Malicious software used in ransom demands
POPULARITY
Categories
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends
Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here. Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Could the disaster recovery plan designed to protect your company make a ransomware incident even worse? In this episode, I speak with Darren Thomson, Vice President and Chief Technology Officer for EMEA at Commvault, about Resilience Operations, commonly known as ResOps, and why cyber recovery now requires security, infrastructure, identity and data teams to work from one coordinated plan. Darren argues that many companies are accepting a difficult reality. Even with considerable investment in prevention and detection, a breach may eventually succeed. That does not make cybersecurity controls any less necessary, but it means recovery can no longer be treated as a secondary activity managed by another department. The problem is that security operations and infrastructure teams have traditionally worked toward different objectives. Security specialists concentrate on identifying and stopping threats. Infrastructure teams protect data, maintain backups and restore systems after outages. During a cyberattack, a successful recovery requires both sets of expertise. A backup administrator may be able to restore data quickly, but a forensic specialist must establish whether that data is clean. Without that confirmation, the company risks restoring malware and restarting the incident. Darren explains why a conventional disaster recovery plan may be particularly dangerous during ransomware. These plans were commonly designed for physical failures such as a lost data center. Data would be copied from one location to another so operations could continue. If the source data is infected, however, fast replication can carry the malware into the recovery environment. This is where ResOps enters the discussion. Darren describes it as an operating model rather than a product. It combines established practices from security and infrastructure management into a continuous program for testing, learning and improving recovery. Individual technology projects may come from the program, but resilience itself never reaches a final completion date. AI adds pressure on both sides. Criminals can use it to create faster and more effective attacks, while defenders can use machine learning to inspect large volumes of information, detect patterns and identify the newest clean recovery point. Companies must also protect AI systems as they would any other business application, including the models, data repositories and identities connected with them. Darren offers one practical starting point for CIOs and CISOs: Mean Time to Clean Recovery, or MTCR. This measures how long it takes to restore an application and its data with evidence that both are free from compromise. Before measuring MTCR, leaders must define their minimum viable company. These are the systems and services the business cannot operate without. Once that list exists, teams can test how long a verified clean recovery would take and replace assumptions with evidence. The initial answer may be uncomfortable. Teams may know how to restore an application without knowing whether the backup is clean. Security may know how to inspect the system but lack an established workflow with the recovery team. Darren sees those gaps as the starting point for a useful ResOps program because they provide everyone with a shared problem and a measurable objective. If your most important systems disappeared today, how long would it take to bring the minimum viable company back using verified clean data? Listen to the episode and share your answer with me.
This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack.This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back.Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one.They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact.Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from.Chapter Markers:00:00 – Encore intro & episode setup00:01:37 – Show intro and banter00:06:21 – Preventing the breach: phishing, droppers, and whitelisting00:14:46 – Blocking lateral movement, RDP/SSH lockdown00:20:28 – Detecting exfiltration and honeypot files00:24:19 – What to do once you've been hit00:25:58 – Building your incident response plan00:30:43 – Decryption, ransom payments, and why it's not over yet
Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers' “intent is now legible,” and what that means for defenders.LinkSysdig research: https://www.sysdig.com/blog/jadepuffe...
An AI just ran an entire hacking campaign on its own. No human at the keyboard, 17,000 actions in a single weekend, against Hugging Face, the platform nearly every company on earth downloads its AI from. If the tool your business relies on can be attacked by software that never sleeps, the math on cybersecurity just changed for everyone. *The cost of attacking just dropped. The value of defending just went up.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the one that should make every owner sit up. Hugging Face, the "GitHub of AI," disclosed that an autonomous AI agent broke in through a poisoned dataset, stole credentials, and moved through its systems, logging more than 17,000 actions before it was caught. That is the workload of a full hacking crew, run by software, at a speed no human team can match. Here is the part that should reframe how you think about your own company: for years the limit on an attacker was people, and people cost money and don't scale, but an agent erases that limit. The new economy runs on agents plus employees, and the criminals are already staffing up with agents. Then it gets physical. A ransomware attack hit Coca-Cola's Fairlife, the premium milk brand doing over $3 billion a year, and shut down every one of its U.S. production plants. This wasn't stolen emails, it reached the operational systems that physically make the product, so a breach turned into a full shutdown. Because Coca-Cola is publicly traded, the attack landed in an SEC filing within days, a reminder that a cyberattack is now a material business event you may legally have to report. One detail worth noting: the Canadian plants kept running because they were separated from the U.S. network, which is exactly what good segmentation buys you. Finally, the numbers behind all of it. The new Sophos State of Ransomware 2026 report surveyed 2,158 companies that actually got hit, and the headline flips a common assumption: 79% of attacks now start with a stolen login, not some exotic exploit. Even more sobering, 97% of the victims whose attack began with stolen credentials already had multi-factor authentication turned on, which means regular MFA is being bypassed. The good news you can act on: two-thirds of encrypted victims recovered from backups instead of paying, and while ransom demands fell to around $700,000, the average cleanup still runs $1.7 million, so prevention is almost always the cheaper line item. Three stories, one thread. The cost of launching an attack keeps falling, which makes every dollar you spend defending worth more than it was a year ago. In this episode, we discuss: • How an autonomous AI agent hacked Hugging Face with no human at the keyboard • Why the Coca-Cola Fairlife ransomware attack shut down U.S. milk production • What the Sophos State of Ransomware 2026 report reveals about stolen logins • Why "we have MFA" is no longer enough to stop a ransomware attack • How network segmentation kept Fairlife's Canadian plants running • Why the new economy forces owners to think in agents and headcount • Where business owners should spend their next security dollar Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #HuggingFace #AI #CocaCola #Fairlife #Ransomware #Sophos #DataBreach #MFA #BusinessRisk #MSP
News sources: https://lmg.gg/L8hqh Timestamps: 0:00 Linus Torvalds welcomes AI coding 1:14 Lenovo's inkjet-printed OLED laptop 2:32 EU forces Google to open Android 4:04 QUICK BITS INTRO 4:13 Ransomware halts Fairlife production 4:44 Samsung foldable specs leak 5:20 Moonshot unveils Kimi K3 5:56 23andMe settles its data breach 6:30 OpenAI sells a $70 basketball 7:04 Credits Learn more about your ad choices. Visit megaphone.fm/adchoices
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs
What happens when a ransomware attack takes less effort than ordering takeout? In this live news episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Tabitha Senty of IT Audit Labs to break down the headlines shaping cybersecurity right now. The crew covers how AI is lowering the barrier to entry for ransomware attacks, why identity and access still sit at the center of every breach, and how threat actors are chaining together low and medium severity vulnerabilities to gain a foothold nobody saw coming. From there, the conversation moves into social engineering and the human side of security, including DEF CON's social engineering contest and lessons on training people without fear or punishment. The crew also digs into a CISA warning on how fast AI is accelerating cyber risk, a fresh executive push on post-quantum cryptography, and closes out with a head-scratching pivot from Midjourney into full-body health scanners at spas, and everything that could go wrong with it. In this episode: Why AI is lowering the cost of ransomware attacks — Identity and access are still the real entry point, and AI just makes the attack faster once someone's in. How threat actors chain low-severity vulnerabilities into major breaches — Eric explains why patching only highs and criticals is no longer enough to protect an environment. The social engineering tactics still fooling smart people — Pretexting as IT, DEF CON's live social engineering contest, and why fear-based training backfires. A CISA warning that cyber risk is accelerating faster than expected — The timeline for AI-driven offensive capability is no longer years away, it's months. Midjourney's pivot into full-body health scanners at spas — The crew unpacks the security, compliance, and data governance nightmare hiding behind a wellness trend. If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #AIRansomware #Cybersecurity #SocialEngineering #PostQuantum #IdentitySecurity #ITAudit #CyberNews #DEFCON #ThreatIntelligence #CyberRisk
The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
The following article of the Cybersecurity industry is: 'Why Is Ransomware So Successful? It May Not Be What You Think' by Carlos Lozano, CEO, Rent A Hacker.
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations. They also discuss the ever so many bugs being patched. This is good for organisations that patch, but it will leave a very long tail of unpatched vulnerabilities. This episode is also available on YouTube Show notes
Stupid News Extra 7-15-2026 …Ransomware Negotiator Busted for Working with Computer Hackers
What happens when a trusted ransomware negotiator secretly works for the very hackers he's supposed to stop?In this episode of Reimagining Cyber, Tyler Moffitt unpacks one of the most shocking insider threat cases in recent cybersecurity history. A ransomware negotiator admitted to providing confidential victim information—including insurance limits and negotiation strategies—to the BlackCat (ALPHV) ransomware gang while representing organizations during active ransomware attacks.Learn how ransomware negotiations really work, why information is the most valuable asset during a cyber incident, and what this case reveals about ransomware-as-a-service, cyber insurance, incident response, and insider threats. Whether you're a CISO, security leader, IT professional, or simply interested in cybersecurity, this episode offers practical lessons on trust, risk, and protecting sensitive information when every decision matters.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com
Heute Morgen mal beide ausgeschlafen, beide im Homeoffice, Sonne draußen – das hatten Max Imbiel und ich wirklich seit Monaten nicht mehr. Die Nachrichtenlage ist dabei auch eher ruhig.Ich bringe JadePuffer mit: Sysdig hat einen Fall agentischer Ransomware veröffentlicht. Einstieg über CVE-2025-3248 in Langflow – gepatcht April 2025, im CISA KEV seit Mai 2025, trotzdem massenhaft ungepatchte Instanzen. Der Agent hat autonom die PostgreSQL-Datenbank gedumpt, API-Keys für AWS, Azure, Alibaba, Anthropic und andere gesammelt, MinIO mit Default-Credentials geöffnet und ist auf einen produktiven MySQL-Server pivotiert, wo er 1.342 Service-Konfigurationen verschlüsselte. Die viel zitierten 31 Sekunden beziehen sich auf eine einzelne Self-Healing-Schleife, nicht den Gesamtangriff. IT-Grundhygiene hat auf ganzer Linie versagt. Was bleibt: ein Agent, der Sackgassen autonom korrigiert, braucht keinen Menschen mehr am Keyboard.Max bringt den EU Cybersecurity Action Plan – kein neues Gesetz, sondern ein Koordinationsrahmen auf Basis von AI Act, NIS2 und CRA. Kernpunkte: Evaluierungskapazitäten für KI-Modelle mit Durchsetzungsbefugnis ab 2. August, ein ENISA-Blueprint für strukturierten Frontier-Modell-Zugang für Security-Zwecke, gemeinsame Testplattform und Open-Source-Resilience-Kampagne. Max findet den Ansatz gut, weil er KI endlich als Chance framt. Ich bleibe skeptisch, ob aus EU-Initiativen am Ende wirklich was wird.Zum Abschluss: Apple hat OpenAI, zwei ehemalige Mitarbeiter und Jony Ives Firma io Products wegen Trade-Secret-Diebstahls verklagt. Noch Vorwürfe, kein bestätigter Sachverhalt – aber bemerkenswert angesichts der ohnehin angespannten Beziehung der beiden Unternehmen.JadePuffer / Sysdig Threat Research https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortionEU Cybersecurity Action Plan (Europäische Kommission) https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-action-planApple verklagt OpenAI (The Verge) https://www.theverge.com/2026/7/8/apple-sues-openai-trade-secrets-io-products
A researcher found an unlocked server...and inside it, working VPN credentials for nearly 74,000 corporate firewalls spanning Chevron, Samsung, Foxconn, and thousands more. In this episode of Darnley's Cyber Café, Darnley breaks down the FortiBleed leak: what was exposed, how attackers allegedly cracked their way in at a billion-attempt scale, and why this story matters even if your organization has never touched a FortiGate. Spoiler: the lesson is bigger than one vendor...Show Notes:If you were affected https://socradar.io/free-tools/fortibleedClick here to send future episode recommendationSupport the showSubscribe now to Darnley's Cyber Cafe and stay informed on the latest developments in the ever-evolving digital landscape.
Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud's Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments. Selected Reading US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer) Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense) Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief (SC Media) Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines) US military targeted in Iran war phone-tracking campaign (Financial Times) Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters) SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer) CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media) Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security) Companies Are Throttling Employees' AI Use Because It's Too Expensive (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected. Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17. Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender. ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint. Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder
How to protect backups from ransomware starts with a hard truth: attackers aren't just encrypting your data anymore, they're stealing it first — and no backup system on earth undoes an exfiltration. In this encore episode of The Backup Wrap-Up, Curtis and Prasanna dig into what real immutability looks like versus the marketing version, why root access quietly undermines most "immutable" storage claims, the difference between virtual and true physical air gaps, and the exact questions you should be firing at your backup vendor before you trust them with your last line of defense.This one's an encore for a reason — it was one of the most listened-to episodes in the show's history, with listeners sticking around for the full runtime and then some. That's the kind of signal that tells you it's worth a second run.Along the way, they cover S3 object lock and what actually happens if your account gets deleted or your credit card stops working, why compromised admin credentials are involved in the majority of attacks and what your vendor should be able to undo, and why bit rot — rare, but nasty when it's silent — still belongs on your checklist. If you manage backup or DR for a living, or you're just trying to figure out whether your current setup would actually hold up, this episode gives you a concrete list of questions to ask and red flags to watch for.Chapters:00:00 – Cold Open: Ransomware Is After Your Backups01:19 – Welcome & Banter05:50 – Topic Setup: Protecting Backups from Ransomware07:36 – The Extortion & Exfiltration Playbook15:25 – What Is an Air Gap?18:22 – Virtual Air Gaps27:57 – Real (Physical) Air Gaps28:12 – What Is Immutability, Really?29:23 – Bit Rot30:42 – Root Access & the Limits of Immutability32:51 – S3 Object Lock40:20 – Questions to Ask Your Backup Vendor42:31 – What Happens If You Delete Your Account?44:29 – Compromised Credentials & Worst-Case Scenarios46:41 – Final Thoughts
Angelo Martino's job at DigitalMint in River North was to negotiate on behalf of companies whose computers were hacked and held, with demands to make multimillion-dollar ransom payments. However, the U.S. Department of Justice says Martino actually helped the hackers he was hired to negotiate against. The victim clients included hospitality, retail, medical and financial services businesses. Overall, Martino and his associates extorted more than $75-million. Martino has been sentenced to nearly six years in prison, with how much he'll pay in restitution to be determined.
News and Updates: FBI World Cup Drone Crackdown: The FBI has seized over 600 drones across all 11 US host cities, with operators facing $100,000 fines and drone fans fearing tighter future regulations. Amazon Prime Air in Baton Rouge: Amazon launched drone delivery from its Cortana Mall fulfillment center, making the Capital Region the first Louisiana area receiving packages by fully electric MK30 drones. Microsoft's Global Device ID: A teenage hacker's arrest revealed Microsoft tracks Windows PCs through a persistent device identifier called GDID, raising surveillance concerns since no easy opt-out exists. Ransomware Dwell Times: ExtraHop research shows hackers hide in networks an average of two and a half weeks, with nearly half of firms unaware until data is stolen. Starlink Satellites Burning Up: SpaceX incinerated 260 aging Starlink satellites in Earth's atmosphere over six months, while scientists debate the effects of metallic vapor on the upper atmosphere. Starlink Gen 3 Constellation: SpaceX filed FCC plans for a 100,000-satellite constellation promising multi-gigabit speeds, positioning it as the communications backbone for billions of AI-powered devices.
Angelo Martino's job at DigitalMint in River North was to negotiate on behalf of companies whose computers were hacked and held, with demands to make multimillion-dollar ransom payments. However, the U.S. Department of Justice says Martino actually helped the hackers he was hired to negotiate against. The victim clients included hospitality, retail, medical and financial services businesses. Overall, Martino and his associates extorted more than $75-million. Martino has been sentenced to nearly six years in prison, with how much he'll pay in restitution to be determined.
Angelo Martino's job at DigitalMint in River North was to negotiate on behalf of companies whose computers were hacked and held, with demands to make multimillion-dollar ransom payments. However, the U.S. Department of Justice says Martino actually helped the hackers he was hired to negotiate against. The victim clients included hospitality, retail, medical and financial services businesses. Overall, Martino and his associates extorted more than $75-million. Martino has been sentenced to nearly six years in prison, with how much he'll pay in restitution to be determined.
Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Wir waren dieses Jahr erneut auf der Head in the Cloud von mittwald in Espelkamp unterwegs und haben dort mit Torben Mallwitz über einen Vortrag gesprochen, den man so vermutlich nur selten auf einer …
The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.
Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchange, where she helps develop AI security frameworks and contributes to international AI security standards. In this conversation we cover the new generation of data-poisoning ransomware, why stolen models and datasets are becoming the ransom, what makes autonomous agents an entirely new attack surface, and how organizations can build resilience into their AI initiatives from day one.Learn more about the OWASP AI Exchange at https://owaspai.org/Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
Got a question or comment? Message us here!Ransomware operators are leveraging the BlueHammer privilege escalation flaw to gain SYSTEM-level access and disable security controls. Get the latest insights and response recommendations. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.
My guest today, John Just, Global Educator with Know Be 4, has trained millions of learners across seventy thousand organizations worldwide.Real cybercrime stories. AI threats. Ransomware attacks. Social engineering tactics that are working against you right now.CHAPTERS00:00 Know Before Platform Overview: Security Awareness Training That Actually Works02:30 Phish Alert Button: How Employees Stop Real Attacks in Real Time05:30 Law Firm Nearly Wires $1M to Hackers: Stopped by Training07:00 Social Engineering Is the Top Breach Vector: Why Tech Alone Fails09:30 Building a Security Culture: Flip the Weakest Link Myth12:00 Psychology Behind Phishing Simulations: Why the Gotcha Approach Backfires14:30 AI-Powered Threats: Spear Phishing Is Now Scalable and Cheap17:00 Voice Cloning and Deepfakes: The New Face of Social Engineering19:30 Gamifying Security: Rewards, Reporting, and Real Culture Change21:30 Inside Man Series: Hollywood-Quality Cybersecurity Training Content24:00 KSAT Platform and Security Culture Survey: Measure What Matters25:30 ADA AI Orchestration Agent: Personalized Security Training at Scale28:00 K-12 and University Cybersecurity: Protecting Schools on Shoestring Budgets30:30 Deepfake Simulation Tool: Train Employees Using Your Own CEO's Face33:00 How to Run Phishing Tests Without Destroying Employee Trust35:00 KnowBefore Con, Inside Man Season 7, and What's Coming NextHosted by David Dean Mauro — experienced former trial lawyer, AI Security Advisor, FBI InfraGard member, VP of NetGain Technologies and Author, Moving Target Trilogy Book Series (#1 Amazon Hot New Release 2026).Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.True crime enters our homes and businesses daily. Learn from actual people who fight it daily and show you how in a thriller story. The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com Support the showNew Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14.Moving Target: The Obedient Machine drops April 21.Book 3 -- Ghost and the Machine -- out soon!
In this episode, Shannon Tynes and Ryan Williams Sr. discuss the alarming rise of AI-driven cyber attacks, recent privacy breaches by intelligence agencies, and the evolving landscape of cybersecurity in the age of AI. They also cover updates on Apple's rapid patching cycle and share personal stories and insights on technology and security. Article: An AI just carried out a cyber attack without any human oversight for the first timehttps://www.the-independent.com/tech/security/ai-cyber-security-ransomware-attack-b3008237.html?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExbnJOMm5USWIybDJZMmQzTnNydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR7Flg-ptEkmASGBodEPmmttjehi5Q_xYMfHRTNen_m7SwxUr87VOXEOkOZ9Vw_aem_-JOQZ2hPL1qCeI454xF2GgDutch intelligence agencies accused of privacy breaches in large-scale data processinghttps://nltimes.nl/2026/07/01/dutch-intelligence-agencies-accused-privacy-breaches-large-scale-data-processing?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExbnJOMm5USWIybDJZMmQzTnNydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR6wWVCrKfjO3Sdtq891gt7lEhOtg-MI0Xxmue-ZV55S2FNJVb24-D6yDnmgXw_aem_ySHm_VD6ya8cRRCetT4JTQApple Reverses Age-Old Patch Policy to Keep Up With AIhttps://www.darkreading.com/cybersecurity-operations/apple-patch-policy-ai?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExbnJOMm5USWIybDJZMmQzTnNydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR48q4EcdpBs3ryWGVcMxw-rY3nRv2h_ryMLbokyjfUhkHfGnUz6M9FCwGN20w_aem_k3vvuJhHFO2Va-J_ZvuUCQ Buy my book: https://www.theothersideofthefirewall.com/ Please LISTEN
Your Social Security number and health history could be sitting on a criminal's hard drive right now, and you wouldn't find out until the letter shows up in your mailbox. That's exactly what happened to nine million Medtronic customers. This week, a global medical giant, a city right outside Atlanta, and an attack run start to finish by artificial intelligence all point to the same uncomfortable lesson. *Nobody is too small to hack, and the basics still decide who survives.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First up, Medtronic. The company that makes pacemakers and insulin pumps is now notifying about nine million people that their names, birth dates, Social Security numbers, and health information were stolen by a crew called ShinyHunters. Here's the part that should worry every business owner: ShinyHunters didn't need a genius hack to get in. They called an employee, pretended to be tech support, and talked their way past the front door, the same move that works on your team. Even a company this size is looking at a cleanup that averages 279 days for a healthcare breach, and a small business doesn't have that kind of runway. Then we bring it home. On June 8th, the City of Acworth, right here in Cobb County, got hit hard enough to call in outside cybersecurity pros and law enforcement. Weeks later, the city still won't say what kind of attack it was or whether any data walked out the door. The good news buried in the story: everything was restored with no lasting disruption, which almost always means one thing, working backups. Government ransomware jumped about 65 percent in the first half of 2025, and attackers hunt small cities for the same reason they hunt small businesses: thin teams and tight budgets. We close with the one that keeps us up at night. Researchers at Sysdig say they caught the first ransomware attack run entirely by an AI, no human at the keyboard. It broke in, stole credentials, locked up a database, and wrote its own ransom note. When one login failed, it diagnosed the problem, rewrote its own code, and was back in within about 31 seconds. And in this case, even paying the ransom may not have brought the data back, which means backups are not your plan B anymore, they are your plan A. Three very different targets. One playbook that decides who walks away fine and who doesn't. In this episode, we discuss: • The Medtronic breach that exposed Social Security numbers and health data for about nine million people • Why a cyberattack on the City of Acworth is a preview of what hits small businesses • The first ransomware attack researchers say was run entirely by an AI, with no human directing it • Why the size of the target stopped mattering a long time ago • The three boring fundamentals, backups, multi-factor, and patching, that decide how every one of these stories ends • What business owners should actually check this week before they need it Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Medtronic #ShinyHunters #DataBreach #Ransomware #AI #Acworth #SmallBusiness #VendorRisk #MSP #BusinessRisk
An AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime debut that last week's headlines suggested. Also, the U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief." Learn more about your ad choices. Visit podcastchoices.com/adchoices
In today's episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: Ransomware attacks remain similar in strategy, but have become more industrialized in recent years. Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors. An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: Geoff's investigation into Conti, one of the world's most notorious ransomware gangs (7:33) The impact of AI on ransomware attacks (13:52) How money laundering is changing (17:03) Standout Quotes: “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.
Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)Episode: AI for OT Cybersecurity: Real-World Strategies to Protect Critical InfrastructurePub date: 2026-07-06Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationAI is changing OT cybersecurity - but success still depends on understanding your operations. In this episode of Protect It All, host Aaron Crow welcomes Vivek Ponnada for a practical conversation about how artificial intelligence is transforming the way organizations defend critical infrastructure. With decades of experience in industrial automation and OT security, Vivek shares firsthand insights into the realities of protecting legacy control systems while preparing for a future increasingly shaped by AI, automation, and digital transformation. Together, Aaron and Vivek discuss how organizations can use AI to improve visibility, accelerate threat detection, prioritize vulnerabilities, and strengthen operational resilience, without losing sight of the fundamentals that keep industrial environments safe. Key Learning: How AI is transforming OT cybersecurity and industrial operations Practical AI use cases for protecting critical infrastructure Why legacy systems remain one of the biggest OT security challenges How AI can improve vulnerability management and incident response The role of digital twins in strengthening cyber resilience Why trust, collaboration, and operational knowledge remain essential in OT security Whether you're responsible for manufacturing, utilities, energy, water, or other critical infrastructure, this episode provides practical insights into balancing innovation with operational reliability. Tune in to discover how AI can strengthen OT cybersecurity while helping organizations protect the systems that keep the world running. Key Moments: 06:43 AI and cloud adoption in OT 13:27 Controller logic changes and safety steps 21:24 Discussing Digital Twins for Security Use 26:51 Managing vulnerabilities at scale 32:41 Understanding Power Plant Limitations 37:17 Keeping up with plant changes 41:43 Automating infrastructure and maintenance 49:08 Rising importance of cybersecurity investment 52:16 Early days in cybersecurity and OT 01:00:03 Ransomware impacts on industries 01:01:53 Using GPUs for security and OT About the guest : Vivek Ponnada is an Operational Technology (OT) Security practitioner with global experience and currently serves as the SVP of Growth & Strategy at Frenos, the world's first Simulated OT Pentesting Platform. Having started his career in Industrial Control Systems (ICS) as a Technician, Vivek became a Controls Engineer and commissioned Gas Turbines in Europe, Middle-East, Africa and South-East Asia. Post MBA, Vivek held multiple roles in Sales, Marketing & Business Development and Services covering ICS and OT Security solutions for Critical Infrastructure industries (Power, Oil & Gas etc.) at GE, XenonCyber Dynamics and Nozomi Networks. He was a co-lead for the Top 20 Secure PLC Coding Practices Project and regularly speaks at Information Security Conferences. Vivek has a C.Eng. from IEI, MBA from McCombs (UT Austin) and holds the ISA/IEC 62443 Cybersecurity Expert & GICSP certifications. He is a member of the ISA, ISACA, Public Safety Canada ICS Security Symposium Advisory Committee and is a CS2AI Fellow. How to connect Vivek: Frenos: https://frenos.io LinkedIn: https://www.linkedin.com/in/1ot/ Frenos YouTube: https://www.youtube.com/@Frenos_Security Learn more about PrOTect IT All: Email: info@protectitall.co Website: http://protectitallpod.com/ep113 X: https://twitter.com/protectitall YouTube: https://www.youtube.com/@PrOTectITAll FaceBook: https://facebook.com/protectitallpodcast To be a guest or suggest a guest/episode, please email us at info@protectitall.co Please leave us a review on Apple/Spotify Podcasts: Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124 Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
These may be the last days of Amazon's Mechanical Turk. Also, the hacking operations disclosed in a Canadian spy agency's annual report underscores some pressing national security threats facing the country and its top allies. Learn more about your ad choices. Visit podcastchoices.com/adchoices
The Monday Microsegment for the week of July 6. All the cybersecurity news you need to stay ahead, from Illumio's The Segment podcast. Hackers break into a network tailor-made for sharing World Cup and other security plans. Ransomware just married AI in the first known completely autonomous ransomware attack. And from Brussels to Travis County, spyware watchers just got a wake-up call. Plus, Trupti Shiralkar joins to discuss how AI is reshaping software security. Head to The Zero Trust Hub: hub.illumio.com Get the Industry's First Vendor-Neutral Zero Trust Certification: https://www.illumio.com/zero-trust-certification
AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key. It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240. A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices. Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day. 00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off
JadePuffer ransomware used AI agent to automate entire attack AdaptHealth suffers cyberattack UK's National Cyber Action Plan launch delayed by political leadership crisis Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Hoy hablamos de JadePuffer, el ransomware agentico que explota Langflow y pivota solo hasta produccion; de China apagando agentes humanizados en ByteDance y Alibaba; de Tesla probando Robotaxi sin monitor en una zona limitada de Miami; de Threads superando los 500 millones de usuarios mensuales y queriendo parecerse mas a Reddit; y del primer mapa global del micelio, una red subterranea que mueve carbono en silencio.Puedes seguirnos en YouTube en https://youtube.com/olivernabani y puedes unirte al Discord Mashain en https://olivernabani.com/discord
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from Seoul
Teams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby with labels, and require organizer approval, with future allow lists, full blocks, reports, and audit logs planned. Anthropic's Fable 5 returns globally after U.S. export controls are lifted, though higher‑risk requests may be routed to weaker models and Mythos restrictions remain, with Commerce reserving the right to reimpose controls. Researchers describe "Bioshocking," tricking AI browsers into abandoning guardrails via delusional puzzle prompts, while Adversa AI's "Guardfall" shows how Bash text rewriting can bypass command filters in many coding agents. SOC Radar links FortiBleed credential theft to InkRansom and Lynx ransomware activity across hundreds of FortiGate portals. Nissan confirms employee data theft tied to a PeopleSoft zero‑day campaign linked to ShinyHunters. 00:00 Today's Cyber Headlines 00:27 Teams Blocks Meeting Bots 01:58 Anthropic Fable Returns 03:22 Bioshocking Browser Attack 05:09 Guardfall Shell Bypass 06:51 FortiBleed Fuels Ransomware 07:59 Nissan PeopleSoft Breach 10:10 Wrap Up And Sign Off
Ransomware has become a far more serious threat to government than many organizations realize, and it's no longer just about paying a ransom. This week on Feds At the Edge, cybersecurity experts explore what agencies can do to strengthen their defenses, including adopting Zero Trust principles, improving network segmentation, and planning for recovery before an attack occurs. Cesar Gamez from City of Roseville, CA explains how ransomware attacks have evolved, from encrypting files for financial gain to tactics that threaten to expose sensitive data or target victims' customers if demands aren't met. And Travis Rosiek of Rubrik Public Sector, introduces an even more alarming trend: "wiper" attacks. Unlike traditional ransomware, these attacks - often associated with nation-state actors - are designed to permanently destroy or corrupt data, leaving organizations with nothing to recover even if they were willing to pay. Tune in on your favorite podcast platform as our guests also examine the security challenges of hybrid and cloud environments and explain why collaboration and information sharing are essential to staying ahead of increasingly sophisticated cyber threats.
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR
In this episode, Ryan and Shannon discuss cybersecurity standards for emergency alert systems, the cyber threats facing the 2026 FIFA World Cup, Europe's increasing ransomware attacks, and the latest in entertainment and gaming. Article: FCC requires emergency-alert distributors to secure their systems https://www.cybersecuritydive.com/news/fcc-emergency-alerts-cybersecurity-requirements/823880/?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExVkV4dFBhOWpqOFBxbjl2M3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR7_kN7EFANBEBdNJuCl51cHd2E4IHAL-obxSYFtzdyHU4bhG1pq6XT9bu-XZQ_aem_2DsJrDEgKtf2fAGyf8cd_w 2026 FIFA World Cup Faces Surge in Cyber Threats https://www.darkreading.com/cybersecurity-operations/2026-fifa-world-cup-faces-surge-cyber-threats?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExVkV4dFBhOWpqOFBxbjl2M3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR7oImHk5PY5DwjH2yhVi2lTjupB1wvLi9Z7ePrW0Hdo8x_WQ3l7uoYZhR3kYw_aem_xiwl3F6aJfCSpVBsL5g3Aw Europe Evolves Into Ransomware's Favorite Region https://www.darkreading.com/cybersecurity-analytics/europe-evolves-ransomware-favorite-region?fbclid=IwZXh0bgNhZW0CMTAAYnJpZBExVkV4dFBhOWpqOFBxbjl2M3NydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR6pDkxcW3H_UeqC6OuIsB63G3b97-gohTHlKhMKpraytKr-fPjmTcZJY9Ryww_aem_88eyaUsHkIuqBOmptVpkHQ Buy my book: https://www.theothersideofthefirewall.com/ Please LISTEN
Movie hacking tropes are pure fiction. Learn why the actual cyber security methods look nothing like your favorite thriller.Hollywood loves a specific image of a hacker: a lone genius in a hoodie smashing keys to bypass firewalls in seconds. This visual shorthand is designed to keep audiences entertained, but it completely ignores the tedious, technical reality of computer science. Real digital threats rarely involve dramatic interfaces or high-speed typing battles, yet these movie hacking myths persist because they translate easily to the screen.We break down the gap between cinematic storytelling and genuine cyber security operations. By examining how movies prioritize pace over tech accuracy, you gain a clearer view of how systems are actually compromised. While the film industry focuses on tension, the truth involves complex, long-term strategies that look significantly less exciting than what you see in action films.CHAPTERS00:00 Why This One Is Different02:27 Fourteen Companies. Broken English. One Accomplice.03:42 No Skill, No Code, Just a Chat Window05:53 The Con That Got Him In08:05 Why the AI Believed Him09:41 The Line It Refused to Cross12:13 The Boundary Nobody Is Talking About14:30 Mistake One: The Agent on the Victim's Server15:34 The Resume and the Home Address17:32 The Organization Collapsed Into One Man19:38 The Real Company on the Other End21:49 Weapon or Shield, Same Tool23:41 What To Do Monday MorningReal cybercrime stories. AI threats. Ransomware attacks. Social engineering tactics that are working against you right now.Hosted by David Dean Mauro — experienced former trial lawyer, AI Security Advisor, FBI InfraGard member, VP of NetGain Technologies and Author, Moving Target Trilogy Book Series (#1 Amazon Hot New Release 2026).Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.True crime enters our homes and businesses daily. Learn from actual people who fight it daily and show you how in a thriller story. The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com Support the showNew Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14.Moving Target: The Obedient Machine drops April 21.Book 3 -- Ghost and the Machine -- out soon!
LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here. Selected Reading Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch) Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch) Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps (Zafran) 23 ClawHub Plugins Squat Official Org Scopes (Manifold Security) Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr) Indian auto giant Bajaj Auto hit by ransomware incident (The Record) U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times) Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek) US adds sanctions against accused Cambodian scammers Prince Group (Reuters) Ushering in the Next Frontier of Quantum Innovation (The White House) Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
You asked, we answered!
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow