POPULARITY
Categories
2026 年 5 月に修正された Microsoft Defender を構成するソフトウェアの脆弱性を悪用するエクスプロイトコードが公開されています。
Ryan Fetterman from Cisco Talos sits down with Decipher's Lindsey O'Donnell-Welch to talk about ClosedQuorum, the first reported malware binary with an autonomous command-and-control. They talk about the wide range of ways threat actors are using AI, and useful detection strategies for AI-assisted attacks. LinksTalos analysis: https://blog.talosintelligence.com/th...
FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware Hackers Claim They Breached the FBI and Stole Data on Nearly Every Agent A criminal crew says it stole data on nearly every FBI agent and job applicant through the bureau's hiring system. The reported way in was the kind of business software your company might run. "We're too small to be a target" doesn't hold up. *The tools you trust are now the attacker's way in.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to track cyber news but can't afford to be blindsided by it. First, the FBI. The extortion group ShinyHunters claims it stole more than two terabytes of data on almost every agent and job applicant. The bureau has confirmed it's investigating. The reported way in was a flaw in Oracle's PeopleSoft HR software, the kind thousands of mid-size companies run. From there, the attackers reportedly jumped into the FBI's cloud. That flaw has been disclosed since June and used all year. Any company still running an unpatched box faces the same risk. Leaked HR and applicant data could give the next attacker a ready-made kit for targeting people and their families. Next, malware that brings its own AI. Researchers found a botnet called Carbonato that hijacks Docker servers left exposed to the internet. It installs an AI agent on the machine and lets that agent decide what to do next. The attackers didn't build the AI. They took an open-source tool and rewrote a single 39-line instruction file to turn it hostile. Running an adaptive attack now takes little more than editing a text file. Its number-one target is your AI keys. The crew uses stolen keys to run its own bootleg AI service, so a leak costs you data and funds the attacker. The way in wasn't a nation-state exploit. It was a server left open with no password. Finally, a defense supplier on a ransomware leak site. A group calling itself Storm posted Applied Composites, a California company that makes composite parts for aircraft, missiles, and satellites. There's no ransom number yet and no list of stolen files. Posting the name first puts pressure on the victim; details can follow if it stays quiet. A 500-to-1,000-person manufacturer deep in the defense supply chain is an attractive target: pressure to pay, without a Fortune 500 security budget. For a supplier, a leak-site listing isn't just downtime. It's a customer-trust and compliance event that can cost contracts. None of these started with a genius hack. Trusted software left unpatched, a server left open, a supplier left under-protected. The attackers walked through the door. • How ShinyHunters claims it breached the FBI and what data is at risk • Why the software running your HR and cloud is now the front line • Carbonato: the malware that installs its own AI agent to hack for it • Why stolen AI keys are the new top prize for attackers • How a small defense manufacturer ended up on a ransomware leak site • Why attackers target the small supplier to reach the big customer • What business owners should do before their name is the one on the list Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #FBI #ShinyHunters #Ransomware #DataBreach #AI #Docker #VendorRisk #SupplyChainSecurity #MSP #BusinessRisk
According to ars Technica, Xbox announced a radical restructuring of its internal studios that is seemingly designed to reduce that “independence” for the teams behind some of gaming's biggest franchises. In this episode, host Paul John Spaulding, Kyle Haglund, VP, Audio Engineering at Cybercrime Magazine, and Sam White, Video Producer at Cybercrime Magazine, discuss this story, alongside several others making news in the gaming industry recently, including Steam's recent hit by malware, and more. • For more on cybersecurity, visit us at https://cybersecurityventures.com
ShinyHunters hijacks Clop's own leak site Fake LastPass installers kill security tools Trusted npm release carries GHAPPIER malware Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries Get the show notes here: https://cisoseries.com/cybersecurity-news-september-22-2026/
Na 25 minuten AI-gebruik drie uur verplicht aandacht voor je partner. Zo kun je tokenlimieten ook bekijken, vindt Ronald. Zelf heeft hij andere technische problemen: de antennes uit de vorige aflevering hielden het maar twee minuten vol op zijn autodak. Toch derde geworden bij de foxhunt. Met een gewoon radiootje. Voor het hoofdverhaal hoeven we gelukkig niets op het dak te plakken. Die auto zit al vol sensoren. Je mag de kazerne op. Maar je auto ook? Camera's, microfoons, radar, soms lidar en een internetverbinding: een moderne auto heeft behoorlijk wat mee om de omgeving in kaart te brengen. Handig bij het parkeren. Ook interessant als je wilt weten wat er op een defensieterrein staat of wie bij de R&D-afdeling van ASML naar binnen loopt. Defensie onderzoekt of slimme auto's van kazernes en uit de omgeving moeten worden geweerd. We bespreken wie bij die sensoren en gegevens kan, wat een gerichte software-update mogelijk maakt en waarom een Europees logo weinig zegt over waar je auto gebouwd wordt. Inclusief de elektrische Mini van BMW en Great Wall Motor. Klinkt als een samenwerking waar we even over moeten praten. Maar zou een fabrikant zijn hele handel riskeren met een achterdeur? En