POPULARITY
Categories
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Back in 2005 The U.S. "allegedly" spearheaded Operation Olympic Games, the torch was passed to Obama, and the primary objective was to create a virus that would make Iranian Machinery tear itself apart!--------------------------------------------------------To Sign up for our Patreon go to-> Patreon.com/cultofconspiracypodcastTo Find The Cajun Knight Youtube Channel---> click hereTo Find The Meta Mystics Spotify--> Click Herehttps://flavorsforest.com/cult/Become a supporter of this podcast: https://www.spreaker.com/podcast/cult-of-conspiracy--5700337/support.
In this episode: How a virus-infected Prince of Persia floppy disk on a Commodore 64 sparked a lifelong obsession with cybersecurity (03:03 - 06:45) From NYU to Yale cryptography PhD to Goldman Sachs to Gilt Groupe, and the near-miss that changed everything (03:03 - 06:45) What SecurityScorecard actually does and why the pen and paper questionnaire era had to end (06:55 - 08:18) What it looked like in the early days, including an IKEA furniture test for business partnerships (08:26 - 12:01) Why SecurityScorecard now scores every company in the world, not just twelve million organizations (12:01 - 12:29) The Gilt Groupe credit card near-miss, what the first 24 hours looked like, and why fear was the first reaction (12:50 - 17:30) What it takes to create an entire market category from scratch and why the job to be done never changes (17:48 - 20:20) The difference between the CISO version and CEO version of Alex, and what Satya Nadella said about zooming out (20:49 - 22:36) Which version of Alex people would rather have a beer with and why any job besides CEO is more fun (22:43 - 23:45) How North Korea used a fake hedge fund to try to recruit SecurityScorecard developers (24:06 - 25:47) Why the world is not becoming safer and the critical difference between robustness and resilience (25:59 - 26:42) The True Confessions keynote: why openly admitting breaches makes the whole ecosystem stronger (27:13 - 29:22) The Jaguar Land Rover breach and what it took to double a UK company's security budget overnight (27:13 - 29:22) The single most dangerous thing a board member has ever said in a meeting about cybersecurity (29:45 - 31:09) What one thing a non-technical CEO could do this week to make their CISO's life better (31:25 - 32:12) The Lifestyle Polygraph: restaurant health scores, PowerPoint ban, The Inner Game of Tennis, chess, false advertising, and podcast advice (33:07 - 41:32) Timestamp Highlights: (03:03) Prince of Persia, a floppy disk, and the origin of a cybersecurity career (06:07) The realization that changed everything: you can do everything right and still lose (08:26) The IKEA furniture test for business partnerships (12:50) The Gilt Groupe near-miss and what the first 24 hours looked like (17:48) What it takes to create a market category from scratch (20:49) CISO vs CEO: zooming in vs zooming out (22:43) Which version of Alex would you rather have a beer with? (24:06) North Korea's fake hedge fund operation (25:59) Robustness vs resilience: why the mindset has to change (29:45) The most dangerous thing a board member has ever said (31:25) One thing every non-technical CEO should do this week (36:48) The Inner Game of Tennis and the infinite game (40:00) Chess, false advertising, and meeting his future wife Resources & Links: SecurityScorecard — securityscorecard.com The Perfect Scorecard by Aleksandr Yampolskiy ThreatLocker — Presenting sponsor of No Password Required DerScanner — Episode sponsor Cyber Florida — The Mother Ship
In dieser Folge von „Cyber Security ist Chefsache" sprechen Nico und Ann-Katrin mit Ronny Bodach, Professor für IT-Sicherheit und Digitale Forensik an der Hochschule Mittweida und über 15 Jahre bei der Kriminalpolizei, davon zuletzt in der Leitung der IT-Forensik, über ein Feld, das die meisten nur aus dem Fernsehen kennen: digitale Forensik. Was passiert eigentlich wirklich, wenn ein Rechner beschlagnahmt wird, und wie weit ist es von „Ich weiß, was passiert ist" bis „Ich kann es beweisen"?Ronny räumt zuerst mit zwei verbreiteten Erwartungen auf. Die Polizei ist für die Strafverfolgung zuständig, nicht für die Wiederherstellung von Systemen: „Ich kenne keine Polizei, die für die Wiederherstellung von Daten zuständig ist." Und die Forensik-Abteilungen der Cyberversicherungen sind noch jung und verfolgen ein eigenes Interesse, nämlich unter anderem zu klären, ob fahrlässig gehandelt wurde und ob sich eine Lösegeldzahlung vermeiden lässt. Wer nach einem Vorfall darauf wartet, dass jemand anderes aufräumt, verliert genau die Zeit, in der flüchtige Spuren verschwinden.Danach wird es praktisch. Forensik heißt wörtlich „fürs Gericht arbeiten", und genau daran hängt das Handwerk: Spuren erkennen, sichern, dokumentieren, interpretieren. Ronny erklärt, warum bei einem Ransomware-Fall der Hauptspeicher essenziell ist, weil moderne Schadsoftware oft nur noch im RAM läuft und auf der Festplatte gar nicht mehr auftaucht, warum Verschlüsselung die Reihenfolge der Arbeitsschritte diktiert und wie mit Schreibblockern und einer 1:1-Kopie die Chain of Custody gehalten wird, damit vor Gericht Bestand hat, was man gefunden hat. Dazu ein ehrlicher Blick auf die Grenzen: Nicht alles lässt sich zu 100 Prozent beweisen, oft macht erst die Menge unterschiedlicher Spuren das Indiz.Im dritten Teil geht es um Ausbildung und Alltag: warum Kriminalistik, Hypothesenbildung und Programmierung für Forensiker genauso dazugehören wie Betriebssystem-Wissen, warum Mittweida eigene Tools entwickelt und frei zur Verfügung stellt, und warum Incident Response im Unternehmenskontext anders arbeitet als die klassische Forensik in der Behörde, wo man auch mal Wochen Zeit hat.Im Gespräch geht es außerdem um:Warum die Polizei Spuren sichert, aber keine Systeme wiederherstelltWelches Interesse Cyberversicherungen bei der Aufklärung eines Vorfalls tatsächlich habenWas digitale Forensik umfasst, von Smartphone und ERP-System bis 3D-Tatort-ScanWarum moderne Malware oft nur im RAM existiert und was das für den ersten Zugriff bedeutetVerschlüsselte Geräte: warum „niemals ausschalten" mehr als eine Faustregel istSchreibblocker, 1:1-Kopie und Chain of Custody, also wie Beweiskraft entstehtMetadaten, Logs, Zeitstempel und gelöschte Dateien und warum sie immer schwerer zu bekommen sindDer Unterschied zwischen „Ich weiß es" und „Ich kann es beweisen", inklusive Wahrscheinlichkeiten in GutachtenIncident Response im Unternehmen vs. klassische Forensik in der BehördeWarum es den goldenen Schlüssel nicht gibt und wo der Rechtsrahmen Grenzen setztWie man Forensiker ausbildet: Kriminalistik, Python, eigene Tools und DurchhaltevermögenEine Folge für Geschäftsführungen, IT- und Security-Verantwortliche, Krisenteams und alle, die verstehen wollen, was nach dem Alarm technisch und rechtlich wirklich passiert.Das ist Teil 1 des Gesprächs, Teil 2 folgt.____________________________________________
Intel Chat with Matt Bromiley and Chris Luft.• AI-generated patches fix vulnerabilities about half the time. 1Password's Off-By-1 team tested ChatGPT-5.5 and Opus 4.8 against six vulnerabilities: across 6,080 generated patches only 46% fixed the underlying flaw, and some that did were narrow enough to be bypassed. Separate Veracode research found a 56% security pass rate across 100+ models, with 44% of AI-generated code carrying detectable OWASP Top 10 issues. Matt's pushback: what is the HUMAN success rate for comparison, and why is nobody publishing that number?• LiteLLM supply chain attack. CloudSEK reports 2,500+ organizations and 434,000 CI/CD pipelines potentially exposed. LiteLLM was not the initial target: the compromise came in through Aqua Security's Trivy scanner and spread when LiteLLM's CI automatically installed it, ending with malicious versions 1.82.7 and 1.82.8 on PyPI. They were live for roughly 40 minutes, which automated dependency resolution and cached layers were more than enough to propagate.• Anthropic's models reached real systems during evaluations. Reviewing 141,006 evaluation runs, Anthropic found three incidents where Claude models gained unauthorized access to real organizations during capture-the-flag exercises, after a misunderstanding with an evaluation partner left the environments internet-connected. One model published a malicious package to the real PyPI, where it ran on 15 real systems. Matt argues this is a lab test rather than a threat report, and asks what defenders are supposed to do with it.• North Korea behind the npm compromises. Amazon Threat Intelligence links the typo-crypto, debug, chalk and axios incidents to the same DPRK actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA and BlueNoroff. Wiz found roughly one in ten cloud environments touched by the debug and chalk incident within two hours. The technique has shifted: malicious functionality is now split across several innocuous-looking packages that only do anything once combined, plus slopsquatting and prompt injection aimed at AI code scanners.Stories covered:• https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time• https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/• https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals• https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/Chapters:0:00 Back from Black Hat3:31 AI-generated patches fix vulnerabilities about half the time6:23 What is the human success rate?10:53 LiteLLM supply chain attack13:03 Pin your dependencies15:59 Anthropic models reached real systems during evals22:12 This is a lab test, not a threat report27:06 North Korea behind the debug, chalk and axios compromises30:59 Malware assembled from harmless-looking parts33:27 Clever people on the other side of the fenceThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #AIsecurity #supplychainsecurity #threatintel
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Bing malvertising campaign tricks users into downloading a fake Claude desktop app that quietly installs the SectopRAT info-stealing trojan. - https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/ The malicious "FakeAgent" campaign hit at least 29 organizations on July 21–22; the poisoned Claude Artifact (hosted on Anthropic's own domain) was downloaded 7,100 times before removal, with the fake installer (ClaudeDesktop.exe) sideloading a malicious DLL to drop SectopRAT — a HVNC-capable info-stealer active since 2019 that targets browser logins, crypto wallets, Discord/Telegram/Steam credentials, and uses Ethereum smart-contract transactions (EtherHiding) to fetch its C2 address; researchers even used Claude Opus 4.8 themselves to help reverse-engineer the payload. Iran allegedly exploited decades-old cell network flaws to physically locate and target US troops during the Iran War. - https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/ Per a Financial Times report citing the Mobile Surveillance Monitor and government officials, Iran exploited SS7 — the legacy signaling protocol still underpinning 2G/3G global roaming — to track US personnel at bases and hotels in Iraq, Bahrain, and elsewhere in the Middle East, contributing to strikes that wounded upwards of 150 US troops; Iran reportedly also abused ad-tech location data as a secondary tracking vector. A multi-university study found dozens of apps marketed directly to US troops are quietly shipping Chinese and Russian code. - https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/ Researchers from Purdue, West Point, and Florida International University analyzed 220+ apps aimed at service members (fitness trackers, base-living-condition raters, National Guard-affiliated apps) and found 64% contain third-party SDKs from foreign countries, with roughly 1-in-8 to 1-in-14 apps (reporting varies) carrying code tied directly to China or Russia — including at least 12 apps embedding Huawei's mobile framework and others using the Russian ad service Yandex; no active exfiltration was observed, but researchers warn the dormant SDK code is an exploitable backchannel. A 21-year-old allegedly stole $220K in crypto by hiding malware in Steam games — and got caught because he spent it on Uber Eats. - https://www.pcmag.com/news/fbi-traces-malware-infected-steam-games-to-21-year-old-in-florida The FBI arrested Florida's Zyaire Dontaevious Zamarion Wilkins for allegedly running eight malware-laced Steam games (including BlockBlasters and PirateFi) between May 2024–Feb 2026, infecting ~8,000 devices and draining ~80 crypto wallets for at least $220,000 — including $35,000 stolen from a streamer's cancer-treatment fundraiser; investigators cracked the case by tracing stolen Bitcoin to 150+ Bitrefill gift cards mostly spent on Uber Eats orders tied to his home and university email address. Thrillist crowned Doritos Nacho Cheese the single greatest snack of all time, edging out Oreos and Pringles for the top spot. - https://www.thrillist.com/eat/nation/best-snack-foods-chips-candy-ranking The top five, in order: Doritos (Nacho Cheese, specifically) at #1, Oreos (Double Stuf gets the nod) at #2, Pringles at #3, Reese's Peanut Butter Cups at #4, and Goldfish rounding out the top five; other notable placements include Cheez-Its at #8, M&Ms at #7, Cheetos (the curls, not puffs) at #6, and Lay's Original topping the chip-specific competition at #12. Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Glenn - https://www.linkedin.com/in/glennmedina/ Ben - https://www.linkedin.com/in/benjamincorll/
Will man einen Windows-PC auf Virenbefall prüfen, sollte das am besten nicht aus dem laufenden Windows heraus passieren, sondern „von außen“ – also wenn Windows selbst nicht läuft und eventuelle Schädlinge sich nicht aktiv vor der Erkennung drücken können. Diesen Zweck erfüllt seit vielen Jahren das c't-Projekt Desinfec't: Ein Live-Linux auf Basis von Ubuntu, mit mehreren Virenscannern und einer Handvoll weiterer Analysetools. In dieser Folge des c't uplink sprechen wir über die frisch erschienene 2026er-Ausgabe, denn bei der hat sich einiges geändert. So gibts nicht nur eine komplett neue (und viel praktischere) Scan-Oberfläche, sondern auch ein maßgeschneidertes Tool zum Erstellen bootfähiger Desinfec't-Medien.
If malware has you ready to give up and buy a new computer, don't. I'll explain why your old one can be completely restored to a malware-free state, using steps to wipe out even the worst infections without spending a dime on new hardware.
In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.Send us Fan MailSupport the show
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com
Was, wenn die wichtigste Frage nach einem Börsenhalbjahr nicht lautet "Welche Aktie lief am besten?", sondern "Welche Entscheidungen waren richtig?" Genau darum geht es in unserem vierten gemeinsamen Summer Special mit Finanzjournalist Clemens Faustenhammer: kein Ranking aus Gewinnern und Verlierern, sondern Prozess statt Prognose. Ich erzähle, warum ich trotz erwarteter Korrektur mein Depot konsequent umgebaut habe, wieso mein ETF-Portfolio mit rund 16,5 % im Plus die größte Überraschung des Halbjahres war und welche Rolle UnitedHealth, CVS Health und Fastenal dabei gespielt haben.Clemens teilt seine eigene Sicht auf ein Halbjahr voller Überraschungen, wir sprechen über Zinseszins und Haltestrategien, den Wandel vom klassischen Finanzblog zu Substack und darüber, wie Profi-Investoren wie Terry Smith ihre Strategie anpassen. ⏱️ KAPITEL0:00 Begrüßung und Einleitung zum Summer Special3:15 IBM & die Marktkorrektur im Juli 20266:45 Depotqualität statt Markttiming10:20 Zinseszins-Strategie: Clemens über Haltedauer14:50 (Teil-)Verkauf von AT&T und Stanley Black & Decker19:30 KI als Werkzeug für die Aktienanalyse24:10 Finanzblogs vs. Substack: Wandel im Finanzjournalismus29:00 Terry Smith & der Strategiewechsel bei Profi-Investoren34:15 SaaS-Aktien im KI-Hype: Zukunftsaussichten39:00 Abspaltungen und M&A: Aktuelle Trends43:45 Einzelaktien vs. Themen-ETFs im Performance-Check48:30 Südkorea-Volatilität und Samsung-Spekulationen53:20 Zoetis: Fehleranalyse einer schwierigen Position58:00 US-Konsumschwäche: Tractor Supply im Fokus1:02:45 Erfolge mit Corning, Broadcom, Cisco und Fastenal1:06:50 Ausblick: Unser Fokus fürs zweite Halbjahr 20261:09:30 Fazit: Zufriedenheit statt Markt schlagen1:11:12 Outro
In this episode of Robots and Red Tape, our host Nick Schutt sits down with Varun Badhwar, Founder & CEO of Endor Labs, to unpack the security implications of the AI coding explosion.Varun shares why this wave feels fundamentally different from the cloud shift he saw with RedLock/Prisma Cloud, how AI agents have turned 20–30 million developers into 200–300 million potential coders, and why we're now generating 100x–1000x more code—much of it carrying the same insecure patterns the models learned from open source.They dig into:-The shift from code generation as the bottleneck to verification, quality, scale, and security -Why even frontier models produce only ~20% secure code (per Endor's CMU/Columbia benchmark)-Democratization of cyber warfare: attacks that once took years now take hours-Open-source realities—80% of software, average 77 transitive dependencies, low maintainer response rates, and intentional malware campaigns-How Endor Labs embeds security oversight directly into agentic workflows so fixes happen at assembly time, not after shipping-Practical paths for large enterprises sitting on millions of findings to burn down real risk without bankrupting themselves on pure-AI token costsPodcast: Robots and Red Tape | Host: Nick Schutt | Channel: @RobotsandRedTapeAI#RobotsAndRedTape #Ai #Cybersecurity #SoftwareSupplyChain #AppSec #OpenSourceSecurity #AgenticAI #AICoding #DevSecOps #EndorLabs #TechLeadership #EnterpriseAI #CodeSecurity #AISecurity #SupplyChainSecurity
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.
Chris and Hector break down a critical WordPress vulnerability discovered with AI, the Steam malware campaign that stole cryptocurrency from gamers, Madison Square Garden's secret facial recognition database, AI voice cloning scams targeting families, leaked evidence of AI music training on copyrighted songs, and the White House employee accused of profiting from prediction markets. They also discuss SafeHill's latest work, insider threats, and why today's biggest cyber risks often begin with simple social engineering. Join our Patreon for weekly bonus episodes: https://www.patreon.com/c/hackerandthefed Send HATF your questions at questions@hackerandthefed.com
Top Headlines: Group-IB | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels: https://www.group-ib.com/blog/hollowgraph-microsoft-365/ The Hacker News | New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html Elastic | New North Korean campaign uses fake coding interviews to steal developer credentials: https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Island.io | AgentBaiting: How Fake AI Skills Deliver Malware at Scale: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Im Podcast geht es mal wieder um einen bunten Strauß an Themen der vergangengen Wochen, angefangen mit einer sehr unangenehmen aber auch wichtige Diskussion zur zukünftigen Absicherung von TLS. Weiter geht es mit LLMs, die angeblich autonom Ransomware ausliefern, und Cisco, die keine einzelnen CVEs mehr ausliefern. Außerdem besprechen die Hosts elektrische Infrastruktur, die man fernsteuern und insbesondere aus der Ferne abschalten kann – leider kann das jeder der mag.
Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: Conficker Still Exists? The Hidden OT Malware Threat Putting Critical Infrastructure at RiskPub date: 2026-07-20Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationSome of the biggest cybersecurity threats to critical infrastructure aren't new - they've simply never gone away. In this episode of Protect It All, host Aaron Crow welcomes back Lesley Carhart for a fascinating conversation about why decades-old malware like Conficker continues to infect operational technology (OT) environments around the world. Drawing on nearly two decades of industrial incident response experience, they share real-world stories from the front lines of critical infrastructure, explaining why legacy systems, operational constraints, and workforce shortages continue to make remediation incredibly challenging. The discussion goes far beyond "just patch it," exploring the difficult risk decisions organizations face when uptime, safety, and cybersecurity all compete for priority. Aaron and Lesley also examine one of the industry's most pressing issues: the growing shortage of OT cybersecurity talent and the need to rebuild foundational technical skills for the next generation of defenders. Key Learnings: Why malware like Conficker still exists in modern OT environments The unique challenges of removing malware from industrial control systems Why patching isn't always possible in operational technology How legacy infrastructure creates long-term cybersecurity risk The growing OT cybersecurity skills gap - and how the industry can address it Practical lessons from real-world industrial incident response Key Moments: 05:47 Challenges with Old Industrial Systems 06:58 Struggles with malware cleanup 11:02 Challenges in Cyber Security Careers 16:19 Dealing with malware spread 17:53 Managing infection risk long-term 23:04 Challenges with nuclear hardware upgrades 27:05 Training the Next Tech Generation 29:33 Importance of Computer Basics 34:04 Discovering hidden technical issues 37:01 Troubleshooting in industrial environments 39:10 Malware and botnets era 42:20 Developing low-touch security solutions Whether you're responsible for manufacturing, utilities, energy, transportation, or any critical infrastructure environment, this episode provides practical insight into one of OT cybersecurity's longest-running challenges. Tune in to discover why yesterday's malware is still creating today's biggest industrial cybersecurity problems - and what organizations can do about it. About the guest : Lesley Carhart is a Principal Industrial Incident Responder at Dragos and a recognized expert in OT and industrial cybersecurity. With nearly two decades of experience in incident response, digital forensics, and threat hunting, they help organizations defend critical infrastructure from cyber threats targeting industrial control systems. Lesley is also a respected speaker, instructor, and advocate for cybersecurity education, regularly sharing their expertise with industry professionals and the next generation of defenders. How to connect Lesley: LinkedIn: https://www.linkedin.com/in/lcarhart/ Youtube: https://www.youtube.com/user/hacks4pancakes Bluesky : https://bsky.app/profile/hacks4pancakes.com Instagram: https://www.instagram.com/hacks4pancakes/ Website: https://tisiphone.net/ Learn more about PrOTect IT All: Email: info@protectitall.co Website: https://protectitallpod.com/ep115 X: https://twitter.com/protectitall YouTube: https://www.youtube.com/@PrOTectITAll FaceBook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Hosts: Gene MitchellAir date: July 18, 2026 Topic: Organic Maps, Contactless Payment Problems, Google is using your Photos,and Malware that destroys PCs
Panel with Dr Sergio Sanchez and Inventor Mike Acerra on how far AI goes to render truth and become a truth machine.Discover the truth about AI and its potential to be a truth machine. In this video, we delve into the capabilities and limitations of artificial intelligence in determining what is true and what is not. CHAPTERS00:00 Welcome to Cyber Crime Junkies + Guest Introductions02:00 Anthropic's Secret AI Mythos Finds Decade-Old Vulnerabilities04:30 How AI Is Finding Security Holes at Scale in Small Businesses06:30 New Books: Moving Target, The God Prompt, and Future Visions09:00 What American Education Is Getting Wrong11:30 Why Forgetting History Destroys Countries14:00 Nixon, the Deep State, and Political Accountability17:00 Property Taxes, Home Ownership, and the Banking Lie20:00 Tax Season Stress and Why Big Refunds Are a Bad Sign23:00 Flat Tax, the IRS, and Why the System Is Built to Confuse You26:00 The Knights Templar Invented Modern Banking29:00 AI as a Truth Machine Against Political Propaganda32:00 How Kennedy Beat Nixon on TV but Lost on Radio37:00 Hack or Hype: Employee Security Risks After Termination40:00 Hack or Hype: The Kaseya Supply Chain Ransomware Attack43:00 Hack or Hype: Does Cyber Insurance Actually Pay Out49:00 What SMBs Get Wrong When Applying for Cyber Insurance52:00 Windows Defender, Malware, and Layers of Endpoint Security Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.True crime enters our homes and businesses daily. Learn from actual people who fight it daily and show you how in a thriller story. The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com Support the showNew Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14.Moving Target: The Obedient Machine drops April 21.Book 3 -- Ghost and the Machine -- out soon!
ShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware. David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity path traversal flaw in Storage Zone Controller 5.x/6.x with patches available (5.12.5 and 6.0.2) and no evidence of prior exploitation. Microsoft's analysis of a year of ShinyHunters activity compromising corporate Salesforce environments by abusing trust via OAuth (IT-support phone cons, vendor token theft such as Salesloft/Drift, and misconfigured guest access), prompting new monitoring tooling. A Fortified Health Security report finding healthcare fixed only 6% of identified risks in H1 2026 amid surging vulnerabilities, third-party risk, and weak identity hygiene. ReversingLabs and ReliaQuest research showing ClickFix social-engineering is now a leading malware delivery method; and Telstra's nationwide outage traced to an obsolete time server hit by a GPS rollover bug, disrupting Triple Zero calls and prompting Senate scrutiny. 00:00 Sponsor NordLayer 00:37 Headlines Overview 01:06 ShareFile Patch Explained 03:25 Salesforce OAuth Break Ins 06:01 Hospitals Drowning in Risks 08:24 ClickFix Malware Surge 11:13 Telstra Time Server Outage 12:32 Wrap Up and Sign Off
Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident response in ICS networks, how ancient malware can cause trouble for years on end, and why we need more ICS security engineers desperately.
https://youtu.be/XPA2l1q-CLk Abonnez-vous et soutenez cette chaîne : https://fr.ulule.com/canardpc/Tous nos magazines et nos offres d'abonnement : https://boutique.canardpc.com/Notre édition web sur abonnement : https://www.canardpc.com/Notre newsletter sur les nouvelles technologies : lepavenumerique.substack.com/about ► Twitch : https://www.twitch.tv/canardpc► Bluesky : https://bsky.app/profile/canardpc.com► X : https://twitter.com/Canardpcredac► Discord : https://discord.gg/nJJFe9r► Facebook : https://www.facebook.com/CanardPCmagazine► Instagram : https://www.instagram.com/canardpc/► Tiktok : @canardpcredac Tous droits réservés Presse Non-Stop / Canard PC. Aucun youtubeur n'a été maltraité pendant le tournage.
In this episode of Unspoken Security, AJ Nash and Faith MacGregor tackle the private sector's sloppy relationship with the word "intelligence" — the gap between raw data, contextual information, and verified, actionable intelligence — and how vendors, circular reporting, and fragmented disciplines like "cyber threat intelligence" have eroded that discipline. From there they turn to AI, weighing real utility against real danger: hallucinations that persist even with vetted sources, analysts pulled toward premature conclusions under time pressure, and the EY finding that roughly 40% of AI-generated conclusions had to be recalled. Nash's sharpest line - if a human analyst behaved this way, you'd fire them - sets up a back half that's cautiously optimistic, pointing to Recorded Future's human-curated, AI-assisted model as a template, while widening the lens to AI in government targeting decisions and the quiet brain drain hollowing out the intelligence profession. Send us Fan MailSupport the show
AI-Powered Malware and the Future of Threat HuntingOn this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hammond to unpack the reality of autonomous AI hacking and why cybercriminals are operating like Fortune 500 startups.1. Why modern ransomware groups have sales teams, HR, and go-to-market strategies.2. How autonomous AI agents are finding zero-days while researchers sleep.3. Glimpsing the future of non-deterministic, AI-driven command and control (C2) servers.4. Real talk on incident response burnout and why the "always-on" hustle is breaking defenders.
US Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs. The episode covers the US State Department's up to $10 million reward for information on Russia-linked hacker groups UNC 5792 and UNC 4221 tied to phishing campaigns that compromise Signal and WhatsApp accounts by stealing Signal backup recovery keys. It also explains a US Supreme Court 6–3 ruling limiting geofence warrants by recognizing Fourth Amendment privacy protections for phone location data and requiring probable cause and narrower requests. Mozilla ODIN researchers demonstrate a proof of concept where a clean GitHub repo can cause AI coding agents to run an init command that executes attacker-controlled code via DNS and opens a reverse shell. A hotel-focused phishing campaign using Calendly and Google redirects delivers ZIP files that install the Tonrat implant through PowerShell and a user-space Node.js runtime. Finally, Canada's CSE says it disrupted infrastructure used by 10 major ransomware groups and reports incident volumes rising nearly 26% year over year. 00:24 Top Headlines Rundown 00:54 10 Million Bounty Russian Hackers 02:42 Supreme Court Limits Geofence Warrants 03:56 AI Coding Agent Repo Trap 05:31 Listener Thanks And Reviews 05:51 Hotel Front Desk Phishing Attack 08:01 Canada Disrupts Ransomware Gangs 09:45 Closing And Sign Off
How are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't install packages as soon as they are released! There are effective tools for detecting malware in code, but they take time. Waiting 48 hours can eliminate a lot of risk! Links Aikido Software Trivy Claude Mythos OpenClaw Shai-Hulud Guidance ClawHub Open Source Malware Windows Update Management Recorded June 15, 2026
Mac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating it via a Telegram bot. Microsoft and Europol disrupted the Amadey and SteelC info-stealer ecosystem by seizing/shuttering infrastructure after identifying 140,000 infections in early May and over 200 command-and-control domains and IPs, as part of Operation Endgame. OpenAI announced "Patch the Planet," a joint effort with Trail of Bits and HackerOne to help open-source projects find and fix bugs amid AI-generated report flooding, alongside a new GPT 5.5 Cyber benchmark result. New FortiBleed reporting underscores that the campaign relies on credential reuse against exposed FortiGate devices and may require rotating far more than just firewall passwords. 00:00 Sponsor Message 00:25 Headlines Overview 00:55 Mac Malware Gaslight 02:00 Telegram C2 And Stealer 02:50 Info Stealer Takedown 04:08 Operation Endgame Impact 04:47 OpenAI Patch The Planet 06:16 AI Models And Export Rules 07:08 FortiBleed Recap 08:13 Inside The FortiGate 08:59 Rotate Credentials Now 09:26 Closing And Sign Off
In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.
In this episode of Elixir Wizards, Charles Suggs and Emma Whamond are joined by Mallory Knodel, executive director and founder of the Social Web Foundation, to talk about internet governance, open standards, and the future of the social web. Mallory shares how her work as an activist, systems administrator, and public interest technologist led her into the organizations and working groups that shape how the internet functions, including the IETF, W3C, ICANN, and ITU. The conversation explores how the internet shifted from a collection of open protocols toward a small number of dominant platforms, and what that centralization means for users, developers, and independent service providers. Mallory explains how decisions made at the protocol level can affect everything from email deliverability to identity, data portability, trust and safety, and the ability to move between platforms. We also discuss the Social Web Foundation, ActivityPub, the Fediverse, and the idea of building a more multipolar social web. Mallory also looks at what happens when AI agents, automated accounts, and algorithmic feeds enter open social ecosystems. She shares her perspective on privacy, usability, encrypted messaging, and designing technology around user needs rather than engagement alone. Key Topics Discussed What it means to be a public interest technologist How internet governance affects everyday software development The role of global internet standards organizations How the IETF and W3C develop technical standards Corporate influence inside internet governance and standards bodies The internet's shift from protocols to centralized platforms Email deliverability and the hidden costs of centralization How platform control affects identity and user autonomy Why data portability remains difficult across social platforms The mission behind the Social Web Foundation How the Fediverse connects independent social platforms ActivityPub and Activity Streams as open web protocols AT Protocol, an alternative to ActivityPub How federated servers exchange content and user activity Why a multipolar web differs from decentralization What Meta's ActivityPub adoption means for federation The embrace, extend, extinguish risk for open protocols Discoverability challenges across federated social networks Trust and safety for smaller platform operators How protocol decisions can affect human rights AI agents entering open social web ecosystems Whether federated platforms should block automated crawlers Designing algorithmic feeds around values and user choice Privacy-first principles for developers building social software Encrypted direct messaging for the open social web Elixir projects building across the Fediverse ecosystem Links Mentioned: Mallory's Website https://malloryknodel.net/ Internet Protocol (IP) https://en.wikipedia.org/wiki/Internet_Protocol Internet Engineering Task Force (IETF) https://www.ietf.org/ International Communication Union https://www.itu.int/en/ Internet Corporation for Assigned Names and Numbers (ICANN) https://www.icann.org/ World Wide Web Consortium (W3C) https://www.w3.org/ Huawei https://www.huawei.com/en/ Cisco https://www.cisco.com/ Messaging, Malware and Mobile Anti-Abuse Working Group (M³AAWG) https://www.m3aawg.org/ Social Web Foundation https://socialwebfoundation.org/ ActivityPub https://www.w3.org/TR/activitypub/ AT Protocol https://atproto.com/ MeWe Decentralized Social Networking Protocol (DNSP) https://dsnp.org/about/MeWe-use-case.html BlueSky https://bsky.app/ Mastodon https://joinmastodon.org/ Internet Society https://www.internetsociety.org/ Fediverse https://fediverse.party/ NCSA Mosaic Browser https://www.ncsa.illinois.edu/research/project-highlights/ncsa-mosaic/ Webring https://en.wikipedia.org/wiki/Webring https://tags.pub/ Elixir projects: Pleroma https://pleroma.social/ Akkoma https://akkoma.social/ Bonfire Networks https://bonfirenetworks.org/ Mobilizon https://mobilizon.org/
Timestamps: 0:00 Steam Workshop Malware 1:25 ChatGPT Market Share Slips 2:40 Snap AR Glasses 5:00 QUICK BITS INTRO 5:14 Microsoft Surface Announcement 5:50 Samsung Changes Product Testing 6:25 Commodore Flip Phone 6:56 Sandisk's 8TB PS5 SSD 7:41 Nvidia Reveals Self Taught Robots NEWS SOURCES: https://lmg.gg/Pj2Lf Learn more about your ad choices. Visit megaphone.fm/adchoices
Athena coalition looks to secure open source Estonia to quarantine Russian email domains Malicious package wave hits Arch Linux Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Meta confirms 20,225 Instagram accounts were hijacked after attackers exploited a bug in its AI-powered High Touch Support tool to reset passwords without verifying email ownership. https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/ The Silent Ransom Group is targeting U.S. law firms with fake IT help desk calls, moving from first contact to data exfiltration in hours and sending ransom demands within 30 minutes of leaving the network. https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/ Weil Gotshal reportedly paid $18–20 million to prevent hackers from publishing stolen client data after a Silent Ransom Group attack. https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/ Jones Day confirms a cyberattack that gave hackers access to client files, also attributed to the Silent Ransom Group campaign targeting BigLaw. https://www.legalcheek.com/2026/04/jones-day-confirms-cyber-attack-after-hackers-access-client-files/ Dark Reading's breakdown of how Silent Ransom Group's law firm extortion campaign operates at scale. https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks Apple announces that iOS 27's Passwords app will use agentic AI to automatically detect and replace weak or compromised passwords in the background, no user effort required. https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/ https://www.macrumors.com/2026/06/08/apple-passwords-can-now-automatically-fix-passwords-with-agentic-ai/ Citizen Lab researcher John Scott-Railton flags a new attacker technique: malware developers are embedding nuclear and biological weapons text inside their spyware to deliberately trigger AI safety refusals, preventing LLM-based security tools from analyzing the malicious code — a real-world demonstration of how over-tuned safety guardrails create exploitable blind spots. https://x.com/jsrailton/status/2064661778978533571 UK Prime Minister Starmer gives Apple and Google a three-month deadline to install device-level software that detects and blocks explicit images on consumer hardware, with privacy advocates and Signal already calling the mandate a blueprint for mass surveillance. https://metro.co.uk/2026/06/08/phone-will-change-new-government-rules-explicit-images-28694073/ Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Ben - https://www.linkedin.com/in/benjamincorll/
An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most. The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use.
https://rhr.tv/stream Keonne Rodriguez (Samourai dev) updates on prison transfer & furlough request https://x.com/keonne/status/2063959631383179277 Bark Ark Protocol Launches on Bitcoin Mainnet https://blog.second.tech/bark-now-on-bitcoin-mainnet/ Second Introduces Noah and Arké Bitcoin Ark Wallets https://blog.second.tech/introducing-noah-and-arke/ Signal: UK Surveillance Is Not Safety https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf Mullvad explains UK spyware proposal: mandatory real-time scanning & blocking on all devices https://x.com/mullvadnet/status/2064342870937509988 SimpleX Network Consortium Governance and Foundation Overview https://simplexnetwork.org/consortium.html Pump.fun launches GO: bounty platform to pay anyone for any task https://x.com/pumpfun/status/2062557004829233504 Man tattoos forehead for $2,400 Pump.fun bounty (spells it wrong) https://x.com/discordiaclips/status/2063406281130398012 Strategy Announces Approval of STRC Semi-Monthly Dividends https://www.strategy.com/press/strategy-announces-approval-of-strc-semi-monthly-dividends_06-08-2026 Polymarket Cracks Down on VPN Users Amid Legal Pressure https://gizmodo.com/polymarket-cracks-down-on-vpn-users-as-legal-pressure-intensifies-in-dozens-of-countries-2000765379 Karpathy on Claude Fable 5: strong benchmarks but overly trigger-happy safeguards https://x.com/karpathy/status/2064409694761054332 Malware devs add WMD keywords to spyware to evade LLM scanners https://x.com/jsrailton/status/2064661778978533571 Anthropic Dario Pushes for Regulatory Moat https://darioamodei.com/post/policy-on-the-ai-exponential HRF Freedom Tech in Oslo: https://www.youtube.com/watch?v=QUcG_CJkT6A Dark Wisp Android v1.0.0 Adds Private Interactions, Tor Routing, and NIP-A3 Payments https://github.com/barrydeen/dark-wisp-android/releases/tag/v1.0.0 Kickstr World Cup Game https://kickstr.einundzwanzig.dev/games/7ea5d40f-be37-4895-94cd-2adaf53f45ad Bitaxe ESP-Miner v2.14.0 Release https://github.com/bitaxeorg/ESP-Miner/releases/tag/v2.14.0 Ulendo: borderless calling via Nostr + Bitcoin without local SIM cards https://x.com/codamw/status/2063340269785784526 Microsoft Patches Record 206 Security Flaws https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html Milei proposes AI framework with "non-human corporations" & zero regulation https://x.com/trajektoriepl/status/2062594306670535130 Cuba Poised for Largest U.S. Fuel Shipment Since Cold War Embargo https://financialpost.com/pmn/business-pmn/cuba-poised-for-biggest-us-fuel-shipment-since-cold-war-embargo 3:33 - Guess who's back 12:13 - Dashboard 19:13 - Keonne update 22:43 - Bark 34:33 - UK surveillance 41:03 - Noah & Arké 47:01 - Simple Network Consortium 53:13 - Pumpfun 57:38 - STRC semi-monthly 1:07:33 - Polymarket VPN crackdown 1:11:23 - Fable 1:24:43 - WMD LLM keyword bypass 1:30:38 - Anthropic is too good 1:33:08 - HRF Oslo 1:33:58 - HRF Story of the Week 1:35:23 - Boosts 1:37:33 - Software updates 1:49:03 - Milei AI 1:51:48 - Cuba fuel Shoutout to our sponsors: Coinkite https://coinkite.com/ Strike https://strike.me/ Stakwork https://stakwork.ai/ Salt of the Earth https://drinksote.com/rhr Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/marty Newsletter https://tftc.io/martys-bent/ Podcast https://tftc.io/podcasts/ Follow Odell: Nostr https://primal.net/odell Newsletter https://discreetlog.com/ Podcast https://citadeldispatch.com/
⛓️ SOFTWARE FOR HOME SERVICE BUSINESS: https://home.works
A federal watchdog questions NIST over its vulnerability database backlog. Google patches an Android zero-day. Citizen Lab exposes a powerful location-tracking platform. Malware hides commands in Steam comments. Researchers spot AI-assisted malware development. Attackers compromise Red Hat's npm namespace. DriveSurge spreads malware through ClickFix and fake updates. FreePBX patches a critical flaw. And Dashlane responds to a brute-force attack. Our guest is Laure Lydon, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on digital health platforms. Meta's AI support bot proves a bit too eager to help. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Maria Varmazis speaks with Laure Lydon, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on privacy, security, and trust in digital health platforms, especially in sensitive areas like women's health. This interview is part of our partnership with Infosecurity Europe. Selected Reading Inspector general finds NIST mistakes have made vulnerability database ineffective (The Record) Google fixes one actively exploited Android zero-day, 124 flaws (Bleeping Computer) Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech (The Citizen Lab) GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure (Security Affairs) Threat Actor Uses AI to Build EDR Evasion Tools (Infosecurity Magazine) Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets (Infosecurity Magazine) Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks (Bleeping Computer) Critical Hard-Coded Credentials Vulnerability in FreePBX User Control Panel (Beyond Machines) Dashlane password manager users locked out by brute force attacks (Bleeping Computer) Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources: Shai-Hulud worm returns stronger and more automated than ever before ‘Mini Shai-Hulud' malware compromises hundreds of open-source packages in sprawling supply-chain attack What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise
Originally recorded: Friday May 29, 2026In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026.Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting the “/mnt/user-data” directory.Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained franchise-related documents. SecurityWeek article Matt references.CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being actively exploited in the wild.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024 Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
New Malware Libraries means New Signatures https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986 Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498 Microsoft Authenticator Update CVE-2026-41615 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615 ssh-keysign-pwn (CVE-2026-46333) Patches Released https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/
The FCC eases restrictions on foreign-made routers. Shiny Hunters hit Canvas and Zara. SailPoint discloses unauthorized access to its GitHub repositories. TrickMo Android banking malware has more tricks up its sleeve. Polish officials warn of increased targeting of ICS and public infrastructure. A federal judge orders $10 million in restitution for stolen zero days. German authorities takedown the Crimenetwork marketplace, again. Monday business breakdown. Dan Lorenc, Chainguard CEO and co-founder, is talking about a recent wave of supply chain attacks. Malware gets signed, sealed and delivered. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dan Lorenc, Chainguard CEO and co-founder, is talking about how the recent wave of supply chain attacks is fundamentally different – and more dangerous –than previous incidents, as well as immediate steps organizations should take as this continues to unfold. Selected Reading US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates (Infosecurity Magazine) ShinyHunters Escalates Canvas Extortion (Infosecurity Magazine) Zara Data Breach Impacts Nearly 200,000 Customers (Infosecurity Magazine) SailPoint Discloses GitHub Repository Hack (SecurityWeek) TrickMo Android banker adopts TON blockchain for covert comms (Bleeping Computer) Polish ABW warns cyberattacks shifting from espionage and data theft toward physical disruption of critical infrastructure (Industrial Cyber) Trenchant Exec Who Sold Zero Days to Russian Buyer Ordered to Pay $10 Million in Restitution to Former Employers (Zero Day) Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested (SecurityWeek) XBOW secures an additional $35 million in Series C funding. (N2K Pro Business Briefing) Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com