Act of attempting to acquire sensitive information by posing as a trustworthy entity
POPULARITY
Categories
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Heute im Pendler-Update: Immer mehr Grenzgänger leiden laut einer Psychologin unter Stress, Erschöpfung und psychischer Belastung im Job. Deutschland will die Kontrollen an den Außengrenzen bis mindestens Mitte März 2027 verlängern – Luxemburg will erneut dagegen vorgehen. Die Krankenkasse warnt vor Phishing-Mails, mit denen Betrüger an persönliche und finanzielle Daten von Versicherten gelangen wollen. Die Fouer startet und bringt 20 Tage lang Fahrgeschäfte, Gastronomie und Unterhaltung auf das Glacis. Hier geht‘s zum letzten Pendler-Update: Rauch über Luxemburg, Niedrigwasser & Streit im Gesundheitswesen Schon gehört? Grenzgänger gesucht: Zieht Luxemburg noch immer Deutsche an? Schreibt uns eure Fragen und Anregungen gerne an pendler@wort.lu! Der Pendler Club ist ein Podcast vom Luxemburger Wort. Mediahuis Luxembourg sind Teil des internationalen Trust Project, das für transparenten und vertrauenswürdigen Journalismus steht. Weitere Informationen dazu gibt es hier. Moderation und Produktion: Jil Reale Redaktion: Luxemburger WortSee omnystudio.com/listener for privacy information.
GTA 6 geleakt, KI-Werbung, Fake-Downloadseiten und rassistische KI-Antworten – in dieser Folge ist wieder einiges los. Tobi und Rüdiger sprechen über den spektakulären GTA-6-Leak, kostenlose digitale Zeitungen, Rüdigers Gmail-/Outlook-Spamproblem und die Frage, warum Claude mit mehr Geld offenbar bessere Antworten liefert. Außerdem: Werbung in ChatGPT, Kameras in AirPods, Meta-Brillen, Mathematik auf Pornhub, KI-Avatare im Teams-Meeting und das Ende des guten alten „Fahr mit der Maus über den Link“-Security-Tipps. Zum Schluss wird es ernst: KI-Erkennung, die echte Texte als KI-generiert einstuft, rassistische KI-Antworten und die Frage, ob eigentlich die KI das Problem ist – oder diejenigen, die sie bauen und betreiben. -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast
This week’s Cyber Sense feature focuses on “reservation hijacking”, a growing online scam targeting travellers after they make legitimate hotel bookings. Lester Kiewit speaks to Boikokobetso Makhetloane, also known online as Mr Fingerz, a cybersecurity expert, educator, trainer, and TikTok content creator, about how criminals can use stolen booking information and compromised hotel accounts to impersonate accommodation providers. The discussion looks at how scammers use genuine reservation details to create urgency, convince guests to make additional payments, and potentially hand over card or banking information, as well as the steps travellers can take to verify unexpected requests before paying. Good Morning Cape Town with Lester Kiewit is a podcast of the CapeTalk breakfast show. This programme is your authentic Cape Town wake-up call. Good Morning Cape Town with Lester Kiewit is informative, enlightening and accessible. The team’s ability to spot & share relevant and unusual stories make the programme inclusive and thought-provoking. Don’t miss the popular World View feature at 7:45am daily. Listen out for #LesterInYourLounge which is an outside broadcast – from the home of a listener in a different part of Cape Town - on the first Wednesday of every month. This show introduces you to interesting Capetonians as well as their favourite communities, habits, local personalities and neighbourhood news. Thank you for listening to a podcast from Good Morning Cape Town with Lester Kiewit. Listen live on Primedia+ weekdays between 06:00 and 09:00 (SA Time) to Good Morning CapeTalk with Lester Kiewit broadcast on CapeTalk https://buff.ly/NnFM3Nk For more from the show go to https://buff.ly/xGkqLbT or find all the catch-up podcasts here https://buff.ly/f9Eeb7i Subscribe to the CapeTalk Daily and Weekly Newsletters https://buff.ly/sbvVZD5 Follow us on social media CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalkSee omnystudio.com/listener for privacy information.
In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking “secure enough” Back to basics: know what's on your network Get off my PCI lawn Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-939
In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking "secure enough" Back to basics: know what's on your network Get off my PCI lawn Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-939
What happens when a QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud.Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways.Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/
These reports and academic studies examine the escalating threat of AI-powered phishing in 2025 and 2026, highlighting how generative tools have collapsed attack timelines from days to mere seconds. Artificial intelligence now acts as an autonomous operator, generating convincing, error-free emails and dynamic malicious websites that bypass traditional security filters. Research indicates that over 80% of phishing attempts now integrate AI, leading to a massive surge in sophisticated business email compromise and personalized social engineering. To counter these automated tactics, experts advocate for a shift toward proactive, real-time detection and post-delivery defense strategies. Technical evaluations demonstrate that machine learning and deep learning models, specifically SVM and BiLSTM, can identify AI-generated content with high accuracy by analyzing subtle linguistic patterns. Ultimately, the sources emphasize that as cybercriminals weaponize AI for speed and scale, defensive infrastructure must evolve to prioritize automated intelligence and human oversight.