geldt dit niet net zo goed voor Tesla? Daar zijn we niet in twee zinnen uit. China beperkte zelf al de toegang van Tesla's tot bepaalde overheidslocaties. Ook Polen, het Verenigd Koninkrijk en België komen voorbij. En als Defensie maatregelen neemt, waarom zouden andere ministeries en vitale bedrijven dan achterblijven? Heel naar voor de medewerker die net een nieuwe auto heeft gekocht. Ondertussen publiceert Anthropic hoe aanvallers Claude inzetten. Malware aanpassen zodra de antivirus aanslaat, gestolen sleutels uit Android-apps vissen en aanvallen draaien op andermans AI-budget. We bespreken wat er verandert als één operator met agents werk kan verzetten waarvoor eerder een team nodig was. En wat een AI-leverancier daardoor allemaal van die operaties meekrijgt. De vraag of wij zelf al in het rapport staan, wordt uiteraard ook gesteld. Verder: OpenAI claimt een wiskundige doorbraak rond Navier-Stokes, Iraanse aanvallers gebruiken zelfs een MRI-scan als lokmiddel om regimecritici malware te laten installeren, en Chinese typsoftware blijkt een ingang voor een China-gelinkte hackgroep. Je wilt Chinese tekens typen, maar krijgt via een verouderde browser in de themawinkel GRAYRABBIT binnen. Wie wil juist déze gebruikers hebben, en waarom? Bronnen: - Slimme auto's, Kamerbrief en TNO-onderzoek: https://open.overheid.nl/documenten/8b4abbc1-092d-43a9-83b6-1eb73bc65209/file - Sensoren en datastromen in auto's: https://fpf.org/wp-content/uploads/2024/09/FPF_connected_vehicl_v2_03_nosidebar-2.pdf - Reuters over Tesla-beperkingen in China: https://www.euronews.com/next/2021/05/21/uk-tesla-china - Anthropic, threat report september 2026: https://www.anthropic.com/threat-intelligence-report-september-2026 - OpenAI over Navier-Stokes: https://openai.com/index/navier-stokes-solution/ - NCSC over CHOSEN BRICK: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists - Gen Threat Labs over Sogou en GRAYRABBIT: https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts. We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend's account can lead to an infection. Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks. In this interview: • Microsoft Defender's strengths and limitations • Free tools for investigating suspicious Windows activity • How infostealers and initial access brokers operate • Stolen session tokens and the limits of 2FA • Fake download sites, malicious ads and targeted phishing • Preparing recovery options before your accounts are compromised • Security and privacy trade-offs across Windows, Linux and macOS // Leo's SOCIAL // YouTube: / @pcsecuritychannel X: https://x.com/leotday Discord: / discord // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:35 - Intro 0:48 - Leo's Background & How Malware Has Evolved 03:27 - How to Detect Malware on Your Computer 05:21 - Best Sysinternals Tools for Malware Analysis 08:21 - Windows Device Tracking & Privacy Concerns 10:42 - Would you Recommend Windows in 2026? 11:59 - Privacy Laws & the Future of Tracking 12:50 - How Telemetry Helps Catch Cybercriminals 14:02 - ThreatLocker Sponsor 15:18 - How Hackers Actually Get Into Systems 16:42 - How to Protect Yourself From Getting Hacked 19:12 - Do You Really Need Antivirus? 21:35 - Security Advice for Home Users 25:59 - Why Smart People Still Get Hacked 26:59 - What Happens After Your Credentials Are Stolen 28:06 - Linux vs Mac vs Windows 29:40 - Is Windows Really Targeted More by Malware? 31:18 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #malware #bhusa2026 #microsoftdefender
In this episode of Unspoken Security, host AJ Nash sits down with Snehal Antani, co-founder and CEO of Horizon3.ai and former first CTO of Joint Special Operations Command (JSOC), to dissect what AI is really doing to the economics of cyber attacks - and cyber defense. Snehal opens with a jaw-dropping data point: his team compromised a defense industrial base supplier and achieved full domain admin in 77 seconds. From there, the conversation moves into the surprising counter-strategy his team uncovered - that today's LLMs and agentic attackers are dramatically more gullible than human hackers, clicking on well-placed honey tokens up to 95% of the time.The two dig into why "train like you fight" - a principle Snehal absorbed at JSOC - is now essential for cyber teams, why compliance frameworks like CMMC are failing to produce real resilience, and why the future of cyber warfare is "AI versus AI with humans by exception." Snehal walks through Horizon3.ai's architectural bet on disposable models, persistent knowledge graphs, and constrained-action-space agents, and explains why the "haves and have-nots" of red teaming is finally being disrupted by autonomous pentesting that IT admins - not elite ethical hackers - can operate.The conversation closes with a candid look at the industry itself: the ChatGPT-driven sameness of vendor messaging, the Black Hat gimmick arms race, and Snehal's plea to return to technical authenticity. He ends with a deeply personal reflection on his late father - the electrical engineer who sabotaged toy robots so his six-year-old son would learn to troubleshoot them - and the weight of trying to pass that same gift on to his own kids.Send us Fan MailSupport the show
