Podcasts about notepad

  • 397PODCASTS
  • 988EPISODES
  • 51mAVG DURATION
  • 1DAILY NEW EPISODE
  • Feb 26, 2026LATEST
notepad

POPULARITY

20192020202120222023202420252026


Best podcasts about notepad

Latest podcast episodes about notepad

Decoder with Nilay Patel
Inside Xbox's executive shakeup

Decoder with Nilay Patel

Play Episode Listen Later Feb 26, 2026 43:08


Today, we're talking about the future of Xbox. Phil Spencer, a two-time Decoder guest who's led Xbox for more than a decade, resigned. But in a shocking twist, his deputy long-assumed successor Sarah Bond is also out too, and the Xbox division is now in the hands of an Asha Sharma, one of Microsoft's AI executives with no prior game industry experience. There is no better person to talk to about all of this than Tom Warren, senior editor here at The Verge and author of the excellent Notepad newsletter. Tom is actually on parental leave right now, but Microsoft has a longstanding habit of disrupting his well-earned time off. So, Tom was gracious enough to come on the show after publishing a major scoop about what went down at Xbox this past week. Links: Inside Microsoft's big Xbox leadership shake-up | The Verge Billions of dollars later and still nobody knows what an Xbox is | The Verge Xbox chief Phil Spencer is leaving Microsoft | The Verge Read Xbox chief Phil Spencer's memo about leaving Microsoft | The Verge Here's what Xbox is working on for 2026 | The Verge AMD hints Microsoft could launch its next-gen Xbox in 2027 | The Verge The next Xbox is going to be very different | The Verge Xbox co-founder believes it's being ‘sunsetted' in favor of AI | VGC Subscribe to The Verge to access the ad-free version of Decoder! Credits: Decoder is a production of The Verge and part of the Vox Media Podcast Network. Decoder is produced by Kate Cox and Nick Statt and edited by Ursa Wright. Our editorial director is Kevin McShane. Learn more about your ad choices. Visit podcastchoices.com/adchoices

PolySécure Podcast
Actu - 22 février 2026 - Parce que... c'est l'épisode 0x712!

PolySécure Podcast

Play Episode Listen Later Feb 23, 2026 48:54


Parce que… c'est l'épisode 0x712! Shameless plug 25 et 26 février 2026 - SéQCure 2026 31 mars au 2 avril 2026 - Forum INCYBER - Europe 2026 14 au 17 avril 2026 - Botconf 2026 28 et 29 avril 2026 - Cybereco Cyberconférence 2026 9 au 17 mai 2026 - NorthSec 2026 3 au 5 juin 2026 - SSTIC 2026 19 septembre 2026 - Bsides Montréal 1 au 3 décembre 2026 - Forum INCYBER - Canada 2026 Notes IA Sécurité et le code Kevin Beaumont: “Today in InfoSec Job Security …” - Cyberplace AI Found Twelve New Vulnerabilities in OpenSSL Anthropic rolls out embedded security scanning for Claude Cyber Stocks Slide As Anthropic Unveils ‘Claude Code Security' Plagiat chez Microsoft Microsoft deletes blog telling users to train AI on pirated Harry Potter books Microsoft Uses Plagiarized AI Slop Flowchart To Explain How Git Works The Promptware Kill Chain Why ‘secure-by-design' systems are non-negotiable in the AI era Side-Channel Attacks Against LLMs Gentoo dumps GitHub over Copilot nagware European Parliament bars lawmakers from AI tools AI chatbots to face strict online safety rules in UK LLM-generated passwords ‘fundamentally weak,' experts say PromptSpy ushers in the era of Android threats using GenAI Claude just gave me access to another user's legal documents OpenClaw Security Fears Lead Meta, Other AI Firms To Restrict Its Use Was an Amazon Service Taken Down By Its AI Coding Bot? Kevin Beaumont: “Microsoft need a better way of…” - Cyberplace OpenAI Employees Raised Alarms About Canada Shooting Suspect Months Ago The Internet Is Becoming a Dark Forest — And AI Is the Hunter Souveraineté ou tout ce que je peux faire sur mon terrain India's New Social Media Rules: Remove Unlawful Content in Three Hours, Detect Illegal AI Content Automatically UK to require tech firms to remove nonconsensual intimate images within 48 hours or face fines Greece throws support behind social media bans for kids Kevin Beaumont: “Ireland's data protection watc…” - Cyberplace Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites Poland bans Chinese-made cars from entering military sites Texas sues TP-Link over Chinese hacking risks, user deception Microsoft throws spox under the bus in ICC email flap Digital sovereignty must define itself before it can succeed “Made in EU” - it was harder than I thought. Privacy ou tout ce qui devrait rester à la maison Underground Facial Recognition Tool Unmasks Camgirls Leaked Email Suggests Ring Plans to Expand ‘Search Party' Surveillance Beyond Dogs Mysk

Buongiorno da Edo
Notepad++ aveva una backdoor cinese - Buongiorno 313

Buongiorno da Edo

Play Episode Listen Later Feb 23, 2026 11:42


Per sei mesi, il meccanismo di aggiornamento di Notepad++ è stato dirottato da un gruppo hacker cinese. Vi racconto come hanno fatto, cosa hanno installato, e cosa ci insegna sulla fragilità dell'open source.Fonti e approfondimenti:- Kaspersky Securelist: https://securelist.com/notepad-supply-chain-attack/118708/- The Register: https://www.theregister.com/2026/02/02/notepad_plusplus_intrusion/- The Hacker News: https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html- Palo Alto Unit42: https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/- Notepad++ chiarificazione ufficiale: https://notepad-plus-plus.org/news/clarification-security-incident/- ACN/CSIRT Italia: https://www.acn.gov.it/portale/en/w/compromissione-dell-infrastruttura-di-aggiornamento-di-notepad-- Notepad++ scuse e timeline: https://notepad-plus-plus.org/news/hijacked-incident-info-update/- CISA KEV Catalog: https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalogLa mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it00:00 Intro01:40 Cos'è un supply chain attack (e perché Notepad++)04:42 Sei mesi dentro la catena di aggiornamento07:11 La fix e la lezione10:03 Outro#notepad #cybersecurity #lotusblossom #chrysalis #opensource #cina

Brad & Will Made a Tech Pod.
327: Two Hours of War

Brad & Will Made a Tech Pod.

Play Episode Listen Later Feb 22, 2026 64:21


There's... a lot going on lately, so we're rounding up some of that news this week, starting with Discord's forthcoming age verification policy rolling out globally, with cursory discussion of some of the alternative platforms starting to assert themselves out there. We also touch on the targeting and compromise of Notepad++ by state-level actors, and the latest effects of the computing supply crisis on hard drives, the Steam Machine, and the PlayStation 6. Lastly, we talk about the bizarre case of the autonomous AI agent that started a flame war against an open source maintainer that... well, you really need to just hear/read about that one yourself. Discord's age verification announcement: https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally Notepad++ compromised: https://notepad-plus-plus.org/news/hijacked-incident-info-update/ An AI Agent Published a Hit Piece on Me: https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/ (Much more has emerged about the AI agent story since we recorded, including contact with the agent's operator, all described at the link above.) Support the Pod! Contribute to the Tech Pod Patreon and get access to our booming Discord, a monthly bonus episode, your name in the credits, and other great benefits! You can support the show at: https://patreon.com/techpod

The CyberWire
Rooted and patient.

The CyberWire

Play Episode Listen Later Feb 18, 2026 33:22


A China-linked group exploits a critical Dell zero-day for 18 months. A Microsoft 365 Copilot bug risks sensitive email oversharing. A new Linux botnet leans on old-school IRC for command and control. Switzerland tightens critical infrastructure rules with mandatory cyber reporting. AstarionRAT emerges as a custom post-exploitation implant. Researchers find serious flaws in popular PDF platforms. A suspected Iranian-aligned campaign targets protest supporters. Notepad++ rolls out a “double-lock” update fix. And a Spanish court orders NordVPN and ProtonVPN to block illegal football streams. Our guest is Keith Mularski, Former FBI Special Agent and Chief Global Ambassador at Qintel, reflecting on the 25th anniversary of notorious spy Robert Hanssen's arrest. Dutch Defense flaunt F-35 firmware freedom.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Keith Mularski, Former FBI Special Agent and Chief Global Ambassador at Qintel, to talk about the 25th anniversary of Robert Hanssen's arrest. If you enjoyed Keith's conversation, you can hear more from him over on the Only Malware in the Building podcast. Selected Reading Chinese hackers exploited a Dell zero-day for 18 months before anyone noticed (CyberScoop)  Microsoft says bug causes Copilot to summarize confidential emails (Bleeping Computer) New Linux Botnet Discovered (Linux Magazine) Switzerland's NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure (Industrial Cyber) ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion (Huntress) Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration (SecurityWeek) CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign (Acronis) Notepad++ boosts update security with ‘double-lock' mechanism (Bleeping Computer) Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites (Bleeping Computer) Dutch defense chief: F-35s can be jailbroken like iPhones (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Black Hills Information Security
Live From WWHF Mile High 2026 – 2026-02-11

Black Hills Information Security

Play Episode Listen Later Feb 18, 2026 33:22 Transcription Available


Live from Wild West Hackin' Fest Denver 2026, the Black Hills Information Security crew brings their signature mix of sharp security insight and off-the-cuff banter to a packed in-person audience. This episode centers on a controversial Notepad update that introduced Markdown rendering—along with a potential remote code execution (RCE) issue. The hosts unpack what this says about modern software bloat, “vibe coding,” and the growing push to embed AI into everything—whether it belongs there or not. They also explore the implications of Discord's Age verification requirements, AI-generated code, including OpenAI's latest Codex model, and debate whether we're headed toward a wave of AI-assisted vulnerabilities.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis

Passwort - der Podcast von heise security
Von unsicheren Schalentieren, quantensicheren Bundesämtern und Editoren-Hintertüren

Passwort - der Podcast von heise security

Play Episode Listen Later Feb 18, 2026 138:11 Transcription Available


Nach den ausschweifenden Jubiläumsfeiern finden Sylvester und Christopher zurück zum gewohnten Rhythmus. Zunächst schauen sie auf ein System zur Geräteverwaltung (MDM), das in den letzten Wochen bei verschiedenen europäischen Regierungen angegriffen wurde - der Hersteller war bereits mehrfach Thema im Podcast. Dann geht's allerdings weiter mit einem kurzen Abriß zu OpenClaw, dem gehypten KI-Assistenten, und seinen vielen Unsicherheiten. Sylvester kann dem Helferlein eine gewisse Faszination abgewinnen, warnt jedoch vor seinem unreflektierten Einsatz. Und Christopher erzählt, wie das Bundesamt für Sicherheit in der Informationstechnik die Verschlüsselung in Deutschland quantensicher machen will und dazu seine Richtlinien modernisiert. Betrachtungen zu unabsichtlichen Kommandos bei der Softwareentwicklung und zu Problemen verschiedener Texteditoren runden die Folge ab und entlassen Sylvester in den wohlverdienten Urlaub. Leider gibt es auf der Tonspur in dieser Folge einen leichten Hall von Christophers Stimme. Wir bitten das zu entschuldigen.

The Cloud Pod
343: AWS CloudWatch Finally Hits Snooze

The Cloud Pod

Play Episode Listen Later Feb 17, 2026 71:34


Welcome to episode 343 of The Cloud Pod, where the forecast is always cloudy! Justin, Ryan, and Matt are in the studio this week bringing you all the latest in Cloud and AI news, including some of the smaller clouds like Cloudflare and Crusoe Cloud, as well as announcements from the big guys like Google's Gemini DeepThink, Anthropic's big pay day, and Microsoft's Notepad problem. We've got all this plus Matt screwing up his outro AGAIN, so let's get started!  Titles we almost went with this week Chrome’s WebMCP Protocol: Teaching AI Agents to Stop Doom-Scrolling the DOM and Actually Get Work Done Claude Enterprise Self-Service: Because Sometimes You Just Want to Buy AI Without Small Talk AWS EC2 Goes Inception Mode: Now You Can Virtualize Your Virtualization Without Going Broke Amazon EC2 Nested Virtualization: Because Your Virtual Machine Was Lonely and Needed Its Own Virtual Machine CloudWatch Alarm Mute Rules: Because Your Deployment Doesn’t Need a Standing    Ovation at 3 AM Anthropic’s $380 Billion Valuation Proves AI Funding Has Gone Claude Nine AWS EC2 Nested Virtualization Finally Escapes the Expensive Hardware Jail Cloudflare Teaches AI Agents the Magic Words: Accept text/markdown and Save 13,000 Tokens Crusoe Cloud’s MCP Server: Teaching AI Assistants to Stop Asking for the Manager and Just Fix Your Infrastructure Azure’s New Agentic Copilot: Because Manually Clicking Through Dashboards Was So 2023 Chrome’s WebMCP Gives AI Agents a GPS for Websites Because Apparently They’ve Been Lost in the HTML This Whole Time  Anthropic Cuts Out the Middleman: Claude Enterprise Now Available Without the Enterprise Sales Dance AWS Gives CloudWatch the Silent Treatment: New Mute Rules Let Alarms Sleep Through Maintenance Windows AWS CloudWatch Hits Snooze: Mute Rules End On-Call Nightmares AWS Gives CloudWatch the Silent Treatment General News  00:45 Bloat Risk? Microsoft’s Notepad Upgrade Also Introduced a Vulnerability | PCMag Microsoft’s recent Notepad modernization introduced CVE-2026-20841, a vulnerability in the new Markdown support feature that allows malicious links in files to execute remote code.  The flaw has been patched in the February 2026 security updates, but it highlights the security trade-offs when adding features to historically simple applications. The vulnerability exploits Notepad’s Markdown rendering capability, which Microsoft added in May to support lightweight markup language formatting. When Notepad opens a specially crafted Markdown file, embedded malicious links can trigger unverified protocols that load and execute remote files on the system. This incident raises questions about feature bloat in core Windows utilities, particularly as Microsoft continues adding network-dependent capabilities like AI-powered text writing to Notepad. Security researchers are debating

Blue Security
Notepad++ supply chain compromise and 7-Zip malware

Blue Security

Play Episode Listen Later Feb 17, 2026 26:03


SummaryIn this episode of the Blue Security Podcast, hosts Andy and Adam discuss significant cybersecurity incidents involving Notepad++ and 7-Zip, highlighting the vulnerabilities in open-source software and the importance of enterprise software management. They emphasize the need for ad blockers, the challenges of identifying legitimate software downloads, and the necessity of implementing robust security measures in organizations.----------------------------------------------------YouTube Video Link: ----------------------------------------------------Documentation:https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/https://msendpointmgr.com/2025/10/04/taming-browser-extensions-with-intune/https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Blue Security
Notepad++ supply chain compromise and 7-Zip malware

Blue Security

Play Episode Listen Later Feb 17, 2026 26:58


SummaryIn this episode of the Blue Security Podcast, hosts Andy and Adam discuss significant cybersecurity incidents involving Notepad++ and 7-Zip, highlighting the vulnerabilities in open-source software and the importance of enterprise software management. They emphasize the need for ad blockers, the challenges of identifying legitimate software downloads, and the necessity of implementing robust security measures in organizations.----------------------------------------------------YouTube Video Link: ----------------------------------------------------Documentation:https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/https://msendpointmgr.com/2025/10/04/taming-browser-extensions-with-intune/https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Paul's Security Weekly
Hardware-level zero trust, don't trust AI with your employees, and the news - J Wolfgang Goerlich, Matias Katz - ESW #446

Paul's Security Weekly

Play Episode Listen Later Feb 16, 2026 107:12


Segment 1: Interview with Mathias Katz What if you had enterprise-grade network security protections traveling with your users' laptops? What if it could be built into the laptop, but still stay safe even if the laptop OS and firmware were entirely compromised? Mathias and his company, Byos have built such a thing, and BOY do we have some questions for him. Segment 2: Interview with Wolfgang Goerlich Addressing the nuanced, nefarious threats of AI Sure, we need to worry about AI prompt injection and AI data leakage, but what about the threats to our BRAINS? Seriously, as we start to have daily conversations with this technology, how are they going to shape how we think? What inherent biases in the training, fine tuning, guardrails, or lack of guardrails are going to affect our decisions or how we work? Wolfgang is concerned about this, so he performed a human/AI experiment. With almost 1000 people partaking in the experiment, the results are sure to be intriguing. Segment 3: This week's enterprise security news Finally, in the enterprise security news, survey results on how folks are feeling about openclaw some hidden drama discovered in KEV updates some new KEV tools is AI replacing traditional code scanning tools? remote code execution in notepad no, not notepad++, NOTEPAD.EXE you know, the one that ships preinstalled on Windows the RSAC innovation sandbox finalists dealing with legacy vulnerabilities Don't accept OpenClaw Mac Minis from strangers! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-446

Enterprise Security Weekly (Audio)
Hardware-level zero trust, don't trust AI with your employees, and the news - J Wolfgang Goerlich, Matias Katz - ESW #446

Enterprise Security Weekly (Audio)

Play Episode Listen Later Feb 16, 2026 107:12


Segment 1: Interview with Mathias Katz What if you had enterprise-grade network security protections traveling with your users' laptops? What if it could be built into the laptop, but still stay safe even if the laptop OS and firmware were entirely compromised? Mathias and his company, Byos have built such a thing, and BOY do we have some questions for him. Segment 2: Interview with Wolfgang Goerlich Addressing the nuanced, nefarious threats of AI Sure, we need to worry about AI prompt injection and AI data leakage, but what about the threats to our BRAINS? Seriously, as we start to have daily conversations with this technology, how are they going to shape how we think? What inherent biases in the training, fine tuning, guardrails, or lack of guardrails are going to affect our decisions or how we work? Wolfgang is concerned about this, so he performed a human/AI experiment. With almost 1000 people partaking in the experiment, the results are sure to be intriguing. Segment 3: This week's enterprise security news Finally, in the enterprise security news, survey results on how folks are feeling about openclaw some hidden drama discovered in KEV updates some new KEV tools is AI replacing traditional code scanning tools? remote code execution in notepad no, not notepad++, NOTEPAD.EXE you know, the one that ships preinstalled on Windows the RSAC innovation sandbox finalists dealing with legacy vulnerabilities Don't accept OpenClaw Mac Minis from strangers! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-446

Paul's Security Weekly TV
Hardware-level zero trust, don't trust AI with your employees, and the news - Matias Katz, J Wolfgang Goerlich - ESW #446

Paul's Security Weekly TV

Play Episode Listen Later Feb 16, 2026 107:12


Segment 1: Interview with Mathias Katz What if you had enterprise-grade network security protections traveling with your users' laptops? What if it could be built into the laptop, but still stay safe even if the laptop OS and firmware were entirely compromised? Mathias and his company, Byos have built such a thing, and BOY do we have some questions for him. Segment 2: Interview with Wolfgang Goerlich Addressing the nuanced, nefarious threats of AI Sure, we need to worry about AI prompt injection and AI data leakage, but what about the threats to our BRAINS? Seriously, as we start to have daily conversations with this technology, how are they going to shape how we think? What inherent biases in the training, fine tuning, guardrails, or lack of guardrails are going to affect our decisions or how we work? Wolfgang is concerned about this, so he performed a human/AI experiment. With almost 1000 people partaking in the experiment, the results are sure to be intriguing. Segment 3: This week's enterprise security news Finally, in the enterprise security news, survey results on how folks are feeling about openclaw some hidden drama discovered in KEV updates some new KEV tools is AI replacing traditional code scanning tools? remote code execution in notepad no, not notepad++, NOTEPAD.EXE you know, the one that ships preinstalled on Windows the RSAC innovation sandbox finalists dealing with legacy vulnerabilities Don't accept OpenClaw Mac Minis from strangers! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-446

Enterprise Security Weekly (Video)
Hardware-level zero trust, don't trust AI with your employees, and the news - Matias Katz, J Wolfgang Goerlich - ESW #446

Enterprise Security Weekly (Video)

Play Episode Listen Later Feb 16, 2026 107:12


Segment 1: Interview with Mathias Katz What if you had enterprise-grade network security protections traveling with your users' laptops? What if it could be built into the laptop, but still stay safe even if the laptop OS and firmware were entirely compromised? Mathias and his company, Byos have built such a thing, and BOY do we have some questions for him. Segment 2: Interview with Wolfgang Goerlich Addressing the nuanced, nefarious threats of AI Sure, we need to worry about AI prompt injection and AI data leakage, but what about the threats to our BRAINS? Seriously, as we start to have daily conversations with this technology, how are they going to shape how we think? What inherent biases in the training, fine tuning, guardrails, or lack of guardrails are going to affect our decisions or how we work? Wolfgang is concerned about this, so he performed a human/AI experiment. With almost 1000 people partaking in the experiment, the results are sure to be intriguing. Segment 3: This week's enterprise security news Finally, in the enterprise security news, survey results on how folks are feeling about openclaw some hidden drama discovered in KEV updates some new KEV tools is AI replacing traditional code scanning tools? remote code execution in notepad no, not notepad++, NOTEPAD.EXE you know, the one that ships preinstalled on Windows the RSAC innovation sandbox finalists dealing with legacy vulnerabilities Don't accept OpenClaw Mac Minis from strangers! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-446

Binärgewitter
Binärgewitter Talk #375: Club im Club

Binärgewitter

Play Episode Listen Later Feb 14, 2026 91:17


Karnevalskater trifft Open-Source-Kater: Zwischen FOSDEM-Raumsuche, MySQL-Gerüchten und ethischen Grundsatzdebatten stolpern wir durch Tech-Trends und AI-News. Dazu gibt's Abo-Detox, Desktop-Frust und die Erkenntnis: Digitale Souveränität beginnt manchmal mit „Kündigen“-Button statt Keynote. Blast from the Past MySQL - Bericht vom FOSDEM Stand Rant extended - same as posting blogposts on linkedin applies - of course - to medium. Static Site Generators with AsciiDoc support Toter der Woche Google Pixel 3a Untoter der Woche notepads Windows Notepad Ursache Markdown feature Microsoft seite Notepad++ AI der Woche AI agent seemingly tries to shame open source developer for rejected pull request AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty) Selfish AI Anthropic raises $30B Series G funding at $380B post-money valuation (Anthropic) Nvidia shares are down after a report that its OpenAI investment stalled. Here's what's happening News Wero: Commerzbank macht mit

Security Conversations
Palo Alto and the uncomfortable politics of APT attribution

Security Conversations

Play Episode Listen Later Feb 13, 2026 150:30


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 85: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft's zero-day treadmill and AI-enabled attack surfaces; and Apple's “extremely sophisticated” iOS exploits. Plus, Europe's growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Cyber Briefing
February 13, 2026 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Feb 13, 2026 7:59


If you like what you hear, please subscribe, leave us a review and tell a friend!

2.5 Admins
2.5 Admins 286: Windows Crashed

2.5 Admins

Play Episode Listen Later Feb 12, 2026 25:41


Notepad++ falls victim to a state-sponsored attacker, AI agents talk nonsense to each other on an insecure vibe coded social network, and backing up a laptop properly. Plugs Support us on patreon and get an ad-free RSS feed with early episodes sometimes ZFS vs Btrfs: Architecture, Features, and Stability News/discussion Notepad++ Hijacked by State-Sponsored Hackers AI agents now have their own Reddit-style social network, and it’s getting weird fas Hacking Moltbook: AI Social Network Reveals 1.5M API Keys Free consulting We were asked about backing up a laptop properly. See our contact page for ways to get in touch.

Privacy Please
S7, E265 - Don't Trust, Verify: Even Your Update Button Might Be Lying

Privacy Please

Play Episode Listen Later Feb 12, 2026 26:25 Transcription Available


Send a textAutonomy sounds like progress until the system turns your choices against you. We dive into how AI agents change the risk equation, why “don't trust, verify” now beats “trust but verify,” and what to do when the update button itself becomes the attack vector.We start with the Ivy League leak tied to Harvard and UPenn, where attackers exposed admissions hold notes that map influence rather than credit cards. That context turns routine records into leverage for extortion, social pressure, and geopolitical targeting. From there, we trace the surge of agentic AI in the workplace as employees paste code, legal docs, and sensitive files into chat interfaces. The real accelerant is MCP, the model context protocol that standardizes connections across Google Drive, Slack, databases, and more. Like USB for AI, MCP makes integration simple and powerful, but a single prompt injection can pivot across everything the agent can reach.Security gets messier with supply chain compromise. A China‑nexus campaign allegedly hijacked the Notepad++ update mechanism, handing a bespoke backdoor to developers who did the right thing. We unpack how to keep patching while reducing risk: signed updates, independent checksum checks, tight egress policies for updaters, and strong monitoring around update flows. On the policy front, Rhode Island's vendor transparency rule forces companies to name who buys data. It is a nutrition label for privacy, and it lets users and watchdogs finally connect the dots between friendly interfaces and aggressive brokers.We close with concrete defenses that raise the floor. Move high‑value accounts to FIDO2 hardware keys or platform passkeys to block phishing at the protocol level. Scope agent permissions narrowly, isolate MCP connectors by function, and require explicit approvals for sensitive actions. Log everything an agent touches and review those trails. Autonomy should be earned, minimal, and observable. If AI is going to act on your behalf, it must prove itself at every step.If this conversation helps you think differently about agents, influence mapping, and how to lock down your stack, subscribe, share with a teammate, and leave a quick review telling us the one control you plan to implement this week.Support the show

Late Night Linux All Episodes
2.5 Admins 286: Windows Crashed

Late Night Linux All Episodes

Play Episode Listen Later Feb 12, 2026 25:41


Notepad++ falls victim to a state-sponsored attacker, AI agents talk nonsense to each other on an insecure vibe coded social network, and backing up a laptop properly. Plugs Support us on patreon and get an ad-free RSS feed with early episodes sometimes ZFS vs Btrfs: Architecture, Features, and Stability News/discussion Notepad++ Hijacked by State-Sponsored Hackers AI agents now have their own Reddit-style social network, and it’s getting weird fas Hacking Moltbook: AI Social Network Reveals 1.5M API Keys Free consulting We were asked about backing up a laptop properly. See our contact page for ways to get in touch.

The CyberWire
When Windows breaks and chips crack.

The CyberWire

Play Episode Listen Later Feb 11, 2026 32:40


Patch Tuesday. Preliminary findings from the European Commission come down on TikTok. Switzerland's military cancels its contract with Palantir. Social engineering leads to payroll fraud. Google hands over extensive personal data on a British student activist. Researchers unearth a global espionage operation called “The Shadow Campaigns.” Notepad's newest features could lead to remote code execution. Our guest is Hazel Cerra, Resident Agent in Charge of the Atlantic City Office for the United States Secret Service. Ring says it's all about dogs, but critics hear the whistle. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, we're joined by Hazel Cerra, Resident Agent in Charge of the Atlantic City Office for the United States Secret Service, as she discusses the evolution of the Secret Service's investigative mission—from its early focus on financial crimes such as counterfeit currency and credit card fraud to the growing challenges posed by cryptocurrency-related crime. Selected Reading Microsoft February 2026 Patch Tuesday Fixes 58 Vulnerabilities, Six actively Exploited Flaws (Beyond Machines) Adobe Releases February 2026 Patches for Multiple Products (Beyond Machines) ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, Phoenix Contact (SecurityWeek) Chipmaker Patch Tuesday: Over 80 Vulnerabilities Addressed by Intel and AMD (SecurityWeek) Commission preliminarily finds TikTok's addictive design in breach of the Digital Services Act (European Commission) Palantir's Swiss Exit Highlights Global Data Sovereignty Challenge (NewsCase) Payroll pirates conned the help desk, stole employee's pay (The Register) Google Fulfilled ICE Subpoena Demanding Student Journalist's Bank and Credit Card Numbers (The Intercept) The Shadow Campaigns: Uncovering Global Espionage (Palo Alto Networks Unit 42) Notepad's new Markdown powers served with a side of RCE (The Register) With Ring, American Consumers Built a Surveillance Dragnet (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Packet Pushers - Full Podcast Feed
PP096: Taking Note of a Notepad++ Attack; Telnet and NTLM Are Still a Thing?

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Feb 10, 2026 51:18


Everything old is new again in today’s Packet Protector news roundup, as a decade-old Telnet exploit resurfaces, and Microsoft unfolds its roadmap to phase out the ancient NTLM protocol. In other news, Google takes down a sprawling residential proxy network, the popular Notepad++ app takes steps to recover from a serious compromise, and a Polish... Read more »

Packet Pushers - Fat Pipe
PP096: Taking Note of a Notepad++ Attack; Telnet and NTLM Are Still a Thing?

Packet Pushers - Fat Pipe

Play Episode Listen Later Feb 10, 2026 51:18


Everything old is new again in today’s Packet Protector news roundup, as a decade-old Telnet exploit resurfaces, and Microsoft unfolds its roadmap to phase out the ancient NTLM protocol. In other news, Google takes down a sprawling residential proxy network, the popular Notepad++ app takes steps to recover from a serious compromise, and a Polish... Read more »

This Week in Tech (Audio)
TWiT 1070: A Yacht for Your Yacht - Super Bowl LX Gets a Surge of AI Ads!

This Week in Tech (Audio)

Play Episode Listen Later Feb 9, 2026


Will Elon Musk really launch a million data centers into orbit, and why is McDonald's so worried about you using "McNuggets" as your password? This week's tech roundtable takes on wild new frontiers and everyday security headaches with insight and a bit of irreverence. More schools are banning phones so students can focus. Ohio's results show it's not that simple After Australia, Which Countries Could Be Next to Ban Social Media for Children EU says TikTok must disable 'addictive' features like infinite scroll, fix its recommendation engine Anthropic and OpenAI release dueling AI models on the same day in an escalating rivalry Sam Altman says Anthropic's Super Bowl spot is 'dishonest' about ChatGPT ads, but he agrees it's funny Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source code Alphabet reports Q4 2025 revenue of $113.8 billion Amazon's blowout $200 billion AI spending plan stuns Wall Street A New Gilded Age: Big Tech goes on a $600 billion AI spending splurge Hidden Cameras in Chinese Hotels Are Livestreaming Guests To Thousands of Telegram Subscribers AI-generated ads hit the Super Bowl SpaceX acquires xAI, plans to launch a massive satellite constellation to power it Russia suspected of intercepting EU satellites Notepad++ hijacked by state-sponsored actors New York Wants to Ctrl+Alt+Delete Your 3D Printer Western Digital Plots a Path To 140 TB Hard Drives Using Vertical Lasers and 14-Platter Designs A Crisis comes to Wordle: Reusing old words The Wayback Machine debuts a new plug-in designed to fix the internet's broken links problem Project Hail Mary is getting its own LEGO set Dave Farber Host: Leo Laporte Guests: Larry Magid, Mike Elgan, and Louis Maresca Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT meter.com/twit trustedtech.team/twitCSS zscaler.com/security

This Week in Tech (Video HI)
TWiT 1070: A Yacht for Your Yacht - Super Bowl LX Gets a Surge of AI Ads!

This Week in Tech (Video HI)

Play Episode Listen Later Feb 9, 2026


Will Elon Musk really launch a million data centers into orbit, and why is McDonald's so worried about you using "McNuggets" as your password? This week's tech roundtable takes on wild new frontiers and everyday security headaches with insight and a bit of irreverence. More schools are banning phones so students can focus. Ohio's results show it's not that simple After Australia, Which Countries Could Be Next to Ban Social Media for Children EU says TikTok must disable 'addictive' features like infinite scroll, fix its recommendation engine Anthropic and OpenAI release dueling AI models on the same day in an escalating rivalry Sam Altman says Anthropic's Super Bowl spot is 'dishonest' about ChatGPT ads, but he agrees it's funny Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source code Alphabet reports Q4 2025 revenue of $113.8 billion Amazon's blowout $200 billion AI spending plan stuns Wall Street A New Gilded Age: Big Tech goes on a $600 billion AI spending splurge Hidden Cameras in Chinese Hotels Are Livestreaming Guests To Thousands of Telegram Subscribers AI-generated ads hit the Super Bowl SpaceX acquires xAI, plans to launch a massive satellite constellation to power it Russia suspected of intercepting EU satellites Notepad++ hijacked by state-sponsored actors New York Wants to Ctrl+Alt+Delete Your 3D Printer Western Digital Plots a Path To 140 TB Hard Drives Using Vertical Lasers and 14-Platter Designs A Crisis comes to Wordle: Reusing old words The Wayback Machine debuts a new plug-in designed to fix the internet's broken links problem Project Hail Mary is getting its own LEGO set Dave Farber Host: Leo Laporte Guests: Larry Magid, Mike Elgan, and Louis Maresca Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT meter.com/twit trustedtech.team/twitCSS zscaler.com/security

All TWiT.tv Shows (MP3)
This Week in Tech 1070: A Yacht for Your Yacht

All TWiT.tv Shows (MP3)

Play Episode Listen Later Feb 9, 2026 148:39


Will Elon Musk really launch a million data centers into orbit, and why is McDonald's so worried about you using "McNuggets" as your password? This week's tech roundtable takes on wild new frontiers and everyday security headaches with insight and a bit of irreverence. More schools are banning phones so students can focus. Ohio's results show it's not that simple After Australia, Which Countries Could Be Next to Ban Social Media for Children EU says TikTok must disable 'addictive' features like infinite scroll, fix its recommendation engine Anthropic and OpenAI release dueling AI models on the same day in an escalating rivalry Sam Altman says Anthropic's Super Bowl spot is 'dishonest' about ChatGPT ads, but he agrees it's funny Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source code Alphabet reports Q4 2025 revenue of $113.8 billion Amazon's blowout $200 billion AI spending plan stuns Wall Street A New Gilded Age: Big Tech goes on a $600 billion AI spending splurge Hidden Cameras in Chinese Hotels Are Livestreaming Guests To Thousands of Telegram Subscribers AI-generated ads hit the Super Bowl SpaceX acquires xAI, plans to launch a massive satellite constellation to power it Russia suspected of intercepting EU satellites Notepad++ hijacked by state-sponsored actors New York Wants to Ctrl+Alt+Delete Your 3D Printer Western Digital Plots a Path To 140 TB Hard Drives Using Vertical Lasers and 14-Platter Designs A Crisis comes to Wordle: Reusing old words The Wayback Machine debuts a new plug-in designed to fix the internet's broken links problem Project Hail Mary is getting its own LEGO set Dave Farber Host: Leo Laporte Guests: Larry Magid, Mike Elgan, and Louis Maresca Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT meter.com/twit trustedtech.team/twitCSS zscaler.com/security

Radio Leo (Audio)
This Week in Tech 1070: A Yacht for Your Yacht

Radio Leo (Audio)

Play Episode Listen Later Feb 9, 2026 148:39


Will Elon Musk really launch a million data centers into orbit, and why is McDonald's so worried about you using "McNuggets" as your password? This week's tech roundtable takes on wild new frontiers and everyday security headaches with insight and a bit of irreverence. More schools are banning phones so students can focus. Ohio's results show it's not that simple After Australia, Which Countries Could Be Next to Ban Social Media for Children EU says TikTok must disable 'addictive' features like infinite scroll, fix its recommendation engine Anthropic and OpenAI release dueling AI models on the same day in an escalating rivalry Sam Altman says Anthropic's Super Bowl spot is 'dishonest' about ChatGPT ads, but he agrees it's funny Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source code Alphabet reports Q4 2025 revenue of $113.8 billion Amazon's blowout $200 billion AI spending plan stuns Wall Street A New Gilded Age: Big Tech goes on a $600 billion AI spending splurge Hidden Cameras in Chinese Hotels Are Livestreaming Guests To Thousands of Telegram Subscribers AI-generated ads hit the Super Bowl SpaceX acquires xAI, plans to launch a massive satellite constellation to power it Russia suspected of intercepting EU satellites Notepad++ hijacked by state-sponsored actors New York Wants to Ctrl+Alt+Delete Your 3D Printer Western Digital Plots a Path To 140 TB Hard Drives Using Vertical Lasers and 14-Platter Designs A Crisis comes to Wordle: Reusing old words The Wayback Machine debuts a new plug-in designed to fix the internet's broken links problem Project Hail Mary is getting its own LEGO set Dave Farber Host: Leo Laporte Guests: Larry Magid, Mike Elgan, and Louis Maresca Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT meter.com/twit trustedtech.team/twitCSS zscaler.com/security

The Cybersecurity Defenders Podcast
#291 - Intel Chat: OpenClaw saga continues, React Native Community vulnerability, Notepad++ & GTIG targets IPIDEA proxy network

The Cybersecurity Defenders Podcast

Play Episode Listen Later Feb 9, 2026 28:23


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.OpenClaw, an open source AI agent formerly known as MoltBot and ClawdBot, has rapidly become the fastest-growing project on GitHub, amassing over 113,000 stars in under a week.A critical vulnerability in the React Native Community CLI NPM package, tracked as CVE-2025-11953 with a CVSS score of 9.8, has been actively exploited in the wild since late December 2025, according to new findings by VulnCheck. JFrog article.Following the disclosure in the Notepad++ v8.8.9 release announcement, further investigation confirmed a sophisticated supply chain attack that targeted the application's update mechanism.Google, in coordination with multiple partners, has undertaken a large-scale disruption effort targeting the IPIDEA proxy network, which it identifies as one of the largest residential proxy networks globally.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

DOU Podcast
Домен за за $70 млн | «Білий список» Starlink | Серіал Baldur's Gate 3 від HBO — DOU News #236

DOU Podcast

Play Episode Listen Later Feb 9, 2026 40:59


У свіжому дайджесті DOU News аналізуємо свіжий звіт про зарплати Data Science та обговорюємо мега-угоду Ілона Маска. Також у випуску: обов'язкова реєстрація Starlink в Україні через «Дію» та ЦНАПи, український стартап Swarmer іде на IPO, та анонс серіалу за мотивами Baldur's Gate 3 від творця «The Last of Us». Дивіться ці та інші новини українського та глобального тек-сектору. Таймкоди 00:00 Інтро 00:21 Зарплати дата-фахівців: у AI Engineer знижуються, у Product Analyst зростають 04:32 Обов'язкова верифікація Starlink 09:13 Український дефтек-стартап Swarmer готується до IPO 11:02 Столи з електрорегулюванням висоти, зручні крісла та аксесуари STIYSTIL 12:15 ПДВ для ФОПів: мінімальний поріг на дохід можуть підняти 13:18 Збір DOU та KOLO для НГУ 14:33 SpaceX купує xAI за $1,25 трлн 17:46 Злам Notepad++: як хакери підмінили систему оновлень популярного редактора 19:31 OpenClaw та «жахи» безпеки: чому ШІ-скіли можуть вкрасти ваші дані 23:42 ЄС проти TikTok: алгоритми нескінченної стрічки визнали незаконними 26:16 Рекордний продаж домену AI.com за $70 млн 27:58 Битва на Super Bowl: OpenAI Codex проти Anthropic Claude 30:14 Релізи тижня: Claude Opus 4.6 та OpenAI GPT-5.3-Codex 34:06 Xcode 26.3: Apple додає підтримку «vibe coding» 35:53 Valve відкладає Steam Machine через дефіцит пам'яті 37:23 HBO анонсувала серіал Baldur's Gate 3 38:44 Що рекомендує Женя: AI 2027 та відео «I shipped code I don't understand»

PEBCAK Podcast: Information Security News by Some All Around Good People
Episode 241 - Open Claw, Moltbot, Clawdbot, NotePad++ Supply Chain Attack, Microsoft Ending MTLM, Brian's Food Travels

PEBCAK Podcast: Information Security News by Some All Around Good People

Play Episode Listen Later Feb 9, 2026 58:56


Welcome to this week's episode of the PEBCAK Podcast!  We've got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link https://simple6.co/r/CFUR98   Open Claw https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/  https://www.bleepingcomputer.com/news/security/viral-moltbot-ai-assistant-raises-concerns-over-data-security/    Notepad++ update servers hijacked in supply chain attack https://notepad-plus-plus.org/news/hijacked-incident-info-update/  https://www.bleepingcomputer.com/news/security/notepad-plus-plus-update-feature-hijacked-by-chinese-state-hackers-for-months/  https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/    Microsoft deprecating NTLM https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526 https://www.bleepingcomputer.com/news/microsoft/microsoft-to-disable-ntlm-by-default-in-future-windows-releases/   Carrot tartare https://www.foodrepublic.com/recipes/very-veggie-make-this-ethiopian-carrot-tartare/   Dad Joke of the Week (DJOW)   Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/ Glenn - https://www.linkedin.com/in/glennmedina/ Kush - https://www.linkedin.com/in/kushaagra/

All TWiT.tv Shows (Video LO)
This Week in Tech 1070: A Yacht for Your Yacht

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Feb 9, 2026 148:39 Transcription Available


Will Elon Musk really launch a million data centers into orbit, and why is McDonald's so worried about you using "McNuggets" as your password? This week's tech roundtable takes on wild new frontiers and everyday security headaches with insight and a bit of irreverence. More schools are banning phones so students can focus. Ohio's results show it's not that simple After Australia, Which Countries Could Be Next to Ban Social Media for Children EU says TikTok must disable 'addictive' features like infinite scroll, fix its recommendation engine Anthropic and OpenAI release dueling AI models on the same day in an escalating rivalry Sam Altman says Anthropic's Super Bowl spot is 'dishonest' about ChatGPT ads, but he agrees it's funny Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source code Alphabet reports Q4 2025 revenue of $113.8 billion Amazon's blowout $200 billion AI spending plan stuns Wall Street A New Gilded Age: Big Tech goes on a $600 billion AI spending splurge Hidden Cameras in Chinese Hotels Are Livestreaming Guests To Thousands of Telegram Subscribers AI-generated ads hit the Super Bowl SpaceX acquires xAI, plans to launch a massive satellite constellation to power it Russia suspected of intercepting EU satellites Notepad++ hijacked by state-sponsored actors New York Wants to Ctrl+Alt+Delete Your 3D Printer Western Digital Plots a Path To 140 TB Hard Drives Using Vertical Lasers and 14-Platter Designs A Crisis comes to Wordle: Reusing old words The Wayback Machine debuts a new plug-in designed to fix the internet's broken links problem Project Hail Mary is getting its own LEGO set Dave Farber Host: Leo Laporte Guests: Larry Magid, Mike Elgan, and Louis Maresca Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit NetSuite.com/TWIT meter.com/twit trustedtech.team/twitCSS zscaler.com/security

Security Conversations
From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks

Security Conversations

Play Episode Listen Later Feb 8, 2026 137:38


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 84: We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft's security executive changes, Anthropic's AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Paul's Security Weekly
AI: No One Is Safe - PSW #912

Paul's Security Weekly

Play Episode Listen Later Feb 5, 2026 125:37


In the security news this week: Residential proxy abuse is everywhere this week: from Google's takedown of IPIDEA to massive Citrix NetScaler scanning and the Badbox 2.0 botnet Supply chain fun time: Notepad++ updates were hijacked Attackers set their sights on: Ivanti EPMM, Dell Unity storage, Fortinet VPNs/firewalls, and ASUSTOR NAS devices Russian state hackers went after Poland's grid Is ICE on a surveillance shopping spree and into hacking anti-ICE apps? Ukraine's war-time Starlink problem is turning into a policy and controls experiment The AI security theme is alive and well with exposed LLM endpoints, OpenClaw/Moltbot/Moltbook fiasco, and letting anyone hijack agents Signed forensic driver for Windows is still an EDR killer The Trump administration's rollback of software security attestation National Cyber Director Sean Cairncross says: “less regulation, more cooperation.” Finally, there are some “only in infosec” human stories: * pen testers arrested in Iowa now getting a settlement, * a Google engineer convicted over stolen AI IP, * Booz Allen losing Treasury work over intentional insider leaks, * and an “AI psychosis” saga at an adult-content platform. Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-912

Geekshow Podcast
Geekshow Helpdesk: Bubble Blowing

Geekshow Podcast

Play Episode Listen Later Feb 5, 2026 57:28


-Carbonation Station: Ghost Blue Raspberry (New New) and New Blue Red Bull Iced Vanilla Berry -Artemis 2 pushed back: https://www.engadget.com/science/space/nasa-moves-artemis-2-launch-to-march-after-hydrogen-leak-during-testing-140000351.html -Elon's Shell Game Continues: https://www.engadget.com/ai/elon-musks-spacex-has-acquired-his-ai-company-xai-221617040.html Jarron:  -Bitcoin's selloff seems different this time: https://slashdot.org/story/26/02/01/2146224/bitcoin-drops-40-in-four-months-bloomberg-blames-absence-of-buyers-and-belief?utm_source=rss0.9mainlinkanon&utm_medium=feed -Walmart rolling out EV charging nationwide: https://tech.slashdot.org/story/26/02/01/1959234/walmart-begins-building-out-nationwide-ev-charging-network-across-america?utm_source=rss0.9mainlinkanon&utm_medium=feed -Lemonade cuts rates 50% for FSD: https://tech.slashdot.org/story/26/01/24/0736248/us-insurer-lemonade-cuts-rates-50-for-drivers-using-teslas-full-self-driving-software?utm_source=rss0.9mainlinkanon&utm_medium=feed -THE PENCILVAC IS OUT! https://www.theverge.com/tech/872981/dyson-pencilvac-fluffycones-vacuum-hands-on-review Owen: -Not quite the end of the “Line” https://news.slashdot.org/story/26/01/26/1528240/saudi-arabia-to-scale-back-neom-megaproject -Update your Notepad++ manually. https://notepad-plus-plus.org/news/hijacked-incident-info-update/ -Solar panels? Nah Lunar Panels! https://www.extremetech.com/science/reverse-solar-panel-generates-electricity-at-night -Have you checked to see if you're in the Epstein files? Another dump of the Epstein files go public and wooooah baby. https://www.justice.gov/epstein

Paul's Security Weekly TV
AI: No One Is Safe - PSW #912

Paul's Security Weekly TV

Play Episode Listen Later Feb 5, 2026 125:37


In the security news this week: Residential proxy abuse is everywhere this week: from Google's takedown of IPIDEA to massive Citrix NetScaler scanning and the Badbox 2.0 botnet Supply chain fun time: Notepad++ updates were hijacked Attackers set their sights on: Ivanti EPMM, Dell Unity storage, Fortinet VPNs/firewalls, and ASUSTOR NAS devices Russian state hackers went after Poland's grid Is ICE on a surveillance shopping spree and into hacking anti-ICE apps? Ukraine's war-time Starlink problem is turning into a policy and controls experiment The AI security theme is alive and well with exposed LLM endpoints, OpenClaw/Moltbot/Moltbook fiasco, and letting anyone hijack agents Signed forensic driver for Windows is still an EDR killer The Trump administration's rollback of software security attestation National Cyber Director Sean Cairncross says: "less regulation, more cooperation." Finally, there are some "only in infosec" human stories: * pen testers arrested in Iowa now getting a settlement, * a Google engineer convicted over stolen AI IP, * Booz Allen losing Treasury work over intentional insider leaks, * and an "AI psychosis" saga at an adult-content platform. Show Notes: https://securityweekly.com/psw-912

Security Now (MP3)
SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

Security Now (MP3)

Play Episode Listen Later Feb 4, 2026 175:34


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

Risky Business
Risky Business #823 -- Humans impersonate clawdbots impersonating humans

Risky Business

Play Episode Listen Later Feb 4, 2026 56:09


Patrick Gray and Adam Boileau are joined by the newest guy on the Risky Business Media team, James WIlson. They discuss the week's cybersecurity news, including: Notepad++ update supply chain attack has been attributed to China The AI agent future is even more stupid than expected; behold the OpenClaw/Clawdbot/Moltbook mess The Epstein files claim he had a personal hacker? Microsoft is finally getting ready to (think about starting to begin to) disable NTLM by default The usual bugs in the usual things! Ivanti, Fortinet, and Solarwinds. Again. Telco hides a free trip in its privacy policy, someone actually reads it and wins! This weeks's episode is sponsored by opensource IDP platform Authentik. CEO Fletcher Heisler talks to Pat about their new endpoint agent that can enforce device posture policies during login. This episode is also available on Youtube. Show notes The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's toolkit Notepad++ Hijacked by State-Sponsored Hackers | Notepad++ Notepad++ v8.8.3 - Self-signed Certificate: Certified by Code, Not Corporations | Notepad++ Hacking Moltbook: AI Social Network Reveals 1.5M API Keys | Wiz Blog lcamtuf on X: "Moltbook debate in a nutshell" / X Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site AndrewMohawk on X: "How exactly did an attacker send a message to your bot since you need to approve all the channels and set keys etc" / X Signal president warns AI agents are making encryption irrelevant Massive AI Chat App Leaked Millions of Users Private Conversations Runa Sandvik on X: New court record from the FBI details the state of the devices seized from Washington Post reporter Hannah Natanson EFTA01683874.pdf Disrupting the World's Largest Residential Proxy Network | Google Cloud Blog Nobel Committee says Peace Prize winner likely revealed early by digital spying | Reuters County pays $600,000 to pentesters it arrested for assessing courthouse security - Ars Technica Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog Critical flaws in Ivanti EPMM lead to fast-moving exploitation attempts | Cybersecurity Dive CISA orders federal agencies to patch exploited SolarWinds bug by Friday | The Record from Recorded Future News CISA, security researchers warn FortiCloud SSO flaw is under attack | Cybersecurity Dive Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach | TechCrunch We Hid a Free Trip to Switzerland in Our Privacy Policy. Someone Found It in 2 Weeks. - Cape Between Two Nerds: The internal logic of Russian power grid attacks - YouTube

All TWiT.tv Shows (MP3)
Security Now 1063: Mongo's Too Easy

All TWiT.tv Shows (MP3)

Play Episode Listen Later Feb 4, 2026 175:34


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

Security Now (Video HD)
SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

Security Now (Video HD)

Play Episode Listen Later Feb 4, 2026


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

Security Now (Video HI)
SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

Security Now (Video HI)

Play Episode Listen Later Feb 4, 2026


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

Radio Leo (Audio)
Security Now 1063: Mongo's Too Easy

Radio Leo (Audio)

Play Episode Listen Later Feb 4, 2026 175:34


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

Security Now (Video LO)
SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

Security Now (Video LO)

Play Episode Listen Later Feb 4, 2026


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

All TWiT.tv Shows (Video LO)
Security Now 1063: Mongo's Too Easy

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Feb 4, 2026 175:34 Transcription Available


When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Feb 3, 2026 6:25


Scanning for exposed Anthropic Models https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674 Notepad++ Hijacked by State-Sponsored Hackers https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ https://notepad-plus-plus.org/news/hijacked-incident-info-update/ Insecure Websockets in OpenClaw https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability Malicious OpenClaw Skills https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting Exposed OpenClaw Instances https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant

TechLinked
Firefox AI kill switch, SpaceX sats, xAI merger, Notepad++ hack + more!

TechLinked

Play Episode Listen Later Feb 3, 2026 10:30


Timestamps: 0:00 i saw the soup, and it opened up... 0:09 Firefox announces AI kill switch 2:02 SpaceX 1M+ satellites, xAI merger 3:44 Notepad++ hack, patch 5:36 QUICK BITS INTRO 5:47 Apple store adds Mac customization 6:30 iOS 26.3 location privacy feature 7:11 Fire TV sideloading crackdown 7:54 Moto G17 gets no OS updates 8:51 Hair computers! NEWS SOURCES: https://lmg.gg/54TmY Learn more about your ad choices. Visit megaphone.fm/adchoices

Paul's Security Weekly
DBII, Notepad++, Covenant, Fancy Bear, CTFs, Firefox, AI Slop, Josh Marpet, and More - SWN #552

Paul's Security Weekly

Play Episode Listen Later Feb 3, 2026 36:43


DBII, Notepad++, Covenant, Fancy Bear, CTFs, Firefox, AI Slop, Josh Marpet, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-552

The Cloud Pod
341: AWS Layoffs: Scaling Down Instead of Scaling Out

The Cloud Pod

Play Episode Listen Later Feb 3, 2026 73:29


Welcome to episode 341 of The Cloud Pod, where the forecast is always cloudy! Matt & Ryan are picking up Justin's slack this week while he's traveling for work, but don't worry, because they have plenty of news! We're talking about those mass layoffs over at AWS, a major security breach over at Notepad++, and some new slight of hand over at Elon's companies. There's a lot to cover, so let's get into it!  Titles we almost went with this week Finally, a Chatbot That Actually Knows Where Your Data Lives **Anthropic Microsoft Adds Security Analyzer to MSSQL Extension: Because Bobby Tables Jokes Are Only Funny Until They Happen to You From Sequential Sadness to Parallel Paradise: GKE Node Pools Get Concurrent From Vibe Coding to Production: AWS MCP Server Gets SOPs One Prompt to Deploy Them All: AWS MCP Server Automates Infrastructure AWS Layoffs: Scaling Down Instead of Scaling Out Mutual TLS: Because CloudFront and Your Origin Need Couples Therapy Claude Team Plan: Now With More Seats and Less Bills From Snowflake to Snowball: Rolling Data and Dev Into One Platform From Notepad++ to Notepad Pwned: A Six-Month Hosting Horror Story EventBridge Payload Capacity Gets a 4x Upgrade: No More Event Splitting Headaches CloudFront Finally Learns to Check ID Before Knocking on Origin’s Door General News  01:30 SpaceX acquires xAI, plans to launch a massive satellite constellation to power it – Ars Technica SpaceX has acquired xAI to create a vertically integrated AI and space infrastructure company, with plans to deploy up to 1 million satellites as orbital data centers.  This represents a significant bet that space-based compute infrastructure can be cost-competitive with traditional ground-based data centers for AI workloads. The merger combines SpaceX’s launch capabilities and satellite manufacturing expertise with xAI’s Grok chatbot and X social platform.  The strategy assumes AI demand will continue to grow and that compute capacity, rather than other factors, is the primary bottleneck to AI adoption. The orbital data center concept raises questions about latency, power requirements, thermal management, and maintenance compared to terrestrial facilities.  Traditional cloud providers have invested heavily in ground-based infrastructure optimized for these factors. This consolidation of Musk’s companies creates potential conflicts between SpaceX’s established government and commercial contracts and xAI’s more controversial products.  The integration of a proven aerospace company with a newer AI venture introduces execution risk to SpaceX’s core business. The plan depends on several unproven assumptions, including sustained AI market growth, viable economics for space-based computing, and the ability to manufacture and launch satellite

Hacker News Recap
February 2nd, 2026 | Notepad++ hijacked by state-sponsored actors

Hacker News Recap

Play Episode Listen Later Feb 3, 2026 15:02


This is a recap of the top 10 posts on Hacker News on February 02, 2026. This podcast was generated by wondercraft.ai (00:30): Notepad++ hijacked by state-sponsored actorsOriginal post: https://news.ycombinator.com/item?id=46851548&utm_source=wondercraft_ai(01:55): The Codex AppOriginal post: https://news.ycombinator.com/item?id=46859054&utm_source=wondercraft_ai(03:21): xAI joins SpaceXOriginal post: https://news.ycombinator.com/item?id=46862170&utm_source=wondercraft_ai(04:47): Show HN: Wikipedia as a doomscrollable social media feedOriginal post: https://news.ycombinator.com/item?id=46850803&utm_source=wondercraft_ai(06:12): Claude Code is suddenly everywhere inside MicrosoftOriginal post: https://news.ycombinator.com/item?id=46854999&utm_source=wondercraft_ai(07:38): Todd C. Miller – Sudo maintainer for over 30 yearsOriginal post: https://news.ycombinator.com/item?id=46858577&utm_source=wondercraft_ai(09:04): TermuxOriginal post: https://news.ycombinator.com/item?id=46854642&utm_source=wondercraft_ai(10:30): The TSA's New $45 Fee to Fly Without ID Is IllegalOriginal post: https://news.ycombinator.com/item?id=46863162&utm_source=wondercraft_ai(11:55): Anki ownership transferred to AnkiHubOriginal post: https://news.ycombinator.com/item?id=46861313&utm_source=wondercraft_ai(13:21): Court orders restart of all US offshore wind power constructionOriginal post: https://news.ycombinator.com/item?id=46863112&utm_source=wondercraft_aiThis is a third-party project, independent from HN and YC. Text and audio generated using AI, by wondercraft.ai. Create your own studio quality podcast with text as the only input in seconds at app.wondercraft.ai. Issues or feedback? We'd love to hear from you: team@wondercraft.ai

Cyber Security Headlines
OpenClaw targets ClawHub users, Notepad++ update delivers malware, APT28 attackers abuse Microsoft Office zero-day

Cyber Security Headlines

Play Episode Listen Later Feb 3, 2026 7:25


OpenClaw targets ClawHub users Notepad++ update delivers malware APT28 attackers abuse Microsoft Office zero-day Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-targets-clawhub-users-notepad-update-delivers-malware-apt28-attackers-abuse-microsoft-office-zero-day/ Huge thanks to our sponsor, Strike48 It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.  

The Changelog
The tech monoculture is finally breaking (News)

The Changelog

Play Episode Listen Later Feb 2, 2026 8:46


Jason Willems believes the tech monoculture is finally breaking, Don Ho shares some bad Notepad++ news, Tailscale's Avery Pennarun pens a great downtime apology, Milan Milanović explains why you can only code 4 hours per day, and Addy Osmani on managing comprehension debt when leaning on AI to code.