Podcasts about Phishing

Act of attempting to acquire sensitive information by posing as a trustworthy entity

  • 2,238PODCASTS
  • 5,915EPISODES
  • 32mAVG DURATION
  • 1DAILY NEW EPISODE
  • Jul 20, 2026LATEST
Phishing

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Phishing

Show all podcasts related to phishing

Latest podcast episodes about Phishing

Datenschutz Plaudereien
DAT410 KI: Amerikanische Anbieter, lokale Hardware und Alternativen in der Schweiz (Follow-up)

Datenschutz Plaudereien

Play Episode Listen Later Jul 20, 2026 21:39 Transcription Available


Andreas Von Gunten und Martin Steiger diskutieren Rückmeldungen und Themen aus früheren Podcast-Episoden. Es geht insbesondere um KI in verschiedenen Varianten, aber auch um Creative Commons-Lizenzen, HIN-E‑Mails und den Schutz vor Phishing.

XY Mag
QR Code : L'arnaque invisible

XY Mag

Play Episode Listen Later Jul 18, 2026 7:31


QR Code : L'arnaque invisible qui vide votre compte en banque Par la rédaction de XY Magazine Au restaurant pour consulter la carte, sur un parcmètre pour payer votre stationnement, ou à une borne de recharge pour alimenter votre véhicule électrique : les QR code est devenu le roi de nos interactions estivales. Mais en ce mois de juillet 2026, au cœur des départs en vacances, ce petit carré de pixels noirs et blancs s’est transformé en l’une des armes de cyberextorsion les plus redoutables de l’année. Son nom ? Le Quishing (la contraction de QR Code et Phishing). En coulisses, des réseaux criminels industrialisent le piratage physique de l’espace public pour dépouiller les touristes. XY Magazine décrypte ce piège indétectable à l’œil nu et vous donne le guide de survie pour protéger votre compte bancaire. Une étude de Microsoft montre que sur le premier quarter 2026 les attaques sont passées de 7 millions à 18 millions et les tentatives de phishing par mail avec QR code de 1 million à 5 millions (graph ci dessous) #image_title L'arnaque du « sticker miroir » Contrairement à un piratage informatique classique qui s’attaque aux serveurs d’une entreprise, le quishing utilise une méthode d’ingénierie sociale d’une simplicité enfantine, mais redoutable d’efficacité. [ QR Code légitime du restaurant ] │ ( Les escrocs collent par-dessus ) ▼ [ Autocollant malveillant ] ──> [ Scan du smartphone ] ──> [ Faux site de paiement ] Le QR code que vous scanner est un leurre qui vous dirige vers un site malveillant et va vous faire réaliser un paiement à un tiers. C’est vous seul qui commettez l’erreur. L’arnaqueur à juste à coller ses faux QR codes partout. Le repérage physique Les escrocs ciblent des lieux à fort passage et à faible surveillance : les terrasses de café bondées, les horodateurs municipaux, ou les stations de charge en libre-service. tous les services de confiance pour lesquels vous savez que vous allez devoir payer. Le masquage Les pirates génèrent un QR code malveillant et l’impriment sur un petit rouleau d’autocollants transparents de haute qualité. Ils viennent ensuite coller manuellement leur sticker exactement par-dessus le QR code légitime de l’établissement ou de la borne de paiement. Le clonage d’interface Lorsque vous scannez ce code avec l’appareil photo de votre smartphone, vous n’êtes pas redirigé vers le site officiel, mais vers une copie conforme (un site miroir). L’interface affiche le logo de la ville pour le stationnement, ou la charte graphique exacte du restaurant. Pensant régler votre note de 15 € ou votre place de parking, vous entrez vos coordonnées bancaires ou validez un accès Apple Pay / Google Pay. À l’autre bout du fil, l’escroc récupère vos jetons d’authentification et vide votre compte en quelques minutes. Pourquoi l’arnaque explose cet été Le quishing fait des ravages pour une raison psychologique simple : nous faisons naturellement confiance au support physique. Un internaute a appris à se méfier d'un e-mail suspect ou d’un SMS inconnu. En revanche, face à une borne de recharge ou une table de restaurant bien réelle, son niveau de vigilance baisse drastiquement. Pour l’utilisateur, l’objet physique valide la sécurité du lien numérique. Un angle mort que les cybercriminels exploitent au maximum. Le piratage des parcmètres ou des menus de restaurant (le Quishing par sticker) n’est que la face émergée de l’iceberg. Les cybercriminels ont compris que le QR code est le cheval de Troie parfait pour s’introduire dans nos smartphones. Trois autres illustration du mode opératoires des escrocs avec les QR codes. L’arnaque à la “Fausse Amende” sur le pare-brise C’est une variante particulièrement perverse qui touche de nombreuses municipalités françaises. Le mode opératoire : Vous retrouvez sur votre pare-brise un avis d'infraction qui ressemble en tout point à un véritable avis de contravention (mots d’ordre juridiques, logos officiels de la République Française ou de l’ANTAI). Le papier cartonné comporte un QR code avec la mention : “Payez votre amende minorée en ligne sous 48h pour éviter les poursuites”. Le piège : Pris de panique à l’idée de payer plus cher, l’automobiliste scanne le code. Il arrive sur une réplique parfaite du site de l’ANTAI (l’Agence nationale de traitement automatisé des infractions). Non seulement la victime se fait voler ses coordonnées bancaires, mais elle donne également son numéro de permis de conduire et son adresse (des données en or pour l’usurpation d’identité). La parade : En France, l’ANTAI n’envoie jamais d’amendes physiques à scanner directement sur le pare-brise. Les vrais avis de verbalisation arrivent toujours par courrier postal ou par e-mail sécurisé via le site officiel antai.gouv.fr. Le “Reverse Quishing” : L’arnaque au faux paiement de l’acheteur Cette technique cible directement les millions de Français qui vendent des objets d’occasion sur des plateformes comme Leboncoin ou Vinted. Le mode opératoire : Vous vendez un meuble ou un vêtement. Un acheteur se montre très intéressé et vous propose de vous payer immédiatement via une application populaire (Paylib, Lydia ou PayPal). Il vous envoie par SMS ou via la messagerie de l’application un QR code en vous disant : “Scannez ce code pour recevoir directement l’argent sur votre compte”. Le piège : C’est une inversion des rôles. Ce QR code n’est pas un ordre de crédit, mais un ordre de débit ou un lien vers une fausse page d’authentification bancaire. En le scannant et en validant sur votre application bancaire, vous n’encaissez pas de l’argent : vous autorisez un virement vers le compte de l’escroc. La parade : On n’a jamais besoin de scanner un QR code pour recevoir un paiement. Un simple numéro de téléphone ou une adresse e-mail suffit pour recevoir de l’argent via les applications sécurisées. Le piratage des avis de passage de colis (La fausse livraison) Face à la méfiance grandissante vis-à-vis des SMS frauduleux (comme les arnaques de faux colis Chronopost), les escrocs sont repassés au papier dans les boîtes aux lettres. Le mode opératoire : Vous trouvez un papier jaune ou blanc dans votre boîte aux lettres qui imite un avis de passage de La Poste, de DHL ou d’Amazon. Il y est écrit : “Votre colis n’a pu être livré. Pour planifier une nouvelle livraison à domicile, scannez ce QR code sous 24 heures”. Le piège : Le code renvoie vers un faux site de transporteur. On vous demande d’entrer vos coordonnées et de payer “des frais de reprogrammation” minimes (souvent entre 0,49 € et 1,95 €). Ce petit paiement sert d’hameçon pour enregistrer votre carte bancaire et déclencher, quelques jours plus tard, des abonnements cachés de plusieurs dizaines d’euros par mois ou des achats frauduleux. La parade : Les vrais transporteurs laissent des avis de passage comportant un numéro de colis clair. Il faut aller soi-même sur le site officiel du transporteur et taper manuellement le numéro de suivi pour vérifier le statut de la livraison. Comment déjouer le piège ? Pour éviter que vos vacances ne virent au cauchemar financier, trois réflexes élémentaires doivent être adoptés dès aujourd’hui : Pratiquez le « test du toucher » Avant de dégainer votre smartphone et de scanner un QR code dans l’espace public, passez simplement votre doigt sur le support. Sentez-vous une surépaisseur ? S’agit-il d’un autocollant collé à la va-vite par-dessus le panneau d’origine ? Si le QR code bouge ou se décolle, ne le scannez sous aucun prétexte et prévenez le personnel de l’établissement ou la mairie. Si c’est un restaurant demandez aux employés si c’est le bon code. Analysez l'URL avant de cliquer Lorsque l’appareil photo de votre smartphone (iOS ou Android) détecte un QR code, il affiche un petit encadré jaune ou une notification indiquant l’adresse web (l’URL) de destination. Ne cliquez pas machinalement. Prenez deux secondes pour lire l’adresse. Si vous êtes censé payer un stationnement à Paris et que l’URL se termine par un domaine étrange (ex: .ru, .cc, .xyz) ou contient des fautes d’orthographe dans le nom de la marque (ex: pariis-stationnement.com), fuyez. Utilisez une application de scan sécurisée L’application photo native de votre téléphone ouvre les liens de manière aveugle. Pour vos déplacements, téléchargez une application de scan intégrant un filtre de sécurité. Des outils gratuits conçus par des laboratoires de cybersécurité reconnus (comme Kaspersky QR Scanner ou Trend Micro Check) analysent la réputation du lien en temps réel et bloquent instantanément l’affichage si le site de destination est répertorié comme frauduleux ou malveillant. C’est le système le plus sur. Conclusion : Restez connectés, restez protégés Le QR code reste un outil formidable de praticité au quotidien, mais l’espace public n’est plus une zone de confiance absolue. Cet été, le mot d’ordre est la vérification.The post QR Code : L'arnaque invisible first appeared on XY Magazine.