Wir haben schon das neue ENVE Melee V2 2027 auf unserer "Couch"! Es bleibt so schön und zurückhaltend wie der Vorgänger, ist aber technisch viel mehr als nur ein Facelift. Krass, wieviel Neues und vor allem Schnelles in dem Rad steckt ohne die DNA des aktuellen Melees zu verlieren. Außerdem: COROS lässt unerwartet Karten auf die Pace 4! Aktuell ist die Beta-Phase und die ist schon voll, aber es wird nicht mehr lange dauern, dass die beliebteste COROS Uhr wohl noch beliebter wird. Nicht ganz ernst gemeint diskutieren wir außerdem darüber iPhone Duo für Bikepacking ;-) – Es löst irgendwie ein "Will-Haben" bei uns aus und gleichzeitig ist es ein "BRAUCHT MAN NICHT"-Ding. ------------------------------------------------------------ PICKLISTE & PARTNERSHOPS ------------------------------------------------------------ EYB Pickliste aller je gemachten Podcast-Picks: https://docs.google.com/document/d/1UjfitykkrWqKdWUTrYY0JBX-T4Qn8pdSm6RiWlM4j0M/edit?usp=sharing Unsere Partner-Shops: https://www.enjoyyourbike.com/neu/aktuelles/partner-shops/ ------------------------------------------------------------ NORDVPN (Werbung) ------------------------------------------------------------ Exklusiver Deal mit dem Promo-Code enjoyyourbike: 2-Jahres-Tarif + 4 Extra-Monate gratis! Nicht nur VPN – schützt auch vor Phishing, Betrug und Malware. Ein Konto schützt bis zu 10 Geräte. 30-Tage-Geld-zurück-Garantie. https://nordvpn.com/enjoyyourbike ------------------------------------------------------------ ALLE INFOS & LINKS ZUR SENDUNG ------------------------------------------------------------ COROS Pace 4 Pro – Karten kommen: https://coros.com/de/stories/coros-metrics/c/september-2026 iPhone Duo: https://www.apple.com/de/iphone-duo/ Ortlieb Tidura – neues Eigengewebe: https://de.ortlieb.com/collections/tidura ENVE Melee V2 2027: https://www.enjoyyourbike.com/detail/index/sArticle/30434/sCategory/2092177 Formel Reifenumfang: (622 + 2 × Reifenbreite × 0,85) × π = Reifenumfang in mm ------------------------------------------------------------ PICKS ------------------------------------------------------------ Brot Topping: https://www.spicebar.de/crunchy-brot-topping Other Means – Das Fahrradmagazin: https://othermeansmag.com/ ------------------------------------------------------------ INHALT ------------------------------------------------------------ 00:00:00 Intro 00:01:58 Reifenumfang – Ingo und André rechnen sich um Kopf und Kragen 00:10:43 COROS Pace 4 bekommt Karten – Pace 4 Pro Teaser 00:28:36 NordVPN (Werbung) 00:33:47 iPhone Duo – Arbeiten auf Reisen? 00:57:37 TPU mit Dichtmilch beim Pendeln 01:16:58 Ortlieb entwickelt eigenes Gewebe: Tidura 01:19:27 ENVE Melee V2 2027 – für viele der Tarmac-Killer! 01:45:28 Picks 01:56:31 Preshow: Dating Apps
On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hultquist, Chief Analyst at Google Threat Intelligence Group (ex-Mandiant, ex-FireEye, founder of CYBERWARCON & SLEUTHCON).Drawing on over two decades of tracking state-sponsored adversaries like Sandworm, John cuts through the hype to explain what modern threat intelligence actually does: it keeps CISOs from burning millions of dollars on the wrong technology, spots adversary shifts before static IOCs exist, and bridges the gap between raw binary reverse-engineering and executive decision-making.In this episode, John unpacks how threat actors are weaponizing AI and bypassing commercial costs entirely and traces the real shift underway: adversaries embedding adversarial prompt-injection payloads inside malware to shut down automated SOC scanners.What's Inside:1. The economics of illicit AI: Underground access vs. hijacked enterprise compute2. Malware poison pills designed to neutralize automated LLM triage3. Why firmware and ICS layers are becoming primary targets for disruption4. Behavioral detection models when living-off-the-land means zero usable IOCs5. Lessons from tracking Sandworm and convincing leadership to act before the lights go out
Referências do EpisódioThe banana stand: brokering and managing infections across Asia using MQTTParaShells: Parallels Desktop Turns Appliance Install Into a Root ShellRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
In dieser Folge geht's ums (fast) selbstfahrende Auto, einen Ex-Partner, der per App noch auf den Tesla seiner Ex zugreifen konnte, Rechenzentren aus echten Hirnzellen, spionierende Fernseher und einen Wurm, der sich per Telefonanruf verbreitet – plus jede Menge Apple- und iPod-Anekdoten zum Schluss. **Themen dieser Folge:** - QR-Code per Longpress öffnen: Rüdiger und Tobi werten die Reaktionen aus ihrer exklusiven WhatsApp-Gruppe aus - Autonomes Fahren: Rüdiger testet ein Auto, das auf der Autobahn komplett selbst fährt – und erinnert sich an seinen Stern-TV-Test von 2015 - Zukunftsvision: Fährt euer Auto bald selbst zum Supermarkt und lädt den Einkauf ein? - Tesla-Stalking-Fall aus Sydney: Ein verurteilter Ex-Partner konnte über eine geteilte App-Freigabe das Auto seiner Ex während der Fahrt auf 40 km/h drosseln – und die Betroffene konnte ihm den Zugriff nicht ohne seine Zustimmung entziehen - Biocomputer aus menschlichen Hirnzellen: Ein Startup baut Rechenzentren mit im Labor gezüchteten Neuronen statt Siliziumchips – Ziel ist Energieeffizienz, nicht Rechenleistung - Bundesweiter Warntag am 10. September: Wer hat den Alarm mitbekommen? - Tobis neues Google Pixel mit GrapheneOS – und der Fall aus den USA, in dem ein Reisender wegen einer versehentlich ausgelösten "Erase-PIN" wegen Vernichtung von Beweismitteln angezeigt wurde - Wie Handys im Gefängnis unentdeckt bleiben – und wie Inhaftierte früher über RTL-Teletext (Seite 673) Nachrichten von draußen empfangen konnten - "WeWorm": Ein Zero-Click-Wurm, der sich über Sprachanrufe in WeChat verbreitet und potenziell Milliarden Geräte hätte infizieren können - LG-Fernseher im Visier von Sicherheitsforschern: Raumgespräche, Netzwerk-Scans und Standortdaten landen offenbar bei LG – fürs Ad-Targeting - Ein US-Fernsehhersteller wird für 2,7 Milliarden Dollar verkauft – nicht wegen der Geräte, sondern wegen der gesammelten Nutzerdaten - Die Ukraine launcht "Trophy Lab": eine (halb-offene) Datenbank mit erbeuteten russischen Waffensystemen für Rüstungsentwickler - Apple Mail erinnert künftig aktiv an unbeantwortete Nachfragen – Rüdiger war not amused - Zum Ausklang: Karl Lagerfelds legendäre Sammlung von über 500 iPods, die neuen Apple EarPods und Rüdigers Pläne für ein Foldable iPhone -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast
Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving over 153 million U.S. driver's license scans and 1.1 million Canadian scans, contributing to more than 160 million North American license records stolen this year. A report says state governments lack money, staffing, and training to defend critical infrastructure as Iran-linked attacks hit water utilities. Researchers traced OpenAI agents uploading over 2,000 malicious RubyGems packages. Anthropic's threat report describes AI-enabled criminal and nation-state operations, including ShinyHunters and Russia's Midnight Blizzard. Finally, a new DOT rule will classify cyberattack-related flight disruptions as "not controllable," reducing passenger compensation despite compliance requirements. 00:00 Headlines Preview 00:35 Florida DMV Breach 01:14 IDScan Mega Leak 02:52 States Lack Cyber Resources 04:31 OpenAI Agents Malware Flood 06:28 Anthropic AI Espionage 08:13 Regulate Weaponized AI 08:53 Airlines Compliance Trap 11:10 Wrap Up And Sign Off
In deze aflevering van Techzine Talks spreken we met Werner Vermeylen, CISO bij Klarrio. We hebben het over datgene waar Klarrio zich al lang mee bezighoudt, namelijk maatwerk dataplatformen. Uiteraard komen ook zaken zoals datasoevereiniteit en security aan bod, ook in gereguleerde omgevingen. Klarrio bouwt al tien jaar cloud-agnostische en open-source dataplatformen voor grote bedrijven in sectoren als halfgeleiders, telecom en energie. Een van de basisprincipes i bij dit alles is dat de klant zelf de volledige controle heeft en houdt.Vermeylen legt uit waarom grote bedrijven ondanks eigen IT-teams toch vastlopen bij het bouwen van dataplatformen. Klarrio heeft zich gedurende tien jaar onder andere gespecialiseerd in het uitvoeren van migraties zonder downtime (van DC/OS naar Kubernetes). Ook de rol van de CISO, NIS2, CRA en de groeiende druk vanuit regelgeving komen uitgebreid aan bod.Het gesprek gaat ook diep in op de impact van AI op datasecurity: exploittijden dalen hard, malware verstopt zich in open-source packages op GitHub. Tot slot gaan we in op de zoektocht naar soevereine defensieve AI-tooling met lokale LLM-modellen.Belangrijkse inzichten:• Klarrio bouwt geen product, maar volledig maatwerk dataplatformen op basis van open source en cloud-agnostisch design• Datasoevereiniteit gaat verder dan cloudkeuze: ook de architectuur, licenties en componenten bepalen echte controle• Zero-day exploittijden dalen hard, terwijl AI aanvallen sterk versnelt• Open source is niet automatisch soeverein: botnetwerken op GitHub plaatsen malware in populaire packages• Niets is 100% veilig: wie dat wel beweert, liegtHoofdstukken:1:11 - Wat doet Klarrio: custom dataplatformen2:09 - Doelgroep: grote bedrijven in gereguleerde sectoren3:48 - Controle over je eigen data: soevereiniteit als kernfilosofie8:13 - Architectuurkeuzes: van DC/OS naar Kubernetes13:32 - Use case: verkeersplatform voor de Nederlandse overheid16:27 - Projectoplevering en kennisoverdracht18:58 - De CISO-rol bij Klarrio: security by design22:58 - AI en de versnelling van zero-day exploits24:31 - Soevereine defensieve AI en lokale LLM-modellen29:03 - Malware in open source: GitHub-botnetwerken ontdekt32:21 - Kwetsbaarheidsbeheer: risico's analyseren en accepteren43:27 - Beslissingen nemen in onzekerheid
Critical NetScaler vulnerability exploited in attacks AdaptHealth data breach impacts 4.1 million people MantaxOtax Android malware delivers ransomware and spyware together Get the show notes here: https://cisoseries.com/cybersecurity-news-netscaler-vulnerability-exploited-adapthealth-suffers-breach-new-android-malware/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.
Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft's CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware delivery.They cover what HTTPS and VPNs actually protect, why a lock icon does not prove a page is legitimate, the warning signs that should make travelers disconnect, and when a cellular hotspot is the better choice. Scott also shares an update on his Digital Legacy Tree book and tools.** Links mentioned on the show **Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/FBI hotel Wi‑Fi guidance https://watech.wa.gov/fbi-warns-cyber-risks-when-telecommuters-use-hotel-wi-fiFCC — Cybersecurity Tips for International Travelers https://www.fcc.gov/consumers/guides/cybersecurity-tips-international-travelersScott Wright — Digital Legacy Tree book and tools https://securityperspectives.com/digital-legacy-tools** Watch this episode on YouTube **https://youtu.be/TBqKfiGayfo** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
The copy-paste hack that stole $150K. CrowdStrike and federal authorities dismantled Sality, a botnet that spent eight years swapping copied wallet addresses for the attacker's, so victims unknowingly sent crypto to a stranger. The fix is simple: check the first and last characters of any address after you paste it. CoinDesk's Jennifer Sanasie hosts "CoinDesk Daily." - This episode is brought to you by RealFi, a smarter stablecoin, backed by real-world assets. Find out more at realfi.co. - This episode is brought to you by Grayscale, the world's largest digital asset-focused investment platform. Grayscale's mission is to make digital asset investing simple and open to every investor. Learn more at grayscale.com. - This episode was hosted by Jennifer Sanasie. “CoinDesk Daily” is produced by Jennifer Sanasie and edited by Victor Chen.
