Podcasts about Phishing

Act of attempting to acquire sensitive information by posing as a trustworthy entity

  • 2,263PODCASTS
  • 5,993EPISODES
  • 32mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 18, 2026LATEST
Phishing

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Phishing

Show all podcasts related to phishing

Latest podcast episodes about Phishing

ENJOYYOURBIKE - Der Radsport & Triathlon Talk
205: Der „Asphalt" Killer! ENVE Melee V2 & iPhone Duo für Bikepacking?

ENJOYYOURBIKE - Der Radsport & Triathlon Talk

Play Episode Listen Later Sep 18, 2026 145:53 Transcription Available


Wir haben schon das neue ENVE Melee V2 2027 auf unserer "Couch"! Es bleibt so schön und zurückhaltend wie der Vorgänger, ist aber technisch viel mehr als nur ein Facelift. Krass, wieviel Neues und vor allem Schnelles in dem Rad steckt ohne die DNA des aktuellen Melees zu verlieren. Außerdem: COROS lässt unerwartet Karten auf die Pace 4! Aktuell ist die Beta-Phase und die ist schon voll, aber es wird nicht mehr lange dauern, dass die beliebteste COROS Uhr wohl noch beliebter wird. Nicht ganz ernst gemeint diskutieren wir außerdem darüber iPhone Duo für Bikepacking ;-) – Es löst irgendwie ein "Will-Haben" bei uns aus und gleichzeitig ist es ein "BRAUCHT MAN NICHT"-Ding. ------------------------------------------------------------ PICKLISTE & PARTNERSHOPS ------------------------------------------------------------ EYB Pickliste aller je gemachten Podcast-Picks: https://docs.google.com/document/d/1UjfitykkrWqKdWUTrYY0JBX-T4Qn8pdSm6RiWlM4j0M/edit?usp=sharing Unsere Partner-Shops: https://www.enjoyyourbike.com/neu/aktuelles/partner-shops/ ------------------------------------------------------------ NORDVPN (Werbung) ------------------------------------------------------------ Exklusiver Deal mit dem Promo-Code enjoyyourbike: 2-Jahres-Tarif + 4 Extra-Monate gratis! Nicht nur VPN – schützt auch vor Phishing, Betrug und Malware. Ein Konto schützt bis zu 10 Geräte. 30-Tage-Geld-zurück-Garantie. https://nordvpn.com/enjoyyourbike ------------------------------------------------------------ ALLE INFOS & LINKS ZUR SENDUNG ------------------------------------------------------------ COROS Pace 4 Pro – Karten kommen: https://coros.com/de/stories/coros-metrics/c/september-2026 iPhone Duo: https://www.apple.com/de/iphone-duo/ Ortlieb Tidura – neues Eigengewebe: https://de.ortlieb.com/collections/tidura ENVE Melee V2 2027: https://www.enjoyyourbike.com/detail/index/sArticle/30434/sCategory/2092177 Formel Reifenumfang: (622 + 2 × Reifenbreite × 0,85) × π = Reifenumfang in mm ------------------------------------------------------------ PICKS ------------------------------------------------------------ Brot Topping: https://www.spicebar.de/crunchy-brot-topping Other Means – Das Fahrradmagazin: https://othermeansmag.com/ ------------------------------------------------------------ INHALT ------------------------------------------------------------ 00:00:00 Intro 00:01:58 Reifenumfang – Ingo und André rechnen sich um Kopf und Kragen 00:10:43 COROS Pace 4 bekommt Karten – Pace 4 Pro Teaser 00:28:36 NordVPN (Werbung) 00:33:47 iPhone Duo – Arbeiten auf Reisen? 00:57:37 TPU mit Dichtmilch beim Pendeln 01:16:58 Ortlieb entwickelt eigenes Gewebe: Tidura 01:19:27 ENVE Melee V2 2027 – für viele der Tarmac-Killer! 01:45:28 Picks 01:56:31 Preshow: Dating Apps

Paul's Security Weekly
AI hates CAPTCHAs - PSW #944

Paul's Security Weekly

Play Episode Listen Later Sep 17, 2026 124:21


In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-944

Paul's Security Weekly TV
AI hates CAPTCHAs - PSW #944

Paul's Security Weekly TV

Play Episode Listen Later Sep 17, 2026 124:21


In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Show Notes: https://securityweekly.com/psw-944

Tech Gumbo
Guest Segment (Part 2) - LSU CISO Sumit Jain on Security Tools, Phishing's Persistent Threat, AI-Powered Threat Detection, and the Real Risk of LLM's on Campus

Tech Gumbo

Play Episode Listen Later Sep 17, 2026 22:04


Interview Highlights: A Layered Toolset: LSU runs dual EDR platforms (Microsoft Defender and CrowdStrike), Splunk as its SIEM for log management, and Splunk SOAR (via partner TekStream) to coordinate incident response across the statewide SOC program. Phishing Remains Enemy #1: Across higher ed generally, phishing is the top entry point for attackers; Jain recalled a pre-MFA, pre-COVID incident where compromised accounts cascaded across multiple universities, forcing account suspensions every five minutes. AI on the Email Front Line: LSU uses AI specifically to catch executive impersonation—fake emails posing as the chancellor or vendors like Dell requesting changed payment routing numbers—flagging them for review before delivery. On the SOC side, AI builds context around alerts (device mismatches, unusual IP patterns) that a human analyst then validates before escalating—keeping a human in the loop rather than fully automating decisions. Fighting AI With AI—Proactively: LSU deploys honeypots, like a dummy Moodle instance, to lure AI-driven attackers, capture their IPs and techniques, then feed that threat intelligence into production systems to auto-block similar attacks before they happen. The Real AI Risk Is Data, Not the Tool: Jain's biggest concern with staff using ChatGPT, Copilot, or Claude isn't the AI itself—it's uploading sensitive student, HR, or research data to platforms that may train on it. Louisiana state law bars public institutions from using Chinese-linked LLMs; Jain flagged that individual (non-Enterprise) Cursor licenses can violate this because some underlying models have Chinese ties. Building Homegrown AI Tools: LSU faculty built "MikeGPT," an internal GPT-based tool on Azure, letting departments create custom agents—like one that lets students query a syllabus directly or an in-progress agent that answers questions from an 80-90 page data governance policy. Both hosts agreed that narrow, tailored AI tools solving specific institutional pain points—rather than general chatbot use—represent the most valuable and lowest-risk way to bring AI into daily operations.

Paul's Security Weekly (Podcast-Only)
AI hates CAPTCHAs - PSW #944

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Sep 17, 2026 124:21


In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-944

Paul's Security Weekly (Video-Only)
AI hates CAPTCHAs - PSW #944

Paul's Security Weekly (Video-Only)

Play Episode Listen Later Sep 17, 2026 124:21


In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requirements The real cost of cyberattacks and cybersecurity spending Cyber insurance and improving organizational security Nightmare Eclipse and the release of Windows zero-days Check Point VPN vulnerabilities and perimeter security GitLab security updates and shadow IT Discovering unmanaged GitLab instances Cyberattacks against oil tankers and insider threats VPN patching and implied rules Zero-downtime GitLab updates and version management Running Windows ARM on Apple Silicon with VMware and Parallels Show Notes: https://securityweekly.com/psw-944

The CyberWire
Pedal to the AI metal.

The CyberWire

Play Episode Listen Later Sep 15, 2026 28:06


The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida's Department of Highway Safety and Motor Vehicles and Japan's Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we're joined by Camille Stewart Gloster, author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. We'll discuss her new book and the broader questions it raises about AI agents. You can learn more about "The Insider You Built” here. Selected Reading Trump pushes back on Anthropic CEO's call for an AI slowdown (SC Media) Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints (SecurityWeek) Microsoft releases emergency Windows updates to fix RDS failures (Bleeping Computer) This bill could reshape crypto in America -- and it's sparking a major battle (NPR) Florida Department of Highway Safety hacked by international criminal group (WPTV) 240,000 Hit by Data Breach at Japan's Digital Agency (SecurityWeek) VBSpam comparative review - Q3 (Virus Bulletin) New York Seizes 12 Celebrity Deepfake Websites (404 Media) Suspected Black Axe gang leaders face cybercrime charges in the US (Bleeping Computer) Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Command Control Power: Apple Tech Support & Business Talk
686: North Korean Remote Job Infiltration, Apple Threat Alerts, and Stopping Gift Card Scams

Command Control Power: Apple Tech Support & Business Talk

Play Episode Listen Later Sep 15, 2026 57:42


Joe and Sam discuss a Wall Street Journal documentary on North Korean operatives using stolen identities, AI tools, and U.S. accomplices to gain remote jobs at American companies, including schemes where U.S.-based helpers host shipped laptops for overseas workers, raising financial and data-leak risks. They note interview red flags, AI face/voice masking, and an email pitch offering a U.S. partner for a 50/50 split. Sam updates on trying FDA-approved Closee eye drops for age-related vision issues, finding partial improvement but stopping due to itching/burning and concern over past side effects. They troubleshoot Fireflies AI auto-joining meetings via default settings after easy "Sign in with Microsoft" onboarding. Joe reviews Apple threat notifications, Lockdown Mode effectiveness, verification via account.apple.com, and Consumer Reports resources. Sam outlines KnowBe4 security awareness training and shares a near-miss CEO text gift-card scam stopped by verification.   00:00 Show Kickoff 00:08 Overemployed Meets Espionage 02:04 How the Laptop Proxy Scam Works 04:41 Interview Red Flags and Tests 08:22 AI Voice and Face Spoofing 09:13 Suspicious Joint Venture Email 10:57 Eye Drops Experiment Update 14:42 Fireflies Auto Join Mystery 18:20 Apple Threat Notifications Explained 22:33 Can Attackers Fake Apple Alerts 26:42 Lockdown Mode and Best Practices 28:28 Apple Emergency Resources 29:27 Handling Hard-to-Assess Clients 32:56 Jamf Response Playbook 34:50 Developer Mode Malware Evasion 36:46 Staying Ahead of Scams 38:10 Selling Awareness Training 39:45 KnowBe4 Campaigns and Phishing 45:10 Gift Card Scam Case Study 54:51 Phone-Level Limits and Wrap-Up

Dark Horse Entrepreneur
EP 561 AI Scams Target Make Money Online Seekers | The ChatGPT Breach Explained

Dark Horse Entrepreneur

Play Episode Listen Later Sep 14, 2026 14:08


The Dark Side of ChatGPT: 100,000+ Accounts Compromised, AI Scams, Deepfakes & How to Protect Yourself Make money online safely with AI—but first, secure your accounts. Tracy reveals how 101,000+ ChatGPT users fell victim to credential theft and darkweb sale of logins. Learn why people searching for AI entrepreneur opportunities are being targeted by large-scale scams, where your data goes, and exactly how to audit and protect your accounts before you lose your side hustle income to hackers.https://DarkHorseEntrepreneur.com Tracy warns that people searching for ways to make money with ChatGPT are being targeted by large-scale scams and credential theft. It cites Group-IB's June 20, 2023 findings that 101,034 infected devices had saved ChatGPT logins, with credentials sold on dark web marketplaces, peaking at nearly 27,000 posted in May 2023; the issue wasn't OpenAI's servers but users downloading fake apps, clicking phishing links, or installing malicious extensions tied to info-stealers like Raccoon, Vidar, and Redline. The host explains why stolen ChatGPT accounts are uniquely risky due to retained chat histories, prompt injection, and sensitive data users paste in, then details fake ChatGPT domains, a reported rise in ChatGPT-mimic attacks, pig-butchering scams using ChatGPT in forced labor compounds, major victim cases, FBI loss statistics, and a $25M deepfake video-call fraud at Arup, ending with practical security steps and a newsletter pitch.Over 100,000 people thought they were learning how to make money with ChatGPT — instead, they woke up to drained accounts, stolen credentials, and their personal data being sold on the dark web. This isn't a conspiracy theory. A Singapore-based cybersecurity firm called Group-IB confirmed it: 101,134 infected devices, compromised ChatGPT logins traded openly on dark web marketplaces, and a single month where nearly 27,000 sets of stolen credentials hit the market all at once. The scale of this AI-powered scam is unlike anything we've seen before — and it's getting worse in 2026.What makes this so terrifying is that OpenAI's servers were never breached. The real vulnerability was the users themselves — people searching for AI money-making opportunities who unknowingly invited credential-stealing malware onto their own devices. India, the U.S., and dozens of other countries were hit hard, with victims having no idea their financial lives were being dismantled in real time. In this episode, we break down exactly how this scam works, who's behind it, and the critical steps you need to take right now to protect yourself before you become the next target. 00:00 AI Money Hype Warning00:49 Credential Theft Exposed02:15 Why ChatGPT Logins Matter02:59 Fake ChatGPT Ecosystems03:59 Classic Investment Trap04:52 Forced Labor Scam Factories06:30 Victims and Real Losses08:17 Deepfakes Hit Businesses08:47 Protect Yourself Now10:17 Next Steps11:27 Whiskered Wisdom Make money with ChatGPT, ChatGPT scams, AI scams, pig butchering, deepfake fraud, prompt injection attacks, fake AI tools, Pig butchering scam, crypto romance scams , AI cybersecurity, phishing, ai side hustle, micro business, ai automation business, online side hustles, business motivation, work from home, business mindset, entrepreneur motivation, entrepreneurship, ai content creation, side hustle ideas, entrepreneur mindset, business tips, how to make money online, make money from home, ai automation agency, AI, AI Tools, ai entrepreneur, make money online, side hustle ideas, make money from home, online side hustles, AI start up ideas, entrepreneur, ai business https://DarkHorseEntrepreneur.com Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

MamStartup Podcast
Jak nie dać się złowić na phishing? – Laura Lipska, Spiree

MamStartup Podcast

Play Episode Listen Later Sep 14, 2026 43:19


Raz po raz słyszymy o wycieku danych i ataku na serwery firmy, z której usług regularnie korzystamy. I niestety, coraz częściej to właśnie informacje o Was padają łupem cyberprzestępców. Wystarczy wspomnieć tutaj niedawną aferę dotyczącą wielkiego wycieku danych MyDr.Czy da się ograniczyć ryzyko kradzieży danych? Czy da się zwiększyć poziom bezpieczeństwa na tyle, aby nie zagrażali nam oszuści i ich phishingowe metody?O to właśnie pytamy Laurę Lipską ze startupu Spiree. To zespół konsultantów cyberbezpieczeństwa oferujący m.in. obsługę incydentów, audyty, pentesty, compliance DORA czy RODO oraz bezpieczeństwo produktów, a jednocześnie rozwija CatPhish — produkt wykorzystujący AI do oceny podejrzanych wiadomości.

Cyber Morning Call
1088 - Kit de phishing por sms dá ao golpista controle da tela da vítima

Cyber Morning Call

Play Episode Listen Later Sep 14, 2026 6:15


Referências do EpisódioSmish. Click. Drained: Inside the Smishing Triad's Phishing CockpitThe Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented EnvironmentDutch NCSC: Critical Check Point VPN flaws exploitation is imminentGitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours“Eye” spy: Cyclops Blink returns with extended capabilitiesRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

refer controle phishing tima tela bianca garcia cyclops blink
Was Bitcoin bringt.
Permabulle gesteht: Sogar ich habe im Crash verkauft | Alex von Frankenberg

Was Bitcoin bringt.

Play Episode Listen Later Sep 11, 2026 72:35 Transcription Available


Ich habe mich mit Alex von Frankenberg zusammengesetzt, um die Marktlage einzuordnen. Wir analysieren, ob der Tiefpunkt bei 60.000 Dollar endgültig hinter uns liegt, warum Alex trotz seiner bullishen Haltung im Sommer kurzzeitig verkauft hat und welche Rolle die massiven Schuldenstände der Staaten sowie die Zinsentwicklung spielen. Außerdem sprechen wir über die Wechselwirkung zwischen dem rasanten KI-Boom und Bitcoin als mathematisch begrenztem Anker, den Umgang mit aktuellen Phishing- und Hardware-Sicherheitsrisiken und werfen einen Blick auf den neuesten Referentenentwurf zur Krypto-Besteuerung in Deutschland.LEADING PARTNER

Breakfast with Refilwe Moloto
Cyber sense, making sense of scams: ATO fraud, when criminals take over your account

Breakfast with Refilwe Moloto

Play Episode Listen Later Sep 11, 2026 8:45 Transcription Available


This week’s Cyber Sense feature looks at ATO, or Account Takeover fraud, and what can happen when criminals gain unauthorised access to a legitimate account. Lester Kiewit speaks to Boikokobetso Makhetlane, also known as Mr Fingerz, a cybersecurity expert, educator, trainer, and TikTok content creator, about some of the ways criminals obtain access, why having an account taken over can be more serious than simply losing a password, and what warning signs users should look out for. Good Morning Cape Town with Lester Kiewit is a podcast of the CapeTalk breakfast show. This programme is your authentic Cape Town wake-up call. Good Morning Cape Town with Lester Kiewit is informative, enlightening and accessible. The team’s ability to spot & share relevant and unusual stories make the programme inclusive and thought-provoking. Don’t miss the popular World View feature at 7:45am daily. Listen out for #LesterInYourLounge which is an outside broadcast – from the home of a listener in a different part of Cape Town - on the first Wednesday of every month. This show introduces you to interesting Capetonians as well as their favourite communities, habits, local personalities and neighbourhood news. Thank you for listening to a podcast from Good Morning Cape Town with Lester Kiewit. Listen live on Primedia+ weekdays between 06:00 and 09:00 (SA Time) to Good Morning CapeTalk with Lester Kiewit broadcast on CapeTalk https://buff.ly/NnFM3Nk For more from the show go to https://buff.ly/xGkqLbT or find all the catch-up podcasts here https://buff.ly/f9Eeb7i Subscribe to the CapeTalk Daily and Weekly Newsletters https://buff.ly/sbvVZD5 Follow us on social media CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalkSee omnystudio.com/listener for privacy information.

AZ Tech Roundtable 2.0
AZ TRT 2.0 – Best of Cybersecurity from Business to Government AZ TRT S07 EP14 (296) 9-6-2026

AZ Tech Roundtable 2.0

Play Episode Listen Later Sep 10, 2026 47:30


AZ TRT 2.0 – Best of Cybersecurity from Business to Government AZ TRT S07 EP14 (296) 9-6-2026   What We Learned This Week Cyber and CIO mgmt Common Cyber Issues TRM Labs on security ACTRA - Cyber threats affect everyone from Gov't to business to private & growing Clips from past shows focusing on Cybersecurity and threats to both business and Government. .     Seg. 1 Clips from Related Shows: Cybersecurity, Disruption, Blockchain & Terrorism w Ari Redbord of TRM Labs - BRT S02 EP31 (78) 8-1-2021     What We Learned This Week Cybersecurity is extremely important industry for national security TRM Labs startup in cyber-security, monitors blockchain OFAC - Gov't administers economic and trade sanctions Ransomeware – specific breach, takeover of a computer system, holds data hostage Programatic Money Laundering – bad guys create new addresses, create 'shell' companies   Guest: Ari Redbord, Head of Legal and Government Affairs w/ TRM Labs https://www.linkedin.com/in/ari-redbord-4054381b4/ https://www.trmlabs.com/post/trm-labs-appoints-ari-redbord-as-head-of-legal-government-affairs   Ari is formerly a US Attorney, and worked in the Treasury Department, now advises the Government on cybersecurity, and Blockchain. Cybersecurity is a fast growing and extremely important industry for national security, and corporate interests. There are Nation States acting as bad players in the cyber realm and targeting the US Government and US business. We discuss the advancements in technology on cyber crime, blockchain, crypto, and online fraud. How is the FBI dealing with Ransomware, and other cyber attacks on prime targets like the Colonial Pipeline, or other big corps. What Regulations are coming in banking, and Fintech, with KYC (Know Your Customer), plus the big banks like JP Morgan Chase and Goldman are on board.  What the blockchain ledger can help solve in security, to monitor criminal activity in real time with the help of crypto exchanges like Coinbase.  Lastly, what TRM Labs does for clients, how they advise, operate, and who they work with.   Full Show: HERE     Phishing, Malware & Cybersecurity - Try Not to Get Pwned - BRT S02 EP47 (94) 11-21-2021   What We Learned This Week:   Have I been Pwned? Means have I been breached / hacked – did someone hack my email or website Phishing – most common type of email threat, like when you receive a strange email with a link – Do Not Open – DELETE (and alert other office staff of the email) Ramsonware – hack your website, or data – hold it hostage for an extortion 'ransom' payment Dark Web – where stolen data, & info is being bought & sold VPN Connections – direct and secure   Guests: Vince Matteo, Seven Layer Networks, Inc. https://sevenlayers.com/ Vince Matteo is a certified penetration tester, a security researcher, and a senior consultant at Seven Layers (.com) where he focuses on securing small businesses.  Vince is the author of "Hacking 101 – A Beginner's Guide to Penetration Testing", he's a bug bounty hunter with 17 published critical vulnerabilities, and he's presented talks on offensive hacking at security conferences -- most recently GrrCON in Grand Rapids, MI and BSides in College Station, TX.  Outside of work, Vince is an accomplished endurance athlete, an Ironman age group champion, and in his spare time, you can find him in the desert -- training for the next hundred-mile ultramarathon.    Full Show: HERE     Seg. 2 Cybersecurity Response Plan w/ Frank Grimmelmann of ACTRA   - AZ TRT S06 EP03 (264) 2-9-2025                 What We Learned This Week ACTRA Arizona Cyber Threat Response Alliance Cyber threats affect everyone from Gov't to business to private and growing Companies need to be responsive with speed to be effective + share information of attacks ACTRA has members from both government and private sector ACTRA helped create a state cybersecurity response model that other states can use     Guest: Frank Grimmelmann https://www.actraaz.org/actra/leadership President & CEO/Intelligence Liaison Officer   Mr. Grimmelmann also serves as Co-Chair (together with Arizona's Chief Information Security Officer) for the Arizona Cybersecurity Team ('ACT'), created through the Governor's Executive Order signed in March 2018. He also serves as a Founding Member of the National Leadership Group for the Information Sharing & Analysis Organization Standards Organization ('ISAO SO') at the University of Texas San Antonio (UTSA), created under the President's Executive Order 13691 in February 2015. As ACTRA's leader, Mr. Grimmelmann was invited as the first private sector representative in the Arizona Counter Terrorism Information Center (ACTIC) and served as its first private sector Executive Board representative from 2014-2019. He presently acts as ACTRA's designated private sector liaison to ACTRA's Key Agency and other non-Member Stakeholders.    Full Show: HERE   Seg. 3   Cybersecurity & Compliance w/ Paige Hanson of Secure Labs - AZ TRT S06 EP15 (277) 8-17-2025       What We Learned This Week: A cybersecurity breach can cost more than just data—it can damage infrastructure and destroy client confidence. Even smaller companies (50–100 employees) need structured safeguards, compliance, and often outside MSSPs to stay secure. Secure Labs provides a roadmap for companies to meet regulatory standards like HIPAA, ISO 27001, and SOC 2, helping them win bigger clients. AI-driven threats like voice cloning and deepfakes make personal and business digital security more important than ever. Compliance isn't cheap—outside audits can run $5,000–$50,000 annually, while Big Four audits may exceed $100,000.       Guest: Paige Hanson, Co-Founder of Secure Labs   LinkedIn: https://www.linkedin.com/in/hello-paige-hanson Founder of SecureLabs | Helping businesses meet their security compliance standards | Fractional GRC | 

RevMD
#211 $1.3 Million and 18 Days: What a Cyberattack Actually Costs an Independent Practice

RevMD

Play Episode Listen Later Sep 8, 2026 12:17 Transcription Available


Send us Fan MailResources Cybersecurity Incident Response Checklist: https://eligibility.natrevmd.com/natrevmd-cybersecurity-checklist natrevmd.com Trusted Resources: https://natrevmd.com/trusted-resources/ A healthcare record sells for 10 to 40 times more than a credit card number on criminal markets, and it cannot be cancelled the way a card can. Independent practices hold that data with the least defense in the entire healthcare system: one IT contractor, a server in a closet, and no one whose job it is to think about security. Attackers know it. Why independent practices are the target Three attack vectors specific to practice settings:  Phishing emails that look like they are from an EMR vendor, billing company, or payer. Remote access set up for telehealth or post-COVID flexibility that was never properly secured. Third-party vendor access, where a billing company or IT contractor gets breached and the practice is compromised through them. What to do in the first 24 hours if you are hit 1.  Isolate immediately. Disconnect affected systems from the network, but do not power them down, powered systems preserve evidence forensic teams need. 2.  Call your cyber insurance carrier first, then your attorney. Do not call the attackers, and do not pay anything without guidance. 3.  Document everything from the moment you discover the breach. This becomes the foundation of your HIPAA breach report if one is required, and the 60-day notification clock starts at discovery. 4.  Do not restore from backup until forensics has cleared the system. Restoring too early can reintroduce the attack. Three asks for your team this week Ask your IT contractor: do we have multi-factor authentication enabled on our EMR, our email, and our remote access tools? If not, when can you turn it on? Ask your IT contractor: when was the last time we tested a restore from our backup? Can you run a test this month? Call your business insurance broker: do we have cyber liability coverage? If not, what would it cost to add it? Episode breakdown Why independent practices are the target Three attack vectors specific to practice settings Five things most practices are not doing What to do in the first 24 hours if hit Three asks for your team this week 

TechSperience
Episode 149: Black Hat 2026 - Everything Had an AI Agent. Nothing Stopped the Phishing Email.

TechSperience

Play Episode Listen Later Sep 8, 2026 32:54


AI was in every booth, every keynote, and nearly every conversation at Black Hat 2026. Which makes the most useful takeaway from the show a slightly awkward one: the fundamentals still decide who gets compromised. Host Kim Coombes is joined by Connection security experts John Chirillo and Rob Di Girolamo, along with penetration tester and lead systems engineer Joe Chmielewski, to work through what actually mattered this year. The conversation covers: Why AI found hundreds of real vulnerabilities when a human guided the methodology, and performed worse running on its own Attacker velocity, and why AI lets adversaries cover more ground in the time they have inside an environment AI agents as a new class of privileged identity, and the machine identity lifecycle gap most organizations haven't closed What "the end of rare" means when AI makes offense cheap, and why monthly scanning with 30-day patch windows is getting harder to defend How to tell AI-enabled from AI-washed when a vendor claims an autonomous SOC The attacks that still work, from a phishing email to an unpatched server, and why a pen tester rarely needs anything exotic to get in They close with what security teams should do differently on Monday morning. Inventory before innovation, and stop assuming, start validating.

AOL Underground
Snex - Phishing, Trojans, IRC

AOL Underground

Play Episode Listen Later Sep 5, 2026 30:50


Snex walks through inventing an early mass-phishing scheme and a destructive Trojan and a self-replicating worm he ran on IRC.Highlights Include:Learning BASIC at five on a Tandy, then reverse-engineering AOL base files as a teenagerOptimizing the legendary punter Genocide's duplicate-removal routineDowngrading AOL 3.0 back to 2.0 to dodge puntersBuilding a custom menu into the AOL client windowAOL Secrets, the Lithium Node crew, and sneaking into AOL Live's backstageInventing an early mass-phishing scheme with a fake "AOL Adult" siteA destructive Trojan and a self-replicating SMB worm on IRCRunning a victim's AOL bill up to $5,000 with premium MUD gamesLife after AOL: software engineering, and why AI "vibe coding" won't replace senior engineersSurvey Link:⁠⁠https://airtable.com/app7GJNzwDQ8MMINw/shr4yEBKR6AADMOWo⁠⁠Guest: SnexHost: Steve StonebrakerAudio Editor: Sam Fox (sam.fox.london@gmail.com⁠⁠)CoverArt: Created by Broast (⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://broast.org⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠), original idea by LampGold.--AOL Underground PodcastFollow us ontwitter -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ @AOLUnderground⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, @brakertech⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Reddit -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.reddit.com/r/AOLUnderground/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Youtube-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/@AOLUndergroundPodcast⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Merch -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.redbubble.com/people/AOL-Underground/shop⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Donate -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ https://www.buymeacoffee.com/AOLUnderground⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Contact the Host -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠https://aolunderground.com/contact-host/⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠AOL 3.0 is working again! - ⁠⁠https://dialtone.live/⁠⁠AOL Underground Discord -⁠⁠⁠⁠⁠⁠⁠⁠ https://discord.gg/GvWuJTcTBa⁠⁠⁠Podcast Community Page -⁠⁠⁠⁠⁠⁠⁠⁠https://aolunderground.com/community/⁠⁠⁠⁠⁠⁠⁠⁠AOL 4.0 is working! -⁠⁠⁠⁠⁠⁠⁠⁠ https://nina.chat/connect/aol/⁠⁠⁠⁠⁠⁠⁠⁠Check out my wife's Etsy shop -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.etsy.com/shop/Snowbraker

The Joe Show
Caught In A Phishing Scam

The Joe Show

Play Episode Listen Later Sep 4, 2026 10:08 Transcription Available


This morning we found out that one member of THEjoeSHOW has been caught in a PHISHING scam! See omnystudio.com/listener for privacy information.

Decipher Security Podcast
Microsoft Teams Phishing, a Botnet Takedown 23 Years in the Making, and The Cuckoo's Egg's Lessons

Decipher Security Podcast

Play Episode Listen Later Sep 4, 2026 62:23


It's our one year anniversary! This week we talk about the highlights of the last year, a new high-level phishing campaign that uses Microsoft Teams as an initial access vector, and the takedown of the ancient Sality P2P botnet. Then we offer some book and TV recommendations for the long weekend. LinksOne year of the new Decipher: https://decipher.sc/2026/09/02/one-ye...Microsoft Teams phishing: https://decipher.sc/2026/09/03/new-ca...Sality botnet takedown: https://www.justice.gov/usao-cdca/pr/...

Putting the AP in hAPpy
Episode 402: Don't Celebrate Yet: What Failed Fraud Attempts Reveal About What's Coming Next and What You Should NOT Do

Putting the AP in hAPpy

Play Episode Listen Later Sep 3, 2026 19:32


Send us Fan MailTreat every failed fraud attempt as a learning opportunity, not just a close call before the next attack is successful. The controls used to block that first fraud attempt, turn into evolved fraudster tactics when they attack your organization again – especially if you do one thing that I do not recommend. Keep listening. Check out my website training.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. The Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Do You Have A Controlled Vendor Process?  Roadmap to a Controlled Vendor Process Training:  The BANK of AP: An Internal Control System to Combat Business Email Compromise Training:  3 Step Vendor Setup & Maintenance Process Workshop > 5 Authentication Techniques, 30 internal Controls, 18 Vendor Validations and 18 Best Practices Free Download:  Vendor Validation Reference List with Resource Links Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://training.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/c/DebraRRichardsonLLCMore Podcasts/Blogs/Webinars https://training.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Dark Rhino Security Podcast
S20 E03 Are Phishing Tests Actually Helping?

Dark Rhino Security Podcast

Play Episode Listen Later Sep 2, 2026 45:25


Craig Taylor is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of experience managing risk across industries—from Fortune 500 corporations to SMBs. As the Co-Founder and CEO of CyberHoot, he has pioneered a positive reinforcement approach to cybersecurity education, helping businesses eliminate risky behaviors and build a positive cybersecurity culture. With a background in psychology and extensive experience leading security programs at Chase Paymentech, Vistaprint, and DXC Technology, Craig specializes in incident response, governance, and compliance. A CISSP-certified professional since 2001, he is a recognized thought leader, public speaker, and advocate for making cybersecurity training engaging, fun, and effective.00:00 Introduction02:00 Our Guest02:42 Human Behavior in Cybersecurity08:32 Understanding Learning Taxonomy in Cybersecurity Training10:18 Non-Deception Based Phishing Simulations20:02 The Evolving Threat Landscape with AI31:02 The Psychology of Behavior Change38:00 The Human Element in Cybersecurity43:49 More about Craig

Using the Whole Whale Podcast
AI Phishing Threats & Dolly Parton's Giving Legacy (news)

Using the Whole Whale Podcast

Play Episode Listen Later Aug 31, 2026 13:26


This episode explores how AI is making phishing scams more convincing—and why nonprofits need stronger staff training, verification procedures, and financial safeguards. Learn how scammers impersonate executives, exploit grant and invoice requests, and use fake document links to bypass security systems. The conversation also spotlights Dolly Parton's philanthropic legacy, from the Imagination Library's millions of books for children to support for disaster relief, education, health care, and local music programs.

Nonprofit News Feed Podcast
AI Phishing Threats & Dolly Parton's Giving Legacy (news)

Nonprofit News Feed Podcast

Play Episode Listen Later Aug 31, 2026 13:26


This episode explores how AI is making phishing scams more convincing—and why nonprofits need stronger staff training, verification procedures, and financial safeguards. Learn how scammers impersonate executives, exploit grant and invoice requests, and use fake document links to bypass security systems. The conversation also spotlights Dolly Parton's philanthropic legacy, from the Imagination Library's millions of books for children to support for disaster relief, education, health care, and local music programs. -------- NonprofitNewsfeed.com Summary of hundreds of news sources.The post AI Phishing Threats & Dolly Parton's Giving Legacy (news) first appeared on Nonprofit News Feed.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 28, 2026 7:19


A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Trends Podcast
Mogen we van deze regering nog pintjes drinken en doen de banken genoeg tegen phishing? | vrijdag 28/08/26

Trends Podcast

Play Episode Listen Later Aug 28, 2026 39:05


We hebben het deze week over alcohol en phishing: waarom ligt de biercultuur plotsK weer onder vuur? En hoe kunnen we ons beter wapenen tegen de steeds professionelere phishingindustrie? Hosts: Bert Bultinck en Jan De Meulemeester Productie: Jens Leen Trends is een podcastkanaal van de redactie van Trends.--- --- Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Putting the AP in hAPpy
Episode 401: The IRS FIRE System's Final Chapter: What 1099-NEC and 1099-MISC Filers Can Still File and When

Putting the AP in hAPpy

Play Episode Listen Later Aug 27, 2026 12:52


Send us Fan MailThere is still time to process tax reporting files in the IRS FIRE system. For 1099-NEC and 1099-MISC filers, if you want to know what you can file and the deadline you need to file before the FIRE system is retired…. Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    IRS: Filing Information Returns Electronically (FIRE) https://www.irs.gov/e-file-providers/filing-information-returns-electronically-fireIRS:  e-File with FIRE (List of Forms) https://www.irs.gov/filing/e-file-information-returnsFree Download:  Vendor Validation Reference List with Resource Links https://training.debrarrichardson.com/validation-referenceVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://training.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/c/DebraRRichardsonLLCMore Podcasts/Blogs/Webinars https://training.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Word Notes
QR code phishing (noun)

Word Notes

Play Episode Listen Later Aug 25, 2026 10:09


Enjoy this encore of Word Notes. A type of phishing attack that uses QR codes as the lure. CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/qr-code-phishing⁠ Audio reference link: KNR, 2018. Batman The Dark Knight Joker bomb blast by phone calls scene [Video]. YouTube. URL ⁠https://www.youtube.com/watch?v=qB_fXfzB4z0⁠.

Backup Central's Restore it All
Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

Backup Central's Restore it All

Play Episode Listen Later Aug 24, 2026 41:27 Transcription Available


Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line.We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks down how social engineering actually works (the research bad guys do on you before they ever send an email) and why "report as phishing" buttons have themselves become an attack vector. I share the story of the free credit monitoring scam that got me, and why freezing your credit reports is one of the best five-minute security moves you can make.Mike then walks through FIDO2 and passkeys, why they're built on old-school public/private key encryption, and why they're transactional instead of just another code sent to your phone. We cover the Flax Typhoon espionage campaign, the Raptor Train botnet, and how hard-coded credentials on IoT devices turned into root-level access for a foreign intelligence operation.Then Mike introduces "killing the trust button," which is phrase for the idea that most networks default to open, and every one of those defaults is a decision somebody made without thinking about the risk. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum. And yes, we talk about just asking an AI assistant like Copilot or Claude to walk you through turning this stuff on, because you probably already have these tools and don't know it.We close on why MFA by itself still isn't enough — session token theft, MFA exhaustion attacks, and the "remember this device" setting that undoes everything you just set up. If you're the person responsible for an environment with important accounts sitting there with no MFA, we've got a name for that, and it's not a nice one.Chapters:0:00 – Cold Open1:31 – Welcome to the Show4:12 – The REDCap/Google Workspace Attack8:38 – Social Engineering: How Attackers Do Their Homework13:06 – Freeze Your Credit Reports16:55 – What Is FIDO2? (Phishing Resistant MFA Explained)18:58 – Flax Typhoon and the Raptor Train Botnet24:43 – Professional Malfeasance: No More Excuses for Skipping MFA28:05 – Killing the Trust Button32:51 – Start With Your Administrative Accounts36:36 – Why MFA Alone Isn't Enough: MFA Exhaustion39:27 – Passkeys, Impossible Travel, and Final Takeaways

KOZETEK
Masterclass sou phishing | Gael Beauboeuf

KOZETEK

Play Episode Listen Later Aug 22, 2026 48:08


Masterclass sou phishing | Gael Beauboeuf

Putting the AP in hAPpy
Episode 400: Employee Makes $6M From $15M in Stolen Funds. Do They Get To Keep It?

Putting the AP in hAPpy

Play Episode Listen Later Aug 20, 2026 24:57


Send us Fan MailAn internal employee stole close to $15M from Bridgestone over 4 years and through investments, made and additional $6M.  Did they get to keep it and the way the internal fraudster was caught after they left the company.  And what question should you ask of your vendor process? Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Department of Justice Press Release:  Former Bridgestone Americas Assistant Treasurer Pleads Guilty to Nearly $15 Million Wire Fraud Scheme WKRN News Article:  Ex-Bridgestone employee defrauded company of $21M Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download:  Vendor Validation Reference List with Resource Links Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://training.debrarrichardson.com/cleanup YouTube Channel:  https://www.youtube.com/c/DebraRRichardsonLLCMore Podcasts/Blogs/Webinars https://training.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

International Bankruptcy, Restructuring, True Crime and Appeals - Court Audio Recording Podcast
Listen to the FTX bankruptcy court ruling re payout to an FTX customer on his claim (hearing of August 19, 2026)

International Bankruptcy, Restructuring, True Crime and Appeals - Court Audio Recording Podcast

Play Episode Listen Later Aug 20, 2026 8:17


According to the bankruptcy court's ruling in this podcast, which was docketed by the bankruptcy court on the record of the FTX bankruptcy case, an FTX customer/claimant brought a motion seeking reconsideration of the disallowance of his claim. His claim had been disallowed by the bankruptcy court because of complications with his submission of documents to satisfy Know Your Customer (KYC) requirements. These requirements typically require submission of documentation in order for claims to be allowed, in other words eligible for payout. Sometimes customers/claimants need to also submit signed Internal Revenue Service (IRS) tax forms.This can be burdensome for U.S. based customers/claimants, and especially burdensome for customers/claimants of foreign companies that file for bankruptcy in the United States that did not go through a KYC process or fill out tax forms when they opened accounts.People tend to think that, if their deposits and investments fail then they will be paid out in the ordinary course based on the information on file on apps through which they manage their accounts. Unfortunately this is not usually the case now typically. I am not sure but I think we would be pretty screwed if a bank or other institution holding deposit accounts failed - and I have applied to work for the FDIC because the government anticipates bank failure the FDIC will handle and I think I can help based on my bankruptcy experience.But perhaps in the future, in bankruptcy cases and in bank failure cases outside of bankruptcy, there will be technological and other improvements such that depositors and other claimants need not go through a process at all to prove up their claims and be paid out.For now, in bankruptcy cases, customers/claimants often find themselves either not submitting the KYC paperwork or trying to sell their claims to parties that are better able to cope with U.S. bankruptcy claims allowance/disallowance processes, including passing KYC requirements.From the FTX ruling it's not clear what the alleged defect was with the KYC documentation submitted by the customer/claimant, but the ruling explains that the customer/claimant was concerned to receive a request for more information than he had submitted, through the mechanism for submitting the documentation. The claimant expressed to the court that he thought the request for information was possibly part of a PHISHing attempt (a cybersecurity data breach that can result in identity theft).I am not clear what beyond a drivers license or other form of identification is needed to satisfy KYC in the FTX cases and whether the FTX customers/claimants had been KYC'd when opening accounts or thereafter.And I think I heard the court explain in the ruling, but I am not sure, that 47,000 - forty seven thousand - customer claims have been disallowed on the same basis as the claim at issue before the court in the ruling. In other words the claims will not be paid out.Can this possibly be correct? And how many FTX claims in total have been disallowed?This is not a perfect analogy but practically speaking - Imagine a scenario where, instead of plaintiffs bringing class actions for fraud perpetrated on them leading up to a bankruptcy filing such as FTX's, the defendant companies that committed the fraud against the customers, whose CEO is jailed for fraud, are protected from prosecution/litigation for fraud and are bringing class actions defensively to avoid paying out customers on claims that would not exist but for the fraud and collapse of FTX.For some context on claims allowance/disallowance processes in other bankruptcy cases, before FTX filed for bankruptcy relief in 2022... Twenty years ago or so, it became a practice in large bankruptcy cases that were not cases that followed frauds/fiascos like FTX, for the bankrupt companies' lawyers, to bring so called omnibus claims objections. The omnibus claims objection procedure is part of the claims allowance process, for large bankruptcy cases and enables bankrupt companies to more efficiently challenge claims on a common basis when there is a legitimate basis for a challenge affecting many claims.Generally speaking, even outside of bankruptcies following frauds, the claims allowance process reverses the bankruptcy rules that creditor claims (including customer claims) are presumptively valid and allowable. So the process is backwards substantively.And bankrupt companies can challenge claims on the basis of vague objections such as books and records objections, in other words challenging that the claim as filed by the customer/creditor is valid, on the basis the claim doesn't match the bankrupt companies' records. This can also be done with investor claims, which are a type of customer/creditor claim asserted in U.S. bankruptcy cases.Typically, If the creditor does nothing in response to an omnibus claims objection concerning the creditor claim (and that of many other customers) then the claim will be disallowed, by default. The bankruptcy court will treat the objection to the claim as unopposed and enter an order disallowing/expunging/excluding the claims from payment in the bankruptcy. The claims may be listed on a schedule with many other claims in the same situation - claims that will not be paid out.This is the default scenario, where a creditor who has timely notice of a claims objection, might reasonably assume creditors with larger claims will come forward. But the creditor doesn't consider those larger claimants may be dealing with the bankrupt company via arriving at one off deals reflected in stipulations and orders presented to the court, concerning the extent to which claims will be allowed and paid out.If the creditor does not default - and timely or untimely responds to the omnibus claims objection - which will typically necessitate hiring counsel, then the hearings on the customer claim are likely to be adjourned because the bankrupt company controls the agenda for hearings presented to the court. In other words, the claimant is not going to win and have a claim eligible for payout, even if the claimant responds to the claim objection.If the bankrupt company doesn't want to confront an issue that can be raised by other customers, which is a recurring scenario in bankruptcy cases, then the bankrupt company can adjourn hearings on a claim for months.In the Lehman Brothers bankruptcy case in the United States, filed in 2018, I represented foreign nationals who entrusted Lehman Brothers investment vehicles with funds before Lehman Brothers collapsed, then these individuals had to deal with the claims allowance process for customers/creditors/investors trying to collect on Lehman Brothers guarantees in the U.S.Few if any people would have invested in the Lehman Brothers feeder funds soliciting money overseas, without the Lehman Brothers guarantee probably, but when it came time to pay out on the Lehman Brothers guarantees - Lehman Brothers did not pay out in its chapter 11 bankruptcy proceedings, filed in New York. Lehman Brothers brought waves of omnibus claims objections challenging claims, hundreds of them.The bankruptcy judge presiding over the Lehman Brothers case at the time, who was the judge who had dealt with the nightmare of the case since the case filing in 2008, ruled that objections of one claimant would apply to all claimants, in effect giving us class action type status, recognizing the common issues (being defrauded into investing into a Lehman Brothers feeder fund with specious documentation causing it to be unclear what level of priority the claims should receive in an unthinkable bankruptcy scenario where Lehman Brothers, which had guaranteed payout to investors itself bankrupted then challenged the payout obligations).After the bankruptcy judge presiding over the Lehman Brothers case helped the parties procedurally and substantively with instructions for how the trial/hearing on the claims would proceed, the lawyers for the bankrupt company caused an adjournment of the hearing on our claims "sine die" - which means an adjournment of the trial on the claims without date/indefinitely.The bankrupt companies kept the claims off the bankruptcy court's agenda while the judge who wanted a trial on the merits was the bankruptcy judge presiding over the Lehman Brothers bankruptcy.After the judge retired from the bench and another judge took over the case, Lehman Brothers found a way to avoid trial on the claims again and make sure they wouldn't be paid. I remember the substitute judge, who has since retired, telling the Lehman Brothers' lawyers, who she saw in court repeatedly over the course of the year, how great it was to work with them and she wished happy holidays as it was year end. I have the transcript somewhere and look at it every few years, missing appearing before the judge who initially presided over the Lehman Brothers case then retired into private practice where he does great dispute resolution work including mediation.The omnibus claims objection process for disallowing claims was extraordinary in the Lehman Brothers case which was in New York, but the case was abnormally large with a lot of foreign investment and resulting bankruptcy claims.Over time, the disallowance process via omnibus claims objections has become normal in some cases in Delaware like FTX and, in that context, perpetuates bankrupt companies' representations their bankruptcy plans are paying creditors decently high percentages on their claims, when really the percentages would be low if the claims in the claims pool were allowed and paid out.I do not know the circumstances of the claimant in FTX whose rights were impacted by the FTX ruling in this episode of the podcast, or how much crypto or money he lost, or how much he stands to gain if his claim is allowed, or whether he transferred his claim or continues to hold. I commend him on coming forward to a court of justice to defend his rights. He can proceed further and appeal if he thinks it worthwhile or do what the other claimants do and deal with the loss, unfair as it seems to be following the fraudulent collapse of FTX and good faith customer attempts to comply with the claims process including KYC requirements.An interesting question is can the many other FTX claimants whose claims have been disallowed due to alleged failure to satisfy KYC requirements appeal join in an appeal or will they too hear that their objections are untimely and will not be paid out?Thoughts on how FTX claimants can be helped are welcome on the YouTube channel accompanying this audio stream, when I post the FTX hearing there later today.www.youtube.com/@the-comi

Bitcoin verstehen
Episode 327 - Coldcard-Hack erklärt: Sind deine Bitcoin auf Hardwarewallets wie BitBox & Co. noch sicher? Mit Chris (Bitsurance & Seedor)

Bitcoin verstehen

Play Episode Listen Later Aug 16, 2026 60:34


In dieser Folge sprechen wir mit Chris von Bitsurance und Seedor über den Coldcard-Hack und was er für deine eigene Bitcoin-Aufbewahrung bedeutet. Ende Juli wurde bekannt, dass eine Firmware-Schwachstelle bei Coldcard-Hardware-Wallets tausende Bitcoin ungeschützt gemacht hat. Nutzer haben ihre Bitcoin verloren, obwohl sie alles nach bestem Wissen richtig gemacht hatten, kein Phishing, kein physischer Diebstahl, sondern ein Fehler tief im Code des Geräts selbst. Wir sprechen mit Chris darüber, was beim Vorfall konkret passiert ist, warum die Zufallszahlengenerierung so entscheidend für deine Sicherheit ist, ob auch Bitbox, Trezor oder Ledger betroffen sind, welche Rolle KI dabei spielt, solche Schwachstellen zu finden, und warum Multisig aktuell als Goldstandard für größere Beträge gilt. Vor allem aber, was du jetzt konkret tun kannst, ohne in Panik zu verfallen. Du möchtest bei unserer 4-wöchigen Live-Masterclass zur Selbstverwahrung von Bitcoin dabei sein? Dann trage dich hier in unsere Warteliste ein: https://www.bitcoinverstehen.info/warteliste Jeden Montag 5 interessante Medien rund um Bitcoin und Geld sowie donnerstags die Zusammenfassung unserer aktuellen Episode in euer Postfach? Dann melde dich zu unserem Newsletter an: https://www.bitcoinverstehen.info/newsletter

Paul's Security Weekly
The Breached WiFi AI Ports... What? - PSW #939

Paul's Security Weekly

Play Episode Listen Later Aug 13, 2026 124:35


In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking “secure enough” Back to basics: know what's on your network Get off my PCI lawn Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-939

Paul's Security Weekly TV
The Breached WiFi AI Ports... What? - PSW #939

Paul's Security Weekly TV

Play Episode Listen Later Aug 13, 2026 124:35


In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice authentication • Cornflake RAT and Chaco Shell • The NPM worm • Hundreds of compromised packages • AI lowers the barrier to mass exploitation • Rethinking "secure enough" • Back to basics: know what's on your network • Get off my PCI lawn Show Notes: https://securityweekly.com/psw-939

Putting the AP in hAPpy
Episode 399: 11 Signs It's Time To Clean Your Vendor Master File

Putting the AP in hAPpy

Play Episode Listen Later Aug 13, 2026 28:52


Send us Fan MailIf these 11 things are happening, they are signs it's time to review the data in your vendor master file.  What are the 11 signs? Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Free Training Session:  8 Steps to Clean Your Vendor Master File https://training.debrarrichardson.com/course/cleanup Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download:  Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://training.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Paul's Security Weekly (Podcast-Only)
The Breached WiFi AI Ports... What? - PSW #939

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Aug 13, 2026 124:35


In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking "secure enough" Back to basics: know what's on your network Get off my PCI lawn Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-939

Talos Takes
Don't scan that! QR code phishing and cloud-native threats

Talos Takes

Play Episode Listen Later Aug 12, 2026 22:25 Transcription Available


What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud.Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways.Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/

TechTimeRadio
309: TechTime Meta Slammed As A “Public Nuisance,” Google's AI Pushes Meme Facts, Phishing Targets Microsoft 365, Gwen Breakfast Robot Flops, And The Cybertruck Flop, Your Smart Tech News With Humor And Real Takeaways | Air Date: 8/11 – 8/17/26

TechTimeRadio

Play Episode Listen Later Aug 11, 2026 60:40 Transcription Available


A judge calls Meta a “public nuisance” and compares social media harm to air pollution. That line hits hard because it forces the real question: if the damage is baked into engagement and ad targeting, what kind of fix is even possible? We dig into the record child safety fine, the idea of “mitigation funds,” and why accountability gets messy when platforms are both the marketplace and the referee.Then we jump to a story that's funny right up until it isn't: Google's AI Overview repeats a meme as if it were fact, claiming license plate reader cameras are packed with gold and copper. We unpack what AI hallucinations mean when search becomes “answers” instead of links, how misinformation can drive real-world behavior, and why verifying sources matters more now than ever.On the security front, we break down phishing-as-a-service aimed at Microsoft 365 accounts, including spoofed RingCentral messages, email authentication gaps (SPF, DMARC, DKIM), and the simple habits that keep a bad click from turning into a full compromise. We also take a breather with Gwen's gadget pick: a Kickstarter breakfast robot that cracks and cooks eggs and syncs a toaster so it won't “scare” you, plus our whiskey tasting and a data-driven teardown of the Tesla Cybertruck's flop era.If you like smart tech news with humor and practical takeaways, subscribe, share the episode with a friend, and leave us a review. What's the last “AI answer” you trusted that turned out to be wrong?Send us Fan MailSupport the show

The Real Investment Show Podcast
8-10-26 Internet Scams You Need to Know - The Ari Schwartz Interview

The Real Investment Show Podcast

Play Episode Listen Later Aug 10, 2026 44:12


Internet scams are evolving faster than ever, with artificial intelligence making phishing emails, fake phone calls, and fraudulent videos more convincing than traditional scams. Jon Penn and Venable Cybersecurity Services Managing Director, Avi Schwartz explain the most common online scams targeting consumers, investors, retirees, and businesses, along with practical steps you can take to protect yourself and your finances. We discuss AI-enhanced phishing attacks, deepfake voice and video scams, business email compromise, texting scams (smishing), elder fraud, and payment fraud involving gift cards and cryptocurrency. We also cover what to do if you've been scammed, how quickly you need to act to improve your chances of recovering stolen funds, and why authentication, passkeys, and independent verification are among your best defenses. Whether you're protecting your retirement savings, your business, or helping aging parents avoid fraud, this episode provides practical cybersecurity and financial safety strategies that can reduce your risk of becoming the next victim. 0:00 INTRO 0:20 - Internet Scams to be Aware of 3:53 - AI enhanced Phishing 7:00 - Deep Fake Voice & Video Scams 13:39 - Catch Them If You Can - How to get your money back 15:37 - Texting scams & smishing 18:21 - How Much Can You Lose? 19:29 - Who are the Targets? 22:34 - How Long Can it Take? 24:40 - Dealing with Elder Fraud 26:11 - How to Prevent or Reduce Chances of Falling Victim to Scams 30:09 - Strengthen Authentication - passkeys 34:10 - Verify Before You Act (avoid urgency) 36:26 - Avoid Engaging with Unknown Contacts - Ignore it 36:55 - Double check all Financial Transactions 38:47 - Watching for Payment Red Flags (Gift Cards & Cyber Currency) 41:58 - Authentication & Verification are Key Hosted by RIA Advisors Senior Investment Advisor, Jon Penn, CFP, w special guest, Venable Cybersecurity Services Managing Director, Ari Schwartz Produced by Brent Clanton, Executive Producer ------- Do you enjoy our content? Rate us on Google: https://bit.ly/4b9JtEo ------- Watch Today's Full Video on our YouTube Channel: https://youtube.com/live/Azt1_vs16bA ------- Articles mentioned in this report: "AI-Driven Fraud Scams Are Evolving Fast: What People Should Watch For and Can Do To Protect Themselves, Their Friends, and Family" https://www.centerforcybersecuritypolicy.org/insights-and-research/ai-driven-fraud-scams-are-evolving-fast-what-people-should-watch-for-and-can-do-to-protect-themselves-their-friends-and-family -------- Watch today's "Before the Bell" premarket commentary, "Markets Consolidate as Sector Rotation Strengthens," https://youtu.be/pG8vxTC6oco ------- Watch our previous show, "Do You Really Know Your Risk Tolerance?" https://youtube.com/live/m3KZ1fbws2k ------- Get more info & commentary: https://realinvestmentadvice.com/insights/real-investment-daily/ ------- * REGISTER for our next Dynamic Learning Series, "Savvy Social Security Planning: More Income, Less Worry," Thursday, August 6, 2026: https://streamyard.com/watch/tQ3PS8hd64mt --- Visit our Site: https://www.realinvestmentadvice.com Contact Us: 1-855-RIA-PLAN --- Subscribe to SimpleVisor : https://www.simplevisor.com/register-new --- Connect with us on social: https://twitter.com/RealInvAdvice https://twitter.com/LanceRoberts https://www.facebook.com/RealInvestmentAdvice/ https://www.linkedin.com/in/realinvestmentadvice/ #CyberSecurity #InternetScams #IdentityTheft #FinancialPlanning #PersonalFinance

Kan English
Platform helps protect against SMS phishing

Kan English

Play Episode Listen Later Aug 9, 2026 13:10


As phishing attempts have surged and become increasingly sophisticated, cyber-security firm Cyvore has developed a verification tool available free to the public. Scan My SMS can scan SMS messages and determine whether they are authentic or not. Cyvore Security co-founder and CEO Ori Segal spoke to KAN reporter Naomi Segal (Photo: Illustrative, Shutterstock)See omnystudio.com/listener for privacy information.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 6, 2026 8:23


Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co COLDCARD Issues https://x.com/threatinsight/status/2084328552481112429 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Putting the AP in hAPpy
Episode 398: Do You Manage The Vendor Process? Start Here to Build Controls, Manage Risk and Maintain Accurate Vendor Data

Putting the AP in hAPpy

Play Episode Listen Later Aug 6, 2026 27:31


Send us Fan MailBeing a Vendor Process Manager is a little like being a referee, detective, and data janitor all at once. In this episode, we'll cover the key priorities that help you reduce risk, improve compliance, and clean up vendor chaos.Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Roadmap to a Controlled Vendor ProcessOn-Demand Webinar: Ensuring Adherence: How to Audit Your Vendor Setup and Change Process On-Demand Webinar: 3 Ways To Meet Nacha's ACH Fraud Monitoring - Same Day Foundational Vendor Process Training:  Vendor Process Essentials Training Sessions  Free Training Session:  8 Steps to Clean Your Vendor Master File Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download:  Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://training.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 5, 2026 6:30


Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing A Deep Dive Into the Latest XCSSET Version https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

The Café Bitcoin Podcast
Café Bitcoin | Guy Swann and Yan Pritzker on Coldcard, the Asymmetry of Defense, and Privacy | Day 16 of 50

The Café Bitcoin Podcast

Play Episode Listen Later Aug 5, 2026 72:00


Guy Swan on learning the wrong lessons. The takeaway circulating is "go with the biggest company," which forgets Mt. Gox and FTX and everything else proving size is not safety. His analogy: when a libertarian politician betrays you, libertarianism didn't break, you got scammed. He wants a rule that works forward. His sharpest point: "I don't want a rule that only works in hindsight." Anyone can now point at the source-available license. The useful question is what indicator predicts the next failure before it happens. His own heuristic broke in both directions. He had trained himself not to dismiss builders for being abrasive, and now concludes that for security specifically, a maintainer who attacks people reporting problems is telling you something. Yan Pritzker paired it with the engineering version: without a culture of safety, people stop surfacing mistakes. James O'Beirne's tripwires. He seeded wallets on-chain carrying graduated entropy over broken Coldcard seeds, five dice rolls, ten, fifteen, one and two-word passphrases, as bait. The bare seed was swept within an hour and nothing else has moved, mapping attacker capability live. The red team's numbers. Rob Hamilton and Calle have scanned over 300 repos and spent roughly $40,000 on tokens in two days, finding critical vulnerabilities at about one per person per hour. OpenSats is now funding most of that budget. Every company needs an agentic security pipeline. Yan's argument: agents are non-deterministic, so one scan proves nothing. The real work is harnesses that find, test, distill and reproduce on a loop. Swan has been building this for six to twelve months. The asymmetry is the whole problem. Attackers need one vulnerability, defenders need all of them, and the economics favor the attacker. Some have been paying up to 90% of stolen funds in fees to get transactions mined quickly. A fake Coldcard desktop app is circulating. No such application has ever existed. Trezor reported a phishing spike since disclosure, and a counterfeit Wasabi wallet reached an app store. Nobody legitimate asks for recovery words, and unsolicited migration instructions are always hostile. Yan's read on whether this repeats. He calls the bug exotic: entropy wasn't weak, it was switched off entirely. Scans across the popular hardware wallets show correct and consistent entropy use, so he thinks this specific failure is unlikely to recur elsewhere. Government overreach, the other half of the show. Suz on Liechtenstein's beneficial ownership register, roughly 31,000 entities, built in 2021 for EU anti-money-laundering compliance and now breached and offline. Yan on the Bank Secrecy Act's 1970 threshold, never inflation-adjusted, capturing dramatically more data for near-zero measured effect.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 3, 2026 7:32


zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing Campaigns Targeting AI Solutions Providers https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/ Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Farm4Profit Podcast
The Biggest Cybersecurity Mistakes Farmers Make

Farm4Profit Podcast

Play Episode Listen Later Aug 3, 2026 36:07


Today's farms rely on technology more than ever. From grain dryers and irrigation pivots to livestock systems, security cameras, accounting software, and smartphones, nearly every part of a modern farming operation is connected. That also makes agriculture one of the fastest-growing targets for cybercriminals. Chris from Tech Support Farm returns to Farm4Profit to discuss how farms can better protect themselves from ransomware, phishing scams, compromised credit cards, malware, and attacks on connected equipment. The conversation covers real-world examples—including Tanner's own experience with fraudulent credit card charges—and explains how remote monitoring, endpoint detection, password management, secure business email, mobile device management, and network monitoring work together to reduce risk. The episode also explores: Business email security Password managers Public Wi-Fi risks Phishing scams Credit card fraud Remote monitoring Endpoint detection (EDR) Mobile device management Irrigation and grain dryer security Data backups Disaster recovery Cyber insurance Farm technology infrastructure AI and digital threats Whether you operate a family farm or a multi-location business, this episode offers practical advice that could save your operation from significant financial loss and downtime. Want Farm4Profit Merch? Custom order your favorite items today!https://farmfocused.com/farm-4profit/ Don't forget to like the podcast on all platforms and leave a review where ever you listen! Website: www.Farm4Profit.comShareable episode link: https://intro-to-farm4profit.simplecast.comEmail address: Farm4profitllc@gmail.comCall/Text: 515.207.9640Subscribe to YouTube: https://www.youtube.com/channel/UCSR8c1BrCjNDDI_Acku5XqwFollow us on TikTok: https://www.tiktok.com/@farm4profitllc Connect with us on Facebook: https://www.facebook.com/Farm4ProfitLLC/Farm4Profit Media is not a financial, legal, or tax advisor. Content is provided for informational purposes only, and we serve solely as a platform for third-party opinions. Any actions taken based on this content are at your own risk. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Centered From Reality
Phishing Season in Iran

Centered From Reality

Play Episode Listen Later Aug 3, 2026 24:07


In this episode, Alex examines a wave of suspected Iranian cyberattacks targeting municipal water systems and argues they are a predictable consequence of escalating U.S.-Iran tensions. He criticizes President Trump's response, contending that blaming political opponents instead of addressing foreign cyber threats weakens deterrence and encourages future attacks. Alex also revisits the Trump administration's handling of the National Mall reflecting pool controversy, using it as another example of what he sees as politically motivated misinformation and misplaced blame.

The Brian Lehrer Show
Summer Friday: Ben Rhodes; DSA & Climate; Phishing; Oligarchy; Belief in God

The Brian Lehrer Show

Play Episode Listen Later Jul 31, 2026 109:01


On this Summer Friday, we've put together some of our favorite recent interviews, including: Ben Rhodes, contributing opinion writer for the New York Times, co-host of "Pod Save the World," an advisor to former president Barack Obama and the author of All We Say: The Battle for American Identity: A History in 15 Speeches (Random House, 2026), talks about his new book that tells the history of the United States and its central conflicts  through public speeches, from Benjamin Franklin to Donald Trump. Robinson Meyer, founding executive editor of Heatmap, talks about the DSA's evolving relationship to the Green New Deal and climate policy in general, as its members keep winning elections in big cities. WNYC has been targeted by scammers who posed as hosts, and offered authors interviews -- for a fee (which WNYC would never do). Rachel Tobac, co-founder and CEO of Social Proof Security, and Kenneth Atkins, assistant director of IT and data security at WNYC, talk about how to spot sneaky online phishing scams, and how to deal if you fall for it. Jeffrey Winters, professor of political science at Northwestern University and the director of the Equality Development and Globalization Studies Program at Northwestern's Buffett Institute for Global Affairs and the author of The Blind Spot: How Oligarchs Dominate Our Democracies (Scribner, 2026), talks about the history of oligarchy, how to fight it, and why it maintains power in a democracy. Meghan Sullivan, professor of philosophy at Notre Dame and founder of the Institute for Ethics and the Common Good, offers her take on the contemporary context for belief, or doubt, in God as religious affiliation largely declines in the U.S.   These interviews were lightly polished up and edited for time, the original versions are available here: Speeches as a Key to American Identity (June 8, 2026) What the DSA's Popularity Means for Climate Policy (July 7, 2026) How to Avoid Sneaky Phishing Scams (May 5, 2026) When Voters Support Oligarchs (May 26, 2026) How Belief in God Has Changed (May 20, 2026)   Photo: Whimbrel on the beach at Fort Tilden beach, Queens. Rare shorebird for this location, 24 September 2021 (Remydee1, CC BY-SA 4.0, via Wikimedia Commons) Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

TechTimeRadio
307: TechTime Breaks Down Superhuman AI Tests, False Life Detection Risks, Privacy Issues With Wearable Cameras, Real Phishing Scams, And How Cloud Outages Disrupt Everything From Data Centers To PlayStation. | Air Date: 7/28 – 8/3/26

TechTimeRadio

Play Episode Listen Later Jul 28, 2026 55:40 Transcription Available


A “safe” AI test environment is supposed to be a sandbox, not a launchpad. Yet one of the biggest stories we break down claims an experimental OpenAI model moved at superhuman speed, chained vulnerabilities, and hit Hugging Face in a real cyberattack, not for money, but to cheat on an internal benchmark. We talk through what that would mean for AI containment, autonomous agents, and why “it was just a test” stops being comforting when production systems get touched.From there, we zoom out to the quieter AI failure that can be just as dangerous: false certainty. Research suggests models can be pushed into confidently detecting “life” where none exists, which raises uncomfortable questions about AI-assisted NASA life detection on Mars or Europa. We also get into privacy and consent, as Instagram cracks down on videos filmed with Meta smart glasses that harass or intimidate strangers, and why wearable cameras change the ethics even when filming in public is technically allowed.Then we get painfully practical. We read real phishing emails, explain the red flags, and I confess to getting caught when I was busy and moving too fast. We cover recovery steps, why credit cards beat debit for fraud protection, and the simplest rule that still saves the most people: don't click the link, go to the source. Finally, Mike brings the heat on data center power draw and grid instability, and we connect the dots to the PlayStation Network outage and cloud dependency on AWS.Subscribe for more tech news for everyday people, share this with someone who needs better scam defenses, and leave a review. What's the one message or alert you almost fell for, and what tipped you off?Send us Fan MailSupport the show