Putting the AP in hAPpy
Episode 395: Your Vendor's Validations Were Successful - So Why Could It Still Be Fraud?

Putting the AP in hAPpy

Play Episode Listen Later Jul 16, 2026 34:00


Send us Fan Mail Many organizations have as part of the vendor validation process to verify vendor's information against state business registrations, IRS TIN Match records, and bank records.  If validations are successful that information is trusted and payments are made.  Fraudsters are now taking advantage of this trust.  How?....Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    JD Supra Article:  Business Identity Theft: How Corporate Hijacking Works and What to DoFind the State A Vendor Is Registered In:  OpenCorporatesLinks To State Business Entity Searches:  Vendor Process Training Center > Resource LibraryCustomized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download:  Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Engineering Kiosk
#276 Social Engineering: Nicht gehackt, nur nett gefragt

Engineering Kiosk

Play Episode Listen Later Jul 14, 2026 63:22 Transcription Available


Social Engineering klingt erstmal nach ein bisschen Tricksen am Telefon. In Wahrheit geht es um viel mehr. Es geht um Vertrauen, Druck, Hilfsbereitschaft und um die unangenehme Erkenntnis, dass nicht nur Software, sondern auch Menschen angreifbar sind. Ein harmloser Support-Anruf, eine überzeugende Geschichte, ein bekannt klingender Name und plötzlich werden interne Informationen preisgegeben, die einzeln belanglos wirken, zusammen aber den Weg für einen echten Angriff ebnen.In dieser Episode sprechen wir darüber, wie Social Engineering in der Praxis funktioniert. Wir starten mit einem nachgesprochenen Fall aus dem DEF CON Social Engineering CTF und zerlegen danach die Mechanik dahinter. Wir schauen auf Open Source Intelligence (OSINT), auf typische Angriffsphasen, psychologische Hebel wie Autorität, Zeitdruck und Social Proof sowie auf moderne Fälle wie den Axios Supply Chain Angriff im Open Source Umfeld. Außerdem geht es um Phishing, Voice Cloning, Deepfakes, LinkedIn als Recherchequelle und die Frage, warum interne Informationen noch lange keine Identität beweisen.Wenn du verstehen willst, wie Angreifer nicht dein System hacken, sondern eine berechtigte Person dazu bringen, es für sie zu öffnen, dann ist diese Folge für dich. Und ja, vielleicht ist das nächste freundlich klingende Support-Gespräch spannender, als dir lieb ist.Unsere aktuellen Werbepartner findest du auf https://engineeringkiosk.dev/partnersDas schnelle Feedback zur Episode:

Cyber Morning Call
1046 - Servidor mal configurado expõe três operações de phishing contra o Microsoft 365

Cyber Morning Call

Play Episode Listen Later Jul 14, 2026 7:35


Referências do EpisódioWEBINAR: A CONFIANÇA COMO PORTA DE ENTRADA DO ATACANTEOne Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing OperatorsImprove Router Hygiene to Protect Against Russian State-Sponsored TargetingCrashStealer: C++ macOS infostealer posing as crash reporterOAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration Roteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

The Shared Security Show
Signal Phishing and Russian Intelligence Targeting Messaging Apps

The Shared Security Show

Play Episode Listen Later Jul 13, 2026 15:50


Russian intelligence services are targeting Signal, WhatsApp, and Telegram users — not by breaking encryption, but by stealing accounts through phishing, QR code tricks, linked-device abuse, and backup recovery key theft. Tom and Kevin break down the FBI warning, the $10 million Rewards for Justice bounty, and the practical security lesson for anyone relying on encrypted messaging: your app can be secure while your account, endpoint, or recovery path is still the weak link.They also discuss why QR-code phishing and linked-device abuse can bypass what users expect from encrypted messaging, why endpoint and account recovery hygiene matter as much as encrypted transport, what to do when "support" asks for recovery keys or codes, and Tom's personal career update joining Secure Ideas as Executive Director of Consulting.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show **FBI IC3 PSA — Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626The Hacker News — FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.htmlInfosecurity Magazine — FBI Sounds Alarm Over Russian Intelligence Signal Phishing https://www.infosecurity-magazine.com/news/fbi-alarm-russian-intelligence/Rewards for Justice — UNC5792 https://rewardsforjustice.net/rewards/unc5792/SecurityWeek — US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/** Watch this episode on YouTube **https://youtu.be/fxFfY_e_MOI** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

Caffe 2.0
3944 LONG Disabili digitali e tutti gli errori possibili dalla notifica alla multa per 1km all'ora

Caffe 2.0

Play Episode Listen Later Jul 11, 2026 23:08 Transcription Available


Sara' una puntata noiosa. lo anticipo. Ma tocca tutti. In conclusione il problema e la ricetta per la semplificazione: ripensare i processi e tornare alla trasparenza.Epopea per una notifica sbagliata di una multa per 1km all'ora oltre i limiti.E' dalle multe che vediamo lo Stato nel portafoglio. Se da questi verbali esce il caos invece che autorevolezza c'e' da piangere.Assurdità per un normodotato figurarsi un diversamente abile:notifica alla residenza di 25 anni fa- ritiro in posto non del verbale ma di un altro (il terzo) avvisol'avviso chiede di collegarsi a internet e scaricaresi entra con pec per leggere l'avviso, e si scavalca la richiesta di delegargli la gestione del domicilio digitale per qualsiasi notifica ipotizzabile. Richiesta piu' volte ripetuta anche rispondendo no (anche se farebbe risparmiare i costi della notifica)scarichi l'avviso. Cerchi di pagarlo nel termine che scade in giornata, ma e' sabato e pagopa sposta il pagamento a lunedi', senza sapere se anche il sabato vale come giorno festivo. Sarebbe un costo ulterioreSul sito l'importo da pagare e' diverso, non si capisce perche'. Phishing ?Rinuncio a pagopa e provo a pagare dal sito stesso: con la prepagata aspetti 5 minuti senza nessun messaggio. Ripetere da' errore. Devi uscire e ripipparti la storia della delegaRinuncio all'online: vado in posta con il tuo avviso di 36 euro e n e paghi 49. Non si capisce ne' dal verbale ne' dalla ricevuta in postaInvio richiesta informazioni sui dati sbagliati della notifica: il form online non funziona, nemmeno disattivando i 14 avvisi di sicurezza dell'antivirus (gia' tolti per cercare di pagare online).E questi signori si permettono di chiedermi se voglio delegarli a gestire le mie notifiche digitali ? NO !Abbiamo diritto alla semplificazione e alla trasparenza ?

Solo con Adela / Saga Live by Adela Micha
Max Espejel con toda la información en Saga Noticias 9 julio 2026

Solo con Adela / Saga Live by Adela Micha

Play Episode Listen Later Jul 10, 2026 56:53


En este episodio de Saga Noticias, analizamos una de las mayores incógnitas del caso de Ismael "El Mayo" Zambada: ¿su captura fue resultado de un secuestro o de una operación encubierta? Junto al periodista Óscar Balderas, Ignacio Gómez Villaseñor desmenuza las contradicciones entre la FGR, Ken Salazar y el FBI, así como los errores y posibles complicidades detrás del caso, con especial atención al papel del piloto "El Jando". Además, conversamos con Víctor Ruiz, CEO de Silikn, sobre los riesgos de ciberseguridad que plantea la nueva campaña de registro de la CURP vía SMS y cómo proteger nuestros datos ante posibles fraudes y ataques de phishing. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

HIPAA Critical
Attackers abuse Microsoft 365 Groups to create phishing invitations

HIPAA Critical

Play Episode Listen Later Jul 10, 2026 4:00 Transcription Available


This episode examines three emerging cybersecurity threats affecting healthcare organizations: Microsoft 365 Groups being exploited for calendar-based phishing attacks, newly discovered vulnerabilities in the widely used DICOM Toolkit that could impact medical imaging systems, and a data breach that originated through social engineering targeting third-party applications. The hosts provide actionable guidance on tightening platform configurations, vetting vendors, and strengthening staff training to address these preventable security gaps.

Canaltech Podcast
O golpe que não precisa da sua senha: entenda o Device Code Phishing

Canaltech Podcast

Play Episode Listen Later Jul 10, 2026 16:46


Você já imaginou ter uma conta invadida sem que ninguém descubra sua senha? Esse é o princípio do Device Code Phishing, um golpe digital que vem chamando a atenção de especialistas em segurança por explorar um mecanismo legítimo de autenticação usado por serviços e dispositivos conectados. No novo episódio do Podcast Canaltech, Fernanda Santos conversa com Rodrigo Cunha, gerente de Red Team Services da Cipher, unidade de cibersegurança do Grupo Prosegur. Na entrevista, ele explica como funciona esse tipo de ataque, por que ele tem ganhado espaço nos últimos anos e quais cuidados empresas e usuários precisam adotar para se proteger. Durante a conversa, o especialista também fala sobre o papel da inteligência artificial na evolução dos golpes digitais, compartilha exemplos observados em investigações e mostra por que a conscientização continua sendo uma das principais ferramentas de defesa. Você também vai conferir: OpenAI confirma lançamento de sua IA mais poderosa até hoje, vazamento de dados de 500 mil pacientes passa a ser investigado pelo órgão que fiscaliza a proteção de dados no Brasil e chineses criam colete que funciona como um ar-condicionado portátil. Este podcast foi roteirizado e apresentado por Fernanda Santos e contou com reportagens de Marcelo Fischer, Bruno de Blasi e João Melo. A trilha sonora é de Guilherme Zomer, a edição de Leandro Gomes e a arte da capa é de Erick Teixeira.See omnystudio.com/listener for privacy information.

Me lo dijo Adela con Adela Micha
Max Espejel con toda la información en Saga Noticias 9 julio 2026

Me lo dijo Adela con Adela Micha

Play Episode Listen Later Jul 10, 2026 56:53


En este episodio de Saga Noticias, analizamos una de las mayores incógnitas del caso de Ismael "El Mayo" Zambada: ¿su captura fue resultado de un secuestro o de una operación encubierta? Junto al periodista Óscar Balderas, Ignacio Gómez Villaseñor desmenuza las contradicciones entre la FGR, Ken Salazar y el FBI, así como los errores y posibles complicidades detrás del caso, con especial atención al papel del piloto "El Jando". Además, conversamos con Víctor Ruiz, CEO de Silikn, sobre los riesgos de ciberseguridad que plantea la nueva campaña de registro de la CURP vía SMS y cómo proteger nuestros datos ante posibles fraudes y ataques de phishing. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The Cybersecurity Defenders Podcast
Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 9, 2026 34:26


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.Stories covered:• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlChapters:0:00 Intro & catching up4:31 Google Dialogflow CX "Rogue Agent" flaw11:03 EvilTokens & "ghost phishing"17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 1024:56 HalluSquatting: weaponizing AI hallucinations33:16 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #phishing

Putting the AP in hAPpy
Episode 394: Your Vendor's Bank Routing Numbers Do Change – 3 Ways You Find Out Before Nacha Fines or Returned Payments

Putting the AP in hAPpy

Play Episode Listen Later Jul 9, 2026 24:04


Send us Fan MailBanks merge, get acquired or fail – often.  This is not something your vendor normally makes their clients aware of, so if you want three ways to find out before fines or returned payments…..Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Vendor Master File Tip of the Week (YouTube): What Vendor Teams Need to Know About US Routing #'s – ABA and ACH Federal Deposit Insurance Corporation (FDIC):  Failed Bank List PCBB:  Closed Bank Mergers and Acquisitions Free Download:  Vendor Validation Reference List with Resource Links Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Altalex News
Altalex Settimanale n. 25/2026: le notizie dal 6 al 10 luglio

Altalex News

Play Episode Listen Later Jul 9, 2026 10:11


La prima causa "dell'intelligenza artificiale" e il sequestro preventivo di contenuti illeciti GenAI. Inoltre, sinistri stradali e fauna selvatica, correntisti e frodi phishing con tecniche di spoofing.>> Leggi anche l'articolo: https://tinyurl.com/236tb426>> Scopri tutti i podcast di Altalex: https://bit.ly/2NpEc3w

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 8, 2026 7:20


More Odd DNS Records: NIMLOC https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/ Tenda firmware (multiple versions) contains hidden authentication backdoor https://kb.cert.org/vuls/id/213560 GitLost: GitHub AI Agent Leak https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Podcast der Deutschen Anwaltauskunft
Podcast der Deutschen Anwaltauskunft – Urteil der Woche (711): Online-Verkauf, Chat und falsche Mitarbeiter – wann die Versicherung beim Phishing wirklich zahlt

Podcast der Deutschen Anwaltauskunft

Play Episode Listen Later Jul 6, 2026 4:32


Online-Plattformen wie Vinted oder Kleinanzeigen gehören für viele Menschen zum Alltag. Schnell ist ein gebrauchter Kinderwagen, ein Handy oder ein Möbel eingestellt – und meist findet sich rasch ein interessierter Käufer. Doch parallel zu diesem Trend haben sich auch Betrugsmaschen etabliert: Täter geben sich als Käufer oder Plattformmitarbeiter aus, lotsen Nutzer aus der vertrauten Umgebung […]

The Best of Weekend Breakfast
Personal Finance: Scammers are everywhere: How they operate and how to stay safe

The Best of Weekend Breakfast

Play Episode Listen Later Jul 5, 2026 8:56 Transcription Available


Gugs Mhlungu speaks with Paul Roelofse, resident Certified Financial Planner, about the many ways scammers target unsuspecting victims. They unpack the warning signs to watch for, including high-pressure tactics, creating a false sense of urgency, and requests for personal information or quick approvals, as well as practical tips to help you avoid falling victim to fraud. Gugs Mhlungu gets you ready for the weekend each Saturday and Sunday morning on 702. She is your weekend wake-up companion, with all you need to know for your weekend. The topics Gugs covers range from lifestyle, family, health, and fitness to books, motoring, cooking, culture, and what is happening on the weekend in 702land. Thank you for listening to a podcast from 702 Weekend Breakfast with Gugs Mhlungu. Listen live on Primedia+ on Saturdays and Sundays from 06:00 and 10:00 (SA Time) to Weekend Breakfast with Gugs Mhlungu broadcast on 702 https://buff.ly/gk3y0Kj For more from the show go to https://buff.ly/u3Sf7Zy or find all the catch-up podcasts here https://buff.ly/BIXS7AL Subscribe to the 702 daily and weekly newsletters https://buff.ly/v5mfetc Follow us on social media: 702 on Facebook: https://www.facebook.com/TalkRadio702 702 on TikTok: https://www.tiktok.com/@talkradio702 702 on Instagram: https://www.instagram.com/talkradio702/ 702 on X: https://x.com/Radio702 702 on YouTube: https://www.youtube.com/@radio702 See omnystudio.com/listener for privacy information.

Security Conversations
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen

Security Conversations

Play Episode Listen Later Jul 4, 2026 96:03


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from Seoul

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 2, 2026 6:15


Why Ask Credentials If There Are Secret Codes? https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118 Adobe Patches and Updated Patch Release Policy https://helpx.adobe.com/security/Home.html https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery Google Chrome Update (link had issues loading while recording) https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Decipher Security Podcast
Fable 5 Export Controls, the Dual Use Paradox, and the ARToken Phishing Framework

Decipher Security Podcast

Play Episode Listen Later Jul 2, 2026 37:28


It's a pre-July 4th extravaganza! To celebrate, we dive into a little cybersecurity history with a story about the MySpace Samy worm, then we jumpe into the news of the week, including an update on the Fable 5 export control drama, and the emergence of the ARToken operator panel.

The Cybersecurity Defenders Podcast
Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 1, 2026 30:01


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR

WSKY The Bob Rose Show
Bugged by travel outfits, definition of “IS,” Iran embarrassment, cat love, Yahoo replies, email phishing training

WSKY The Bob Rose Show

Play Episode Listen Later Jun 26, 2026 6:35


Putting the AP in hAPpy
Episode 393: 5 Reasons to Establish a Vendor Process Audit

Putting the AP in hAPpy

Play Episode Listen Later Jun 25, 2026 27:19


Send us Fan MailOrganizations put processes in place when adding new vendors and changing existing vendor information to avoid fraud, regulatory fines and bad vendor data.  But are they being followed?Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Free Webinar:  Ensuring Adherence: How to Audit Your Vendor Setup and Free On-Demand Training:  8 Steps To Clean Your Vendor Master File Free Download:  Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 22, 2026 6:06


eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090 NGINX ngx_http_v3_module vulnerability CVE-2026-42530 https://my.f5.com/manage/s/article/K000161616 Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Backup Central's Restore it All
The REDCap Attack that Phishing-Resistant MFA Could Have Stopped

Backup Central's Restore it All

Play Episode Listen Later Jun 22, 2026 34:01 Transcription Available


Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it.A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin credentials, planted custom malware called Infinite.red directly into REDCap's upgrade process, harvested credentials for over a year, then used those credentials to log into Google Workspace as a domain admin and create fake compliance rules to silently forward sensitive research emails — military strategy, geostrategic policy, advanced tech, specific pathogens — straight to Gmail accounts they controlled. And nobody noticed for a very long time.Prasanna and I break down the full attack chain, then walk through every prevention layer that could have stopped it: inventory management, patching, password hygiene, SSO, phishing-resistant MFA, passkeys, DBSC, context-aware access, compliance rule monitoring, credential separation across security domains, and logging. We also get into what backups can and can't do for you in a long-dwell-time attack like this — and why infrastructure-as-code and truly immutable golden images matter more than you might think.If you're running any kind of research platform, academic institution, or medical network — or honestly any organization that uses Google Workspace — this one's for you.Chapters:00:00 — Intro: The attack that phishing-resistant MFA could have stopped01:03 — Show intro & woodworking banter03:26 — What is a living-off-the-land attack?04:02 — Who is UNC5608 and who did they target?05:08 — How REDCap's multi-version design was exploited06:11 — Infinite.red malware and credential harvesting09:01 — Google Workspace infiltration via fake compliance rules10:18 — The keywords they were stealing: pathogens, military strategy, and more11:50 — What could the victims have done differently?12:42 — Inventory management, patching, and legacy version removal14:00 — Why you can't trust application-level authentication alone — use SSO15:18 — Phishing-resistant MFA and why it matters16:00 — Passkeys, FIDO, and why there are zero known attacks against them17:57 — Device-bound session credentials (DBSC) and context-aware access19:38 — Monitor your compliance rules — have a compliance rule for the compliance rule20:40 — Credential separation across security domains23:00 — Get some logging — XDR, SIEM, and catching exfiltration in progress24:00 — What can backups actually do in a long-dwell-time attack?27:00 — Infrastructure-as-code and the right cyber recovery approach28:58 — Protecting your golden images with immutable storage31:59 — Wrap-up

The Break Room
AI Insta Baddies & Grand-Sugar Daddies

The Break Room

Play Episode Listen Later Jun 19, 2026 40:34


THE BREAK ROOM, WCMF, Friday 6/19, 8am Hour 1) Happy Father's Day! Treat yourself this year with an offsite man cave! 2) Phishing scams via Italian bakeries and AI women. What would YOU fall for? 3) How far would Tommy go for Tony Danza?

Libertópolis - Ideas con valor
Phishing y estafas bancarias: las trampas más comunes

Libertópolis - Ideas con valor

Play Episode Listen Later Jun 18, 2026 44:43


Libertópolis Negocios, jueves 18-06-2026

Cybercrime Magazine Podcast
Cybercrime News For Jun. 18, 2026. FBI Dismantles AI Phishing Service. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Jun 18, 2026 2:57


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Putting the AP in hAPpy
Episode 392: Nacha Fraud Monitoring Rule Compliance for Non-Consumer Originators - Now Everyone Must Comply

Putting the AP in hAPpy

Play Episode Listen Later Jun 18, 2026 16:36


Send us Fan MailPhase 2 of the Nacha Fraud Monitoring Rule for ACH initiators is here and now everyone has to comply.  What are the requirements and are you ready?Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Nacha:  RISK MANAGEMENT TOPICS – (Fraud Monitoring Phase 2)Free Nacha Compliance Webinar: 3 Ways To Meet Nacha's ACH Fraud Monitoring Rule - Same Day Compliance! Confirmation Call / But Better:  Vendor Callback Confirmation ToolkitTM Customized Vendor Validations Session: https://debrarrichardson.com/vendor-validation-sessionFree Download:  Vendor Validation Reference List with Resource Links https://debrarrichardson.com/vendor-validation-downloadVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com 

5bytespodcast
AI Agents Leak Data, Fall For Phishing & More

5bytespodcast

Play Episode Listen Later Jun 17, 2026 26:11


This week, we're seeing a pattern emerge across the industry when it comes to AI. Anthropic is dealing with restrictions on its newest model put in place by the US government. Researchers tricked AI agents into handing over credentials and customer data and Microsoft unfortunately is once again cleaning up after a supply chain compromise. AI is obviously getting more capable but it is also creating entirely new security problems that we all have to come to terms with and I'll be talking about this and much more on this week's episode. Reference Links: https://www.rorymon.com/blog/ai-agents-leak-data-fall-for-phishing-more/

Cyber Security Headlines
Anthropic models defended, FBI shuts down massive phishing service, 1Password acquires Apono

Cyber Security Headlines

Play Episode Listen Later Jun 16, 2026 7:39


Cyber leaders defend Anthropic's banned models FBI disrupts massive phishing service 1Password acquires Apono Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.  

Cyber Security Today
Anthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and more

Cyber Security Today

Play Episode Listen Later Jun 15, 2026 10:35


The U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk. David Shipley examines what may be  behind the decision and what it means for countries and businesses that depend on American AI platforms. The FBI also disrupts Outsider Enterprise, a China-based phishing-as-a-service network linked to more than 9,000 fake websites, one million fraudulent URLs, 3.8 million stolen payment-card records and an estimated $1.9 billion in losses. Also in this episode: A critical Splunk vulnerability could allow an unauthenticated attacker to remotely execute code through a PostgreSQL sidecar service enabled by default in some deployments. A former Iowa school IT worker is sentenced after retaining access for 21 months and using it to delete accounts and disrupt school systems. And FortiWatch returns with a critical FortiSandbox command-injection vulnerability that requires no authentication. Cybersecurity Today is hosted by David Shipley. Chapters 00:00 Cybersecurity Today headlines 00:26 U.S. government shuts down Anthropic AI models 02:59 FBI takes down Outsider Enterprise phishing network 04:47 Critical Splunk vulnerability explained 06:31 Former school IT worker sentenced for cyberattack 08:29 FortiWatch: FortiSandbox command-injection vulnerability 10:08 What's ahead this week

Minimum Competence
Legal News for Mon 6/15 - Judge McConnell Scolds DOJ, Google Sues Chinese Gemini Phishing Ring, Judge Blocks Trump's Xenophobic Parks Orders

Minimum Competence

Play Episode Listen Later Jun 15, 2026 8:12


This Day in Legal History: Magna Carta Sealed at RunnymedeOn this day in 1215, in a meadow at Runnymede on the south bank of the Thames, King John of England affixed his seal to a document the rebellious English barons had drafted, in which the king conceded a series of limits on his own royal authority. We call it Magna Carta — the Great Charter. The immediate political context was a baronial revolt against John's tax exactions for his disastrous French wars, and most of the sixty-three chapters as drafted in 1215 are concerned with the highly specific grievances of a feudal aristocracy: scutage, wardship, the inheritance fees of widows, the freedom of the church, the standardization of weights and measures in the king's markets. The two chapters that the centuries have remembered are 39 and 40. Chapter 39 says that no free man shall be taken or imprisoned or dispossessed except by the lawful judgment of his peers or by the law of the land. Chapter 40 says that to no one will the king sell, deny, or delay right or justice. The Charter was annulled by Pope Innocent III within ten weeks of sealing — the pope held that John, as a vassal of the Holy See, could not be bound by a treaty extracted under duress — and the country immediately collapsed into the First Barons' War. But John died in October 1216, his nine-year-old son Henry III's regents reissued the Charter as a tactical concession the next month, it was reissued again in 1217 and 1225, and by the late thirteenth century the 1225 version had been confirmed by successive kings as a foundational statute of the realm. Edward Coke, writing in the seventeenth century, transformed Chapter 39's “law of the land” into the doctrine of due process, and the founding generation of the American Republic picked up Coke's reading and wrote it directly into the Fifth and Fourteenth Amendments of the United States Constitution. The phrase “due process of law” in those amendments is the most consequential American inheritance from the Runnymede document. The principle the barons were trying to extract from a beleaguered king — that the law constrains the sovereign too — is the substrate on which everything we recognize as constitutionalism is built. Eight hundred and eleven years on, the principle is still the work.The Rhode Island travel-ban lawsuit we covered on June 8 took a sharp turn on Friday. Chief Judge John J. McConnell, Jr., of the District of Rhode Island held a status conference in Dorcas International Institute v. USCIS at which he was openly frustrated with the Justice Department for failing to immediately implement his June 5 vacatur of the four USCIS benefit-freeze policies for nationals of the thirty-nine travel-ban countries. The judge's message, in plain terms, was that vacatur under the Administrative Procedure Act is self-executing — the moment the order was entered, the policies ceased to exist, and the agency was obligated to resume processing affirmative benefits, asylum claims, and adjudicator-instruction reviews on the prior pre-freeze basis. The Trump administration, after the hearing, told the court it would comply, restart adjudications, and clear the backlog. It also did what defendants typically do when they have lost on the merits and lost again on compliance: it filed a notice of appeal with the First Circuit and asked the appellate court to stay the vacatur pending appeal. That is the live question now. The First Circuit's stay analysis runs through the standard Nken v. Holder factors — likelihood of success on the merits, irreparable harm, the balance of equities, and the public interest — and the administration's strongest argument on each is going to be familiar: the executive needs administrative breathing room to implement a travel ban, mass restoration of adjudications creates national-security risk, the harm to applicants is reversible if their adjudications are paused for a few more weeks. The plaintiffs' strongest counterarguments are also familiar: the policies were unlawful when adopted and the agency had no business adopting them, the harm to applicants from continued delay is concrete and accruing daily, and the First Circuit is not in the business of staying vacaturs of unlawful agency action in order to let the agency continue acting unlawfully. Watch the First Circuit's calendar this week. The stay motion is the next inflection point.Trump officials agree to resume asylum processing after being scolded by judge | The Washington PostGoogle filed suit on Friday in the U.S. District Court for the Southern District of New York against a China-based cybercrime network it calls the “Outsider Enterprise,” alleging that the network's members used Google's Gemini large-language model to generate the code, copy, and templates for a phishing-as-a-service platform that has built more than nine thousand fraudulent websites and sent two and a half million scam text messages in the two weeks ending June 1 alone. The complaint is significant for two reasons. First, it is, to Google's knowledge, the first time the company has affirmatively sued threat actors for using its own generative-AI product as the input to a scaled criminal operation, as distinct from the more usual posture of suing scammers who impersonate Google brands. The legal theories are a mix of Lanham Act false-designation-of-origin and trademark-infringement counts, Computer Fraud and Abuse Act counts based on Outsider's unauthorized access to Google services, breach-of-contract counts on the Gemini terms of service, and a RICO count. Second, the factual record will be a road map for the next decade of AI-misuse litigation. The complaint describes Telegram channels in which Outsider members trade prompts that get Gemini to write phishing code, a library of two hundred and ninety prebuilt templates impersonating brands ranging from the U.S. Postal Service to state DMVs to E-ZPass, and an FBI estimate that the broader campaign Outsider participates in has stolen roughly 3.87 million card numbers and caused $1.9 billion in losses since July 2023. The remedy Google is seeking is a permanent injunction shutting the operation down, plus domain seizures and account terminations across Google's services and at major U.S. carriers, which Google says it has been coordinating with the FBI, AT&T, T-Mobile, and Verizon. The deeper legal question the case may end up clarifying is whether and to what extent platforms can use private civil suits as the front-line enforcement mechanism against AI-augmented criminal activity that the public criminal-justice system has had trouble keeping up with.Google sues Chinese cybercrime ring that weaponized Gemini AI for phishing scams | TechCrunchA federal district judge in Washington on Friday issued a preliminary injunction barring the Trump administration from continuing to implement Executive Order 14253, the order under which the National Park Service had been scrubbing exhibits, signage, and online materials at sites administered by the Department of the Interior. The judge gave the administration three weeks to restore the materials it had already removed. The order at issue, signed in March, directed federal cultural agencies to identify and remove content that, in the executive's view, reflected “improper, divisive, or anti-American ideology” or “partisan” framing. In the months that followed, the National Park Service had taken down or altered displays addressing slavery, the Civil Rights Movement, the internment of Japanese Americans during the Second World War, climate change, and the histories of Native American dispossession at sites including the Stonewall National Monument, Independence Hall, and the Manzanar National Historic Site. The case is American Historical Association v. Department of the Interior, brought by historians' professional associations and a coalition of plaintiffs that includes affected park employees and visitor-experience contractors. The legal theory pleaded was multi-strand: First Amendment viewpoint discrimination as applied to government speech that has taken on a public-forum character, Administrative Procedure Act challenges on the ground that the agency failed to provide a reasoned basis for the removals and failed to consider statutory commands under the Organic Act of 1916, and a Federal Records Act challenge to the destruction of materials that constituted federal records. The judge held that the plaintiffs were likely to succeed on the First Amendment claim and the APA claim, found irreparable harm in the ongoing loss of public access to the underlying historical materials, and found that the public interest was best served by restoration. The administration is widely expected to appeal to the D.C. Circuit. In the meantime, the three-week restoration clock is running.Judge blocks Trump national parks order, calling it “censorship” | The Washington Post This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.minimumcomp.com/subscribe

The Audit
Cyber News: Bug Bounty Fail, Open-Source Malware & Facebook SMB Phishing

The Audit

Play Episode Listen Later Jun 15, 2026 36:08 Transcription Available


An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most. The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use. 

Putting the AP in hAPpy
Episode 391: An Article on the Deepfake CEO Call Confirms Why Cybersecurity Awareness Training Is Not Good Enough for AP / Vendor Teams

Putting the AP in hAPpy

Play Episode Listen Later Jun 11, 2026 26:45


Send us Fan MailAn article outlines what's wrong with traditional cybersecurity awareness training against today's fraudsters but misses the mark on the resolution to evolving fraudster tactics.  Let's fill-in the gaps. Keep listening.Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Citybiz Article: The Deepfake CEO Call: Why AI Voice Fraud Is the Business Threat Executives Keep UnderestimatingYouTube:  Authentication | Vendor Master File Tip of the WeekVendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

The Flock Podcast
Women Be Phishing

The Flock Podcast

Play Episode Listen Later Jun 9, 2026 148:04


This week the gang talked about OPTCG pre-release, I Love Boosters, more Mina The Hollower, Esoteric Ebb, Xbox Show Case, PlayStation State of Play, Summer Games Fest, and more! Follow us on Instagram  Leave us a voicemail at (804) 286-0626  and consider supporting us through our Patreon  Check out the Discord!  Theme song remixed by Poisonfrog  News Links:  Xbox Showcase  PlayStation State of Play  Steam console coming?  Nintendo Direct coming 

No Password Required
No Password Required Podcast Episode 73 - Mudita Khurana

No Password Required

Play Episode Listen Later Jun 9, 2026 28:13


Show Summary:    Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this” No Password Required Season 7: Episode 6 - Mudita Khurana   Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team. In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months. Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to. In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas.   Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/     In this episode: Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37) The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00) Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23) The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41) Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29) How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26) The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47) Mudita's favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13) Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36) Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21) Timestamp Highlights: (00:25) Mudita's 10-year journey into cybersecurity starting from India (02:26) Mentorship's critical role in her growth and her admiration for Vandana Verma (09:29) Transition from management back to technical roles and why staying close to the work matters (15:31) How AI fosters layered, modular security systems for faster adaptation (17:06) The importance of community and trusted information sources in security (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days (25:19) Leh, Ladakh: Mudita's ideal remote work location nestled in Himalayan beauty Resources & Links: Vandana Verma - Influential mentor in cybersecurity ThreatLocker - Supporter of this podcast Cyber Florida – The Mother Ship

Putting the AP in hAPpy
Episode 390: Don't Miss The August 1st Deadline for Filing 1099 Corrections & 2 Ways To Avoid IRS Penalties

Putting the AP in hAPpy

Play Episode Listen Later Jun 4, 2026 18:00


Send us Fan MailThe August 1st deadline for filing 1099 corrections is closer than you think—and missing it could cost your company in IRS penalties. In this episode, I'm breaking down which errors demand immediate correction, which ones may not, and the two options to reduce or avoid unnecessary fines.  So, to know exactly what to fix, what to ignore, and how to protect your organization before the deadline hits…..Keep listening.  Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    Vendor Master File Tip of the Week:  IRS 2027 Due Dates for TY 2026 Information Returns For the 1099-NEC | 1099-MISC | 1042-SIRS Page > Information Return Penalties Get Help Identifying Corrections: Vendor Master File Clean-Up Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 3, 2026 3:59


New Wave Of Phishing Emails with SVG Files https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040 Android 2026-06-01 security patch level vulnerability details https://source.android.com/docs/security/bulletin/2026/2026-06-01 Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826 https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083 https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/ Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SECURE AF
Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool

SECURE AF

Play Episode Listen Later Jun 3, 2026 5:39 Transcription Available


Got a question or comment? Message us here!The FBI is warning about Kali365, a new phishing‑as‑a‑service tool designed to steal Microsoft 365 credentials and enable account takeovers at scale. In this episode, we break down how it works, why it's so effective, and what your SOC can do right now to detect and defend against it. 

The Other Side Of The Firewall
Social Engineering, AI Phishing, and IT Impersonation

The Other Side Of The Firewall

Play Episode Listen Later Jun 2, 2026 60:20


This episode covers recent cybersecurity incidents, social engineering tactics, AI vulnerabilities, and best practices for security awareness. Ryan, Shannon, and Chris discuss how organizations and individuals can protect themselves in an increasingly digital world. Article: Carnival Data Breach Exposed 6 Million People https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/amp/?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExTDJiaXU3Yk5hT3hNZTVCN3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR4pzOsAQi5dcv7EV53g1r1KdERC4IuPmhuUCdbbZjdVNNWGt55oTzq3MbA3Hw_aem_aS2cuL5GhCCR5oG0iYRrIA ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html?m=1&fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExTDJiaXU3Yk5hT3hNZTVCN3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR4VJUMvbNLMq7EIlSbtKb0nuC8QICmd_k5AtCuOAOq4I3d8hAhCLSbdKcNhNA_aem_o20R5LIqGBQHwe3sDKkNLw FBI issues alert on cyber actors impersonating IT personnel https://www.aha.org/news/headline/2026-05-29-fbi-issues-alert-cyber-actors-impersonating-it-personnel?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExTDJiaXU3Yk5hT3hNZTVCN3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR7tFwtKnMAcEnTs1hcAdu1CEqbW7nRQFxlgJKkqEIxM72GC0bhFTl-seTvP1g_aem_UDAqahgucKh7qK0h6yyYTQ Buy my book: https://www.theothersideofthefirewall.com/ Please LISTEN

The Human Risk Podcast
Jill Wick on The Human Side of Cybersecurity

The Human Risk Podcast

Play Episode Listen Later May 30, 2026 63:16


What if the best way to improve cybersecurity — or any other form of human risk — wasn't another policy, training course, or piece of technology, but a board game?  That's the kind of question my guest, Jill Wick, loves asking.Episode Summary Jill is a cybersecurity awareness consultant, business psychologist, podcaster, and author. Her work sits at the intersection of psychology, marketing, behavioural science, and cybersecurity, and she is passionate about helping organisations understand that security is fundamentally a human challenge, not simply a technical one. Drawing on her experience in fraud prevention and her academic background in business psychology, Jill explains why traditional approaches to awareness often fail, why experimentation matters, and how a simple Snakes and Ladders-inspired game can create meaningful conversations about risk and decision-making. The discussion ranges far beyond cybersecurity. We explore creativity, curiosity, communication, organisational culture, social media, learning, and the challenge of measuring success when the outcome you're seeking is something that doesn't happen. Key TopicsIn this episode, we discuss:Why cybersecurity is ultimately a human problem rather than a technology problemThe psychology behind phishing, scams, and social engineeringWhy more policies and more training often fail to change behaviourHow unclear policies can create confusion instead of complianceThe role of curiosity, creativity, and experimentation in risk managementHow games can create psychologically safe environments for learningThe importance of conversation and peer learning in awareness programmesWhat compliance, safety, conduct, and operational risk professionals can learn from cybersecurity awarenessWhy awareness professionals should think more like marketersThe value of experimentation, iteration, and A/B testingHow social media can help build communities around important ideasWhy measuring engagement may be just as important as measuring failuresGuest BiographyJill Wick is a cybersecurity awareness consultant, business psychologist, author, and podcast host who specialises in the human side of cybersecurity. Drawing on a background in fraud prevention and behavioural science, she helps organisations build stronger security cultures through creative, engaging approaches that go beyond traditional training and compliance. Known for her innovative use of games, psychology, and marketing techniques, Jill is a passionate advocate for making cybersecurity awareness more human, effective, and enjoyableLinksJill's LinkedIn profile - https://www.linkedin.com/in/jill-wick/Jill's website - https://www.jillwick.com/Cyber & Psych, Jill's podcast - https://open.spotify.com/show/5uteiqHvCTGCVtCsKCzGJ6?si=322ef51fd6a3423c&nd=1&dlsi=c6d8309550784df9Security-Awareness-Tools, Jill's book - https://www.isbn.de/buch/9783658511111/security-awareness-toolsAI-Generated Timestamped Outline00:00 – Introduction02:15 – Jill's background: From fraud prevention and business psychology to cybersecurity awareness.05:30 – Understanding why people fall for scams, phishing attacks, and social engineering.06:00 – Why cybersecurity is fundamentally a human problem, not just a technical one.08:00 – The limitations of rules, policies, and traditional awareness training.12:00 – The origin of Jill's cybersecurity board game and why simplicity matters.14:00 – How games create psychologically safe conversations and improve learning.19:30 – The game as a conversation tool: building culture, peer learning, and engagement.22:00 – Creativity, curiosity, and the courage to experiment with new approaches.26:00 – What cybersecurity awareness can learn from marketing, advertising, and A/B testing.35:30 – Why awareness and technology must work together rather than compete.41:30 – New projects: workshops, events, games, and Jill's forthcoming book Security Awareness Tools.44:00 – Lessons for compliance and risk professionals: attention is a limited resource.51:00 – Measuring success: engagement, participation, reporting, and positive signals.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 28, 2026 6:04


Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024 Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/

Putting the AP in hAPpy
Episode 389: The Profile of an Internal Fraudster and 8 Behavioral Red Flags To Watch Out For According to the ACFE

Putting the AP in hAPpy

Play Episode Listen Later May 28, 2026 23:24


Send us Fan MailAccording to the Association of Certified Fraud Examiners (ACFE) after studying 2,402 cases that led to $3.4 Billion in losses across in 143 countries and territories, they have both the profile of an internal fraudster and 8 behavioral red flags to look for.  Not to mention the #1 weakness that allowed the fraud and the #1way employers found out about the fraud.Keep listening. Check out my website www.debrarrichardson.com if you need help implementing authentication techniques, internal controls, and best practices to reduce the potential for fraudulent payments, compliance fines or bad vendor data. Check out the Vendor Process Training Center for 173+ hours of weekly live and on-demand training for the Vendor team. Links mentioned in the podcast + other helpful resources:    YouTube Video:  All The Queens Horses Association of Certified Fraud Examiners (ACFE):  Occupational Fraud 2026:  A Report To The Nations Training Session:  Mitigating Segregation of Duties Conflicts in the P2P Process Vendor Process Training Center - https://training.debrarrichardson.comCustomized Fraud Training:  https://training.debrarrichardson.com/customized-fraud-training Free Live and On-Demand Webinars: https://training.debrarrichardson.com/webinarsVendor Master File Clean-Up:  https://www.debrarrichardson.com/cleanupYouTube Channel:  https://www.youtube.com/channel/UCqeoffeQu3pSXMV8fUIGNiw More Podcasts/Blogs/Webinars www.debrarrichardson.comMore ideas?  Email me at debra@debrarrichardson.com Music Credit:  www.purple-planet.com

Cyber Security Headlines
Nimbus Manticore, real-time credential harvesting, the 12-hour patch

Cyber Security Headlines

Play Episode Listen Later May 27, 2026 6:44


Nimbus Manticore learning new tricks Phishing moves to real-time credential harvesting India wants 12-hour patches Check out your show notes here: https://cisoseries.com/cybersecurity-news-nimbus-manticore-real-time-credential-harvesting-12-hour-patches/  Huge thanks to our sponsor, Guardsquare Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

The CyberWire
Attackers found a new way around MFA.

The CyberWire

Play Episode Listen Later May 26, 2026 26:07


The FBI warns attackers are abusing Microsoft OAuth authentication. India pushes faster patching as AI speeds up cyberattacks. Iranian hackers blend phishing with SEO poisoning. Anthropic's AI finds thousands of open source flaws, while AI also reshapes bug bounties and fuels supply-chain attacks hitting thousands of GitHub repos. Plus, a new LMS zero-day, bulletproof hosting arrests in the Netherlands, FTC action over bogus “active listening” claims, and another busy week for cyber funding and M&A. Our guest is Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation.” Please disregard all searches for disregard. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Kurtis Minder, author, joining us to discuss his book "Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation." Selected Reading FBI warns of Kali365 phishing service targeting Microsoft 365 accounts (Bleeping Computer) India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws (Infosecurity Magazine) Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign (Infosecurity Magazine) Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects (SecurityWeek)  HackerOne takes an axe to its bug bounty rewards (The Register) Automated 'Megalodon' Campaign Spreads GitHub Repo Backdoors (GovInfo Security) Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment (SecurityWeek) Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands (SecurityWeek) FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers About “Active Listening” AI-Powered Marketing Service (Federal Trade Commission) Socket raises $60 million in Series C funding. (N2K Pro Business Briefing) You can no longer Google the word 'disregard' (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

TechTimeRadio
300: AI Nails Security but Fails at Simple Tasks, Disney's Facial-Scan Fight Heats Up, Phishing Scams Surge, an AI Mix-Up Leads to a Wrongful Arrest, Plus Waymo's Recall, Tech Nostalgia, and Musk's OpenAI Lawsuit | Air Date: 5/26 - 6/1/26

TechTimeRadio

Play Episode Listen Later May 26, 2026 55:43 Transcription Available


Episode 300: AI's extremes are on full display in our 300th episode. Anthropic's Mythos model reportedly uncovered more than 10,000 security flaws in a month, accelerating vulnerability discovery for major partners. Yet the same “AI efficiency” falls apart in the real world, as seen in Starbucks' failed AI inventory rollout that miscounted products and mislabeled items. That contrast sets up the core question of the hour: when is AI a powerful tool, and when is it just expensive theater?We also dig into the rising stakes around biometric privacy, from Disney's facial‑scan lawsuit to stadium and theme‑park “optional” recognition systems that don't feel optional when the alternative line barely moves. Add in real phishing examples hitting DocuSign, Microsoft 365, and fake IRS notices, plus a case where an AI court summarizer caused a wrongful arrest, and the theme becomes clear: trust is getting harder to earn. We close with tech nostalgia, a blunt whiskey review, Waymo's robotaxi recall, and Elon Musk's failed lawsuit against OpenAI all coming up on TechTime Radio, with a little whiskey on the side.-- Full Episode Details:AI is getting dangerously good at the things we want and embarrassingly bad at the things we assumed were easy. We kick off our 300th show with a perfect contrast: Anthropic's Mythos model reportedly uncovers 10,000+ security flaws in a month, boosting vulnerability discovery across major partners, yet the same “automation magic” falls flat when Starbucks tries AI inventory counting and ends up with mislabeled products and missed items. That tension drives the big question we keep circling: when is AI a genuine tool, and when is it just expensive theater? From there we get into facial recognition privacy and consent, sparked by Disney's lawsuit over facial scanning at Disneyland. We compare it to Universal and stadium biometric entry, talk about what “optional” really means when the non-scan line is the long one, and why public tolerance shifts once AI becomes part of the story. If you care about digital identity, biometric data retention, and surveillance creep, this segment lands hard. We also bring the practical stuff: real phishing email examples that mimic DocuSign and Microsoft 365 quarantine notices, plus a fake “IRS statement” that screams malware. Then Mike's AI Guy segment hits a gut-punch case where an AI court summarizer mashed files together and an innocent man got arrested. We round it out with tech nostalgia (Apple Newton), a brutally honest whiskey review, Waymo's robotaxi flood fiasco and recall, and a quick hit on Elon Musk losing his lawsuit against OpenAI. Subscribe for weekly tech news with zero political agenda, share the episode with a friend who clicks too fast, and leave a review so more people can find the show.Send us Fan MailSupport the show

Afternoon Snack
Gone Phishing - Taper Tantrums and Sleazy Scammers

Afternoon Snack

Play Episode Listen Later May 20, 2026 57:57


With the Calgary marathon and Unbound 200 coming up, we (Alex and Meredith) are both in full on taper mode. Tapering is one of the most effective ways to get the most out of your training leading into a race but it doesn't happen without some mental and sometimes physical difficulty. This episode covers the science of tapering and how it works in practice. And in the spirit of mentally challenging situations, we tell the funny and emotionally fraught stories of Meredith's recent experience with scammers.

The Brian Lehrer Show
Brian Lehrer Weekend: Spirit Airlines; Rent Guidelines Board; Avoiding Scams

The Brian Lehrer Show

Play Episode Listen Later May 9, 2026 69:19


Three of our favorite segments from the week, in case you missed them. Demise of Spirit Airlines  (First) | Is a Rent Freeze Coming? (Starts at 38:21) | Avoiding Phishing Scams (Starts at 57:35) If you don't subscribe to the Brian Lehrer Show on iTunes, you can do that here.   Photo: The self-service check-in kiosks of Spirit Airlines stand idle with a message to customers after the company ceased global operations at Fort Lauderdale-Hollywood International Airport in Fort Lauderdale, Florida, on May 2, 2026. US air carriers mobilized Saturday to help passengers and crew members stranded by the overnight shutdown of Spirit Airlines, after last-minute talks with creditors and the White House collapsed. The budget airline known for its bright yellow planes succumbed to crushing fuel prices and announced in the early hours of Saturday that "all flights have been canceled, and customer service is no longer available" as it "started winding down its global operations, effective immediately." (GIORGIO VIERA / AFP via Getty Images)

The Brian Lehrer Show
How to Avoid Sneaky Phishing Scams

The Brian Lehrer Show

Play Episode Listen Later May 5, 2026 11:15


WNYC has been targeted by scammers who posed as hosts and offered authors interviews -- for a fee (which WNYC would never do). Rachel Tobac, co-founder and CEO of Social Proof Security, and Kenneth Atkins, assistant director of IT and data security at WNYC, talk about how to spot sneaky online phishing scams, and how to deal if you fall for it. Photo: Stock image (Vertigo3d via Getty Creative)