John Ternus é o novo CEO da Apple e Tim Cook se despede;Meta, TikTok e YouTube retiram perfis de Renan Santos do ar; IA brasileira usada por policiais reduziu crimes em 27%;E muito mais!
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Available https://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign; https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ DLink Vulnerabliities https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513 Watchguard Patches https://psirt.watchguard.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
How do we stop malware from infecting open-source software libraries?
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The hard truth is that you can never fully prove your computer is malware free... but you can still stack the odds in your favor. I'll discuss why, the habits that keep you safer online, and what to do if something slips through.
Find out when a manual scan makes sense, and how often you should run one for peace of mind.
Bom dia Tech! Tudo bem? Meu nome é Arthur Givigir e hoje é terça-feira, dia 25 de agosto de 2026 e trago para você as principais notícias de tecnologia, vamos lá?No episódio de hoje, o Brasil anunciou um pacote de R$ 2,3 bilhões para ampliar sua infraestrutura de inteligência artificial, incluindo a compra de um supercomputador que deverá ficar entre os dez maiores do mundo em capacidade de processamento para IA. Também falo sobre falsos downloads de GTA VI espalhando malware, uma falha chamada Zombie Card que consegue fazer cartões Visa expirados voltarem a realizar pagamentos, The Witcher 4 sendo confirmado para 2028 às vésperas da Gamescom e a Apple preparando um novo iMac com chip M6 ainda para este ano.Quer patrocinar ou fazer uma parceria com o Bom dia Tech? Mande um e-mail para contato@bomdia.teche vamos conversar!ApoioAmazon: Promoções KindleNotícias00:00: ☀️ Bom dia Tech!00:29: Brasil terá supercomputador entre os maiores do mundo para IA03:35: Falsos downloads de GTA VI estão espalhando malware05:57: Zombie Card faz cartões Visa expirados voltarem a funcionar08:40: The Witcher 4 é confirmado para 2028 antes da Gamescom10:48: Apple prepara novo iMac com chip M6 ainda para 202612:35: Inté a próxima!Produtos do EpisódioSmartphones JoviSamsung Galaxy FoldsNintendo Switch OLEDBundle Nintendo Switch OLED com Mario Kart 8PlayStation 5 SlimPlayStation DualSenseApple iPhone 16 (128 GB)Echo Show 5 (3ª geração)Echo Show 8 (3ª geração)Kindle ScribeComprando por esses links, o Bom dia Tech recebe uma pequena comissão e você ajuda no crescimento do podcast.Redes sociais:InstagramThreadsMastodonCapa:Capa: Gerada por IA
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen. Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys. Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun. 00:00 Top Stories Rundown 00:30 Entra ID Perfect 10 Patch 01:55 Defender Driver Weaponized 03:31 SickKids Hit Again 05:10 Leaked AWS Keys Still Live 06:48 Car Head Unit Botnet 08:25 Wrap Up And Sign Off
video: https://youtu.be/lBJDyzkJbCI Linux 7.2 is here with a ton of new kernel improvements. Desktop Linux has crossed a major milestone for usage with more than 10% in North America and 7% globally. Arch Linux has announced some changes they are making to the way the AUR works because of the latest Malware attacks. Plus there's some big KDE news this week. KDE is bringing back LTS support with a much bigger "Bullet-Proof KDE" approach, and Framework has announced the next edition of the Framework Laptop 12 and it's coming with a preinstalled option of Fedora KDE. There is a LOT happening in the Linux world right now, and some of these stories get pretty wild. So here's Your Source for Linux GNews and see what's happened This Week in Linux. Download as MP3 Support the Show Become a Patron = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:52 Support the show (Become a Member) 01:43 Linux 7.2 Released 04:50 Linux crosses 10% in Desktop Market Share 10:53 Arch Linux changes how AUR Adoptions work after Malware waves 13:06 "Bullet-Proof KDE" brings LTS Support back to KDE 16:29 Framework Laptop 12 with Fedora Linux Preinstalled 19:39 NVIDIA, GOG, & Epic Games to compete with Valve on Linux Gaming Ecosystem 23:01 Steam Deck 1% lows improve by as much as 32% 25:27 Ubuntu Touch 24.04-2.0 Released 27:28 NVIDIA Becomes a Premier Sponsor of LVFS/Fwupd 28:48 FFmpeg 9.0 Released 29:56 Support the show 31:21 Outro Links: Linux 7.2 Released https://lwn.net/Articles/1089033/ https://kernelnewbies.org/Linux_7.2 https://www.phoronix.com/review/linux-72-features https://www.phoronix.com/news/Linux-7.2-Released Linux crosses 10% in Desktop Market Share https://gs.statcounter.com/os-market-share/desktop/north-america#monthly-202505-202606 https://radar.cloudflare.com/explorer?dataSet=http&groupBy=os&dt=2026-07-01_2026-07-31&loc=north-america&filters=deviceType%253DDESKTOP%252CbotClass%253DLIKELY_AUTOMATED https://store.steampowered.com/hwsurvey/ https://www.linux-magazine.com/Online/News/Linux-Surpasses-Double-Digit-Market-Share Arch Linux changes how AUR Adoptions work after Malware waves https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/thread/P5C7GZ4C3OJIH4EXJ62JAF6X6PY2BCQ4/ https://archlinux.org/news/active-aur-malicious-packages-incident/ https://lists.archlinux.org/hyperkitty/list/aur-general%40lists.archlinux.org/latest?count=200 https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/message/NNNGQYXYGBYGESV35AEQV2PLAVMMLW64/ "Bullet-Proof KDE" brings LTS Support back to KDE https://www.kubuntu.org/news/plasma-6.6-lts/ https://pointieststick.com/2026/08/ https://www.phoronix.com/news/KDE-Bullet-Proof-Software Framework Laptop 12 with Fedora Linux Preinstalled https://frame.work/blog/framework-laptop-12-now-with-core-series-3 https://frame.work/laptop12 https://youtu.be/459a7YBmBOE https://youtu.be/yE48_MN8Ng4 https://www.phoronix.com/news/Framework-Laptop-12-WCL NVIDIA, GOG, & Epic Games to compete with Valve on Linux Gaming Ecosystem https://blogs.nvidia.com/blog/geforce-now-thursday-linux-native-app/ https://www.gamingonlinux.com/2026/01/the-native-linux-app-for-nvidia-geforce-now-is-now-in-beta/ https://www.phoronix.com/review/nvidia-geforce-now-linux https://www.gamingonlinux.com/2026/07/gog-confirm-they-are-working-towards-gog-galaxy-on-linux/ https://www.gamingonlinux.com/2026/08/epic-games-store-will-get-a-linux-version-sometime-soon/ https://www.pcgamer.com/hardware/the-epic-games-launcher-will-be-available-on-linux-soon-says-dev-after-its-had-a-bit-of-work Steam Deck 1% lows improve by as much as 32% https://www.phoronix.com/news/AMD-P-State-Better-1p-Lows https://www.pcgamer.com/hardware/handheld-gaming-pcs/linux-kernel-patch-can-boost-the-steam-decks-1-percent-low-frame-rate-by-as-much-as-31-percent-in-early-testing/ Ubuntu Touch 24.04-2.0 Released https://ubports.com/blog/ubports-news-1/ubuntu-touch-24-04-2-0-and-24-04-1-4-release-4007 NVIDIA Becomes a Premier Sponsor of LVFS/Fwupd https://www.linuxfoundation.org/press/linux-foundation-announces-key-industry-support-for-linux-vendor-firmware-service https://www.phoronix.com/news/NVIDIA-Premier-Sponsor-LVFS https://www.gamingonlinux.com/2026/08/nvidia-now-supporting-the-linux-vendor-firmware-service-lvfs-as-a-premier-sponsor/ https://www.fwupd.org/ FFmpeg 9.0 Released https://www.ffmpeg.org/ https://ffmpeg.org/releases/ https://www.phoronix.com/news/FFmpeg-9.0-Released Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/
NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts. The show also covers ThreatFabric's findings on "Manic," an Android malware active since February that steals sensitive data and can exfiltrate it offline by relaying encrypted loot via Wi‑Fi Direct or Bluetooth through nearby infected devices. Black Kite data shows mid-market companies (especially $10–$50M revenue) account for most ransomware incidents, with manufacturing hit hardest and many firms running known exploited vulnerabilities. Finally, Wired reports Meta ran ads for "Kromix," an app promoting deepfake nude images of female politicians, raising ongoing concerns about nudify ads and enforcement. 00:00 Sponsor NordLayer 00:37 Headlines Preview 01:05 AI Exploits Hit PLCs 04:06 Android Malware Manic 06:49 Ransomware Targets Midmarket 09:19 Meta Nudify Ads Scandal 12:26 Wrap Up and Weekend Tease 13:23 Sponsor Message NordLayer
Persistent prompts prove potentially pernicious The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.
Back in 2005 The U.S. "allegedly" spearheaded Operation Olympic Games, the torch was passed to Obama, and the primary objective was to create a virus that would make Iranian Machinery tear itself apart!--------------------------------------------------------To Sign up for our Patreon go to-> Patreon.com/cultofconspiracypodcastTo Find The Cajun Knight Youtube Channel---> click hereTo Find The Meta Mystics Spotify--> Click Herehttps://flavorsforest.com/cult/Become a supporter of this podcast: https://www.spreaker.com/podcast/cult-of-conspiracy--5700337/support.
In this episode: How a virus-infected Prince of Persia floppy disk on a Commodore 64 sparked a lifelong obsession with cybersecurity (03:03 - 06:45) From NYU to Yale cryptography PhD to Goldman Sachs to Gilt Groupe, and the near-miss that changed everything (03:03 - 06:45) What SecurityScorecard actually does and why the pen and paper questionnaire era had to end (06:55 - 08:18) What it looked like in the early days, including an IKEA furniture test for business partnerships (08:26 - 12:01) Why SecurityScorecard now scores every company in the world, not just twelve million organizations (12:01 - 12:29) The Gilt Groupe credit card near-miss, what the first 24 hours looked like, and why fear was the first reaction (12:50 - 17:30) What it takes to create an entire market category from scratch and why the job to be done never changes (17:48 - 20:20) The difference between the CISO version and CEO version of Alex, and what Satya Nadella said about zooming out (20:49 - 22:36) Which version of Alex people would rather have a beer with and why any job besides CEO is more fun (22:43 - 23:45) How North Korea used a fake hedge fund to try to recruit SecurityScorecard developers (24:06 - 25:47) Why the world is not becoming safer and the critical difference between robustness and resilience (25:59 - 26:42) The True Confessions keynote: why openly admitting breaches makes the whole ecosystem stronger (27:13 - 29:22) The Jaguar Land Rover breach and what it took to double a UK company's security budget overnight (27:13 - 29:22) The single most dangerous thing a board member has ever said in a meeting about cybersecurity (29:45 - 31:09) What one thing a non-technical CEO could do this week to make their CISO's life better (31:25 - 32:12) The Lifestyle Polygraph: restaurant health scores, PowerPoint ban, The Inner Game of Tennis, chess, false advertising, and podcast advice (33:07 - 41:32) Timestamp Highlights: (03:03) Prince of Persia, a floppy disk, and the origin of a cybersecurity career (06:07) The realization that changed everything: you can do everything right and still lose (08:26) The IKEA furniture test for business partnerships (12:50) The Gilt Groupe near-miss and what the first 24 hours looked like (17:48) What it takes to create a market category from scratch (20:49) CISO vs CEO: zooming in vs zooming out (22:43) Which version of Alex would you rather have a beer with? (24:06) North Korea's fake hedge fund operation (25:59) Robustness vs resilience: why the mindset has to change (29:45) The most dangerous thing a board member has ever said (31:25) One thing every non-technical CEO should do this week (36:48) The Inner Game of Tennis and the infinite game (40:00) Chess, false advertising, and meeting his future wife Resources & Links: SecurityScorecard — securityscorecard.com The Perfect Scorecard by Aleksandr Yampolskiy ThreatLocker — Presenting sponsor of No Password Required DerScanner — Episode sponsor Cyber Florida — The Mother Ship
Intel Chat with Matt Bromiley and Chris Luft.• AI-generated patches fix vulnerabilities about half the time. 1Password's Off-By-1 team tested ChatGPT-5.5 and Opus 4.8 against six vulnerabilities: across 6,080 generated patches only 46% fixed the underlying flaw, and some that did were narrow enough to be bypassed. Separate Veracode research found a 56% security pass rate across 100+ models, with 44% of AI-generated code carrying detectable OWASP Top 10 issues. Matt's pushback: what is the HUMAN success rate for comparison, and why is nobody publishing that number?• LiteLLM supply chain attack. CloudSEK reports 2,500+ organizations and 434,000 CI/CD pipelines potentially exposed. LiteLLM was not the initial target: the compromise came in through Aqua Security's Trivy scanner and spread when LiteLLM's CI automatically installed it, ending with malicious versions 1.82.7 and 1.82.8 on PyPI. They were live for roughly 40 minutes, which automated dependency resolution and cached layers were more than enough to propagate.• Anthropic's models reached real systems during evaluations. Reviewing 141,006 evaluation runs, Anthropic found three incidents where Claude models gained unauthorized access to real organizations during capture-the-flag exercises, after a misunderstanding with an evaluation partner left the environments internet-connected. One model published a malicious package to the real PyPI, where it ran on 15 real systems. Matt argues this is a lab test rather than a threat report, and asks what defenders are supposed to do with it.• North Korea behind the npm compromises. Amazon Threat Intelligence links the typo-crypto, debug, chalk and axios incidents to the same DPRK actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA and BlueNoroff. Wiz found roughly one in ten cloud environments touched by the debug and chalk incident within two hours. The technique has shifted: malicious functionality is now split across several innocuous-looking packages that only do anything once combined, plus slopsquatting and prompt injection aimed at AI code scanners.Stories covered:• https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time• https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/• https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals• https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/Chapters:0:00 Back from Black Hat3:31 AI-generated patches fix vulnerabilities about half the time6:23 What is the human success rate?10:53 LiteLLM supply chain attack13:03 Pin your dependencies15:59 Anthropic models reached real systems during evals22:12 This is a lab test, not a threat report27:06 North Korea behind the debug, chalk and axios compromises30:59 Malware assembled from harmless-looking parts33:27 Clever people on the other side of the fenceThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #AIsecurity #supplychainsecurity #threatintel
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Bing malvertising campaign tricks users into downloading a fake Claude desktop app that quietly installs the SectopRAT info-stealing trojan. - https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/ The malicious "FakeAgent" campaign hit at least 29 organizations on July 21–22; the poisoned Claude Artifact (hosted on Anthropic's own domain) was downloaded 7,100 times before removal, with the fake installer (ClaudeDesktop.exe) sideloading a malicious DLL to drop SectopRAT — a HVNC-capable info-stealer active since 2019 that targets browser logins, crypto wallets, Discord/Telegram/Steam credentials, and uses Ethereum smart-contract transactions (EtherHiding) to fetch its C2 address; researchers even used Claude Opus 4.8 themselves to help reverse-engineer the payload. Iran allegedly exploited decades-old cell network flaws to physically locate and target US troops during the Iran War. - https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/ Per a Financial Times report citing the Mobile Surveillance Monitor and government officials, Iran exploited SS7 — the legacy signaling protocol still underpinning 2G/3G global roaming — to track US personnel at bases and hotels in Iraq, Bahrain, and elsewhere in the Middle East, contributing to strikes that wounded upwards of 150 US troops; Iran reportedly also abused ad-tech location data as a secondary tracking vector. A multi-university study found dozens of apps marketed directly to US troops are quietly shipping Chinese and Russian code. - https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/ Researchers from Purdue, West Point, and Florida International University analyzed 220+ apps aimed at service members (fitness trackers, base-living-condition raters, National Guard-affiliated apps) and found 64% contain third-party SDKs from foreign countries, with roughly 1-in-8 to 1-in-14 apps (reporting varies) carrying code tied directly to China or Russia — including at least 12 apps embedding Huawei's mobile framework and others using the Russian ad service Yandex; no active exfiltration was observed, but researchers warn the dormant SDK code is an exploitable backchannel. A 21-year-old allegedly stole $220K in crypto by hiding malware in Steam games — and got caught because he spent it on Uber Eats. - https://www.pcmag.com/news/fbi-traces-malware-infected-steam-games-to-21-year-old-in-florida The FBI arrested Florida's Zyaire Dontaevious Zamarion Wilkins for allegedly running eight malware-laced Steam games (including BlockBlasters and PirateFi) between May 2024–Feb 2026, infecting ~8,000 devices and draining ~80 crypto wallets for at least $220,000 — including $35,000 stolen from a streamer's cancer-treatment fundraiser; investigators cracked the case by tracing stolen Bitcoin to 150+ Bitrefill gift cards mostly spent on Uber Eats orders tied to his home and university email address. Thrillist crowned Doritos Nacho Cheese the single greatest snack of all time, edging out Oreos and Pringles for the top spot. - https://www.thrillist.com/eat/nation/best-snack-foods-chips-candy-ranking The top five, in order: Doritos (Nacho Cheese, specifically) at #1, Oreos (Double Stuf gets the nod) at #2, Pringles at #3, Reese's Peanut Butter Cups at #4, and Goldfish rounding out the top five; other notable placements include Cheez-Its at #8, M&Ms at #7, Cheetos (the curls, not puffs) at #6, and Lay's Original topping the chip-specific competition at #12. Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Glenn - https://www.linkedin.com/in/glennmedina/ Ben - https://www.linkedin.com/in/benjamincorll/
If malware has you ready to give up and buy a new computer, don't. I'll explain why your old one can be completely restored to a malware-free state, using steps to wipe out even the worst infections without spending a dime on new hardware.