A judge calls Meta a “public nuisance” and compares social media harm to air pollution. That line hits hard because it forces the real question: if the damage is baked into engagement and ad targeting, what kind of fix is even possible? We dig into the record child safety fine, the idea of “mitigation funds,” and why accountability gets messy when platforms are both the marketplace and the referee.Then we jump to a story that's funny right up until it isn't: Google's AI Overview repeats a meme as if it were fact, claiming license plate reader cameras are packed with gold and copper. We unpack what AI hallucinations mean when search becomes “answers” instead of links, how misinformation can drive real-world behavior, and why verifying sources matters more now than ever.On the security front, we break down phishing-as-a-service aimed at Microsoft 365 accounts, including spoofed RingCentral messages, email authentication gaps (SPF, DMARC, DKIM), and the simple habits that keep a bad click from turning into a full compromise. We also take a breather with Gwen's gadget pick: a Kickstarter breakfast robot that cracks and cooks eggs and syncs a toaster so it won't “scare” you, plus our whiskey tasting and a data-driven teardown of the Tesla Cybertruck's flop era.If you like smart tech news with humor and practical takeaways, subscribe, share the episode with a friend, and leave us a review. What's the last “AI answer” you trusted that turned out to be wrong?Send us Fan MailSupport the show
The hacker who will attack your organization in five years is in school right now, and nobody is teaching that kid what to do online. HackShield is trying to change that. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Tim Murck, co-founder of HackShield, on why security awareness training for adults keeps failing, and what a game built for seven to twelve year olds can teach every CISO about human risk. If your plan is to train 2,000 people to never click the wrong link, this is the episode that explains why you have already lost, and what to do instead.
Internet scams are evolving faster than ever, with artificial intelligence making phishing emails, fake phone calls, and fraudulent videos more convincing than traditional scams. Jon Penn and Venable Cybersecurity Services Managing Director, Avi Schwartz explain the most common online scams targeting consumers, investors, retirees, and businesses, along with practical steps you can take to protect yourself and your finances. We discuss AI-enhanced phishing attacks, deepfake voice and video scams, business email compromise, texting scams (smishing), elder fraud, and payment fraud involving gift cards and cryptocurrency. We also cover what to do if you've been scammed, how quickly you need to act to improve your chances of recovering stolen funds, and why authentication, passkeys, and independent verification are among your best defenses. Whether you're protecting your retirement savings, your business, or helping aging parents avoid fraud, this episode provides practical cybersecurity and financial safety strategies that can reduce your risk of becoming the next victim. 0:00 INTRO 0:20 - Internet Scams to be Aware of 3:53 - AI enhanced Phishing 7:00 - Deep Fake Voice & Video Scams 13:39 - Catch Them If You Can - How to get your money back 15:37 - Texting scams & smishing 18:21 - How Much Can You Lose? 19:29 - Who are the Targets? 22:34 - How Long Can it Take? 24:40 - Dealing with Elder Fraud 26:11 - How to Prevent or Reduce Chances of Falling Victim to Scams 30:09 - Strengthen Authentication - passkeys 34:10 - Verify Before You Act (avoid urgency) 36:26 - Avoid Engaging with Unknown Contacts - Ignore it 36:55 - Double check all Financial Transactions 38:47 - Watching for Payment Red Flags (Gift Cards & Cyber Currency) 41:58 - Authentication & Verification are Key Hosted by RIA Advisors Senior Investment Advisor, Jon Penn, CFP, w special guest, Venable Cybersecurity Services Managing Director, Ari Schwartz Produced by Brent Clanton, Executive Producer ------- Do you enjoy our content? Rate us on Google: https://bit.ly/4b9JtEo ------- Watch Today's Full Video on our YouTube Channel: https://youtube.com/live/Azt1_vs16bA ------- Articles mentioned in this report: "AI-Driven Fraud Scams Are Evolving Fast: What People Should Watch For and Can Do To Protect Themselves, Their Friends, and Family" https://www.centerforcybersecuritypolicy.org/insights-and-research/ai-driven-fraud-scams-are-evolving-fast-what-people-should-watch-for-and-can-do-to-protect-themselves-their-friends-and-family -------- Watch today's "Before the Bell" premarket commentary, "Markets Consolidate as Sector Rotation Strengthens," https://youtu.be/pG8vxTC6oco ------- Watch our previous show, "Do You Really Know Your Risk Tolerance?" https://youtube.com/live/m3KZ1fbws2k ------- Get more info & commentary: https://realinvestmentadvice.com/insights/real-investment-daily/ ------- * REGISTER for our next Dynamic Learning Series, "Savvy Social Security Planning: More Income, Less Worry," Thursday, August 6, 2026: https://streamyard.com/watch/tQ3PS8hd64mt --- Visit our Site: https://www.realinvestmentadvice.com Contact Us: 1-855-RIA-PLAN --- Subscribe to SimpleVisor : https://www.simplevisor.com/register-new --- Connect with us on social: https://twitter.com/RealInvAdvice https://twitter.com/LanceRoberts https://www.facebook.com/RealInvestmentAdvice/ https://www.linkedin.com/in/realinvestmentadvice/ #CyberSecurity #InternetScams #IdentityTheft #FinancialPlanning #PersonalFinance
As phishing attempts have surged and become increasingly sophisticated, cyber-security firm Cyvore has developed a verification tool available free to the public. Scan My SMS can scan SMS messages and determine whether they are authentic or not. Cyvore Security co-founder and CEO Ori Segal spoke to KAN reporter Naomi Segal (Photo: Illustrative, Shutterstock)See omnystudio.com/listener for privacy information.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co COLDCARD Issues https://x.com/threatinsight/status/2084328552481112429 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Send us Fan MailBeing a Vendor Process Manager is a little like being a referee, detective, and data janitor all at once. In this episode, we'll cover the key priorities that help you reduce risk, improve compliance, and clean up vendor chaos.Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources: Roadmap to a Controlled Vendor ProcessOn-Demand Webinar: Ensuring Adherence: How to Audit Your Vendor Setup and Change Process On-Demand Webinar: 3 Ways To Meet Nacha's ACH Fraud Monitoring - Same Day Foundational Vendor Process Training: Vendor Process Essentials Training Sessions Free Training Session: 8 Steps to Clean Your Vendor Master File Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download: Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training: https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://training.debrarrichardson.com/cleanupYouTube Channel: https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas? Email me at debra@debrarrichardson.com Music Credit: www.purple-planet.com
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing A Deep Dive Into the Latest XCSSET Version https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Guy Swan on learning the wrong lessons. The takeaway circulating is "go with the biggest company," which forgets Mt. Gox and FTX and everything else proving size is not safety. His analogy: when a libertarian politician betrays you, libertarianism didn't break, you got scammed. He wants a rule that works forward. His sharpest point: "I don't want a rule that only works in hindsight." Anyone can now point at the source-available license. The useful question is what indicator predicts the next failure before it happens. His own heuristic broke in both directions. He had trained himself not to dismiss builders for being abrasive, and now concludes that for security specifically, a maintainer who attacks people reporting problems is telling you something. Yan Pritzker paired it with the engineering version: without a culture of safety, people stop surfacing mistakes. James O'Beirne's tripwires. He seeded wallets on-chain carrying graduated entropy over broken Coldcard seeds, five dice rolls, ten, fifteen, one and two-word passphrases, as bait. The bare seed was swept within an hour and nothing else has moved, mapping attacker capability live. The red team's numbers. Rob Hamilton and Calle have scanned over 300 repos and spent roughly $40,000 on tokens in two days, finding critical vulnerabilities at about one per person per hour. OpenSats is now funding most of that budget. Every company needs an agentic security pipeline. Yan's argument: agents are non-deterministic, so one scan proves nothing. The real work is harnesses that find, test, distill and reproduce on a loop. Swan has been building this for six to twelve months. The asymmetry is the whole problem. Attackers need one vulnerability, defenders need all of them, and the economics favor the attacker. Some have been paying up to 90% of stolen funds in fees to get transactions mined quickly. A fake Coldcard desktop app is circulating. No such application has ever existed. Trezor reported a phishing spike since disclosure, and a counterfeit Wasabi wallet reached an app store. Nobody legitimate asks for recovery words, and unsolicited migration instructions are always hostile. Yan's read on whether this repeats. He calls the bug exotic: entropy wasn't weak, it was switched off entirely. Scans across the popular hardware wallets show correct and consistent entropy use, so he thinks this specific failure is unlikely to recur elsewhere. Government overreach, the other half of the show. Suz on Liechtenstein's beneficial ownership register, roughly 31,000 entities, built in 2021 for EU anti-money-laundering compliance and now breached and offline. Yan on the Bank Secrecy Act's 1970 threshold, never inflation-adjusted, capturing dramatically more data for near-zero measured effect.
High-profile attacks on organisations like the NHS, Marks & Spencer and the Co-op have shown that cybercrime isn't just a problem for large organisations. In fact, small independent businesses are often the easier target. In this episode of The Optical Entrepreneur Podcast, Conor is joined by Jason Lydford, the straight-talking cyber leader behind Munio, a multi-award-winning IT support and cybersecurity specialist, to discuss one of the biggest risks facing independent business owners today. Jason explains how cyber attacks happen, why phishing emails remain one of the biggest threats, and the practical steps every practice owner can take to protect their business, team and clients. Whether you own one practice or several, this conversation could save you thousands of pounds, weeks of disruption and a huge amount of stress. In this episode you'll learn: • Why independent businesses are increasingly being targeted • The most common cybersecurity mistakes • How phishing attacks really work • Why multi-factor authentication is essential • How password managers improve security • The importance of staff training • Why backups matter more than you think • How to identify the biggest risks in your business Free Cyber Risk Assessment Jason has kindly offered listeners of The Optical Entrepreneur Podcast a free cyber risk assessment to help identify vulnerabilities in your business and highlight practical steps you can take to improve your security. https://munio-it.co.uk/optical/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing Campaigns Targeting AI Solutions Providers https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/ Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Today's farms rely on technology more than ever. From grain dryers and irrigation pivots to livestock systems, security cameras, accounting software, and smartphones, nearly every part of a modern farming operation is connected. That also makes agriculture one of the fastest-growing targets for cybercriminals. Chris from Tech Support Farm returns to Farm4Profit to discuss how farms can better protect themselves from ransomware, phishing scams, compromised credit cards, malware, and attacks on connected equipment. The conversation covers real-world examples—including Tanner's own experience with fraudulent credit card charges—and explains how remote monitoring, endpoint detection, password management, secure business email, mobile device management, and network monitoring work together to reduce risk. The episode also explores: Business email security Password managers Public Wi-Fi risks Phishing scams Credit card fraud Remote monitoring Endpoint detection (EDR) Mobile device management Irrigation and grain dryer security Data backups Disaster recovery Cyber insurance Farm technology infrastructure AI and digital threats Whether you operate a family farm or a multi-location business, this episode offers practical advice that could save your operation from significant financial loss and downtime. Want Farm4Profit Merch? Custom order your favorite items today!https://farmfocused.com/farm-4profit/ Don't forget to like the podcast on all platforms and leave a review where ever you listen! Website: www.Farm4Profit.comShareable episode link: https://intro-to-farm4profit.simplecast.comEmail address: Farm4profitllc@gmail.comCall/Text: 515.207.9640Subscribe to YouTube: https://www.youtube.com/channel/UCSR8c1BrCjNDDI_Acku5XqwFollow us on TikTok: https://www.tiktok.com/@farm4profitllc Connect with us on Facebook: https://www.facebook.com/Farm4ProfitLLC/Farm4Profit Media is not a financial, legal, or tax advisor. Content is provided for informational purposes only, and we serve solely as a platform for third-party opinions. Any actions taken based on this content are at your own risk. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode, Alex examines a wave of suspected Iranian cyberattacks targeting municipal water systems and argues they are a predictable consequence of escalating U.S.-Iran tensions. He criticizes President Trump's response, contending that blaming political opponents instead of addressing foreign cyber threats weakens deterrence and encourages future attacks. Alex also revisits the Trump administration's handling of the National Mall reflecting pool controversy, using it as another example of what he sees as politically motivated misinformation and misplaced blame.
On this Summer Friday, we've put together some of our favorite recent interviews, including: Ben Rhodes, contributing opinion writer for the New York Times, co-host of "Pod Save the World," an advisor to former president Barack Obama and the author of All We Say: The Battle for American Identity: A History in 15 Speeches (Random House, 2026), talks about his new book that tells the history of the United States and its central conflicts through public speeches, from Benjamin Franklin to Donald Trump. Robinson Meyer, founding executive editor of Heatmap, talks about the DSA's evolving relationship to the Green New Deal and climate policy in general, as its members keep winning elections in big cities. WNYC has been targeted by scammers who posed as hosts, and offered authors interviews -- for a fee (which WNYC would never do). Rachel Tobac, co-founder and CEO of Social Proof Security, and Kenneth Atkins, assistant director of IT and data security at WNYC, talk about how to spot sneaky online phishing scams, and how to deal if you fall for it. Jeffrey Winters, professor of political science at Northwestern University and the director of the Equality Development and Globalization Studies Program at Northwestern's Buffett Institute for Global Affairs and the author of The Blind Spot: How Oligarchs Dominate Our Democracies (Scribner, 2026), talks about the history of oligarchy, how to fight it, and why it maintains power in a democracy. Meghan Sullivan, professor of philosophy at Notre Dame and founder of the Institute for Ethics and the Common Good, offers her take on the contemporary context for belief, or doubt, in God as religious affiliation largely declines in the U.S. These interviews were lightly polished up and edited for time, the original versions are available here: Speeches as a Key to American Identity (June 8, 2026) What the DSA's Popularity Means for Climate Policy (July 7, 2026) How to Avoid Sneaky Phishing Scams (May 5, 2026) When Voters Support Oligarchs (May 26, 2026) How Belief in God Has Changed (May 20, 2026) Photo: Whimbrel on the beach at Fort Tilden beach, Queens. Rare shorebird for this location, 24 September 2021 (Remydee1, CC BY-SA 4.0, via Wikimedia Commons) Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Send us Fan MailIf you think you don't have to worry about duplicate vendors because your Accounting System or ERP catches them – just know – that you probably have duplicate vendors. Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources: Free Training Session: 8 Steps to Clean Your Vendor Master File Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download: Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training: https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://training.debrarrichardson.com/cleanupYouTube Channel: https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas? Email me at debra@debrarrichardson.com Music Credit: www.purple-planet.com
Phishing, spoofing…malvertising? The list of ways bad actors try to steal your info online is a long one. We'll go over some of most common ones and how AI is changing the game with Alex Hamerstone, director of advisory solutions for TrustedSec.
In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.What configuration changes and visibility gaps could be the difference between a minor incident and a full-scale breach? How can you harden your environment with limited resources? Tune into this episode to stay one step ahead of an evolving threat landscape.Talos IR Quarterly Trends Report: https://blog.talosintelligence.com/ir-trends-q2-2026Find Talos at Black Hat: https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026/
A “safe” AI test environment is supposed to be a sandbox, not a launchpad. Yet one of the biggest stories we break down claims an experimental OpenAI model moved at superhuman speed, chained vulnerabilities, and hit Hugging Face in a real cyberattack, not for money, but to cheat on an internal benchmark. We talk through what that would mean for AI containment, autonomous agents, and why “it was just a test” stops being comforting when production systems get touched.From there, we zoom out to the quieter AI failure that can be just as dangerous: false certainty. Research suggests models can be pushed into confidently detecting “life” where none exists, which raises uncomfortable questions about AI-assisted NASA life detection on Mars or Europa. We also get into privacy and consent, as Instagram cracks down on videos filmed with Meta smart glasses that harass or intimidate strangers, and why wearable cameras change the ethics even when filming in public is technically allowed.Then we get painfully practical. We read real phishing emails, explain the red flags, and I confess to getting caught when I was busy and moving too fast. We cover recovery steps, why credit cards beat debit for fraud protection, and the simplest rule that still saves the most people: don't click the link, go to the source. Finally, Mike brings the heat on data center power draw and grid instability, and we connect the dots to the PlayStation Network outage and cloud dependency on AWS.Subscribe for more tech news for everyday people, share this with someone who needs better scam defenses, and leave a review. What's the one message or alert you almost fell for, and what tipped you off?Send us Fan MailSupport the show
Was, wenn die wichtigste Frage nach einem Börsenhalbjahr nicht lautet "Welche Aktie lief am besten?", sondern "Welche Entscheidungen waren richtig?" Genau darum geht es in unserem vierten gemeinsamen Summer Special mit Finanzjournalist Clemens Faustenhammer: kein Ranking aus Gewinnern und Verlierern, sondern Prozess statt Prognose. Ich erzähle, warum ich trotz erwarteter Korrektur mein Depot konsequent umgebaut habe, wieso mein ETF-Portfolio mit rund 16,5 % im Plus die größte Überraschung des Halbjahres war und welche Rolle UnitedHealth, CVS Health und Fastenal dabei gespielt haben.Clemens teilt seine eigene Sicht auf ein Halbjahr voller Überraschungen, wir sprechen über Zinseszins und Haltestrategien, den Wandel vom klassischen Finanzblog zu Substack und darüber, wie Profi-Investoren wie Terry Smith ihre Strategie anpassen. ⏱️ KAPITEL0:00 Begrüßung und Einleitung zum Summer Special3:15 IBM & die Marktkorrektur im Juli 20266:45 Depotqualität statt Markttiming10:20 Zinseszins-Strategie: Clemens über Haltedauer14:50 (Teil-)Verkauf von AT&T und Stanley Black & Decker19:30 KI als Werkzeug für die Aktienanalyse24:10 Finanzblogs vs. Substack: Wandel im Finanzjournalismus29:00 Terry Smith & der Strategiewechsel bei Profi-Investoren34:15 SaaS-Aktien im KI-Hype: Zukunftsaussichten39:00 Abspaltungen und M&A: Aktuelle Trends43:45 Einzelaktien vs. Themen-ETFs im Performance-Check48:30 Südkorea-Volatilität und Samsung-Spekulationen53:20 Zoetis: Fehleranalyse einer schwierigen Position58:00 US-Konsumschwäche: Tractor Supply im Fokus1:02:45 Erfolge mit Corning, Broadcom, Cisco und Fastenal1:06:50 Ausblick: Unser Fokus fürs zweite Halbjahr 20261:09:30 Fazit: Zufriedenheit statt Markt schlagen1:11:12 Outro
Siaybonga Motha speaks to Lebohang Khunou and Mosa Olifant from Lebone Marang Summer who share some insights on the growth and challenges faced in the IT sector across Africa. Tags: 702, The Aubrey Masango Show, Siyabonga Motha, Education Feature, Information Technology, Digital Age, Phishing, Email Scams, Managing Systems, Cybercrime The Aubrey Masango Show is presented by late night radio broadcaster Aubrey Masango. Aubrey hosts in-depth interviews on controversial political issues and chats to experts offering life advice and guidance in areas of psychology, personal finance and more. All Aubrey’s interviews are podcasted for you to catch-up and listen. Thank you for listening to this podcast from The Aubrey Masango Show. Listen live on weekdays between 20:00 and 24:00 (SA Time) to The Aubrey Masango Show broadcast on 702 https://buff.ly/gk3y0Kj and on CapeTalk between 20:00 and 21:00 (SA Time) https://buff.ly/NnFM3Nk Find out more about the show here https://buff.ly/lzyKCv0 and get all the catch-up podcasts https://buff.ly/rT6znsn Subscribe to the 702 and CapeTalk Daily and Weekly Newsletters https://buff.ly/v5mfet Follow us on social media: 702 on Facebook: https://www.facebook.com/TalkRadio702 702 on TikTok: https://www.tiktok.com/@talkradio702 702 on Instagram: https://www.instagram.com/talkradio702/ 702 on X: https://x.com/Radio702 702 on YouTube: https://www.youtube.com/@radio702 CapeTalk on Facebook: https://www.facebook.com/CapeTalk CapeTalk on TikTok: https://www.tiktok.com/@capetalk CapeTalk on Instagram: https://www.instagram.com/ CapeTalk on X: https://x.com/CapeTalk CapeTalk on YouTube: https://www.youtube.com/@CapeTalk567 See omnystudio.com/listener for privacy information.
Modern phishing attacks use AI, QR codes, and session token theft to bypass traditional defenses. Discover five actionable steps small businesses can take to harden email security and close vulnerability windows - no IT team required. TechEd Shield City: Poole Address: Building 148741 Website: https://techedshield.com
Je moet toch een bepaald type hufter zijn om mensen hun spaarcenten te willen stelen. Je moet toch over een ernstig gebrek aan warme gevoelens lijden om iemands toekomst zo te durven afnemen? En toch zijn er best veel. Almaar meer. In het afgelopen jaar kwam 80% van de Belgen in contact met een vorm van online oplichting. Wie zijn die phishers, hoe gaan die te werk en wat kan je zelf doen om je te beschermen? Dat hoor je hier.
Send us Fan MailDo you and your team know what you need to do if there is a fraudulent payment? If you want the five steps that are probably not in your IT team's fraud response plan……Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources: On-Demand Webinar: Build a Fraud Response Plan So You Know What To Do If Business Email Compromise (BEC) Happens https://training.debrarrichardson.com/course/june2024-1Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download: Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training: https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://www.debrarrichardson.com/cleanupYouTube Channel: https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas? Email me at debra@debrarrichardson.com Music Credit: www.purple-planet.com
Send us Fan Mail Many organizations have as part of the vendor validation process to verify vendor's information against state business registrations, IRS TIN Match records, and bank records. If validations are successful that information is trusted and payments are made. Fraudsters are now taking advantage of this trust. How?....Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources: JD Supra Article: Business Identity Theft: How Corporate Hijacking Works and What to DoFind the State A Vendor Is Registered In: OpenCorporatesLinks To State Business Entity Searches: Vendor Process Training Center > Resource LibraryCustomized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download: Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training: https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://www.debrarrichardson.com/cleanupYouTube Channel: https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas? Email me at debra@debrarrichardson.com Music Credit: www.purple-planet.com
Social Engineering klingt erstmal nach ein bisschen Tricksen am Telefon. In Wahrheit geht es um viel mehr. Es geht um Vertrauen, Druck, Hilfsbereitschaft und um die unangenehme Erkenntnis, dass nicht nur Software, sondern auch Menschen angreifbar sind. Ein harmloser Support-Anruf, eine überzeugende Geschichte, ein bekannt klingender Name und plötzlich werden interne Informationen preisgegeben, die einzeln belanglos wirken, zusammen aber den Weg für einen echten Angriff ebnen.In dieser Episode sprechen wir darüber, wie Social Engineering in der Praxis funktioniert. Wir starten mit einem nachgesprochenen Fall aus dem DEF CON Social Engineering CTF und zerlegen danach die Mechanik dahinter. Wir schauen auf Open Source Intelligence (OSINT), auf typische Angriffsphasen, psychologische Hebel wie Autorität, Zeitdruck und Social Proof sowie auf moderne Fälle wie den Axios Supply Chain Angriff im Open Source Umfeld. Außerdem geht es um Phishing, Voice Cloning, Deepfakes, LinkedIn als Recherchequelle und die Frage, warum interne Informationen noch lange keine Identität beweisen.Wenn du verstehen willst, wie Angreifer nicht dein System hacken, sondern eine berechtigte Person dazu bringen, es für sie zu öffnen, dann ist diese Folge für dich. Und ja, vielleicht ist das nächste freundlich klingende Support-Gespräch spannender, als dir lieb ist.Unsere aktuellen Werbepartner findest du auf https://engineeringkiosk.dev/partnersDas schnelle Feedback zur Episode:
Russian intelligence services are targeting Signal, WhatsApp, and Telegram users — not by breaking encryption, but by stealing accounts through phishing, QR code tricks, linked-device abuse, and backup recovery key theft. Tom and Kevin break down the FBI warning, the $10 million Rewards for Justice bounty, and the practical security lesson for anyone relying on encrypted messaging: your app can be secure while your account, endpoint, or recovery path is still the weak link.They also discuss why QR-code phishing and linked-device abuse can bypass what users expect from encrypted messaging, why endpoint and account recovery hygiene matter as much as encrypted transport, what to do when "support" asks for recovery keys or codes, and Tom's personal career update joining Secure Ideas as Executive Director of Consulting.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show **FBI IC3 PSA — Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626The Hacker News — FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.htmlInfosecurity Magazine — FBI Sounds Alarm Over Russian Intelligence Signal Phishing https://www.infosecurity-magazine.com/news/fbi-alarm-russian-intelligence/Rewards for Justice — UNC5792 https://rewardsforjustice.net/rewards/unc5792/SecurityWeek — US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/** Watch this episode on YouTube **https://youtu.be/fxFfY_e_MOI** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
En este episodio de Saga Noticias, analizamos una de las mayores incógnitas del caso de Ismael "El Mayo" Zambada: ¿su captura fue resultado de un secuestro o de una operación encubierta? Junto al periodista Óscar Balderas, Ignacio Gómez Villaseñor desmenuza las contradicciones entre la FGR, Ken Salazar y el FBI, así como los errores y posibles complicidades detrás del caso, con especial atención al papel del piloto "El Jando". Además, conversamos con Víctor Ruiz, CEO de Silikn, sobre los riesgos de ciberseguridad que plantea la nueva campaña de registro de la CURP vía SMS y cómo proteger nuestros datos ante posibles fraudes y ataques de phishing. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This episode examines three emerging cybersecurity threats affecting healthcare organizations: Microsoft 365 Groups being exploited for calendar-based phishing attacks, newly discovered vulnerabilities in the widely used DICOM Toolkit that could impact medical imaging systems, and a data breach that originated through social engineering targeting third-party applications. The hosts provide actionable guidance on tightening platform configurations, vetting vendors, and strengthening staff training to address these preventable security gaps.
Você já imaginou ter uma conta invadida sem que ninguém descubra sua senha? Esse é o princípio do Device Code Phishing, um golpe digital que vem chamando a atenção de especialistas em segurança por explorar um mecanismo legítimo de autenticação usado por serviços e dispositivos conectados. No novo episódio do Podcast Canaltech, Fernanda Santos conversa com Rodrigo Cunha, gerente de Red Team Services da Cipher, unidade de cibersegurança do Grupo Prosegur. Na entrevista, ele explica como funciona esse tipo de ataque, por que ele tem ganhado espaço nos últimos anos e quais cuidados empresas e usuários precisam adotar para se proteger. Durante a conversa, o especialista também fala sobre o papel da inteligência artificial na evolução dos golpes digitais, compartilha exemplos observados em investigações e mostra por que a conscientização continua sendo uma das principais ferramentas de defesa. Você também vai conferir: OpenAI confirma lançamento de sua IA mais poderosa até hoje, vazamento de dados de 500 mil pacientes passa a ser investigado pelo órgão que fiscaliza a proteção de dados no Brasil e chineses criam colete que funciona como um ar-condicionado portátil. Este podcast foi roteirizado e apresentado por Fernanda Santos e contou com reportagens de Marcelo Fischer, Bruno de Blasi e João Melo. A trilha sonora é de Guilherme Zomer, a edição de Leandro Gomes e a arte da capa é de Erick Teixeira.See omnystudio.com/listener for privacy information.
En este episodio de Saga Noticias, analizamos una de las mayores incógnitas del caso de Ismael "El Mayo" Zambada: ¿su captura fue resultado de un secuestro o de una operación encubierta? Junto al periodista Óscar Balderas, Ignacio Gómez Villaseñor desmenuza las contradicciones entre la FGR, Ken Salazar y el FBI, así como los errores y posibles complicidades detrás del caso, con especial atención al papel del piloto "El Jando". Además, conversamos con Víctor Ruiz, CEO de Silikn, sobre los riesgos de ciberseguridad que plantea la nueva campaña de registro de la CURP vía SMS y cómo proteger nuestros datos ante posibles fraudes y ataques de phishing. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.Stories covered:• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlChapters:0:00 Intro & catching up4:31 Google Dialogflow CX "Rogue Agent" flaw11:03 EvilTokens & "ghost phishing"17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 1024:56 HalluSquatting: weaponizing AI hallucinations33:16 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #phishing
Send us Fan MailBanks merge, get acquired or fail – often. This is not something your vendor normally makes their clients aware of, so if you want three ways to find out before fines or returned payments…..Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources: Vendor Master File Tip of the Week (YouTube): What Vendor Teams Need to Know About US Routing #'s – ABA and ACH Federal Deposit Insurance Corporation (FDIC): Failed Bank List PCBB: Closed Bank Mergers and Acquisitions Free Download: Vendor Validation Reference List with Resource Links Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training: https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up: https://www.debrarrichardson.com/cleanupYouTube Channel: https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas? Email me at debra@debrarrichardson.com Music Credit: www.purple-planet.com
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
More Odd DNS Records: NIMLOC https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/ Tenda firmware (multiple versions) contains hidden authentication backdoor https://kb.cert.org/vuls/id/213560 GitLost: GitHub AI Agent Leak https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from Seoul
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Why Ask Credentials If There Are Secret Codes? https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118 Adobe Patches and Updated Patch Release Policy https://helpx.adobe.com/security/Home.html https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery Google Chrome Update (link had issues loading while recording) https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090 NGINX ngx_http_v3_module vulnerability CVE-2026-42530 https://my.f5.com/manage/s/article/K000161616 Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it.A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin credentials, planted custom malware called Infinite.red directly into REDCap's upgrade process, harvested credentials for over a year, then used those credentials to log into Google Workspace as a domain admin and create fake compliance rules to silently forward sensitive research emails — military strategy, geostrategic policy, advanced tech, specific pathogens — straight to Gmail accounts they controlled. And nobody noticed for a very long time.Prasanna and I break down the full attack chain, then walk through every prevention layer that could have stopped it: inventory management, patching, password hygiene, SSO, phishing-resistant MFA, passkeys, DBSC, context-aware access, compliance rule monitoring, credential separation across security domains, and logging. We also get into what backups can and can't do for you in a long-dwell-time attack like this — and why infrastructure-as-code and truly immutable golden images matter more than you might think.If you're running any kind of research platform, academic institution, or medical network — or honestly any organization that uses Google Workspace — this one's for you.Chapters:00:00 — Intro: The attack that phishing-resistant MFA could have stopped01:03 — Show intro & woodworking banter03:26 — What is a living-off-the-land attack?04:02 — Who is UNC5608 and who did they target?05:08 — How REDCap's multi-version design was exploited06:11 — Infinite.red malware and credential harvesting09:01 — Google Workspace infiltration via fake compliance rules10:18 — The keywords they were stealing: pathogens, military strategy, and more11:50 — What could the victims have done differently?12:42 — Inventory management, patching, and legacy version removal14:00 — Why you can't trust application-level authentication alone — use SSO15:18 — Phishing-resistant MFA and why it matters16:00 — Passkeys, FIDO, and why there are zero known attacks against them17:57 — Device-bound session credentials (DBSC) and context-aware access19:38 — Monitor your compliance rules — have a compliance rule for the compliance rule20:40 — Credential separation across security domains23:00 — Get some logging — XDR, SIEM, and catching exfiltration in progress24:00 — What can backups actually do in a long-dwell-time attack?27:00 — Infrastructure-as-code and the right cyber recovery approach28:58 — Protecting your golden images with immutable storage31:59 — Wrap-up
THE BREAK ROOM, WCMF, Friday 6/19, 8am Hour 1) Happy Father's Day! Treat yourself this year with an offsite man cave! 2) Phishing scams via Italian bakeries and AI women. What would YOU fall for? 3) How far would Tommy go for Tony Danza?
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
New Wave Of Phishing Emails with SVG Files https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040 Android 2026-06-01 security patch level vulnerability details https://source.android.com/docs/security/bulletin/2026/2026-06-01 Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826 https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083 https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/ Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024 Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
The FBI warns attackers are abusing Microsoft OAuth authentication. India pushes faster patching as AI speeds up cyberattacks. Iranian hackers blend phishing with SEO poisoning. Anthropic's AI finds thousands of open source flaws, while AI also reshapes bug bounties and fuels supply-chain attacks hitting thousands of GitHub repos. Plus, a new LMS zero-day, bulletproof hosting arrests in the Netherlands, FTC action over bogus “active listening” claims, and another busy week for cyber funding and M&A. Our guest is Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation.” Please disregard all searches for disregard. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation." Selected Reading FBI warns of Kali365 phishing service targeting Microsoft 365 accounts (Bleeping Computer) India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws (Infosecurity Magazine) Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign (Infosecurity Magazine) Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects (SecurityWeek) HackerOne takes an axe to its bug bounty rewards (The Register) Automated 'Megalodon' Campaign Spreads GitHub Repo Backdoors (GovInfo Security) Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment (SecurityWeek) Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands (SecurityWeek) FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (Federal Trade Commission) Socket raises $60 million in Series C funding. (N2K Pro Business Briefing) You can no longer Google the word 'disregard' (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices