Podcasts about Malware

  • 1,801PODCASTS
  • 7,255EPISODES
  • 38mAVG DURATION
  • 1DAILY NEW EPISODE
  • Jul 21, 2026LATEST
Malware

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Malware

Show all podcasts related to malware

Latest podcast episodes about Malware

Computer Corner (5DRadio.com)
Computer Corner July 18, 2026

Computer Corner (5DRadio.com)

Play Episode Listen Later Jul 18, 2026


Hosts: Gene MitchellAir date: July 18, 2026 Topic: Organic Maps, Contactless Payment Problems, Google is using your Photos,and Malware that destroys PCs

Cyber Crime Junkies
Is AI The Ultimate TRUTH Machine?

Cyber Crime Junkies

Play Episode Listen Later Jul 16, 2026 83:58


Panel with Dr Sergio Sanchez and Inventor Mike Acerra on how far AI goes to render truth and become a truth machine.Discover the truth about AI and its potential to be a truth machine. In this video, we delve into the capabilities and limitations of artificial intelligence in determining what is true and what is not. CHAPTERS00:00 Welcome to Cyber Crime Junkies + Guest Introductions02:00 Anthropic's Secret AI Mythos Finds Decade-Old Vulnerabilities04:30 How AI Is Finding Security Holes at Scale in Small Businesses06:30 New Books: Moving Target, The God Prompt, and Future Visions09:00 What American Education Is Getting Wrong11:30 Why Forgetting History Destroys Countries14:00 Nixon, the Deep State, and Political Accountability17:00 Property Taxes, Home Ownership, and the Banking Lie20:00 Tax Season Stress and Why Big Refunds Are a Bad Sign23:00 Flat Tax, the IRS, and Why the System Is Built to Confuse You26:00 The Knights Templar Invented Modern Banking29:00 AI as a Truth Machine Against Political Propaganda32:00 How Kennedy Beat Nixon on TV but Lost on Radio37:00 Hack or Hype: Employee Security Risks After Termination40:00 Hack or Hype: The Kaseya Supply Chain Ransomware Attack43:00 Hack or Hype: Does Cyber Insurance Actually Pay Out49:00 What SMBs Get Wrong When Applying for Cyber Insurance52:00 Windows Defender, Malware, and Layers of Endpoint Security Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.True crime enters our homes and businesses daily. Learn from actual people who fight it daily and show you how in a thriller story. The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com   Support the showNew Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14.Moving Target: The Obedient Machine drops April 21.Book 3 -- Ghost and the Machine -- out soon!

Cyber Security Today
ShareFile explained, healthcare in critical cyber condition and click fix tops malware charts

Cyber Security Today

Play Episode Listen Later Jul 15, 2026 13:57


ShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware.  David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity path traversal flaw in Storage Zone Controller 5.x/6.x with patches available (5.12.5 and 6.0.2) and no evidence of prior exploitation. Microsoft's analysis of a year of ShinyHunters activity compromising corporate Salesforce environments by abusing trust via OAuth (IT-support phone cons, vendor token theft such as Salesloft/Drift, and misconfigured guest access), prompting new monitoring tooling. A Fortified Health Security report finding healthcare fixed only 6% of identified risks in H1 2026 amid surging vulnerabilities, third-party risk, and weak identity hygiene. ReversingLabs and ReliaQuest research showing ClickFix social-engineering is now a leading malware delivery method; and Telstra's nationwide outage traced to an obsolete time server hit by a GPS rollover bug, disrupting Triple Zero calls and prompting Senate scrutiny. 00:00 Sponsor NordLayer 00:37 Headlines Overview 01:06 ShareFile Patch Explained 03:25 Salesforce OAuth Break Ins 06:01 Hospitals Drowning in Risks 08:24 ClickFix Malware Surge 11:13 Telstra Time Server Outage 12:32 Wrap Up and Sign Off

Decipher Security Podcast
Industrial Cybersecurity and Malware Archaeology with Lesley Carhart

Decipher Security Podcast

Play Episode Listen Later Jul 14, 2026 36:11


Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident response in ICS networks, how ancient malware can cause trouble for years on end, and why we need more ICS security engineers desperately.

CuriosITy
Kwh la 1 Euro, Nvidia în România, Dacia Striker e Beton, OpenAI se predă! Malware AI #CURIOSITY 334

CuriosITy

Play Episode Listen Later Jul 11, 2026 128:08


#curiosity #technews #podcast   Vrei un site mișto: https://caravan.ro/pages/creare-magazin-shopify-fastrackhttps://caravan.ro/pages/creare-magazin-shopify-fastrack Magazinul nostru - https://gb.ro/ Pasionat de sport? - https://winwin.fit/ Newsletter - UPDATE YOU - https://georgebuhnici.substack.com/ Hai pe Telegram - https://t.me/s/buhnici Cold Wallet Pentru Crypto - https://gb.ro/ledger-nano-s-plus/   Devino membru în comunitatea Buhnici.ro -  https://www.youtube.com/channel/UCNz5n8PoSGYSwkOH_SMnl2A/join Urmărește-mă cu @gbuhnici pe Instagram, Facebook, Twitter, TikTok-@georgebuhnici   Desfășurătorul Emisiunii / Chapters: 0:00:00 - Secretul din spuma de cappuccino 0:01:12 - De ce să cumperi doar hardware de firmă? 0:02:04 - Componente PC la jumătate de preț! 0:02:48 - Upgrade pe OLX: Prețuri absurde la memorii RAM 0:04:20 - Honor Magic V6 la 2000€! Vin scumpirile de la Apple și Samsung 0:05:46 - Războiul memoriilor: Producătorii chinezi vs. Cartelul RAM 0:08:43 - Samsung a atins 1 trilion $! Din ce se fac banii în tech? 0:10:54 - Ecrane pliabile mai ieftine: BOE cucerește piața 0:13:43 - De ce amână Apple noul iPhone Ultra Fold? 0:15:02 - Boom-ul reparațiilor: Viață nouă pentru roboți și scule 0:16:53 - Capcana ascunsă din uscătoarele de haine noi 0:21:02 - Deep dive în ventilație și haterii de pe YouTube 0:24:00 - Aerul poluat din orașe și problemele respiratorii 0:26:51 - Review Honor Magic V6: Baterii cu silicon și noul NPU 0:29:40 - Procesoarele Intel în 2026: Merită upgrade-ul? 0:30:55 - Goana după Mac Studio pe eBay: AI rulat local 0:33:49 - Zahărul ascuns din batoanele proteice „sănătoase” 0:37:30 - WINWIN.FIT 0:41:16 - GB.RO 0:42:42 - CARAVAN..RO 0:45:43 - Jucătorii belgieni îl trolează pe Trump + Retragerea lui Ronaldo 0:47:47 - Schadenfreude: De ce vrem să-i vedem pe marii sportivi căzând? 0:48:26 - Neil the Seal: Foca de o tonă care face ravagii în Tasmania 0:50:49 - Răzbunarea supremă: Hoți împachetați în scotch! 0:51:38 - Easter Egg în Starlink: Marte e declarată planetă liberă 0:55:40 - Fetița care hipnotizează animalele vs. Captură record de cannabis 0:58:43 - Nvidia în România? Centrele de date din Pipera 1:01:52 - Curentul se scumpește: kW-ul ajunge la 1€? 1:03:07 - Câinii de stână pe Via Transilvanica: Ghid de supraviețuire 1:05:28 - Voluntariat la stână pentru un reset mental în natură 1:09:37 - Exodul tinerilor și economia bazată pe barter de la sat 1:09:54 - Tensiuni în Iran și scumpirea carburanților peste vară 1:10:59 - Criza gazelor în Europa: Facturi uriașe la iarnă? 1:12:38 - Cozi kilometrice la benzină în Rusia 1:13:31 - Ucraina va produce rachete Patriot sub licență 1:14:13 - Tepe mari cu deepfake în Google News: Isărescu și Gâdea 1:17:03 - Primul atac ransomware lansat 100% de un agent AI 1:20:32 - OpenAI și Nvidia bat palma + Noul AI open-source Nemotron 1:22:01 - De ce întârzie Gemini 3.5 Pro? Probleme la Google 1:23:01 - OpenAI lansează GPT 5.6: Versiunile Sol, Tera și Luna 1:24:55 - Întâlnirea G7+3: Sam Altman vrea reglementare pentru AI 1:25:38 - OpenAI oferă 5% din companie gratuit guvernului SUA! 1:30:46 - Mafia, sinecurile și corupția din administrația publică 1:33:02 - Campusul European de AI și succesul DataBricks 1:34:41 - De ce s-a scumpit motorina de la 1 iulie? 1:35:25 - PPC lansează tariful variabil: Trading de energie pentru prosumatori 1:37:38 - Record istoric de stocare în SUA: 9,7 GW în baterii 1:39:54 - Statul român eșuează: Subvenții de pomană în loc de baterii 1:42:47 - Cursa roboților umanoizi: Unitree R1 a scăzut la 4900$ 1:44:44 - Ce se întâmplă cu corpul și creierul în spațiu? 1:47:09 - Explorarea spațiului prin teleprezență și Quantum 1:48:57 - Biologie sintetică, microbiomul și depresia 1:53:26 - Tesla FSD se amână în Europa până în 2027 1:54:05 - Noua Dacia Striker: Design superb și accesorii YouClip 1:57:50 - Recomandări: Filmul Reagan și arhiva culturală TVR 2:03:11 - Sănătatea mintală la bărbați și importanța ierbii naturale 2:06:18 - Apel pentru membri: Facem curățenie în camera tehnică!

Canard PC
[SCROLL NEWS #200] La der, avec Kocobé et Noël Malware

Canard PC

Play Episode Listen Later Jul 10, 2026 108:32


https://youtu.be/XPA2l1q-CLk Abonnez-vous et soutenez cette chaîne : https://fr.ulule.com/canardpc/Tous nos magazines et nos offres d'abonnement : https://boutique.canardpc.com/Notre édition web sur abonnement : https://www.canardpc.com/Notre newsletter sur les nouvelles technologies : lepavenumerique.substack.com/about ► Twitch : https://www.twitch.tv/canardpc► Bluesky : https://bsky.app/profile/canardpc.com► X : https://twitter.com/Canardpcredac► Discord : https://discord.gg/nJJFe9r► Facebook : https://www.facebook.com/CanardPCmagazine► Instagram : https://www.instagram.com/canardpc/► Tiktok : @canardpcredac Tous droits réservés Presse Non-Stop / Canard PC. Aucun youtubeur n'a été maltraité pendant le tournage.

FIAPCAST
FIAP DECODE #128: Fim das mídias físicas, Uber Mulher e Claude Fable 5

FIAPCAST

Play Episode Listen Later Jul 10, 2026 23:49


Aperte o play e atualize seu sistema! Neste episódio do FIAP Decode, André David recebe Fernanda Souza e Bruno Germano para decodificar o fim das mídias físicas do PlayStation, a expansão do Uber Mulher para todo o Brasil e a liberação do Claude Fable 5 após proibição.   Decodifique novas conexões  - André David: LinkedIn e Instagram     - Fernanda Souza: LinkedIn e Instagram   - Bruno Germano: LinkedIn e Instagram Conheça os projetos dos nossos decoders: O Bruno Germano | YouTube NOTÍCIAS: Playstation anuncia que vai encerrar a produção de mídias físicas em 2028    Uber Mulher é liberado para passageiras de todo o Brasil    ChocoPoc, o Malware que ataca os próprios desenvolvedores   Anthropic libera Claude Fable 5 após governo dos EUA retirar proibição    WinRAR agradece aos usuários que compraram o software   

DoctorApple NEWS
DoctorApple NEWS 346

DoctorApple NEWS

Play Episode Listen Later Jul 10, 2026 17:36


10/07/26 - G4 Cube, Apple nas Escolas, AI em Automação, Malware disfarçado, iPhone Dobrável, Bateria maior nos iPhones, HD encriptados, Data de lançamento iPhone 18, Processo Meta, Processo UE, Chips da apple made USA, Mac cresce 10%,https://www.doctorapple.com.br

Breakfast with Refilwe Moloto
Cyber sense, making sense of scams: The download trap, don't trust the first link

Breakfast with Refilwe Moloto

Play Episode Listen Later Jul 10, 2026 5:53 Transcription Available


This week's Cyber Sense feature focuses on a growing cyber threat targeting people downloading software and AI tools online. John Maytham speaks to Boikokobetso Makhetloane, also known online as Mr Fingerz, a cybersecurity expert, educator, trainer, and TikTok content creator, about how cybercriminals are creating fake websites and even buying sponsored Google advertisements to trick users into downloading malware instead of legitimate software. The discussion explores why AI platforms like Claude are being used as bait, how these scams are evolving, and the simple checks everyone should make before downloading apps or software from the internet. Good Morning Cape Town with Lester Kiewit is a podcast of the CapeTalk breakfast show. This programme is your authentic Cape Town wake-up call. Good Morning Cape Town with Lester Kiewit is informative, enlightening and accessible. The team’s ability to spot & share relevant and unusual stories make the programme inclusive and thought-provoking. Don’t miss the popular World View feature at 7:45am daily. Listen out for #LesterInYourLounge which is an outside broadcast – from the home of a listener in a different part of Cape Town - on the first Wednesday of every month. This show introduces you to interesting Capetonians as well as their favourite communities, habits, local personalities and neighbourhood news. Thank you for listening to a podcast from Good Morning Cape Town with Lester Kiewit. Listen live on Primedia+ weekdays between 06:00 and 09:00 (SA Time) to Good Morning CapeTalk with Lester Kiewit broadcast on CapeTalk https://buff.ly/NnFM3Nk For more from the show go to https://buff.ly/xGkqLbT or find all the catch-up podcasts here https://buff.ly/f9Eeb7i Subscribe to the CapeTalk Daily and Weekly Newsletters https://buff.ly/sbvVZD5 Follow us on social media CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalkSee omnystudio.com/listener for privacy information.

Cyber Morning Call
1042 - UAT-7810 amplia arsenal de malware e expande ORB network

Cyber Morning Call

Play Episode Listen Later Jul 8, 2026 10:13


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORT A DE ENTRADA DO ATACANTEUAT-7810 continues building ORB networks using new malwareAn Introduction to Operational Relay Box (ORB) Networks - Unpatched, Forgotten, and ObscuredIonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File InflationThe ‘Ghost' in the Database: Recovering Active ADFS Signing Keys via Machine DPAPIOne Email Closer to the Edge: UNK_MassTraction & the Physics of ExploitationCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Le monde de la cyber
[Tour de France cyber #7] Les collectivités territoriales face au risque cyber - La Farlède

Le monde de la cyber

Play Episode Listen Later Jul 7, 2026 28:54


☀️ Épisode enregistré à La Farlède, dans le Var, en marge d'une journée immersive co-organisée avec le CNFPT (Centre National de la Fonction Publique Territoriale) dédiée à la cybersécurité des collectivités.Rançongiciels, fuites de données, usurpation d'identité : les cyberattaques visant les collectivités se multiplient et font régulièrement la une. Derrière chaque incident, ce sont des services publics paralysés, des données d'administrés exposées, et une confiance envers nos institutions qui s'effrite. Et pourtant, un message ressort avec force de cet épisode : la cybersécurité n'est ni l'affaire exclusive des informaticiens, ni le problème des seules grandes métropoles.Pour cette étape du Tour de France de la cyber, je vous emmène dans le sud de la France dans le Var à La Farlède, une petite commune qui a eu à coeur d'organiser une journée dédiée à la cybersécurité des collectivités territoriales du département. J'y ai rencontré 3 acteurs qui portent le sujet :Antoine Parmentier, responsable du CSIRT Urgence Cyber Région Sud, Lionel Pérès, DGS de Vaison-la-Romaine et auteur du livre « Cyberattaque : assurer la continuité des services publics locaux », et Lilian Cardona, DGS de La Farlède.

Crying Out Cloud
Autonomous AI Malware, Threat Actor Startups & Beating Burnout with John Hammond

Crying Out Cloud

Play Episode Listen Later Jul 2, 2026 29:02


AI-Powered Malware and the Future of Threat HuntingOn this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hammond to unpack the reality of autonomous AI hacking and why cybercriminals are operating like Fortune 500 startups.1. Why modern ransomware groups have sales teams, HR, and go-to-market strategies.2. How autonomous AI agents are finding zero-days while researchers sleep.3. Glimpsing the future of non-deterministic, AI-driven command and control (C2) servers.4. Real talk on incident response burnout and why the "always-on" hustle is breaking defenders.

Cyber Security Today
US puts $10m bounty on Russian hackers, new phish hunts hotels, Supreme Court reins in geofencing

Cyber Security Today

Play Episode Listen Later Jul 1, 2026 11:13


US Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs.  The episode covers the US State Department's up to $10 million reward for information on Russia-linked hacker groups UNC 5792 and UNC 4221 tied to phishing campaigns that compromise Signal and WhatsApp accounts by stealing Signal backup recovery keys.  It also explains a US Supreme Court 6–3 ruling limiting geofence warrants by recognizing Fourth Amendment privacy protections for phone location data and requiring probable cause and narrower requests.  Mozilla ODIN researchers demonstrate a proof of concept where a clean GitHub repo can cause AI coding agents to run an init command that executes attacker-controlled code via DNS and opens a reverse shell. A hotel-focused phishing campaign using Calendly and Google redirects delivers ZIP files that install the Tonrat implant through PowerShell and a user-space Node.js runtime.  Finally, Canada's CSE says it disrupted infrastructure used by 10 major ransomware groups and reports incident volumes rising nearly 26% year over year. 00:24 Top Headlines Rundown 00:54 10 Million Bounty Russian Hackers 02:42 Supreme Court Limits Geofence Warrants 03:56 AI Coding Agent Repo Trap 05:31 Listener Thanks And Reviews 05:51 Hotel Front Desk Phishing Attack 08:01 Canada Disrupts Ransomware Gangs 09:45 Closing And Sign Off

RunAs Radio
AI-Accelerated Supply Chain Attacks with Mackenzie Jackson

RunAs Radio

Play Episode Listen Later Jul 1, 2026 36:45


How are supply-chain attacks evolving? Richard chats with Mackenzie Jackson about his work helping companies protect their software supply chains from malware attacks. Mackenzie discusses the vulnerability of developers to attacks, since their accounts are often highly privileged and invariably contain access to exploitable secrets. The conversation digs into the challenges of securing various code distribution mechanisms like npm and how you can protect your organization - starting with, don't install packages as soon as they are released! There are effective tools for detecting malware in code, but they take time. Waiting 48 hours can eliminate a lot of risk! Links Aikido Software Trivy Claude Mythos OpenClaw Shai-Hulud Guidance ClawHub Open Source Malware Windows Update Management Recorded June 15, 2026

The Tech Authority Podcast
Audio Month Day 28 - MacOS Gaslight Malware

The Tech Authority Podcast

Play Episode Listen Later Jun 28, 2026 1:49


Audio Month Day 28 - MacOS Gaslight Malware

Cyber Security Today
Malware gaslights AI

Cyber Security Today

Play Episode Listen Later Jun 26, 2026 10:56


Mac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating it via a Telegram bot.   Microsoft and Europol disrupted the Amadey and SteelC info-stealer ecosystem by seizing/shuttering infrastructure after identifying 140,000 infections in early May and over 200 command-and-control domains and IPs, as part of Operation Endgame.   OpenAI announced "Patch the Planet," a joint effort with Trail of Bits and HackerOne to help open-source projects find and fix bugs amid AI-generated report flooding, alongside a new GPT 5.5 Cyber benchmark result.    New FortiBleed reporting underscores that the campaign relies on credential reuse against exposed FortiGate devices and may require rotating far more than just firewall passwords.   00:00 Sponsor Message 00:25 Headlines Overview 00:55 Mac Malware Gaslight 02:00 Telegram C2 And Stealer 02:50 Info Stealer Takedown 04:08 Operation Endgame Impact 04:47 OpenAI Patch The Planet 06:16 AI Models And Export Rules 07:08 FortiBleed Recap 08:13 Inside The FortiGate 08:59 Rotate Credentials Now 09:26 Closing And Sign Off

HIPAA Critical
Attackers impersonate ChatGPT, Claude, and DeepSeek to deliver malware

HIPAA Critical

Play Episode Listen Later Jun 26, 2026 4:25 Transcription Available


In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.

Smart Software with SmartLogic
The State of the Open Internet with Mallory Knodel

Smart Software with SmartLogic

Play Episode Listen Later Jun 25, 2026 65:04


In this episode of Elixir Wizards, Charles Suggs and Emma Whamond are joined by Mallory Knodel, executive director and founder of the Social Web Foundation, to talk about internet governance, open standards, and the future of the social web. Mallory shares how her work as an activist, systems administrator, and public interest technologist led her into the organizations and working groups that shape how the internet functions, including the IETF, W3C, ICANN, and ITU. The conversation explores how the internet shifted from a collection of open protocols toward a small number of dominant platforms, and what that centralization means for users, developers, and independent service providers. Mallory explains how decisions made at the protocol level can affect everything from email deliverability to identity, data portability, trust and safety, and the ability to move between platforms. We also discuss the Social Web Foundation, ActivityPub, the Fediverse, and the idea of building a more multipolar social web. Mallory also looks at what happens when AI agents, automated accounts, and algorithmic feeds enter open social ecosystems. She shares her perspective on privacy, usability, encrypted messaging, and designing technology around user needs rather than engagement alone. Key Topics Discussed What it means to be a public interest technologist How internet governance affects everyday software development The role of global internet standards organizations How the IETF and W3C develop technical standards Corporate influence inside internet governance and standards bodies The internet's shift from protocols to centralized platforms Email deliverability and the hidden costs of centralization How platform control affects identity and user autonomy Why data portability remains difficult across social platforms The mission behind the Social Web Foundation How the Fediverse connects independent social platforms ActivityPub and Activity Streams as open web protocols AT Protocol, an alternative to ActivityPub How federated servers exchange content and user activity Why a multipolar web differs from decentralization What Meta's ActivityPub adoption means for federation The embrace, extend, extinguish risk for open protocols Discoverability challenges across federated social networks Trust and safety for smaller platform operators How protocol decisions can affect human rights AI agents entering open social web ecosystems Whether federated platforms should block automated crawlers Designing algorithmic feeds around values and user choice Privacy-first principles for developers building social software Encrypted direct messaging for the open social web Elixir projects building across the Fediverse ecosystem Links Mentioned: Mallory's Website https://malloryknodel.net/ Internet Protocol (IP) https://en.wikipedia.org/wiki/Internet_Protocol Internet Engineering Task Force (IETF) https://www.ietf.org/ International Communication Union https://www.itu.int/en/ Internet Corporation for Assigned Names and Numbers (ICANN) https://www.icann.org/ World Wide Web Consortium (W3C) https://www.w3.org/ Huawei https://www.huawei.com/en/ Cisco https://www.cisco.com/ Messaging, Malware and Mobile Anti-Abuse Working Group (M³AAWG) https://www.m3aawg.org/ Social Web Foundation https://socialwebfoundation.org/ ActivityPub https://www.w3.org/TR/activitypub/ AT Protocol https://atproto.com/ MeWe Decentralized Social Networking Protocol (DNSP) https://dsnp.org/about/MeWe-use-case.html BlueSky https://bsky.app/ Mastodon https://joinmastodon.org/ Internet Society https://www.internetsociety.org/ Fediverse https://fediverse.party/ NCSA Mosaic Browser https://www.ncsa.illinois.edu/research/project-highlights/ncsa-mosaic/ Webring https://en.wikipedia.org/wiki/Webring https://tags.pub/ Elixir projects: Pleroma https://pleroma.social/ Akkoma https://akkoma.social/ Bonfire Networks https://bonfirenetworks.org/ Mobilizon https://mobilizon.org/

ai messaging cisco huawei mastodon malware elixir itu digital identity technology policy mewe online privacy icann w3c digital rights internet society open web internet freedom open internet ietf activitypub internet governance pleroma public interest technology encrypted messaging internet infrastructure assigned names internet corporation data portability numbers icann world wide web consortium w3c internet protocol ip
TechLinked
Steam Workshop Malware, ChatGPT Market Share Slips, Snap AR Glasses + more!

TechLinked

Play Episode Listen Later Jun 18, 2026 9:26


Timestamps: 0:00 Steam Workshop Malware 1:25 ChatGPT Market Share Slips 2:40 Snap AR Glasses 5:00 QUICK BITS INTRO 5:14 Microsoft Surface Announcement 5:50 Samsung Changes Product Testing 6:25 Commodore Flip Phone 6:56 Sandisk's 8TB PS5 SSD 7:41 Nvidia Reveals Self Taught Robots NEWS SOURCES: https://lmg.gg/Pj2Lf Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Headlines
Athena coalition, Estonia's quarantine, Arch hit with malware

Cyber Security Headlines

Play Episode Listen Later Jun 17, 2026 7:54


Athena coalition looks to secure open source Estonia to quarantine Russian email domains Malicious package wave hits Arch Linux Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/  Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.  

iBUG Buzz
#739 June 15, 2026

iBUG Buzz

Play Episode Listen Later Jun 17, 2026 118:27


Facilitator: MariaTopics:  Emoji not working; Where to put Zoom link; Where is the Send Later in email messages;  Focus jumping around;  easiest way to Restart iphone;  Facebook auto-scroll stops at bottom;  Tracking sleep on watch;  Accessible universal remote;  Facebook auto-starts reels;   Malware in emails;  Safety with Uber rides;  Ringing both IOS devices;  spreadsheets; Looking at Safari while on a call;  FaceTime as default calling app; Using WhatsApp;iByte:  Location Based Reminder

CPA Australia Podcast
Tax Time 2026: How ATO protects your financial data

CPA Australia Podcast

Play Episode Listen Later Jun 16, 2026 17:07


Cyber fraud is not going to stop overnight.  It will continue to become more sophisticated and pervasive as time goes on.  Which means this third episode in the tax time 2026 series is even more relevant today as it focuses on fraud risks and how you can protect your financial data.  With guest expertise from Jade Hawkins, assistant commissioner in the ATO's fraud and criminal behaviours business line, and hosted by CPA Australia's tax lead Jenny Wong, deep dive into the ATO's counter-fraud program, emerging scam trends and the practical tools now available to strengthen digital security across the tax system ahead of tax time 2026.  Additionally, explore new features in the ATO app that give taxpayers more control over their accounts to the steps agents can take to protect their clients and their own practices from new threats.  In this episode, you will also gain expert information on:  why identity theft and frauds are becoming more sophisticated  what tax agents can do to protect clients and their own practices  the most common fraud and cyber-attack techniques targeting the sector  why strong myID settings and multifactor authentication matter  how phishing, malware and credential stuffing attacks are evolving  what happens when a taxpayer's account is compromised.  Tune in now.  Host: Jenny Wong, tax lead, CPA Australia  Guest: Jade Hawkins, assistant commissioner in the ATO's fraud and criminal behaviours business line  For more, head to CPA Australia's tax time tools and resources page.  Additionally, you can head to the ATO website or download the ATO app.  The ATO also has online services and you can go on the ATO website to verify or report a scam or learn how to stay scam safe.  And you can phone the ATO on 1800 008 540.  Loving this episode?  Listen to more With Interest episodes and other CPA Australia podcasts on YouTube. https://www.youtube.com/@CPAaustralia/podcasts  And don't forget to click subscribe to the channel for a wide range of content that will help your career.  CPA Australia publishes four podcasts, providing commentary and thought leadership across business, finance and accounting:  With Interest https://www.cpaaustralia.com.au/tools-and-resources/podcasts/with-interest  INTHEBLACK https://www.cpaaustralia.com.au/tools-and-resources/podcasts/intheblack  INTHEBLACK Out Loud https://www.cpaaustralia.com.au/tools-and-resources/podcasts/intheblack-outloud  Excel Tips https://www.cpaaustralia.com.au/tools-and-resources/podcasts/excel-tips  Search for them in your podcast platform. Email the podcast team at podcasts@cpaaustralia.com.au  Chapters:  00:00 Fraud Prevention Urgency: ATO, Tax Agents and Evolving Scam Risks 00:22 Intro - Jenny Wong - Tax Time 2026 00:39 Jade Hawkins (ATO) on the Counter Fraud Program Overview 01:08 What Is the ATO Counter Fraud Program? $187M Investment Explained 01:17 Proactive Fraud Detection: Real-Time Data, Analytics and System Protections (ATO) 03:20 ATO App Security Updates: How Taxpayers Can Stay Safe with myID 03:30 Real-Time Alerts, Account Locking and Fraud Prevention via ATO App 04:01 Case Study: Stopping Tax Refund Fraud Using ATO App Notifications 05:49 ATO "Verify Call" Feature: Detecting Scam Calls and Social Engineering 06:14 ATO App Tools for Taxpayers: myDeductions, Pre-Fill Data, Refund Tracking 07:25 How Tax Agents Can Protect Clients: myID, ATO App and Fraud Awareness 08:21 Cybersecurity Best Practices: MFA, Strong Passphrases, Software Updates 10:23 ATO Resources and Training: Tax Fraud Hub and Cybersecurity Modules 11:03 Current Scam Trends: PII Data Breaches and Identity Theft Risks (ATO Insights) 11:40 Fraud Targeting Tax Agents: Phishing, Malware and Credential Stuffing 13:48 What Happens If a Taxpayer Is Compromised? ATO Safeguards Explained 15:54 Final Advice from Jade Hawkins: Vigilance, ATO App and Strong Access Controls 16:23 Conclusion: Tax Time 2026 Fraud Risks and Key Takeaways for Agents 

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 259 - AI Support Goes Rogue, Silent Ransom, Loud Consequences, Apple's Password Reset Roulette, Nuking the Malware Scanner, UK's New Blackout Protocol

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Jun 15, 2026 46:56


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Meta confirms 20,225 Instagram accounts were hijacked after attackers exploited a bug in its AI-powered High Touch Support tool to reset passwords without verifying email ownership. https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/ The Silent Ransom Group is targeting U.S. law firms with fake IT help desk calls, moving from first contact to data exfiltration in hours and sending ransom demands within 30 minutes of leaving the network. https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/ Weil Gotshal reportedly paid $18–20 million to prevent hackers from publishing stolen client data after a Silent Ransom Group attack. https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/ Jones Day confirms a cyberattack that gave hackers access to client files, also attributed to the Silent Ransom Group campaign targeting BigLaw. https://www.legalcheek.com/2026/04/jones-day-confirms-cyber-attack-after-hackers-access-client-files/ Dark Reading's breakdown of how Silent Ransom Group's law firm extortion campaign operates at scale. https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks   Apple announces that iOS 27's Passwords app will use agentic AI to automatically detect and replace weak or compromised passwords in the background, no user effort required. https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/ https://www.macrumors.com/2026/06/08/apple-passwords-can-now-automatically-fix-passwords-with-agentic-ai/   Citizen Lab researcher John Scott-Railton flags a new attacker technique: malware developers are embedding nuclear and biological weapons text inside their spyware to deliberately trigger AI safety refusals, preventing LLM-based security tools from analyzing the malicious code — a real-world demonstration of how over-tuned safety guardrails create exploitable blind spots. https://x.com/jsrailton/status/2064661778978533571   UK Prime Minister Starmer gives Apple and Google a three-month deadline to install device-level software that detects and blocks explicit images on consumer hardware, with privacy advocates and Signal already calling the mandate a blueprint for mass surveillance. https://metro.co.uk/2026/06/08/phone-will-change-new-government-rules-explicit-images-28694073/   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Ben - https://www.linkedin.com/in/benjamincorll/

The Audit
Cyber News: Bug Bounty Fail, Open-Source Malware & Facebook SMB Phishing

The Audit

Play Episode Listen Later Jun 15, 2026 36:08 Transcription Available


An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most. The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use. 

Rabbit Hole Recap
RABBIT HOLE RECAP #413: BRAVE NEW WORLD

Rabbit Hole Recap

Play Episode Listen Later Jun 11, 2026 121:09


https://rhr.tv/stream Keonne Rodriguez (Samourai dev) updates on prison transfer & furlough request https://x.com/keonne/status/2063959631383179277 Bark Ark Protocol Launches on Bitcoin Mainnet https://blog.second.tech/bark-now-on-bitcoin-mainnet/ Second Introduces Noah and Arké Bitcoin Ark Wallets https://blog.second.tech/introducing-noah-and-arke/ Signal: UK Surveillance Is Not Safety https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf Mullvad explains UK spyware proposal: mandatory real-time scanning & blocking on all devices https://x.com/mullvadnet/status/2064342870937509988 SimpleX Network Consortium Governance and Foundation Overview https://simplexnetwork.org/consortium.html Pump.fun launches GO: bounty platform to pay anyone for any task https://x.com/pumpfun/status/2062557004829233504 Man tattoos forehead for $2,400 Pump.fun bounty (spells it wrong) https://x.com/discordiaclips/status/2063406281130398012 Strategy Announces Approval of STRC Semi-Monthly Dividends https://www.strategy.com/press/strategy-announces-approval-of-strc-semi-monthly-dividends_06-08-2026 Polymarket Cracks Down on VPN Users Amid Legal Pressure https://gizmodo.com/polymarket-cracks-down-on-vpn-users-as-legal-pressure-intensifies-in-dozens-of-countries-2000765379 Karpathy on Claude Fable 5: strong benchmarks but overly trigger-happy safeguards https://x.com/karpathy/status/2064409694761054332 Malware devs add WMD keywords to spyware to evade LLM scanners https://x.com/jsrailton/status/2064661778978533571 Anthropic Dario Pushes for Regulatory Moat https://darioamodei.com/post/policy-on-the-ai-exponential HRF Freedom Tech in Oslo: https://www.youtube.com/watch?v=QUcG_CJkT6A Dark Wisp Android v1.0.0 Adds Private Interactions, Tor Routing, and NIP-A3 Payments https://github.com/barrydeen/dark-wisp-android/releases/tag/v1.0.0 Kickstr World Cup Game https://kickstr.einundzwanzig.dev/games/7ea5d40f-be37-4895-94cd-2adaf53f45ad Bitaxe ESP-Miner v2.14.0 Release https://github.com/bitaxeorg/ESP-Miner/releases/tag/v2.14.0 Ulendo: borderless calling via Nostr + Bitcoin without local SIM cards https://x.com/codamw/status/2063340269785784526 Microsoft Patches Record 206 Security Flaws https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html Milei proposes AI framework with "non-human corporations" & zero regulation https://x.com/trajektoriepl/status/2062594306670535130 Cuba Poised for Largest U.S. Fuel Shipment Since Cold War Embargo https://financialpost.com/pmn/business-pmn/cuba-poised-for-biggest-us-fuel-shipment-since-cold-war-embargo 3:33 - Guess who's back 12:13 - Dashboard 19:13 - Keonne update 22:43 - Bark 34:33 - UK surveillance 41:03 - Noah & Arké 47:01 - Simple Network Consortium 53:13 - Pumpfun 57:38 - STRC semi-monthly 1:07:33 - Polymarket VPN crackdown 1:11:23 - Fable 1:24:43 - WMD LLM keyword bypass 1:30:38 - Anthropic is too good 1:33:08 - HRF Oslo 1:33:58 - HRF Story of the Week 1:35:23 - Boosts 1:37:33 - Software updates 1:49:03 - Milei AI 1:51:48 - Cuba fuel Shoutout to our sponsors: Coinkite https://coinkite.com/ Strike https://strike.me/ Stakwork https://stakwork.ai/ Salt of the Earth https://drinksote.com/rhr Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/marty Newsletter https://tftc.io/martys-bent/ Podcast https://tftc.io/podcasts/ Follow Odell: Nostr https://primal.net/odell Newsletter https://discreetlog.com/ Podcast https://citadeldispatch.com/

Landscape Business Course
Malware, New Industries & Home Services in 2035

Landscape Business Course

Play Episode Listen Later Jun 11, 2026 99:53


⛓️ SOFTWARE FOR HOME SERVICE BUSINESS: https://home.works

Cyber Security Headlines
Claude & Gemini malware, Mythos sneaky flaws, Instagram AI abuse

Cyber Security Headlines

Play Episode Listen Later Jun 9, 2026 7:40


Microsoft malware hits Claude and Gemini users Mythos can exploit new flaws in hours AI tool abuse behind Instagram hacks Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-gemini-malware-mythos-sneaky-flaws-instagram-ai-abuse/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call.   But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception.   We fight relentlessly to protect your business, brand, and people.   Doppel. Outpacing what's next in social engineering.   Learn more at doppel.com.

10 minutos con Sami
Apple resucita Siri, OpenAI mira a bolsa y GitHub limpia malware

10 minutos con Sami

Play Episode Listen Later Jun 9, 2026 6:19


Apple intenta resucitar Siri con IA contextual mientras OpenAI prepara su tercera fase y una posible salida a bolsa. Microsoft desactiva más de 70 repositorios en GitHub por malware roba credenciales, Nvidia quiere llevar agentes al PC con RTX Spark y una nueva plataforma criogénica de carburo de silicio apunta a controlar mejor la computación cuántica.Puedes seguirnos en YouTube en https://youtube.com/olivernabani y puedes unirte al Discord Mashain en https://olivernabani.com/discord

Security Squawk
The Biggest Cybersecurity Threat Isn't Malware Anymore | NYC Hospitals, Carnival & FBI Warning

Security Squawk

Play Episode Listen Later Jun 3, 2026 34:59


Three breaches. No malware. No zero-days. Just trust being exploited. This week on Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity incidents that reveal a growing reality: attackers are increasingly targeting people, vendors, and physical access instead of technology. NYC Health + Hospitals disclosed a breach affecting 1.8 million individuals after a third-party vendor compromise exposed sensitive patient information, including fingerprints. Carnival Corporation confirmed a cyberattack impacting nearly 6 million people after attackers used social engineering to gain access through an employee account. Meanwhile, the FBI is warning law firms about criminals posing as IT personnel, physically entering offices, deploying malicious USB devices, and stealing privileged client data. These attacks didn't begin with sophisticated malware or advanced exploits. They succeeded because trust was exploited. In this episode, we discuss: • The growing risk of third-party vendor breaches • Why biometric data theft creates permanent consequences • How social engineering continues to defeat security controls • The resurgence of physical intrusion attacks • What CEOs, business owners, IT leaders, and MSPs should be evaluating right now • Why many organizations may be defending the wrong attack surface If your cybersecurity strategy focuses only on networks, endpoints, and firewalls, this episode will challenge some assumptions. Support the show: https://buymeacoffee.com/securitysquawk Subscribe for weekly executive-level cybersecurity analysis focused on business impact, operational risk, and real-world consequences. #CyberSecurity #DataBreach #Carnival #NYCHealthAndHospitals #SocialEngineering #VendorRisk #LawFirmSecurity #CyberAttack #InformationSecurity #MSP #BusinessRisk #SecuritySquawk

The CyberWire
The bugs are piling up faster than the fixes.

The CyberWire

Play Episode Listen Later Jun 2, 2026 30:23


A federal watchdog questions NIST over its vulnerability database backlog. Google patches an Android zero-day. Citizen Lab exposes a powerful location-tracking platform. Malware hides commands in Steam comments. Researchers spot AI-assisted malware development. Attackers compromise Red Hat's npm namespace. DriveSurge spreads malware through ClickFix and fake updates. FreePBX patches a critical flaw. And Dashlane responds to a brute-force attack. Our guest is ⁠Laure Lydon⁠, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on digital health platforms. Meta's AI support bot proves a bit too eager to help. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Maria Varmazis speaks with ⁠Laure Lydon⁠, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on privacy, security, and trust in digital health platforms, especially in sensitive areas like women's health. This interview is part of our partnership with Infosecurity Europe. Selected Reading Inspector general finds NIST mistakes have made vulnerability database ineffective (The Record) Google fixes one actively exploited Android zero-day, 124 flaws (Bleeping Computer) Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech (The Citizen Lab) GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure (Security Affairs) Threat Actor Uses AI to Build EDR Evasion Tools (Infosecurity Magazine) Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets (Infosecurity Magazine) Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks (Bleeping Computer) Critical Hard-Coded Credentials Vulnerability in FreePBX User Control Panel (Beyond Machines) Dashlane password manager users locked out by brute force attacks (Bleeping Computer) Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Hacking Humans
Trusting the wrong package. [Only Malware in the Building]

Hacking Humans

Play Episode Listen Later Jun 2, 2026 46:54


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources:  ⁠ Shai-Hulud worm returns stronger and more automated than ever before⁠ ‘Mini Shai-Hulud' malware compromises hundreds of open-source packages in sprawling supply-chain attack⁠ What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

The Cybersecurity Defenders Podcast
"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach & CISA cPanel vulnerability / Intel Chat [#328]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jun 1, 2026 29:05


Originally recorded: Friday May 29, 2026In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026.Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting the “/mnt/user-data” directory.Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained franchise-related documents. SecurityWeek article Matt references.CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being actively exploited in the wild.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 28, 2026 6:04


Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024 Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/

The 404 Media Podcast
Millions of People Are Installing Malware on Their Partners' Phones

The 404 Media Podcast

Play Episode Listen Later May 25, 2026 49:33


This week Joseph speaks to Zack Whittaker, an editor at TechCrunch. Zack has been leading coverage into the spouseware or stalkerware industry. This is malware sold to ordinary people, which they then often install on their girlfriend's or someone else's phone. Zack talks about the crazy scope of this problem. Behind the stalkerware network spilling the private phone data of hundreds of thousands Spyzie stalkerware is spying on thousands of Android and iPhone users Stalkerware tag on TechCrunch This Week In Security Newsletter YouTube Version: https://youtu.be/BLb46310iLs Subscribe at 404media.co Learn more about your ad choices. Visit megaphone.fm/adchoices

HeroicStories
Can Malware Reach My External Drive?

HeroicStories

Play Episode Listen Later May 22, 2026 6:25


Can hackers really get to everything, including your external hard drive? I'll cover what malware can do and what you need to do before it happens to you.

Cyber Security Today
Windows 11 BitLocker Zero-Day, TeamPCP Malware Leak, Iran Gas Station Hacks | Cybersecurity Today

Cyber Security Today

Play Episode Listen Later May 20, 2026 13:10


A serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems.  Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security. David Shipley breaks down four major cybersecurity stories on Cybersecurity Today. First, a newly disclosed zero-day dubbed YellowKey reportedly defeats default Windows 11 BitLocker protection on systems using TPM-only encryption, giving attackers with physical access a path to unencrypted data through the Windows Recovery Environment. Microsoft is investigating, while security experts are urging stronger BitLocker configurations. The episode also examines the TeamPCP threat group's decision to release offensive tooling publicly, dramatically lowering the barrier for copycat supply-chain attacks. Researchers have already spotted malicious NPM packages borrowing similar techniques, including persistence mechanisms aimed at developer environments such as Visual Studio Code and Claude Code. David also looks at disturbing analysis of the FAST16 malware, which researchers believe was engineered to tamper with nuclear weapons simulation software including LS-DYNA and AutoDyn. And finally, U.S. officials reportedly suspect Iranian actors in cyberattacks targeting internet-exposed gas station automatic tank gauge systems, a reminder that weak operational technology security can quickly become a real-world infrastructure problem. 00:00 Sponsor Message 00:24 Headlines Overview 00:50 BitLocker Zero Day 03:32 TeamPCP Tools Leak 06:13 Copycat NPM Malware 06:50 Fast16 Nuclear Sabotage 08:37 Iran Gas Station Hacks 10:28 Hardening Critical Infrastructure 11:16 Wrap Up And Events 11:59 Sponsor Deep Dive #Cybersecurity #Windows11 #BitLocker #ZeroDay #TeamPCP #IranCyberAttack #SupplyChainAttack #CriticalInfrastructure #CyberSecurityToday

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 19, 2026 6:08


New Malware Libraries means New Signatures https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986 Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498 Microsoft Authenticator Update CVE-2026-41615 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615 ssh-keysign-pwn (CVE-2026-46333) Patches Released https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/

The Cybersecurity Defenders Podcast
"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign & AI-developed zero-day exploit / Intel Chat [#324]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 18, 2026 28:49


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Researchers have disclosed a new Linux local privilege escalation technique called “Dirty Frag,” which chains together two kernel vulnerabilities: CVE-2026-43284 in xfrm-ESP handling and CVE-2026-43500 in RxRPC.The breach affecting educational technology provider Instructure has raised broader concerns about the security dependencies schools have on third-party cloud platforms.Security researchers at Aikido are tracking a major expansion of the “Mini Shai-Hulud” malware campaign targeting the npm ecosystem.Google Threat Intelligence Group says threat actors are moving from experimental AI usage toward large-scale operational integration of generative models across the cyberattack lifecycle.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Unspoken Security
Stolen Credentials, Fake Hires, and the New Insider Threat

Unspoken Security

Play Episode Listen Later May 14, 2026 49:21 Transcription Available


In this episode of Unspoken Security, host AJ Nash sits down with Dan O'Day, Senior Consulting Director at Unit 42 by Palo Alto Networks. Dan shares key findings from the 2026 Global Incident Response Report, built from over 750 real-world cyber incidents, covering four major threat trends reshaping the security landscape.Dan breaks down how AI is compressing attack timelines at a dramatic rate. The fastest incidents now move from access to full impact in just 72 minutes, down from 285 minutes the year prior. Attackers are no longer breaking in. They are logging in, using stolen credentials, tokens, and API keys to move laterally and avoid detection. Identity is now the dominant attack surface, playing a material role in nearly 90% of Unit 42's investigations.The conversation closes on a note of cautious optimism. Dan argues that over 90% of breaches stem from preventable gaps, meaning security is solvable. He outlines three priorities for defenders: empowering the SOC to act at machine speed, treating identity as the new perimeter, and securing the entire software supply chain from the first line of code to cloud runtime.Download the Unit 42 Global Incident Response Report 2026 here: https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?utm_source=linkedin&utm_medium=social&utm_campaign=na&utm_content=pa001134 Send us Fan MailSupport the show

Command Control Power: Apple Tech Support & Business Talk
669: Adam Engst (TidBITS): Slack Impersonation Malware, Anthropic's Mythos, and Why You Need a Personal AI Defender

Command Control Power: Apple Tech Support & Business Talk

Play Episode Listen Later May 12, 2026 66:59


Adam Engst (TidBITS) discusses a malware incident in a long-running public "Slack Bits" group where a bad actor impersonated Glenn Fleishman via a duplicate Slack display name, tricking him into downloading an info-stealer, prompting Engst to consider shutting down the 1,400-member community. The conversation shifts to Anthropic's Mythos and Project Glasswing (as covered by TidBITS security editor Rich Mogull), which reportedly found long-standing bugs (including in OpenBSD and FFmpeg), raising concerns about AI-accelerated vulnerability discovery, defender/attacker asymmetries, costs and compute barriers, and impacts on zero-day markets. They also cover Apple's iOS signing and update/upgrade distinctions, why Apple supports macOS differently than iOS, broader distrust in institutions, social media's advertising/algorithm problems (including Section 230), bots and AI-driven phishing, and the idea of local, user-controlled AI agents to help protect individuals online.   00:00 Welcome Back Adam Engst 00:20 Slack Impersonation Scare 02:15 Cleaning Up a Public Slack 03:40 Mythos and Glasswing Explained 05:19 AI Bug Hunting Reality Check 08:25 Red Team Blue Team Asymmetry 09:50 Compute Costs and Access Barriers 12:19 Trust Ethics and Regulation 17:50 Personal AI Security Agents 23:34 Zero Day Markets and Exploit Kits 25:40 iOS Signing and Update Windows 27:13 Why Macs Get Longer Support 32:06 Scams Incentives and Pig Butchering 34:02 Life Offline and Misinformation 35:41 Social Media Hot Garbage 36:43 Addiction By Design 37:46 Advertising Model Flaw 38:47 Infinite Scroll Limits 39:39 Dunbar Number Reality 40:54 Platform Power Responsibility 42:46 AI Influencers And Slop 43:37 Bots And Fake Accounts 46:33 AI Phishing And Passkeys 49:21 Closed Communities Trust 53:25 CAPTCHAs And Human Help 56:08 Section 230 And Algorithms 57:46 Chronological Feed Fix 59:35 Two Week News Rule 01:02:41 Ads In Maps Backlash 01:04:10 Wrap Up And Next Part

TechTimeRadio
298: Fake AI Malware, OnlyFans Psychology, Scam Apps, Rail Hacks, SSD Tips That Everyone Should Know, And Smarter Tech Habits For Listeners Seeking Clear, Practical Weekly Insight, With a Little Whiskey on the Side | Air Date: 5/12 - 5/18/26

TechTimeRadio

Play Episode Listen Later May 12, 2026 58:01 Transcription Available


Episode 298: This week's TechTime episode starts with a cautionary tale: one innocent click on a “totally legit” AI site turns into a malware parade featuring the Beagle backdoor. We break down how a fake Claude page practically begs you to download doom, and why “but it was a Google ad!” is not a legal defense. Then we pivot into the psychology of the OnlyFans boom, where relevance, identity, and questionable career advice collide. Mike the Psychologist weighs in with just enough sass to make you rethink every influencer bio you've ever read.From there, we tackle scam apps people want to believe in, including fake stalking tools with millions of installs—because apparently, common sense is optional. We also cover the Taiwan rail hack, proving once again that outdated radio systems and high‑speed trains are a terrible combo. Add in SSD buying tips that save you from slow‑drive regret, plus a quick Archie Rose single‑malt thumbs‑up. By the end, you'll laugh, you'll learn, and you'll definitely double‑check every download button you see. Tune in to TechTime Radio—where the future is now, the stories matter, and all with a little whiskey on the side.-- Full Episode Details:One bad click can turn “trying a new AI tool” into a full-blown Windows security incident. We walk through a fake Claude AI website that looks real, funnels you into a single download button, and drops a malware chain that ends with the Beagle backdoor. We break down the red flags, what to look for on your PC, and why “it was an ad on Google” is never a safety guarantee.Then we zoom out to the weird intersection of technology and human behavior. We talk about the OnlyFans wave as a modern relevance machine, and why platforms that sell intimacy also reshape identity, privacy, and credibility. From there, we pivot to the upside of AI assistants as a practical Swiss Army knife for daily life, including using prompts to map out a disk cleanup strategy and reduce dependency on random utility apps, while still keeping strict guardrails and verification.Finally, we hit the scams people want to believe, like fake “stalking” apps with millions of installs, and the infrastructure risks we should never tolerate, like high-speed rail systems running on outdated radio security. We cap it with a quick SSD buying tip that can save you from performance disappointment: TLC vs QLC NAND matters more than flashy peak speeds. Add a thumbs-up Archie Rose single malt tasting, and you've got a full hour of breaches, behavior, and better tech choices.Subscribe, share Tech TimeRadio with a friend, and leave a review so more people can find the show.Support the show

The CyberWire
Foreign routers get a longer lifeline.

The CyberWire

Play Episode Listen Later May 11, 2026 29:04


The FCC eases restrictions on foreign-made routers. Shiny Hunters hit Canvas and Zara. SailPoint discloses unauthorized access to its GitHub repositories. TrickMo Android banking malware has more tricks up its sleeve. Polish officials warn of increased targeting of ICS and public infrastructure. A federal judge orders $10 million in restitution for stolen zero days. German authorities takedown the Crimenetwork marketplace, again. Monday business breakdown. Dan Lorenc, Chainguard CEO and co-founder, is talking about a recent wave of supply chain attacks. Malware gets signed, sealed and delivered.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dan Lorenc, Chainguard CEO and co-founder, is talking about how the recent wave of supply chain attacks is fundamentally different – and more dangerous –than previous incidents, as well as immediate steps organizations should take as this continues to unfold. Selected Reading US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates (Infosecurity Magazine) ShinyHunters Escalates Canvas Extortion (Infosecurity Magazine) Zara Data Breach Impacts Nearly 200,000 Customers (Infosecurity Magazine) SailPoint Discloses GitHub Repository Hack (SecurityWeek) TrickMo Android banker adopts TON blockchain for covert comms (Bleeping Computer) Polish ABW warns cyberattacks shifting from espionage and data theft toward physical disruption of critical infrastructure (Industrial Cyber) Trenchant Exec Who Sold Zero Days to Russian Buyer Ordered to Pay $10 Million in Restitution to Former Employers (Zero Day) Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested (SecurityWeek) XBOW secures an additional $35 million in Series C funding. (N2K Pro Business Briefing) Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

a16z
Sarah Rogers: Free Speech, AI Diplomacy, and What America Owes Its Allies

a16z

Play Episode Listen Later May 4, 2026 24:05


Katherine Boyle speaks with Sarah Rogers, Under Secretary for Public Diplomacy, about the intersection of AI, free speech, and global information systems. They discuss how major technological shifts, from the printing press to the internet to AI, have reshaped communication and power, and why this moment may be even more consequential. Recorded at the a16z American Dynamism Summit, the conversation explores the role of public diplomacy in the digital age, the risks of censorship and overregulation, and how governments are approaching AI as both a national security priority and a platform for global influence. Rogers also highlights the importance of maintaining “AI with a Western soul,” and why preserving open systems and freedom of expression will shape the future of innovation.   Resources: Follow Sarah B. Rogers on X: https://x.com/UnderSecPD Stay Updated:Find a16z on YouTube: YouTubeFind a16z on XFind a16z on LinkedInListen to the a16z Show on SpotifyListen to the a16z Show on Apple PodcastsFollow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 30, 2026 6:03


Today's Odd Web Requests https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934 Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202 https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202 Assess Secure Boot status with Microsoft Defender https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356 Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201 SAP Related npm Packages Compromised https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared

Security Now (MP3)
SN 1076: FAST16.SYS - Unmasking the NSA's Most Diabolical Digital Sabotage

Security Now (MP3)

Play Episode Listen Later Apr 29, 2026 155:19


What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com

Risky Business
Risky Business #835 -- Why the Fast16 malware is badass

Risky Business

Play Episode Listen Later Apr 29, 2026 66:28


On this week's show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week's cybersecurity news, including: The US government is mad as hell about Chinese firms stealing American AI technology Dmitri has an opinion or two about the US selling Nvidia chips to China Speaking of Chinese AI, Kimi's new 2.6 is very interesting The US sanctions a Cambodian senator for earning mega bucks through scam compounds And a ransomware family is promoting itself as being … quantum-safe? This week's show is sponsored by Trail of Bits. CEO and co-founder Dan Guido chats to Pat about how private inference works and Trail of Bits' audit of WhatsApp's private AI setup. This episode is also available on Youtube. Show notes Exclusive: US State Dept orders global warning about alleged AI thefts by DeepSeek, other Chinese firms | Reuters moonshotai/Kimi-K2.6 · Hugging Face Discord Sleuths Gained Unauthorized Access to Anthropic's Mythos | WIRED Newly Deciphered Sabotage Malware May Have Targeted Iran's Nuclear Program—and Predates Stuxnet | WIRED Hackers deployed wiper malware in destructive attacks on Venezuela's energy sector | The Record from Recorded Future News Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of "Highly Destructive" Wiper Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack - Risky Business Media AI Tools Are Helping Mediocre North Korean Hackers Steal Millions | WIRED CISA: US agency breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March | The Record from Recorded Future News US, UK authorities warn that Firestarter backdoor malware survives patching | Cybersecurity Dive Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities | CyberScoop UK regulator closes loophole that allowed rogue companies to track phone users' location | Reuters US sanctions Cambodian senator for millions earned through scam compounds | The Record from Recorded Future News Vercel says some of its customers' data was stolen prior to its recent hack | TechCrunch Supply Chain Security Incident Update Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch Kyle Daigle on X: "Wanted to provide more clarity about this. Yesterday, we had a regression in merge queue behavior where, in some cases, squash or rebase commits were generated from the wrong base state, making earlier changes appear reverted in branch history. 2,804 pull requests out of over 4M" / X Securing the git push pipeline: Responding to a critical remote code execution vulnerability - The GitHub Blog One ransomware crew now drives half of all cyber claims: At-Bay | Insurance Business In a first, a ransomware family is confirmed to be quantum-safe - Ars Technica What we learned about TEE security from auditing WhatsApp's Private Inference

All TWiT.tv Shows (MP3)
Security Now 1076: FAST16.SYS

All TWiT.tv Shows (MP3)

Play Episode Listen Later Apr 29, 2026 155:19 Transcription Available


What if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bitwarden's CLI hit with a supply-chain attack. Commercial routers in Iran fail shortly before the war. Meta logging all employee activity to train replacement AI. GRC's DNS Benchmark Release 5. Two miscellaneous AI thoughts. A bunch of terrific listener feedback. Unraveling the diabolical history of "fast16.sys" Show Notes - https://www.grc.com/sn/SN-1076-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: doppel.com threatlocker.com/twit material.security cyberhoot.com/securitynow guardsquare.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, April 22nd, 2026: WAV Malware; GitHub OAUTH Phishing; Perforce Settings

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 22, 2026 7:13


A .WAV With A Payload https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910 The Phishy GitHub Issue Case https://blog.atsika.ninja/posts/the-phishy-github-issue-case/ P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet https://morganrobertson.net/p4wned/