In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.Send us Fan MailSupport the show
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com
Was, wenn die wichtigste Frage nach einem Börsenhalbjahr nicht lautet "Welche Aktie lief am besten?", sondern "Welche Entscheidungen waren richtig?" Genau darum geht es in unserem vierten gemeinsamen Summer Special mit Finanzjournalist Clemens Faustenhammer: kein Ranking aus Gewinnern und Verlierern, sondern Prozess statt Prognose. Ich erzähle, warum ich trotz erwarteter Korrektur mein Depot konsequent umgebaut habe, wieso mein ETF-Portfolio mit rund 16,5 % im Plus die größte Überraschung des Halbjahres war und welche Rolle UnitedHealth, CVS Health und Fastenal dabei gespielt haben.Clemens teilt seine eigene Sicht auf ein Halbjahr voller Überraschungen, wir sprechen über Zinseszins und Haltestrategien, den Wandel vom klassischen Finanzblog zu Substack und darüber, wie Profi-Investoren wie Terry Smith ihre Strategie anpassen. ⏱️ KAPITEL0:00 Begrüßung und Einleitung zum Summer Special3:15 IBM & die Marktkorrektur im Juli 20266:45 Depotqualität statt Markttiming10:20 Zinseszins-Strategie: Clemens über Haltedauer14:50 (Teil-)Verkauf von AT&T und Stanley Black & Decker19:30 KI als Werkzeug für die Aktienanalyse24:10 Finanzblogs vs. Substack: Wandel im Finanzjournalismus29:00 Terry Smith & der Strategiewechsel bei Profi-Investoren34:15 SaaS-Aktien im KI-Hype: Zukunftsaussichten39:00 Abspaltungen und M&A: Aktuelle Trends43:45 Einzelaktien vs. Themen-ETFs im Performance-Check48:30 Südkorea-Volatilität und Samsung-Spekulationen53:20 Zoetis: Fehleranalyse einer schwierigen Position58:00 US-Konsumschwäche: Tractor Supply im Fokus1:02:45 Erfolge mit Corning, Broadcom, Cisco und Fastenal1:06:50 Ausblick: Unser Fokus fürs zweite Halbjahr 20261:09:30 Fazit: Zufriedenheit statt Markt schlagen1:11:12 Outro
In this episode of Robots and Red Tape, our host Nick Schutt sits down with Varun Badhwar, Founder & CEO of Endor Labs, to unpack the security implications of the AI coding explosion.Varun shares why this wave feels fundamentally different from the cloud shift he saw with RedLock/Prisma Cloud, how AI agents have turned 20–30 million developers into 200–300 million potential coders, and why we're now generating 100x–1000x more code—much of it carrying the same insecure patterns the models learned from open source.They dig into:-The shift from code generation as the bottleneck to verification, quality, scale, and security -Why even frontier models produce only ~20% secure code (per Endor's CMU/Columbia benchmark)-Democratization of cyber warfare: attacks that once took years now take hours-Open-source realities—80% of software, average 77 transitive dependencies, low maintainer response rates, and intentional malware campaigns-How Endor Labs embeds security oversight directly into agentic workflows so fixes happen at assembly time, not after shipping-Practical paths for large enterprises sitting on millions of findings to burn down real risk without bankrupting themselves on pure-AI token costsPodcast: Robots and Red Tape | Host: Nick Schutt | Channel: @RobotsandRedTapeAI#RobotsAndRedTape #Ai #Cybersecurity #SoftwareSupplyChain #AppSec #OpenSourceSecurity #AgenticAI #AICoding #DevSecOps #EndorLabs #TechLeadership #EnterpriseAI #CodeSecurity #AISecurity #SupplyChainSecurity
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.
Chris and Hector break down a critical WordPress vulnerability discovered with AI, the Steam malware campaign that stole cryptocurrency from gamers, Madison Square Garden's secret facial recognition database, AI voice cloning scams targeting families, leaked evidence of AI music training on copyrighted songs, and the White House employee accused of profiting from prediction markets. They also discuss SafeHill's latest work, insider threats, and why today's biggest cyber risks often begin with simple social engineering. Join our Patreon for weekly bonus episodes: https://www.patreon.com/c/hackerandthefed Send HATF your questions at questions@hackerandthefed.com
Top Headlines: Group-IB | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels: https://www.group-ib.com/blog/hollowgraph-microsoft-365/ The Hacker News | New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html Elastic | New North Korean campaign uses fake coding interviews to steal developer credentials: https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Island.io | AgentBaiting: How Fake AI Skills Deliver Malware at Scale: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/