Podcasts about NCSC

  • 206PODCASTS
  • 459EPISODES
  • 35mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 9, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about NCSC

Latest podcast episodes about NCSC

SNS Kunskap
Cyberattacker mot kritisk infrastruktur – är vi rustade?

SNS Kunskap

Play Episode Listen Later Sep 9, 2026 59:08


Samhällets kritiska infrastruktur blir alltmer digitaliserad och sammanlänkad. AI och digitalisering skapar nya möjligheter att övervaka, styra och effektivisera samhällsviktig infrastruktur. Samtidigt som allt fler system kopplas upp och automatiseras ökar också sårbarheten för cyberangrepp mot elnät, vattenförsörjning, transporter och kommunikationer. I ett försämrat säkerhetspolitiskt läge har skyddet av kritisk infrastruktur blivit en allt viktigare fråga. Hur ser egentligen de digitala hoten mot vår kritiska infrastruktur ut? Vad krävs för att skydda systemen? Och är Sverige rustat för att möta dessa hot i praktiken? Seminariet genomförs inom ramen för forskningsprojektet SNS Infra. Medverkande Marie Bengtsson, vd, Advenica. Advenica levererar cybersäkerhetslösningar inom kryptering och nätverkssegmentering till sektorer som försvar, myndigheter, infrastruktur och industri. Magnus Jacobson, Senior Adviser Security, Resilience, Civil Preparedness, Svenska Bankföreningen Pontus Johnson, professor i cybersäkerhet och föreståndare för Center for Cyber Defense and Information Security vid KTH samt vice föreståndare för Cybercampus Sweden. Johan Turell, bitr. kontorschef vid Nationellt cybersäkerhetscenter (NCSC). Centrets uppdrag är att stärka Sveriges förmåga att förebygga, upptäcka och hantera cyberhot. NCSC är en del av Försvarets radioanstalt (FRA). Thomas Widén, Director of Information and Cyber Security, Ellevio Samtalet leds av Jonas Klarin, forskningsledare, SNS.

The Gate 15 Podcast Channel
Weekly Security Sprint EP 172. Alphabet soup month, cyber protections, leadership engagement and more!

The Gate 15 Podcast Channel

Play Episode Listen Later Sep 1, 2026 20:08


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Celebrating 5 Years of the Tribal-ISAC: Mid-Year Executive Director Update — TribalHub • FB-ISAO Newsletter, v8, Issue 8 — Faith-Based ISAO • AI/Vishing: The Voice Is Not the Control — Crypto ISAC • National Insider Threat Awareness Month: Protect Our PotentialMain Topics:Iran hackers: Minnesota ‘warning' ignored, ‘critical events' to hit 3 U.S. infrastructure sectors — Threat Beat — 31 Aug 2026. APT IRAN, which has claimed responsibility alongside CyberAv3ngers for recent attacks affecting U.S. municipal water systems, issued a new threat against multiple U.S. critical infrastructure sectors as military tensions with Iran continue. The group characterized its earlier Minnesota activity as a warning and has previously claimed the ability to affect electricity, telecommunications, and water infrastructure, although adversary claims regarding access and capabilities should not be accepted without independent verification. A Tale of Two SOCs: Insights From Two Red Team Assessments — CISA — 25 Aug 2026. CISA released findings from simultaneous red-team assessments of organizations in the Government Services and Facilities Sector and the Water and Wastewater Systems Sector. Both organizations experienced successful initial compromise, but the government organization failed to detect or effectively contain subsequent activity while water-sector defenders quickly identified compromised systems and isolated them. CISA attributed the differing outcomes in part to alert noise, organizational silos, cloud-security weaknesses, and differences in how defenders were empowered to respond. Institutional Wilful Blindness, NCSC Cyber Series — NCSC Cyber Series — 2026. The first installment of a two-part discussion examines why organizations can understand that cyber risks exist yet still fail to take meaningful action before incidents occur. Leadership expert Margaret Heffernan, Professor Genevieve Liveley of the Research Institute for Sociotechnical Cyber Security, and an NCSC social sciences leader discuss how organizational culture, leadership behavior, communication, and the narratives used to describe cybersecurity can create a gap between awareness and action. The discussion emphasizes that resilience depends on more than technical controls and requires leaders to challenge complacency, communicate uncertainty effectively, and create environments where uncomfortable risk information can influence decisions. Quick Hits:• Insights into Suspected DPRK Workers: Red Flags to Look Out For — Huntress • The Who and How of Ten Years of Russian Disinformation — NewsGuard

Gräns
De ska försvara Sverige på valnatten

Gräns

Play Episode Listen Later Sep 1, 2026 25:29


Försvarets Radioanstalt, FRA kommer ha sitt vakande öga öppet på valnatten. Lyssna på alla avsnitt i Sveriges Radios app. Klockan 20:00 på kvällen den 9 september 2018 var det stort jubel på Sverigedemokraternas valvaka. Enligt de preliminära siffrorna från Valu, skulle partiet få nästan 20 procent av rösterna och bli största parti.Men för den som ville följa rösträkningen på Valmyndighetens hemsida blev det allt svårare att komma in på sidan och strax före 21:00 slocknade sidan helt.I tv-valvaka märktes det inget av it-strulet. Valmyndigheten rapporterade in löpande till alla stora medier och allt gick att följa. När kvällen övergick i natt och nästan alla röster var räknade visade det sig att de höga, preliminära siffrorna som Sverigedemokraterna fått, inte stämde. Partiet blev inte näst största parti. Många anhängare blev så besvikna att de inte trodde att det var sant. Bokstavligen. – Då spreds narrativet att vi själva (Valmyndigheten. red.anm) förändrade valresultatet. Vi tog ner webbplatsen för att förändra valresultatet och därför misstämde det väldigt mycket på det som var när sidan gick ner med det som var när sidan kom upp, säger Anna Nyqvist Kanslichef på Valmyndigheten.Det som hade hänt på kvällen var att någon utfört en överbelastningsattack mot Valmyndigheten. Den påverkade som sagt inte rösträkningen på något sätt. Och trots att den här typen av attacker är simpel, fick den konsekvensen att vissa medborgare medborgare i Sverige började ifrågasätta valets legitimitet.– Det är vanligt att jobba på det sättet med en cyberattack som samtidigt bidrar till en ryktesspridning, säger Anna Nyqvist.Artificiell intelligensSedan cyberattacken 2018 har mycket hänt som kan hjälpa den som vill hacka sig in i system och skapa kaos. Ett exempel i närtid är AI-modellen Mythos från företaget Anthropic som rekordsnabbt kunde hitta säkerhetsbrister i it-system. Ett sådant vapen i fel händer kan skapa stor skada. Hittills är det bara ett fåtal aktörer som fått tillgång till Anthropics allra kraftigaste språkmodell. Men det är ingen garanti.– Det är lätt att stirra sig blint och säga att Mythos är den enda läskiga. Tur att det inte finns så mycket mer. Men det finns kapabla modeller. Det finns både stängda modeller hos OpenAI, men även öppna modeller som alla kan göra otrevliga saker redan nu, säger Sebastian Öberg AI-forskare på FOIDet behövs inte särskilt mycket fantasi för att inse att någon aktör med hjälp av en AI-modell först kan hacka ett system, ta över det och samtidigt orkestrera en informationsoperation som ska få människor att misstro valsystemet. Det finns inga konkreta hot mot Sverige och det svenska valet den 13 september. Men tittar man på hur det sett ut vid tidigare val och vid val runt om i Europa i närtid så är val prioriterade mål. Frågan är inte om, utan hur omfattande en attack blir.– Jag skulle bli förvånad om det inte var några attacker. Sen om allmänheten få ta del av att de här attackerna ägt rum? Det är inte lika självklart, skulle jag säga. Men det kommer definitivt att vara attacker, säger Öberg.ValnattenI ljuset av allt som skett vid tidigare val, så är det inte konstigt att svenska myndigheter är på tårna inför, under och efter årets val. Och en nyhet i år är att Regeringen har utsett en av spjutspetsarna inom svensk underrättelsetjänst att skydda valet.– Vi har ett uppdrag från regeringen där vi ser till att bedöma hur hotläget ser ut inför valen från cybersäkerhetsperspektiv. För att säkerställa att vi har en god cybersäkerhetsnivå på de verksamheterna också inför valet, säger John Billow är chef för Nationellt cybersäkerhetscenter, NCSE vid Försvarets radioanstalt, FRATillsammans med flera andra myndigheter kommer FRA:s cyberförsvarsenhet NCSC att bevaka så att ingen försöker sig på någon attack som den vi såg 2018.– Där sitter vi tillsammans för att snabbt reagera. Vi har vår operativa CSIRT-enhet, utöver andra förmågor som finns hos de olika myndigheterna, så att vi kan koordinera det snabbt. och reagera och stötta Valmyndigheten, säger BillowMedborgarens ansvarMyndigheterna är alltså på tårna inför valnatten. Men det är inte enbart de som kan försvara valets legitimitet. Lika stort ansvar ligger på alla de som ska rösta. För om det dyker upp påståenden i sociala medier så betyder inte det att de är sanna. Och påverkansoperationer går att motverka med ganska enkla medel.– Man kommer ganska långt på att kontrollera källan. Att försöka bekräfta information via en annan källa. Vanlig digital källkritik är en jätteviktig del av vår motståndskraft när det gäller psykologiskt försvar, säger Karin Lönnheden vid Myndigheten för psykologiskt försvar. TEXT: Kalle GlasMedverkande:Anna Nyqvist, Kanslichef på ValmyndighetenSebastian Öberg, forskar på AI-system på avdelningen för cyberförsvar och ledningsteknik på Totalförsvarets forskningsinstitut, FOI.John Billow, chef för Nationellt cybersäkerhetscenter, NCSE vid Försvarets radioanstalt, FRAKarin Lönnheden, Myndigheten för psykologiskt försvar. Programledare: Claes Aronsson och Sylvia DahlénReporter: Josefine OwetzProducent: Kalle GlasLjudkällor: SR, SVT, Fox News, ExpressenTV, SwebbTV, AP

Tech Update | BNR
Apple toont 'schokkend bewijs' over OpenAI in zaak over bedrijfsspionage

Tech Update | BNR

Play Episode Listen Later Sep 1, 2026 3:59


Apple heeft 'schokkend bewijs' bij de rechter ingediend in een rechtszaak tegen OpenAI die draait om bedrijfsspionage. Volgens Apple zou voormalig medewerker Chang Liu bedrijfsgeheimen gestolen hebben en gebruikt hebben bij zijn nieuwe werkgever: OpenAI. Verder hoor je over de nieuwe Cyberbeveiligingswet en hoeveel organisaties zich al geregistreerd hebben. Niels Kooloos vertelt erover in deze Tech Update. Volgens Apple heeft Liu via zijn werk-MacBook van Apple ontwerpen voor schakelingen hebben ingezien en bij OpenAI gebruikt hebben. Daar zou OpenAI van op de hoogte zijn, maar niks tegen gedaan hebben. Ook zou Liu een tool gebruikt hebben met dezelfde naam als een interne tool die ontwikkelaars bij Apple gebruiken. Apple kwam Liu op het spoor omdat hij op iCloud inlogde met een Mac mini bij OpenAI. Zijn account zou gesynschroniseerd zijn met zijn werklaptop, waardoor Apple mee kon kijken. OpenAI heeft nog niet gereageerd op de bewijsstukken die Apple gepresenteerd heeft, maar wees de aanklacht over bedrijfsspionage eerder al af. De ChatGPT-maker zegt dat het producten ontwikkelt die 'helemaal nieuw' zijn. Organisaties registreren zich amper voor nieuwe CyberbeveiligingswetHoewel de Cyberbeveiligingswet al ruim twee weken van kracht is in Nederland, zou minder dan de helft van de organisaties met een registratieplicht zich ook daadwerkelijk geregisteerd hebben. Dat stelt Computable op basis van cijfers van het Nationaal Cyber Security Centrum (NCSC). De Cyberbeveiligingswet verplicht organisaties in kritieke sectoren, zoals ziekenhuizen en netbeheerders, om zich te laten registeren bij het NCSC. Volgens Computable zouden zo'n 8 tot 10 duizend organisaties onder de registratieplicht vallen, maar hebben iets meer dan 4 duizend organisaties zich tot nu toe geregistreerd. Apple klaagt medewerker van OpenAI aan om bedrijfsspionage Helft or­ga­ni­sa­ties mist deadline registratie Cy­ber­be­vei­li­gings­wet (NIS2) Over de maker:Niels Kooloos is dagelijks op BNR Nieuwsradio te horen over het laatste technieuws in de Tech Update. Hij interesseert zich vooral in cybercriminaliteit, privacy, social media en (computer)hardware. Hier en daar kan je Niels ook in All in the Game horen, waar hij graag vertelt over zijn favoriete games.See omnystudio.com/listener for privacy information.

Risky Business
Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

Risky Business

Play Episode Listen Later Aug 26, 2026 62:53


On this week's show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK's NCSC, to talk through the week's news, including: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also being targeted… We're stumped on who could be behind that one, too. Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet Prompt injection isn't going away LLMs are deceiving us meat sacks and it's a worry Much, much more… This week's show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week's sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta's new threat intelligence product line. This episode is also available on YouTube Show notes Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media T-Mobile ‘chopped a cable' to expel Chinese hackers from its network | techcrunch.com The long tail of Clop's PTC hack is just beginning to emerge | cyberscoop.com CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer Rust supply chain attack linked to North Korean hackers | securityweek.com Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer Hackers infect Android car head units with proxy botnet malware | BleepingComputer ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com Detections and customer notifications | Okta Threat Intelligence

RNZ: Nine To Noon
Tech: Origin Energy breach, real estate extortion threat

RNZ: Nine To Noon

Play Episode Listen Later Aug 12, 2026 18:59


Cyber security expert Tony Grasso joins Susie to discuss some recent cyber attacks, including one on Australia's biggest energy retailer and another aimed at real estate agents and property managers in Australia. Russian actors have been targeting routers used in many countries including New Zealand. And the NCSC here has had to warn about a scam where people claiming to be employees tell the victim their systems have been compromised and offer to "help". Cybersecurity expert Tony Grasso is Chief Information Security officer at COGENT. He worked at GCHQ in the UK and is a former Intelligence Officer in New Zealand.

Enter
#2 Van NIS2 naar Cbw: De meldplicht, leveranciersketen en een blik op de toekomst

Enter

Play Episode Listen Later Aug 10, 2026 21:48


In de tweede aflevering van Enter over de Cyberbeveiligingswet (Cbw) gaan we dieper in op de meldplicht: wanneer ben je verplicht een incident te melden, hoe werkt de 72-uursregel in de praktijk en wat levert melden je eigenlijk op? Opnieuw aan tafel: jurist Remon Wiekeraad, senior projectleider Bouke van Laethem en cybersecurity-adviseur Luuk Verdonk van het NCSC. We kijken verder naar de rol van leveranciers in je digitale veiligheid, want ook als een leverancier zelf niet onder de wet valt, ben jij wél verantwoordelijk voor de risico's die zij met zich meebrengen. We eindigen met een blik op de toekomst, wat doet de opkomst van AI met het dreigingslandschap en zijn de basismaatregelen van vandaag ook de bescherming van morgen? De boodschap: wees open, hoe eerder je meldt, hoe sneller je uit de problemen bent.Over deze serieDe Cyberbeveiligingswet is de Nederlandse uitwerking van de Europese NIS2-richtlijn en treedt op 15 augustus in werking. Zo'n 8.000 organisaties in Nederland krijgen er direct mee te maken. In deze tweedelige miniserie van Enter duiken we met drie experts van NCSC in de wet: wat staat er precies in, wat betekent dat voor jouw organisatie en hoe zet je de eerste stappen?Presentatie: Yasmine AbiadhGasten: Remon Wiekeraad (jurist, NCSC), Bouke van Laethem (senior projectleider CSIRT, NCSC) en Luuk Verdonk (cybersecurity-adviseur, NCSC)Redactie: NCSC & DPIMontage en geluid: Practical Media

The Pete Kaliner Show
Threats prompt former NC judge to drop out of talk... about civility | Hour 2

The Pete Kaliner Show

Play Episode Listen Later Aug 3, 2026 27:13 Transcription Available


This episode is presented by Create A Video – Former North Carolina Supreme Court judge Mark Martin was scheduled to participate in a panel discussion ahead of the 250th birthday of America. But according to the Carolina Journal, he withdrew from the event after threats of violence against him and the event. Ironically, the panel was slated to discuss political civility.Become a supporter of this podcast: https://www.spreaker.com/podcast/the-pete-kaliner-show--6946691/support.Subscribe to the podcast My preferred podcast platform: SpreakerAll the links to Pete's Prep are free!Get exclusive content here!Media Bias Check: GroundNews promo code!Advertising and Booking inquiries: Pete@ThePeteKalinerShow.com  

Enter
#1 Van NIS2 naar Cbw: Wat houdt de Cyberbeveiligingswet voor mijn onderneming in?

Enter

Play Episode Listen Later Aug 3, 2026 21:39


In de eerste aflevering van Enter over de Cyberbeveiligingswet (Cbw) staan we stil bij de kern van de wet: wat houdt de Cbw precies in, wie valt eronder en welke verplichtingen brengt dat met zich mee? We spreken met Remon Wiekeraad, jurist bij het NCSC en vanaf het begin betrokken bij de totstandkoming van de wet, Bouke van Laethem, senior projectleider van het nationale en sectorale CSIRT, en Luuk Verdonk, cybersecurity-adviseur die organisaties helpt bij de praktische invulling van de zorgplicht. Samen leggen ze uit wat de registratieplicht en de zorgplicht inhouden, hoe je bepaalt of jouw organisatie een essentiële of belangrijke entiteit is en waar je als ondernemer het beste kunt beginnen. De boodschap: de Cbw is niet alleen een verplichting, het is een kans om je organisatie digitaal weerbaarder te maken.Lees hier meer over de zorgplicht.Over deze serieDe Cyberbeveiligingswet is de Nederlandse uitwerking van de Europese NIS2-richtlijn en treedt op 15 augustus in werking. Zo'n 8.000 organisaties in Nederland krijgen er direct mee te maken. In deze tweedelige miniserie van Enter duiken we met drie experts van NCSC in de wet: wat staat er precies in, wat betekent dat voor jouw organisatie en hoe zet je de eerste stappen?Presentatie: Yasmine AbiadhGasten: Remon Wiekeraad (jurist, NCSC), Bouke van Laethem (senior projectleider CSIRT, NCSC) en Luuk Verdonk (cybersecurity-adviseur, NCSC)Redactie: NCSC & DPIMontage en geluid: Practical Media

Naruhodo
Naruhodo Entrevista #72: João Ricardo Sato

Naruhodo

Play Episode Listen Later Jul 20, 2026 82:12


Na série de conversas descontraídas com cientistas, chegou a vez do Professor, Estatístico, Mestre e Doutor em Estatística, Coordenador do Núcleo Intedisciplinar de Neurociência Aplicada da Universidade Federal do ABC, João Ricardo Sato. Só vem! >> OUÇA (82min 13s) * Naruhodo! é o podcast pra quem tem fome de aprender. Ciência, senso comum, curiosidades, desafios e muito mais. Com o leigo curioso, Ken Fujioka, e o cientista PhD, Altay de Souza. Edição: Reginaldo Cursino. http://naruhodo.b9.com.br * João Ricardo Sato é Professor Titular da Universidade Federal do ABC. Por cinco anos, foi coordenador do Núcleo de Cognição e Sistemas Complexos, unidade estratégica vinculada diretamente à reitoria da UFABC que tem como objetivo a realização de atividades em equipes interdisciplinares voltadas para a pesquisa, ensino e extensão na área de neurociências e cognição. Linha de pesquisa atual é interação entre neurociências e ciências exatas, com principal foco no neurodesenvolvimento, bases neurais de transtornos psiquiátricos, conectividade cerebral, inteligência artificial e processamento de sinais neurais. Formou-se no Bacharelado em Estatística pela USP em 2002, tendo concluído três iniciações científicas como bolsista PIBIC/CNPQ na área de séries temporais financeiras, com o intuito de atuar no mercado financeiro. No doutorado que se iniciou em 2004, decidiu focar sua pesquisa no desenvolvimento de novos métodos estatísticos para modelar a conectividade cerebral por meio de sinais de ressonância magnética funcional. Este trabalho interdisciplinar realizou-se sob a orientação de um docente do Departamento de Estatística um docente da Faculdade de Medicina da USP. Em 2006, realizou estágio de pesquisa (doutorado-sanduíche) no Instituto de Psiquiatria do Kings College London, onde integrou técnicas computacionais de aprendizado de máquina à sua linha de pesquisa. Após a conclusão do doutorado em 2007, atuou como consultor estatístico e pesquisador do Hospital das Clínicas de São Paulo. Além disso, também atuou como professor no curso de pós-graduação lato sensu da Universidade Metodista em São Bernardo do Campo. Em janeiro de 2009, foi contratado pela UFABC para o cargo de professor adjunto do Centro de Matemática, Computação e Cognição. Em julho de 2009 tornou-se o coordenador do Núcleo de Cognição e Sistemas Complexos (NCSC). Os docentes associados ao NCSC foram a equipe idealizadora do Bacharelado em Neurociências (pioneiro no Brasil) e do programa de pós-graduação em Neurociências e Cognição da UFABC. Esta equipe também foi responsável por todo o planejamento da infra-estrutura para pesquisa científica em neurociências, hoje disponível no primeiro andar do Bloco Delta no Campus de São Bernardo do Campo. Atualmente é coordenador do Núcleo Intedisciplinar de Neurociência Aplicada da Universidade Federal do ABC. Lattes: http://lattes.cnpq.br/7913813209624175 * APOIE O NARUHODO! O Altay e eu temos duas mensagens pra você. A primeira é: muito, muito obrigado pela sua audiência. Sem ela, o Naruhodo sequer teria sentido de existir. Você nos ajuda demais não só quando ouve, mas também quando espalha episódios para familiares, amigos - e, por que não?, inimigos. A segunda mensagem é: existe uma outra forma de apoiar o Naruhodo, a ciência e o pensamento científico - apoiando financeiramente o nosso projeto de podcast semanal independente, que só descansa no recesso do fim de ano. Manter o Naruhodo tem custos e despesas: servidores, domínio, pesquisa, produção, edição, atendimento, tempo... Enfim, muitas coisas para cobrir - e, algumas delas, em dólar. A gente sabe que nem todo mundo pode apoiar financeiramente. E tá tudo bem. Tente mandar um episódio para alguém que você conhece e acha que vai gostar. A gente sabe que alguns podem, mas não mensalmente. E tá tudo bem também. Você pode apoiar quando puder e cancelar quando quiser.  O apoio mínimo é de 15 reais e pode ser feito pela plataforma ORELO ou pela plataforma APOIA-SE. Para quem está fora do Brasil, temos até a plataforma PATREON. É isso, gente. Estamos enfrentando um momento importante e você pode ajudar a combater o negacionismo e manter a chama da ciência acesa. Então, fica aqui o nosso convite: apóie o Naruhodo como puder. bit.ly/naruhodo-no-orelo

Security Now (MP3)
SN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

Security Now (MP3)

Play Episode Listen Later Jul 15, 2026 168:51


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

All TWiT.tv Shows (MP3)
Security Now 1087: HalluSquatting, GhostApproval & GitLost

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jul 15, 2026 168:51 Transcription Available


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Security Now (Video HD)
SN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

Security Now (Video HD)

Play Episode Listen Later Jul 15, 2026 168:51


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Security Now (Video HI)
SN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

Security Now (Video HI)

Play Episode Listen Later Jul 15, 2026 168:51


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Radio Leo (Audio)
Security Now 1087: HalluSquatting, GhostApproval & GitLost

Radio Leo (Audio)

Play Episode Listen Later Jul 15, 2026 168:51 Transcription Available


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Security Now (Video LO)
SN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

Security Now (Video LO)

Play Episode Listen Later Jul 15, 2026 168:51


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

All TWiT.tv Shows (Video LO)
Security Now 1087: HalluSquatting, GhostApproval & GitLost

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Jul 15, 2026 168:51 Transcription Available


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Radio Leo (Video HD)
Security Now 1087: HalluSquatting, GhostApproval & GitLost

Radio Leo (Video HD)

Play Episode Listen Later Jul 15, 2026 168:51 Transcription Available


AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet" receives an on-the-fly patch. An underused mode to kid-proof an iPhone. Listener feedback and three new AI attacks HalluSquatting, GhostApproval & GitLost Show Notes - https://www.grc.com/sn/SN-1087-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT arcticwolf.com/trends threatlocker.com/twit XBOW.com adaptivesecurity.com cohesity.com/Resilience

Financial Crime Weekly Podcast
Financial Crime Weekly Episode 260

Financial Crime Weekly Podcast

Play Episode Listen Later Jun 21, 2026 25:30


Welcome to episode 260 of the Financial Crime Weekly Podcast. I am Chris Kirkbride. In this episode, a ship's captain is charged for allegedly breaching Russian sanctions, and there are the US Treasury's latest designations against Hizballah-linked officials. In the UK, Nigeria's former oil minister has been acquitted in a bribery case, while the High Court has imposed reporting restrictions in the Entain civil litigation. Furthermore, the episode covers new enforcement data highlighting a lack of prosecutions against professional enablers, and a warning from the NCSC regarding state-sponsored cyber-attacks on critical infrastructure. Finally, we discuss the growing "protection gap" in cyber insurance, and the rise of the converged criminal economy where digital fraud increasingly intersects with real-world exploitation.A transcript of this podcast, with links to the stories, will be available at www.crimes.financial. The photograph on the podcast cover art is by Sora Shimazaki at Pexels, and the stinger sample between each news section is ‘Ben Logo 1' by BenKirb from Pixabay.

The Gate 15 Podcast Channel
Weekly Security Sprint EP 161. Job site risks, patching, and much more

The Gate 15 Podcast Channel

Play Episode Listen Later Jun 9, 2026 19:12


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• A Review of the Fiscal Year 2027 Budget Request for DHS — House Homeland Security Committee• DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels — CyberScoop • DHS chief signals efforts to reshape CISA — The Record • CISA and Partners Release Fact Sheet on Securing Automatic Tank Gauge Systems• Industry Collaboration and Resilience is a Team Sport — Cyber Threat Alliance — 02 Jun 2026. This article is authored by the Executive Director of IT-ISAC and emphasizes the importance of collaboration across industry, government, and nonprofit organizations to improve cyber resilience. Main Topics:Safeguarding OUR SECRETS — IC3 — 03 Jun 2026. Five Eyes agencies warned that Chinese military intelligence services are using Western online job platforms and professional networking sites to recruit people with access to classified, privileged, or sensitive information. • Applicant Beware - Who Is Recruiting You? — NPSA — 03 Jun 2026“Patch Now!” Most organizations that miss 24-hour patch window report breaches. Gate 15 note: We've been discussing this a lot in recent exercises and meetings. The time to safely address Known Exploited Vulnerabilities is limited and decreasing. Attackers' speed is accelerating; exploited vulnerabilities are a major point of attack. CISA KEV & Other Threat Updates: AI! Promoting Advanced Artificial Intelligence Innovation and Security — The White House — 02 Jun 2026• Opinion from Jen Easterly: The Government Is Finally Taking A.I. Risk Seriously • Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator — Anthropic • What we learned mapping a year's worth of AI-enabled cyber threats — Anthropic Quick Hits:• Ransomware Group Claims Cyberattack on Buffalo Convention Center — Skift Meetings — 01 Jun 2026. Skift Meetings reports that the Akira ransomware group claimed it stole 46 gigabytes of data from the Buffalo Convention Center, including employee records, contracts, financial information, and personal data tied to approximately 180,000 individuals. • Knicks Watch Party at Garden Is Canceled, as Game 3 Security Ramps Up — The New York Times • FIFA World Cup 2026 Scams Are Already Here: Fake Tickets, Phishing Sites, and Crypto Cons Exposed • Hackers are hoping to score at the World Cup • At least 12 wounded near Ohio festival as police hunt multiple gunmen • Hurricane Season!• Software supply chain attacks: check your dependencies — NCSC

CISSP Cyber Training Podcast - CISSP Training Program
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 8, 2026 41:38 Transcription Available


Send us Fan MailYour software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines.I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We connect each technique to the CISSP mindset so you can spot it in scenario questions and, more importantly, recognise it in your own environment. Along the way, I explain why Node.js, Python, and Rust projects are especially exposed, how automation can turn “latest version” convenience into an enterprise incident, and why developer environments often become an overlooked attack surface.Then we get practical with controls you can actually implement: pausing automatic dependency updates when compromise is suspected, adding human approval for critical packages, rotating credentials immediately, enforcing MFA on developer and registry accounts, and using private or trusted registries to mirror and vet dependencies. I also zoom out to show how to build supply chain security into the secure SDLC with software composition analysis (SCA), code signing, checksum verification, audit logging, continuous monitoring, and an SBOM so you can respond fast when a package turns toxic.If this helps you tighten your dependency management and level up your CISSP prep, subscribe, share this with a teammate, and leave a quick review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Cyberhelden
Cyberhelden 75 - DigiD, residential proxies en AI die aanvallen niet magisch maakt

Cyberhelden

Play Episode Listen Later Jun 4, 2026 47:28


Ronald, Marco en Jelle zijn terug met DigiD, device-code-phishing, residential proxies en de vraag of AI cyberaanvallers echt onhoudbaar maakt. Eerst kort: Marco repareert tijdens een nachtwacht Home Assistant-data met Claude, Jelle bouwt met AI een lesdashboard, en Ronald rijdt in Kaapstad een fox hunt met antennes op de auto. Daarna DigiD. Staatssecretaris Willemijn Aerdts blokkeert de Amerikaanse overname van Solvinity door Kyndryl. Ronald legt uit waarom dit via de Wet ongewenste zeggenschap telecommunicatie loopt, waarom dat juridisch anders is dan VIFO, en waarom Nederland hiermee feitelijk zegt: Amerikaanse jurisdictie en CLOUD Act-risico's zijn voor DigiD te groot. Marco bespreekt RSI, recursive self-improvement, als nieuwe AI-hypeterm. Het idee: AI die zijn eigen training verbetert. De nuchtere conclusie blijft: losse stappen automatiseren lukt steeds beter, maar richting houden, controleren of iets klopt en echt autonoom onderzoek doen blijft lastig. Jelle pakt Kali365: phishing via Microsoft 365 device-code-flows. Het slachtoffer logt in op de echte Microsoft-site, maar autoriseert het apparaat van de aanvaller. Domeinchecken is dus niet genoeg als de context rond de login vergiftigd is. Het eerste hoofdverhaal: ASocks en residential proxies. Politie en NCSC verstoren een botnet met minstens 17 miljoen besmette apparaten, aangestuurd via ongeveer 200 servers in Nederland. Marco vat het scherp samen: het botnet is de infrastructuur, de residential proxy is het product. Aanvallers kopen verkeer vanaf normale thuisverbindingen in plaats van herkenbare datacenters of Tor-exitnodes. Daardoor lijken phishing, credential stuffing, DDoS en brute-force-pogingen op gewoon verkeer van echte gebruikers. Open vraag: zijn de apparaten echt opgeschoond, of vooral de aansturing geraakt? Jelle sluit af met Lennart Maschmeyers paper Deception and Detection. Maschmeyer stelt dat AI aanval en verdediging helpt, maar verdedigers structureel meer kunnen winnen: verdediging draait veel om detectie en patroonherkenning, aanval verderop in de kill chain om misleiding, context en gecontroleerde effecten. De drie zijn kritisch op zijn dwell-time-argument, maar herkennen de kern: je wilt geen autonome agent die in een vijandelijk netwerk creatief gaat improviseren. Tegelijk maakt AI aanvallers wel sneller als copiloot, codegenerator, parser van scanoutput en phishinghulp. Vooral lagere en middelmatige actoren kunnen daarmee sneller opschalen. *Bronnen* DigiD / Solvinity - NOS: https://nos.nl/artikel/2615885-staatssecretaris-verbiedt-amerikaanse-overname-solvinity-bedrijf-achter-digid - Wet OZT: https://wetten.overheid.nl/BWBR0045423 - Wet VIFO: https://wetten.overheid.nl/BWBR0046686 RSI - TechCrunch: https://techcrunch.com/2026/05/28/rsi-is-the-new-agi-and-its-just-as-hard-to-pin-down/ Kali365 - FBI IC3: https://www.ic3.gov/PSA/2026/PSA260521 - BleepingComputer: https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/ ASocks / residential proxies - Politie: https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html - NCSC expertblog: https://www.ncsc.nl/expertblogs/residential-proxies-en-hun-grote-impact-op-de-digitale-veiligheid-in-nederland - NCSC nieuws: https://www.ncsc.nl/nieuws/gezamenlijke-actie-politie-en-ncsc-legt-groot-botnetwerk-plat - Security.nl: https://www.security.nl/posting/938396/Proxy-botnet+van+17+miljoen+apparaten+na+actie+politie+en+NCSC+offline?channel=rss Maschmeyer / AI - CV Maschmeyer: https://www.lennartmaschmeyer.com/CV_Lennart_Maschmeyer.pdf - Paper: https://doi.org/10.1162/isec.a.398 - M-Trends 2025: https://cloud.google.com/security/resources/m-trends

Tech45
#743: Een flexijob voor smartphones

Tech45

Play Episode Listen Later Jun 3, 2026 80:59


Taskmaster Technieuws De Apple Car is er en hij heet Ferrari Luce | Elektrische Ferrari Luce onthuld: 530 km en 1.050 pk | Het internet vindt de e-Ferrari van Jony Ive maar niks Mistral doopt Le Chat om tot Vibe | Officiële aankondiging | En ook: Proton Lumo

eHealthTALK NZ
Protecting digital health systems – National CISO Pete Booth

eHealthTALK NZ

Play Episode Listen Later May 29, 2026 18:36


Protecting health data isn't just a technical challenge, but a shared responsibility that is critical to maintaining patient trust and system resilience.In this episode Pete Booth, Acting Chief Information Security Officer at Health New Zealand, discusses the evolving cyber landscape in healthcare.He talks about bolstering cybersecurity in health, from managing third-party risks and enforcing the NCSC standards, to embedding security by design in AI and digital health innovations and Health New Zealand's central Security Operations Centre.Note - This episode was recorded before reports into the MMH data breach were released on May 27.

Choses à Savoir TECH
100 états dans le monde espionnent nos smartphones ?

Choses à Savoir TECH

Play Episode Listen Later May 7, 2026 2:23


Le scandale Pegasus avait marqué les esprits. Développé par NSO Group, ce spyware (autrement dit un logiciel capable d'infiltrer un appareil pour en extraire des données) avait été utilisé par plusieurs États pour surveiller journalistes, opposants et militants. Mais selon plusieurs experts, ce cas pourrait n'être que la partie visible d'un phénomène en pleine expansion. D'après le National Cyber Security Centre, plus d'une centaine de pays disposeraient aujourd'hui de ce type d'outils. Un chiffre en forte hausse : ils étaient environ 80 en 2023. Sur les 193 États membres de l'ONU, cela représente désormais une majorité potentielle capable de mener des opérations de surveillance numérique avancée.Comment expliquer cette progression ? Principalement par une baisse des barrières d'accès. Autrefois réservés à quelques puissances, ces logiciels sont aujourd'hui plus faciles à acquérir, parfois via des sociétés privées spécialisées dans la cybersurveillance. Résultat : leur diffusion s'accélère, et avec elle, les usages. Car l'enjeu ne se limite pas au nombre d'acteurs équipés. Les cibles évoluent aussi. Officiellement, ces outils sont utilisés pour lutter contre le terrorisme ou la criminalité organisée. Mais dans les faits, de nombreux cas ont déjà montré qu'ils pouvaient viser des profils bien différents : journalistes, figures de l'opposition, défenseurs des droits humains. Et selon les autorités britanniques, le spectre s'élargit encore. Désormais, des profils économiques comme des banquiers ou des chefs d'entreprise seraient également ciblés. L'espionnage numérique ne se limite plus aux enjeux politiques, il touche aussi les intérêts financiers et stratégiques.Autre point marquant : l'origine des attaques. Contrairement à une idée reçue, elles ne proviennent pas majoritairement de cybercriminels isolés. Selon Richard Horne, directeur du NCSC, une grande partie des cyberattaques d'envergure au Royaume-Uni serait le fait… d'États. Autrement dit, la cybersurveillance s'inscrit de plus en plus dans les relations internationales. Un outil de renseignement, mais aussi de pouvoir. Et dans ce contexte, Pegasus pourrait bien apparaître, avec le recul, comme un simple avertissement. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.

Security Now (MP3)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (MP3)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

All TWiT.tv Shows (MP3)
Security Now 1077: A Browser AI API?

All TWiT.tv Shows (MP3)

Play Episode Listen Later May 6, 2026 155:01 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video HD)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video HD)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video HI)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video HI)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Radio Leo (Audio)
Security Now 1077: A Browser AI API?

Radio Leo (Audio)

Play Episode Listen Later May 6, 2026 155:01 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Security Now (Video LO)
SN 1077: A Browser AI API? - End of Bug Bounties?

Security Now (Video LO)

Play Episode Listen Later May 6, 2026


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

All TWiT.tv Shows (Video LO)
Security Now 1077: A Browser AI API?

All TWiT.tv Shows (Video LO)

Play Episode Listen Later May 6, 2026 155:00 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

Radio Leo (Video HD)
Security Now 1077: A Browser AI API?

Radio Leo (Video HD)

Play Episode Listen Later May 6, 2026 155:00 Transcription Available


Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365

The CyberWire
War hits where it hurts.

The CyberWire

Play Episode Listen Later Apr 28, 2026 24:57


Conflict in the Middle East disrupts the circuit board supply chain. The Supreme Court considers arguments on geofence searches. A new report highlights Chinese digital transnational repression. The NCSC protects HDMI and DisplayPort links. Tennessee bans cryptocurrency ATMs. Researchers expose a financially motivated subgroup of North Korea's Lazarus Group. Medtronic confirms a ShinyHunters data breach. Tim Starks, from CyberScoop discusses telecom vulnerabilities. A helpful AI deletes everything.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We welcome back Tim Starks, Senior Reporter for CyberScoop, discussing telecom vulnerabilities. Selected Reading Iran war disrupts the circuit board supply chain, raises costs for tech firms (Reuters) Iranian hackers expose personal details of thousands of US Marines in Middle East (Metro) Supreme Court signals location data searches should require a warrant (The Record) Tall Tales: How Chinese Actors Use Impersonation and Stolen Narratives to Perpetuate Digital Transnational Repression (The Citizen Lab) NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links (Security Affairs) Tennessee becomes second state to ban cryptocurrency ATMs over scam concerns (The Record) BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector (Arctic Wolf) Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak (SecurityWeek) Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue (Tom's Hardware) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Blue Security
Apple-Signal Bug, NCSC recommends passkeys, Open Source debate

Blue Security

Play Episode Listen Later Apr 28, 2026 34:19


SummaryIn this episode, Andy and Adam discuss a recent vulnerability in the Signal messaging app that allowed the FBI to recover deleted messages from an iPhone due to a flaw in Apple's notification system. They emphasize the importance of user settings and the need for regular updates. The conversation then shifts to the UK National Cyber Security Centre's endorsement of passkeys as a preferred login method for consumers, highlighting the shift away from traditional passwords. Finally, they address the challenges of open source software security, referencing Marcus Hutchins' insights on the lack of bug bounty programs and the potential risks associated with unmonitored code.----------------------------------------------------YouTube Video Link: https://youtu.be/yXuUc32MPL4----------------------------------------------------Documentation: https://arstechnica.com/tech-policy/2026/04/apple-stops-weirdly-storing-data-that-let-cops-spy-on-signal-chats/https://www.infosecurity-magazine.com/news/ncsc-backs-passkeys-new-era-of/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Blue Security
Apple-Signal Bug, NCSC recommends passkeys, Open Source debate

Blue Security

Play Episode Listen Later Apr 28, 2026 34:24


SummaryIn this episode, Andy and Adam discuss a recent vulnerability in the Signal messaging app that allowed the FBI to recover deleted messages from an iPhone due to a flaw in Apple's notification system. They emphasize the importance of user settings and the need for regular updates. The conversation then shifts to the UK National Cyber Security Centre's endorsement of passkeys as a preferred login method for consumers, highlighting the shift away from traditional passwords. Finally, they address the challenges of open source software security, referencing Marcus Hutchins' insights on the lack of bug bounty programs and the potential risks associated with unmonitored code.----------------------------------------------------YouTube Video Link: https://youtu.be/yXuUc32MPL4----------------------------------------------------Documentation: https://arstechnica.com/tech-policy/2026/04/apple-stops-weirdly-storing-data-that-let-cops-spy-on-signal-chats/https://www.infosecurity-magazine.com/news/ncsc-backs-passkeys-new-era-of/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Cyberhelden
Cyberhelden 67 - De lettersoep is compleet — en nu?

Cyberhelden

Play Episode Listen Later Mar 26, 2026 47:09


In deze aflevering duiken Ronald, Jelle en Marco eerst in drie actuele nieuwtjes: de VoidStealer-malware die de masterkey rechtstreeks uit het Chrome-geheugen vist en daarmee Googles Application Bound Encryption omzeilt, een update over de Odido-hack waarbij het team zelf de phishingserver van de Shiny Hunters wist te achterhalen (en het dilemma tussen publiceren en het politieonderzoek niet verstoren), en een Russische informatieoperatie rond een fictieve "Volksrepubliek Narva" in Estland — recht uit het Oekraïne-playbook, maar nu gericht op een NAVO-land. Daarna gaat het over de strategische richting van cybersecurity in Nederland. Aanleiding is het eerdere interview met NCSC-directeur Matthijs van Amelsfort: operationeel gebeurt er veel (fusie afgerond, 10.000 aangesloten entiteiten, House of Cyber in aanbouw), maar wie bewaakt het grotere geheel? Onderzoekers van de Universiteit Leiden telden 29 organisaties verdeeld over 7 ministeries die "iets met cyber" doen — waarvan slechts 3 aan beleidscreatie doen. Het resultaat: een lettersoep waar geen CISO de weg in vindt. Het team legt vervolgens het "gebroken sociaal contract" bloot: organisaties moeten steeds meer inleveren (NIS2-meldplicht, bestuurlijke aansprakelijkheid, zorgplicht), maar krijgen daar weinig concreets voor terug — geen incident response, geen sectorspecifiek dreigingsbeeld, geen kwaliteitsborging van de markt. Ter vergelijking kijken we naar het Verenigd Koninkrijk, waar Robert Hannigan (oprichter UK NCSC) precies hetzelfde probleem beschrijft én hoe ze het oplosten: één herkenbaar loket, politiek eigenaarschap op het hoogste niveau, en Active Cyber Defence — gratis overheidsdiensten als Mail Check, Web Check en Protective DNS die de baseline voor iedereen omhoogtrekken. Ook Frankrijk (ANSSI) en Duitsland (BSI) passeren de revue. De aflevering sluit af met drie concrete bouwstenen voor Nederland: maak het NCSC de "112 voor cyber" die niet alleen adviseert maar ook levert, richt het House of Cyber in als open werkplaats waar overheid en marktpartijen samen aan tafel zitten, en zorg voor politiek eigenaarschap met echte doorzettingsmacht — niet wachten tot de volgende DigiNotar of NotPetya. Bronnen & links: VoidStealer & ABE-bypass – https://www.gendigital.com/blog/insights/research/voidstealer-abe-bypass Hannigan, R. (2019), Organising a Government for Cyber – https://static.rusi.org/20190227_hannigan_final_web.pdf Mirzaei & De Busser, Universiteit Leiden – https://www.sciencedirect.com/science/article/pii/S0267364924000980 "Narva People's Republic" - https://www.propastop.org/en/2026/03/11/separatist-narva-peoples-republic-idea-spreads-on-social-media/

Cyberhelden
Cyberhelden 66 - D-NCSC Matthijs van Amelsfort: Niet de brandweer, wat dan wel?

Cyberhelden

Play Episode Listen Later Mar 18, 2026 52:58


Cyberhelden 66 - D-NCSC Matthijs van Amelsfort: Niet de brandweer, wat dan wel? Het NCSC is geen digitale brandweer , Mathijs van Amelsfoort, directeur van het Nationaal Cyber Security Centrum, legt in deze aflevering aan Ronald Prins en Marco Kuijpers uit wat dat onderscheid in de praktijk betekent. Van de fusie met het Digital Trust Center en de sprong van 300 naar 10.000 entiteiten onder de nieuwe cyberbeveiligingswet, tot het House of Cyber in Den Haag, AI in dreigingsanalyse en de toenemende hybride dreiging vanuit Rusland.

Cyberhelden
Cyberhelden 65 - Luisteraarsvraag: Hoe blijf ik veilig?

Cyberhelden

Play Episode Listen Later Mar 12, 2026 72:04


Cyberhelden 65 - Luisteraarsvraag: Hoe blijf ik veilig? Je hoeft niet onkwetsbaar te zijn. Je hoeft alleen niet het makkelijkste doelwit te zijn. In deze aflevering gaan Ronald, Marco en Jelle terug naar de basis: wat werkt er écht als je jezelf thuis wil beschermen? Aanleiding is de vraag van een luisteraar én het gratis F-Secure abonnement dat Odido uitdeelde na hun grote datalek. Van wachtwoordmanagers en MFA tot routers, phishing-checks en VPN-mythes: een overzicht van wat de moeite waard is, wat niet, en waarom je Windows Defender waarschijnlijk al genoeg is. Nieuwtjes - ZeroDayClock — exploitatietijdlijn: van 2,3 jaar in 2018 naar 1,6 dag in 2026: https://www.zerodayclock.com - China's Cybercrime Prevention and Control Law (VPN-verbod, realname-registratie, zero-day nationalisering): https://jamestown.org/program/chinas-draft-cyber-crime-prevention-and-control-law/ - VS cyberstrategie 2026: hacking back, AI-agents los, CISA uitgekleed: https://www.whitehouse.gov/national-security/cybersecurity/ Updates en lifecycle •⁠ ⁠Microsoft: Windows 10 end of support (oktober 2025): https://www.microsoft.com/en-us/windows/end-of-support •⁠ ⁠Veiliginternetten.nl — basismaatregelen voor consumenten: https://www.veiliginternetten.nl Wachtwoordmanagers •⁠ ⁠Bitwarden (open source): https://bitwarden.com •⁠ ⁠1Password: https://1password.com •⁠ ⁠Proton Pass (Zwitsers): https://proton.me/pass MFA en hardware tokens •⁠ ⁠YubiKey: https://www.yubico.com •⁠ ⁠Google Advanced Protection Program: https://landing.google.com/advancedprotection/ •⁠ ⁠Ente Auth (open source authenticator): https://ente.io/auth/ •⁠ ⁠2FAS (open source authenticator): https://2fas.com Antivirus •⁠ ⁠Microsoft Defender (ingebouwd in Windows): https://www.microsoft.com/en-us/windows/comprehensive-security •⁠ ⁠Bitdefender (Roemenië): https://www.bitdefender.com •⁠ ⁠ESET (Slowakije): https://www.eset.com •⁠ ⁠G DATA (Duitsland): https://www.gdata.de •⁠ ⁠AV-TEST — onafhankelijke antivirus benchmarks: https://www.av-test.org Phishing herkennen •⁠ ⁠NCSC: "Herken phishing": https://www.ncsc.nl/onderwerpen/phishing •⁠ ⁠HaveIBeenPwned — check of je e-mailadres in een datalek zit: https://haveibeenpwned.com DNS-filtering •⁠ ⁠Quad9 (Zwitserland, geblokkeerde malwaredomeinen): https://www.quad9.net — IP: 9.9.9.9 •⁠ ⁠AdGuard DNS: https://adguard-dns.io •⁠ ⁠NextDNS: https://nextdns.io VPN •⁠ ⁠Proton VPN (Zwitserland, met NetShield): https://protonvpn.com •⁠ ⁠Mullvad VPN (Zweden): https://mullvad.net Browser •⁠ ⁠Vivaldi (Noors, Chromium-gebaseerd): https://vivaldi.com

The Gate 15 Podcast Channel
Weekly Security Sprint EP 149. ISAC/ISAO love, Iran, AI and a new cyber strategy

The Gate 15 Podcast Channel

Play Episode Listen Later Mar 10, 2026 21:06


In this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Insider Threat: AI-equipped Employees - Gate 15 - 04 Mar 2026 • Communication and Collaboration Key Themes in GridEx VIII Lessons Learned Report • Health-ISAC Annual Report 2025 Shows Surge in Threat Intel and Tabletop Drills, Putting Resilience in Focus • The Gate 15 Special Edition: Iran, ISACs, & insomnia: What's happening, and not happening, in information sharing — Gate 15 | 06 Mar 2026• White House Unveils President Trump's Cyber Strategy for America — The White House | 06 Mar 2026o Fact Sheet: President Donald J. Trump Combats Cybercrime, Fraud, and Predatory Schemes Against American Citizens — The White House o Ranking Member Thompson Statement on Trump's 3-Page Cyber Strategy — Democrats on the House Homeland Security Committee, 06 Mar 2026 • Fact Sheet: President Donald J. Trump Combats Cybercrime, Fraud, and Predatory Schemes Against American Citizens — The White House | 06 Mar 2026Main Topics:Operation Epic Fury & Related: • White House blocks intelligence report warning of rising US homeland terror threat linked to Iran war • Iran may be activating sleeper cells in the United States, officials warn • Cyber threat bulletin: Iranian cyber threat response to US–Israel strikes February 2026, Canadian Centre for Cyber Security, 03 Mar 2026• Alert: NCSC advises UK organisations to take action following conflict in the Middle East, NCSC, 02 Mar 2026• U.S. threat intelligence units identify hacktivists as prime cyber vector in Iran conflict • Iran-linked hacktivists could target US state and local targets, experts warn • Trump Says ‘I Guess' Americans Should Worry About Iran Attacks Cyber Reports• NCC Group Annual Threat Monitor Review of 2025 NCC Group, 05 Mar 2026• Patch, track, repeat: The 2025 CVE retrospective — Cisco Talos, 05 Mar 2026• Look What You Made Us Patch: 2025 Zero-Days in Review Google Cloud Blog, 05 Mar 2026• Coalition report finds sharp rise in ransomware demands as most businesses refuse to pay — Reinsurance News | 07 Mar 2026• INC Ransom Affiliate Model Enabling Targeting of Critical Networks Australian Cyber Security Centre, 05 Mar 2026Quick Hits:• Top 10 artificial intelligence security actions: A primer Canadian Centre for Cyber Security, 05 Mar 2026• Artificial Intelligence and Machine Learning Supply Chain Risks and Mitigations Australian Signals Directorate, 04 Mar 2026• How AI Assistants Are Moving the Security Goalposts — Krebs on Security | 07 Mar 2026• Preparation hardening destructive attacks — Google Cloud Threat Intelligence | 08 Mar 2026• Tornadoes kill 6 people in Michigan and Oklahoma as powerful storms hit nation's midsection

The CyberWire
Rooted and patient.

The CyberWire

Play Episode Listen Later Feb 18, 2026 33:22


A China-linked group exploits a critical Dell zero-day for 18 months. A Microsoft 365 Copilot bug risks sensitive email oversharing. A new Linux botnet leans on old-school IRC for command and control. Switzerland tightens critical infrastructure rules with mandatory cyber reporting. AstarionRAT emerges as a custom post-exploitation implant. Researchers find serious flaws in popular PDF platforms. A suspected Iranian-aligned campaign targets protest supporters. Notepad++ rolls out a “double-lock” update fix. And a Spanish court orders NordVPN and ProtonVPN to block illegal football streams. Our guest is Keith Mularski, Former FBI Special Agent and Chief Global Ambassador at Qintel, reflecting on the 25th anniversary of notorious spy Robert Hanssen's arrest. Dutch Defense flaunt F-35 firmware freedom.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Keith Mularski, Former FBI Special Agent and Chief Global Ambassador at Qintel, to talk about the 25th anniversary of Robert Hanssen's arrest. If you enjoyed Keith's conversation, you can hear more from him over on the Only Malware in the Building podcast. Selected Reading Chinese hackers exploited a Dell zero-day for 18 months before anyone noticed (CyberScoop)  Microsoft says bug causes Copilot to summarize confidential emails (Bleeping Computer) New Linux Botnet Discovered (Linux Magazine) Switzerland's NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure (Industrial Cyber) ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion (Huntress) Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration (SecurityWeek) CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign (Acronis) Notepad++ boosts update security with ‘double-lock' mechanism (Bleeping Computer) Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites (Bleeping Computer) Dutch defense chief: F-35s can be jailbroken like iPhones (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The Gate 15 Podcast Channel
Weekly Security Sprint EP 146. Management concerns, threat actors targeting AI models, and more

The Gate 15 Podcast Channel

Play Episode Listen Later Feb 17, 2026 19:51


On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• TribalHub 6th Annual Cybersecurity Summit, 17–20 Feb 2026, Jacksonville, Florida• IT-ISAC, Food & Ag ISAC Ransomware Reports!• Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking; Town Hall Meetings • What to Know About the Homeland Security Shutdown New York Times 15 Feb 2026Main Topics:South Korea blames Coupang data breach on management failure, not sophisticated attack – Reuters – 10 Feb 2026. “'It's more of a management problem than an advanced attack,' Choi Woo-hyuk, deputy minister for cyber security and network policy, told a press conference, citing lax oversight of authentication systems.” South Korean authorities released findings on a massive Coupang data leak, concluding that a former engineer exploited known authentication weaknesses and a retained signing key to access customer accounts for months, exposing personal data on about 33.7 million users. AI Threats & Mitigation• GTIG AI Threat Tracker: Distillation, Experimentation, and Continued Integration of AI for Adversarial Use — Google Cloud Blog — 12 Feb 2026. Google Threat Intelligence Group describes observed adversary use of AI across multiple phases of the attack lifecycle and highlights rising model extraction and distillation activity. • What CISOs need to know about ClawDBot, I mean MoltBot, I mean OpenClaw CSO Online — 16 Feb 2026. The article outlines enterprise risk considerations around OpenClaw and similar autonomous agent tooling that can execute actions on behalf of users with broad system access. It includes the warning that “The problem with running this is that these tools can do basically anything that a user can do,” says Rich Mogull, chief analyst at Cloud Security Alliance. Awareness of Preoperational Surveillance Tactics Associated With Terrorism Offers Opportunities — Joint Counterterrorism Assessment Team First Responder's Toolbox, ODNI — 13 Feb 2026. CISA's 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure. Notable highlights include: • Strengthened Collective Defense: Published more than 1,600 products and triaged 30,000+ incidents through CISA's 24/7 Operations Center – keeping critical systems secure. • Blocked Malicious Activity at Scale: Stopped 2.62 billion malicious connections on federal civilian networks and 371 million within critical infrastructure. • Enhanced Preparedness Nationwide: Led 148 cyber and physical security exercises with 10,000+ participants, helping partners refine emergency plans and boost local and national resilience. • Following Executive Order 14305, “Restoring American Airspace Sovereignty,” CISA published the Be Air Aware™ suite of security guides in November to help organization detect, respond to, and safely manage Unmanned Aircraft System Threats. Quick Hits:• Improving your response to vulnerability management — NCSC, 10 Feb 2026• Guidance to Assist Non-Federal Entities to Share Cyber Threat Indicators and Defensive Measures with Federal Entities under the Cybersecurity Information Sharing Act of 2015 – CISA – 03 Feb 2026• CISA Helps Johnny Secure Operational Technology: New Guidance Addresses Cyber Risks from Legacy Protocols. CISA released the guidance Barriers to Secure OT Communication: Why Johnny Can't Authenticate. • Poland energy sector cyber incident highlights OT and ICS security gaps • CISA Updates BRICKSTORM Backdoor Malware Analysis Report• Blended Threats: Axios Future of Cybersecurity – Axios – 10 Feb 2026• A Defector Explains the Remote-Work Scam Helping North Korea Pay for Nukes Wall Street Journal 16 Feb 2026• Hacktivism today: what three years of research reveal about its transformation • Pakistan mosque attack highlights worsening militant threat

Carolina Weather Group
Massive Winter Storm Recap: Historic NC/SC Snow, Mark Sudduth & NASCAR Delays [Ep. 571]

Carolina Weather Group

Play Episode Listen Later Feb 5, 2026 75:13


Tonight on the Carolina Weather Group, we are breaking down the massive winter storm that just walloped the Carolinas. From the mountains to the coast, we cover the historic snowfall totals and the icy impacts felt across North and South Carolina.❄️ In This Episode:NC & SC Storm Recap: James Brierton reports from Charlotte (Piedmont) and Sam Walker joins from the Outer Banks to discuss the monster storm totals across North Carolina. Plus, Frank Strait breaks down the significant snow accumulation across South Carolina.Guest Mark Sudduth: Renowned storm chaser Mark Sudduth (HurricaneTrack) joins the panel to share his experience chasing ice and snow in the Carolinas during this event, as well as his recent coverage of the massive Lake Effect snow bands in New York.Breaking NASCAR News: We are tracking live developments from Winston-Salem, where winter weather continues to disrupt The Clash. Already delayed by the weekend storm, tonight's race at Bowman Gray Stadium faces new delays due to stubborn sleet and rain.The Forecast Ahead: Don't put the coats away yet. We look at the potential for a few lingering snowflakes on Thursday and warn of a dangerous refreeze and frigid temperatures coming Friday morning.Subscribe to the Carolina Weather Group for your weekly verified weather updates!#NCwx #SCwx #WinterStorm #NASCAR #MarkSudduth #Weather#weather #northcarolina #southcarolina #ncwx #scwx #podcast

Cyber Briefing
January 21, 2026 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Jan 21, 2026 7:52


If you like what you hear, please subscribe, leave us a review and tell a friend!

The Gate 15 Podcast Channel
Weekly Security Sprint EP 142. Winter blast, hacktivists, and a dose of cyber resilience

The Gate 15 Podcast Channel

Play Episode Listen Later Jan 21, 2026 17:56


In this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Cyber Insights 2026: Information Sharing (SecurityWeek, 16 Jan 2026)• ICYMI: Homeland Republicans underscore importance of strong public-private sector partnerships to deter cyber threats — House Homeland Security Committee (Majority) | Jan 17, 2026 Main Topics:Pro-Russia hacktivist activity continues to target UK organisations & NCSC warns of hacktivist groups disrupting UK online services (UK National Cyber Security Centre, Jan 2026). The NCSC reports sustained, low-sophistication but high-volume hacktivist campaigns—primarily DDoS and website defacements—linked to pro-Russia narratives and opportunistic targeting of UK public- and private-sector organizations. While technically unsophisticated, the activity is persistent, media-aware, and designed to generate disruption, reputational harm, and psychological impact rather than deep network compromise. The NCSC emphasizes preparedness measures including DDoS resilience, clear incident communications, and executive awareness that “noise” activity can still impose real operational cost. • Russia-linked APT28 targets energy and defense groups tied to NATO • UAT-8837 targets critical infrastructure sectors in North America • A Day Without ICS: The real impact of ICS/OT security threats Ransomware• Worldwide ransomware roundup: 2025 end-of-year report • Global ransomware attacks rose 32% in 2025, as manufacturers emerged as top target• 2025 Shattered Records: Key takeaways from the GRIT 2026 Ransomware & Cyber Threat Report• DeadLock Ransomware: Smart Contracts for Malicious Purposes Domestic Operations: Joint Interagency Task Force-Counter Cartel (JIATF-CC) established & US Northern Command establishes JTF-GOLD Quick Hits:• (TLP:CLEAR) Assessing Terrorism Trends on the Horizon in 2026 — WaterISAC — Jan 15, 2026 • UK NCSC: Designing safer links: secure connectivity for operational technology• NCSC UK: Secure connectivity principles for OT (collection) • FBI: Secure Connectivity Principles for Operational Technology (OT) (PDF)• ACSC (Australia): New publication for small businesses managing cyber risks from AI • Artificial intelligence for small business: Managing cyber security risks• Developing your IT recovery plan (Canadian Centre for Cyber Security, Jan 2026)• Improving cyber security resilience through emergency preparedness planning (Canadian Centre for Cyber Security, Jan 2026)• Developing your incident response plan (Canadian Centre for Cyber Security, Jan 2026)• Developing your business continuity plan (Canadian Centre for Cyber Security, Jan 2026)

The IT Pro Podcast
Are AI cyber threats overhyped?

The IT Pro Podcast

Play Episode Listen Later Jan 9, 2026 32:35


We're just over a week into 2026 but already, enterprise cybersecurity teams will be hard at work repelling attacks – and business leaders will be worrying about the year ahead.On the one hand, we're told that AI tools are beginning to empower security teams to go further and faster. On the other, the use of AI by hackers to launch attacks also appears to be on the rise.All of this is happening against a backdrop of rising geopolitical tensions and continual attacks by state-sponsored hacking groups against businesses. How will all this come together in 2026 and beyond?In this episode, Jane and Rory are joined by Jamie Collier, lead advisor in Europe at Google Threat Intelligence Group, to explore the risks – both novel and ordinary – enterprises face in 2026.Read more:NCSC issues urgent warning over growing AI prompt injection risks – here's what you need to knowCyber experts have been warning about AI-powered DDoS attacks – now they're becoming a realitySalt Typhoon attack on US congressional email system ‘exposes how vulnerable core communications systems remain to nation-state actors'OpenAI says prompt injection attacks are a serious threat for AI browsers – and it's a problem that's ‘unlikely to ever be fully solved'OpenAI turns to red teamers to prevent malicious ChatGPT use as company warns future models could pose 'high' security riskA flaw in Google's new Gemini CLI tool could've allowed hackers to exfiltrate dataGoogle says you shouldn't worry about AI malware – but that won't last long as hackers refine techniquesNorth Korean IT workers: The growing threatNorth Korean hackers...

The CyberWire
America's tech turn.

The CyberWire

Play Episode Listen Later Dec 8, 2025 27:04


How might Trump's new National Security Strategy impact cyber? The UK's NCSC warns LLMs may never get over prompt injection. At least 18 U.S. universities were hit by a months-long phishing campaign. Russia blocks FaceTime. A bipartisan group of senators reviving efforts to strengthen protections across the health sector. Portugal provides legal safe harbor for good-faith security research. A large-scale campaign targets Palo Alto GlobalProtect portals. A Maryland man gets 15 months in prison for his part in a North Korean IT worker scam. Business Brief. Tim Starks from CyberScoop unpacks the President's pending cybersecurity strategy release. An AI image sends UK train schedules off the rails.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks, senior reporter  from CyberScoop, discussing President Trump's pending cybersecurity strategy release and the end of Sean Plankey's nomination process. Selected Reading National Security Strategy (The White House) The National Security Strategy: The Good, the Not So Great, and the Alarm Bells (CSIS) UK intelligence warns AI 'prompt injection' attacks might never go away (The Record) Over 70 Domains Used in Months-Long Phishing Spree Against US Universities (Hackread) Russia restricts FaceTime, its latest step in controlling online communications (AP News) Bipartisan health care cybersecurity legislation returns to address a cornucopia of issues (CyberScoop) Portugal updates cybercrime law to exempt security researchers (Bleeping Computer) New wave of VPN login attempts targets Palo Alto GlobalProtect portals (Bleeping Computer) Maryland man sentenced for N. Korea IT worker scheme involving US government contracts (The Record) ServiceNow reportedly intends to acquire Veza for more than $1 billion (N2K Pro Business Briefing) Trains cancelled over fake bridge collapse image (BBC News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Briefing
December 05, 2025 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Dec 5, 2025 9:41


If you like what you hear, please subscribe, leave us a review and tell a friend!

Security Forum Podcasts
S36 Ep13: Steve Durbin - Preparing for AI-Generated Cyber Intrusions

Security Forum Podcasts

Play Episode Listen Later Dec 2, 2025 13:37


In the second part of his interview with journalist Nick Witchell, Steve and Nick delve into the world of AI and cyber. Steve shares his thoughts on autonomous cyber defense and argues that major actors like the ISF, large private enterprises, and the UK's National Cyber Security Centre, must lead the way and support small and medium-sized businesses in keeping pace with technological advancements. The two also discuss the future of AI, cautioning that we aren't as prepared as we need to be… Key Takeaways: Small and medium-sized businesses must receive support to stay up-to-date with new technologies. As more automation is introduced into business operations, understanding of one's crown jewels and how to protect them is increasingly important. AI is advancing rapidly with evermore funding, and globally society is not preparing as well as it needs to for what's to come.  Tune in to hear more about: Steve's view on autonomous cyber defense (00:55) The National Cyber Security Centre and its role in the cyber resilience of UK businesses (3:36) How AI will impact jobs in cyber (7:55) Standout Quotes: “You'll never get me going into an autonomous car. I just won't do it. And people will say, ‘Yes, they're being looked after by some bloke in a tower somewhere who's watching it.” I'm not buying it. I've been working in technology for far too long to know that it is fallible. And so I think we have to really move toward much more transparency in our understanding of where the AI tool is active, the data that it's using, the decisions it's making.” - Steve Durbin “We are looking for large private enterprise to be working collaboratively with people like the NCSC, with people like the ISF, to really help some of these smaller organizations that don't have the luxury or resources available to them to keep a pace with [technology].” - Steve Durbin “If you go back to the internet, we didn't do a good enough job of trying to forecast the way in which the internet was going to be used. We put it out there and we said, ‘Let everybody use it and let's see where it goes.” We are doing, I fear, a similar kind of thing with AI.” - Steve Durbin Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

ai uk preparing cyber ai generated isf ncsc intrusions national cyber security centre information security forum steve durbin standout quotes you
Source Daily
News Man Weekly: Chess master Carl Boor; Cleveland sports heartbreak; Local news of the week and more!

Source Daily

Play Episode Listen Later Oct 7, 2025 58:16


Episode 68 of News Man Weekly is the “checkmate edition,” where Carl, Zac, and Hayden open with their usual mix of sports heartbreak, newsroom chaos and local headlines. The crew talks Cleveland’s roller-coaster weekend — from the Guardians’ playoff exit to yet another Browns gut punch — before catching up on family life, football byes, and a few folks who’ve landed on the News Man Weekly Shit List. Carl also runs through the week’s top local stories, including the opening of Mansfield’s new multi-use trail and tunnel, county leaders weighing property tax relief and the latest developments in downtown revitalization. Then, the mics turn to strategy and focus as chess master Carl Boor joins the show ahead of National Chess Day. The Mansfield-based player and founder of The Chess Bus shares how he fell in love with the game, what it takes to reach master status and why chess still matters in the age of video games and AI. During the interview, Boor and Zac Hiser actually play a live game of chess — one you’ll want to watch on YouTube — and, not surprisingly, Boor dismantles Hiser while carrying on the conversation. It’s a smart, funny and competitive episode that proves strategy isn’t just for the board. Thanks to Relax, It's Just Coffee for supporting the News Man Weekly. Head over to Relax to check out their fall drink menu. Related links: Learn more about Chess Bus and see their upcoming events Tunnel under Trimble, connector for bike path, open to the public Political hot potato: Richland County leaders face tough choices on property tax reductions NCSC instructor removed from Clear Fork college course after social media posts Upcoming Event: Build a Better Village Upcoming Event: Newsroom After Hours Richland Source hosting 'Candidate Conversations' Oct. 15 in Mansfield Support the show: https://richlandsource.com/membersSee omnystudio.com/listener for privacy information.