service https://www.phoronix.com/news/NVIDIA-Premier-Sponsor-LVFS https://www.gamingonlinux.com/2026/08/nvidia-now-supporting-the-linux-vendor-firmware-service-lvfs-as-a-premier-sponsor/ https://www.fwupd.org/ FFmpeg 9.0 Released https://www.ffmpeg.org/ https://ffmpeg.org/releases/ https://www.phoronix.com/news/FFmpeg-9.0-Released Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/

Cyber Security Today
NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

Cyber Security Today

Play Episode Listen Later Aug 21, 2026 14:24


NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts. The show also covers ThreatFabric's findings on "Manic," an Android malware active since February that steals sensitive data and can exfiltrate it offline by relaying encrypted loot via Wi‑Fi Direct or Bluetooth through nearby infected devices. Black Kite data shows mid-market companies (especially $10–$50M revenue) account for most ransomware incidents, with manufacturing hit hardest and many firms running known exploited vulnerabilities. Finally, Wired reports Meta ran ads for "Kromix," an app promoting deepfake nude images of female politicians, raising ongoing concerns about nudify ads and enforcement. 00:00 Sponsor NordLayer 00:37 Headlines Preview 01:05 AI Exploits Hit PLCs 04:06 Android Malware Manic 06:49 Ransomware Targets Midmarket 09:19 Meta Nudify Ads Scandal 12:26 Wrap Up and Weekend Tease 13:23 Sponsor Message NordLayer

Cyber Security Headlines
AI "mind virus," malware living off Azure, an Irregular post-mortem

Cyber Security Headlines

Play Episode Listen Later Aug 19, 2026 8:11


Persistent prompts prove potentially pernicious  The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/  Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

Cult of Conspiracy
#1135- The Malware That Stopped Iranian Nukes, Stuxnet!

Cult of Conspiracy

Play Episode Listen Later Aug 18, 2026 136:47 Transcription Available


Back in 2005 The U.S. "allegedly" spearheaded Operation Olympic Games, the torch was passed to Obama, and the primary objective was to create a virus that would make Iranian Machinery tear itself apart!--------------------------------------------------------To Sign up for our Patreon go to-> Patreon.com/cultofconspiracypodcastTo Find The Cajun Knight Youtube Channel---> click hereTo Find The Meta Mystics Spotify--> Click Herehttps://flavorsforest.com/cult/Become a supporter of this podcast: https://www.spreaker.com/podcast/cult-of-conspiracy--5700337/support.

No Password Required
No Password Required Podcast Episode 76 - Dr. Aleksandr Yampolskiy

No Password Required

Play Episode Listen Later Aug 17, 2026 43:16


In this episode: How a virus-infected Prince of Persia floppy disk on a Commodore 64 sparked a lifelong obsession with cybersecurity (03:03 - 06:45) From NYU to Yale cryptography PhD to Goldman Sachs to Gilt Groupe, and the near-miss that changed everything (03:03 - 06:45) What SecurityScorecard actually does and why the pen and paper questionnaire era had to end (06:55 - 08:18) What it looked like in the early days, including an IKEA furniture test for business partnerships (08:26 - 12:01) Why SecurityScorecard now scores every company in the world, not just twelve million organizations (12:01 - 12:29) The Gilt Groupe credit card near-miss, what the first 24 hours looked like, and why fear was the first reaction (12:50 - 17:30) What it takes to create an entire market category from scratch and why the job to be done never changes (17:48 - 20:20) The difference between the CISO version and CEO version of Alex, and what Satya Nadella said about zooming out (20:49 - 22:36) Which version of Alex people would rather have a beer with and why any job besides CEO is more fun (22:43 - 23:45) How North Korea used a fake hedge fund to try to recruit SecurityScorecard developers (24:06 - 25:47) Why the world is not becoming safer and the critical difference between robustness and resilience (25:59 - 26:42) The True Confessions keynote: why openly admitting breaches makes the whole ecosystem stronger (27:13 - 29:22) The Jaguar Land Rover breach and what it took to double a UK company's security budget overnight (27:13 - 29:22) The single most dangerous thing a board member has ever said in a meeting about cybersecurity (29:45 - 31:09) What one thing a non-technical CEO could do this week to make their CISO's life better (31:25 - 32:12) The Lifestyle Polygraph: restaurant health scores, PowerPoint ban, The Inner Game of Tennis, chess, false advertising, and podcast advice (33:07 - 41:32)   Timestamp Highlights: (03:03) Prince of Persia, a floppy disk, and the origin of a cybersecurity career (06:07) The realization that changed everything: you can do everything right and still lose (08:26) The IKEA furniture test for business partnerships (12:50) The Gilt Groupe near-miss and what the first 24 hours looked like (17:48) What it takes to create a market category from scratch (20:49) CISO vs CEO: zooming in vs zooming out (22:43) Which version of Alex would you rather have a beer with? (24:06) North Korea's fake hedge fund operation (25:59) Robustness vs resilience: why the mindset has to change (29:45) The most dangerous thing a board member has ever said (31:25) One thing every non-technical CEO should do this week (36:48) The Inner Game of Tennis and the infinite game (40:00) Chess, false advertising, and meeting his future wife   Resources & Links: SecurityScorecard — securityscorecard.com The Perfect Scorecard by Aleksandr Yampolskiy ThreatLocker — Presenting sponsor of No Password Required DerScanner — Episode sponsor Cyber Florida — The Mother Ship

The Cybersecurity Defenders Podcast
Intel Chat: AI patches fail, LiteLLM supply chain, Claude eval incidents & DPRK npm [345]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Aug 14, 2026 34:13


Intel Chat with Matt Bromiley and Chris Luft.• AI-generated patches fix vulnerabilities about half the time. 1Password's Off-By-1 team tested ChatGPT-5.5 and Opus 4.8 against six vulnerabilities: across 6,080 generated patches only 46% fixed the underlying flaw, and some that did were narrow enough to be bypassed. Separate Veracode research found a 56% security pass rate across 100+ models, with 44% of AI-generated code carrying detectable OWASP Top 10 issues. Matt's pushback: what is the HUMAN success rate for comparison, and why is nobody publishing that number?• LiteLLM supply chain attack. CloudSEK reports 2,500+ organizations and 434,000 CI/CD pipelines potentially exposed. LiteLLM was not the initial target: the compromise came in through Aqua Security's Trivy scanner and spread when LiteLLM's CI automatically installed it, ending with malicious versions 1.82.7 and 1.82.8 on PyPI. They were live for roughly 40 minutes, which automated dependency resolution and cached layers were more than enough to propagate.• Anthropic's models reached real systems during evaluations. Reviewing 141,006 evaluation runs, Anthropic found three incidents where Claude models gained unauthorized access to real organizations during capture-the-flag exercises, after a misunderstanding with an evaluation partner left the environments internet-connected. One model published a malicious package to the real PyPI, where it ran on 15 real systems. Matt argues this is a lab test rather than a threat report, and asks what defenders are supposed to do with it.• North Korea behind the npm compromises. Amazon Threat Intelligence links the typo-crypto, debug, chalk and axios incidents to the same DPRK actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA and BlueNoroff. Wiz found roughly one in ten cloud environments touched by the debug and chalk incident within two hours. The technique has shifted: malicious functionality is now split across several innocuous-looking packages that only do anything once combined, plus slopsquatting and prompt injection aimed at AI code scanners.Stories covered:• https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time• https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/• https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals• https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/Chapters:0:00 Back from Black Hat3:31 AI-generated patches fix vulnerabilities about half the time6:23 What is the human success rate?10:53 LiteLLM supply chain attack13:03 Pin your dependencies15:59 Anthropic models reached real systems during evals22:12 This is a lab test, not a threat report27:06 North Korea behind the debug, chalk and axios compromises30:59 Malware assembled from harmless-looking parts33:27 Clever people on the other side of the fenceThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #AIsecurity #supplychainsecurity #threatintel

Security Now (MP3)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (MP3)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (MP3)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (MP3)

Play Episode Listen Later Aug 12, 2026 171:12 Transcription Available


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HD)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HD)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HI)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HI)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video LO)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video LO)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 265 - Malvertising, Malware, Military Metadata, Uber Eats Delivers the Feds, Hot Cheetos

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Aug 3, 2026 49:50


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Bing malvertising campaign tricks users into downloading a fake Claude desktop app that quietly installs the SectopRAT info-stealing trojan. - https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/ The malicious "FakeAgent" campaign hit at least 29 organizations on July 21–22; the poisoned Claude Artifact (hosted on Anthropic's own domain) was downloaded 7,100 times before removal, with the fake installer (ClaudeDesktop.exe) sideloading a malicious DLL to drop SectopRAT — a HVNC-capable info-stealer active since 2019 that targets browser logins, crypto wallets, Discord/Telegram/Steam credentials, and uses Ethereum smart-contract transactions (EtherHiding) to fetch its C2 address; researchers even used Claude Opus 4.8 themselves to help reverse-engineer the payload.   Iran allegedly exploited decades-old cell network flaws to physically locate and target US troops during the Iran War. - https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/ Per a Financial Times report citing the Mobile Surveillance Monitor and government officials, Iran exploited SS7 — the legacy signaling protocol still underpinning 2G/3G global roaming — to track US personnel at bases and hotels in Iraq, Bahrain, and elsewhere in the Middle East, contributing to strikes that wounded upwards of 150 US troops; Iran reportedly also abused ad-tech location data as a secondary tracking vector.   A multi-university study found dozens of apps marketed directly to US troops are quietly shipping Chinese and Russian code. - https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/ Researchers from Purdue, West Point, and Florida International University analyzed 220+ apps aimed at service members (fitness trackers, base-living-condition raters, National Guard-affiliated apps) and found 64% contain third-party SDKs from foreign countries, with roughly 1-in-8 to 1-in-14 apps (reporting varies) carrying code tied directly to China or Russia — including at least 12 apps embedding Huawei's mobile framework and others using the Russian ad service Yandex; no active exfiltration was observed, but researchers warn the dormant SDK code is an exploitable backchannel.   A 21-year-old allegedly stole $220K in crypto by hiding malware in Steam games — and got caught because he spent it on Uber Eats. - https://www.pcmag.com/news/fbi-traces-malware-infected-steam-games-to-21-year-old-in-florida The FBI arrested Florida's Zyaire Dontaevious Zamarion Wilkins for allegedly running eight malware-laced Steam games (including BlockBlasters and PirateFi) between May 2024–Feb 2026, infecting ~8,000 devices and draining ~80 crypto wallets for at least $220,000 — including $35,000 stolen from a streamer's cancer-treatment fundraiser; investigators cracked the case by tracing stolen Bitcoin to 150+ Bitrefill gift cards mostly spent on Uber Eats orders tied to his home and university email address.   Thrillist crowned Doritos Nacho Cheese the single greatest snack of all time, edging out Oreos and Pringles for the top spot. - https://www.thrillist.com/eat/nation/best-snack-foods-chips-candy-ranking The top five, in order: Doritos (Nacho Cheese, specifically) at #1, Oreos (Double Stuf gets the nod) at #2, Pringles at #3, Reese's Peanut Butter Cups at #4, and Goldfish rounding out the top five; other notable placements include Cheez-Its at #8, M&Ms at #7, Cheetos (the curls, not puffs) at #6, and Lay's Original topping the chip-specific competition at #12.   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Glenn - https://www.linkedin.com/in/glennmedina/ Ben - https://www.linkedin.com/in/benjamincorll/

HeroicStories
My Machine’s Full of Malware; Should I Get a New Computer?

HeroicStories

Play Episode Listen Later Jul 31, 2026 7:32


If malware has you ready to give up and buy a new computer, don't. I'll explain why your old one can be completely restored to a malware-free state, using steps to wipe out even the worst infections without spending a dime on new hardware.

Unspoken Security
Should We Be Afraid of Artificial Intelligence (AI)?

Unspoken Security

Play Episode Listen Later Jul 30, 2026 50:26 Transcription Available


In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.Send us Fan MailSupport the show

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 29, 2026 6:59


AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cybercrime Magazine Podcast
Cybercrime News For Jul. 29, 2026. Biggest Game Of Year Hit With Malware Attack. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jul 29, 2026 3:13


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Finanzrocker - Dein Soundtrack für Finanzen und Freiheit
Depot-Update 2026: 5 Lektionen aus unserem ersten Börsenhalbjahr (mit Clemens Faustenhammer)

Finanzrocker - Dein Soundtrack für Finanzen und Freiheit

Play Episode Listen Later Jul 28, 2026 69:56


Was, wenn die wichtigste Frage nach einem Börsenhalbjahr nicht lautet "Welche Aktie lief am besten?", sondern "Welche Entscheidungen waren richtig?" Genau darum geht es in unserem vierten gemeinsamen Summer Special mit Finanzjournalist Clemens Faustenhammer: kein Ranking aus Gewinnern und Verlierern, sondern Prozess statt Prognose. Ich erzähle, warum ich trotz erwarteter Korrektur mein Depot konsequent umgebaut habe, wieso mein ETF-Portfolio mit rund 16,5 % im Plus die größte Überraschung des Halbjahres war und welche Rolle UnitedHealth, CVS Health und Fastenal dabei gespielt haben.Clemens teilt seine eigene Sicht auf ein Halbjahr voller Überraschungen, wir sprechen über Zinseszins und Haltestrategien, den Wandel vom klassischen Finanzblog zu Substack und darüber, wie Profi-Investoren wie Terry Smith ihre Strategie anpassen. ⏱️ KAPITEL0:00 Begrüßung und Einleitung zum Summer Special3:15 IBM & die Marktkorrektur im Juli 20266:45 Depotqualität statt Markttiming10:20 Zinseszins-Strategie: Clemens über Haltedauer14:50 (Teil-)Verkauf von AT&T und Stanley Black & Decker19:30 KI als Werkzeug für die Aktienanalyse24:10 Finanzblogs vs. Substack: Wandel im Finanzjournalismus29:00 Terry Smith & der Strategiewechsel bei Profi-Investoren34:15 SaaS-Aktien im KI-Hype: Zukunftsaussichten39:00 Abspaltungen und M&A: Aktuelle Trends43:45 Einzelaktien vs. Themen-ETFs im Performance-Check48:30 Südkorea-Volatilität und Samsung-Spekulationen53:20 Zoetis: Fehleranalyse einer schwierigen Position58:00 US-Konsumschwäche: Tractor Supply im Fokus1:02:45 Erfolge mit Corning, Broadcom, Cisco und Fastenal1:06:50 Ausblick: Unser Fokus fürs zweite Halbjahr 20261:09:30 Fazit: Zufriedenheit statt Markt schlagen1:11:12 Outro

Robots and Red Tape: AI and the Federal Government
Models, Malware & Mayhem with Varun Badwhar

Robots and Red Tape: AI and the Federal Government

Play Episode Listen Later Jul 28, 2026 47:03


In this episode of Robots and Red Tape, our host Nick Schutt sits down with Varun Badhwar, Founder & CEO of Endor Labs, to unpack the security implications of the AI coding explosion.Varun shares why this wave feels fundamentally different from the cloud shift he saw with RedLock/Prisma Cloud, how AI agents have turned 20–30 million developers into 200–300 million potential coders, and why we're now generating 100x–1000x more code—much of it carrying the same insecure patterns the models learned from open source.They dig into:-The shift from code generation as the bottleneck to verification, quality, scale, and security -Why even frontier models produce only ~20% secure code (per Endor's CMU/Columbia benchmark)-Democratization of cyber warfare: attacks that once took years now take hours-Open-source realities—80% of software, average 77 transitive dependencies, low maintainer response rates, and intentional malware campaigns-How Endor Labs embeds security oversight directly into agentic workflows so fixes happen at assembly time, not after shipping-Practical paths for large enterprises sitting on millions of findings to burn down real risk without bankrupting themselves on pure-AI token costsPodcast: Robots and Red Tape | Host: Nick Schutt | Channel: @RobotsandRedTapeAI#RobotsAndRedTape #Ai #Cybersecurity #SoftwareSupplyChain #AppSec #OpenSourceSecurity #AgenticAI #AICoding #DevSecOps #EndorLabs #TechLeadership #EnterpriseAI #CodeSecurity #AISecurity #SupplyChainSecurity

Cyber Security Headlines
Iran infrastructure warning, ChatGPT global outage, self-assembling malware

Cyber Security Headlines

Play Episode Listen Later Jul 27, 2026 8:17


U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks.    Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings.    Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.

Hacker And The Fed
The Steam Malware That Stole Crypto From Thousands

Hacker And The Fed

Play Episode Listen Later Jul 23, 2026 56:16


Chris and Hector break down a critical WordPress vulnerability discovered with AI, the Steam malware campaign that stole cryptocurrency from gamers, Madison Square Garden's secret facial recognition database, AI voice cloning scams targeting families, leaked evidence of AI music training on copyrighted songs, and the White House employee accused of profiting from prediction markets. They also discuss SafeHill's latest work, insider threats, and why today's biggest cyber risks often begin with simple social engineering. Join our Patreon for weekly bonus episodes: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠questions@hackerandthefed.com

Out of the Woods: The Threat Hunting Podcast
S4 Ep9: Cloudy With a Chance of Malware

Out of the Woods: The Threat Hunting Podcast

Play Episode Listen Later Jul 22, 2026 40:46


Top Headlines: Group-IB | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels: https://www.group-ib.com/blog/hollowgraph-microsoft-365/ The Hacker News | New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html Elastic | New North Korean campaign uses fake coding interviews to steal developer credentials: https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Island.io | AgentBaiting: How Fake AI Skills Deliver Malware at Scale: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/