Malicious software used in ransom demands
POPULARITY
Categories
Ransomware is a looming threat for any business or entity that has an online footprint. But we ask the big question. Should companies pay ransomware or not? We engage each other in a debate for the ages. Plus Walmart began accepting Apple Pay and Google Pay at its Walmart and Sam's Club locations. Robb wants to ask us why aren't more people using tap to pay? Xbox announced its disc-to-digital program that will let owners of physical game discs claim digital copies. You can use those digital copies in Xbox Play Anywhere and Xbox Cloud Gaming. Starring Sarah Lane, Tom Merritt, Robb Dunewood, David Spark, Roger Chang, Joe To read the show notes click here! Support the show on Patreon by becoming a supporter!
The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462
Ransomware used to sound like a fairly straightforward nightmare: attackers get in, encrypt your files, demand money, and ruin everyone's week. Unfortunately, the business model has gotten an upgrade. Today's ransomware groups are stealing massive amounts of data, recruiting affiliates with surprisingly competitive revenue splits, disabling security tools, contacting patients directly, and even hijacking social media accounts to turn up the pressure. Meanwhile, regulators are asking harder questions about risk analysis and looking further into the past for answers. Connect those dots, and the picture gets uncomfortable fast. This episode explores what recent ransomware headlines are really telling healthcare organizations, including the small ones still hoping they're too tiny to attract attention. Spoiler alert: the bad guys appear to have misplaced their minimum-size requirement. More info at HelpMeWithHIPAA.com/574
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
We're back for a brand-new season!
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
(Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.) Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this. Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance. Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade Timestamps: 0:00 Introductory banter 0:58 State of Statecraft, and a late CFP window 3:24 The White House offensive hacking memo 6:37 "Hack back" is the wrong frame for what's being authorized 11:20 Ransomware cases sitting on the shelf 17:01 The million-dollar bond and who can realistically play 22:29 Where DPRK crypto theft falls under the new definitions 28:15 Would TLP Black take a contract? 36:55 Gen Digital's 12 KB backdoor hiding its C2 in desktop.ini whitespace 46:57 Passive DNS, registration patterns, and pivoting on a dead domain 57:32 Feeding a one-off find back into detection engineering 1:02:14 Metador, Mafalda, and the mercenaries who love telcos 1:17:07 Armored Likho and what "Western APT" really means 1:28:16 The IOC market, private reporting, and CTI's matching problem 1:58:10 Google's culture problem, the weekly model churn, and Patch Tuesday math
Ransomware attacks are devastating small businesses, and most owners don't know they're vulnerable until it's too late. This episode covers how phishing emails open the door, why employee training matters more than technology, and three essential strategies to protect your business. Read more at https://fischsolutions.com/real-hudson-valley-ransomware-phishing-examples/ Fisch Solutions City: New Windsor Address: 3188 Route 9W Website: https://fischsolutions.com
Proactive and actionable get used a lot in security, and Michael DeBolt, President and Chief Intelligence Officer at Intel 471, is direct about it. Inside Intel 471, proactive means moving past indicators of compromise, which he describes as temporary, and focusing on adversary behavior instead. Indicators still get blocked. Intent, capability, and motivation are what tell a defender whether they are actually a target. So what is pre-attack intelligence? It is information gathered from inside adversary communities before an attack is launched, built on embedded access to the places where financially motivated actors communicate. DeBolt sets aside the deep and dark web framing, arguing the phrase suggests a space nobody can reach. Mapping it reveals a structured ecosystem of financially motivated cybercrime, with enabling services operating alongside the actors themselves. Why track actors rather than ransomware groups? Because operators move and behaviors stay. Many current groups are staffed by people who ran earlier groups that have since disbanded, and techniques travel with them. A threat hunt built around the behavior holds up whether that person is operating under one banner, another, or on their own. Intel 471 maps techniques to the MITRE framework, which lets a consuming team run threat profiling and decide which actors present more risk than others. The same logic applies to exposure work. An organization scanning its attack surface and finding internet facing vulnerabilities can ask which threat actors are discussing those vulnerabilities, and whether that moves an item to the top of the list. The CISO conversations DeBolt describes land on numbers most security leaders already report on. Mean time to respond, mean time to detect, and alert volume that can absorb half or more of an analyst's day. He uses the phrase decision grade intelligence for intel that informs security operations rather than sitting beside it, with integrations pushing it straight into analyst workflows. Two customer situations show the daily version. Intel 471 helped an organization locate an insider after its own monitoring flagged something unusual. Separately, initial access brokers advertise compromised credentials that feed ransomware operations downstream, and since actors lie and embellish, validating those claims is part of the work. DeBolt closes on a note that sits right next to everyone's AI investment. Credentials, identity, internet facing vulnerabilities, and open remote access tools are still how attackers get in. GUEST Michael DeBolt, President and Chief Intelligence Officer, Intel 471 LinkedIn: https://www.linkedin.com/in/mdebolt/ RESOURCES Black Hat USA 2026 Event Coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Intel 471: https://www.intel471.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Michael DeBolt, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, pre-attack intelligence, adversary behavior, ransomware, initial access brokers, insider threat, MITRE framework, threat hunting, decision grade intelligence, compromised credentials, attack surface, cybercrime underground, Black Hat USA 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Geoff White has spent over a decade at the intersection of technology and organized crime. As Channel 4 News' technology correspondent, he reported on the Snowden leaks, exposed the Talk Talk hack, and dug into fraud across the online dating industry. He's the co-creator of the BBC's Lazarus Heist, a chart-topping podcast on North Korea's hacking operations, and the author of three books — Crime Dot Com, Rinsed, and, for Audible, The Dark Web and AI: Friend or Foe, the latter released back in 2019, well before AI became a household conversation.In this episode, Geoff joins Yitzy to talk about his path from local newspapers to investigative journalism, the difference between writing a book and building a podcast, and how crypto has genuinely changed the mechanics of money laundering — not made it impossible to trace, but made it faster to move. He also breaks down how his team pieced together 350,000 leaked internal messages from the Conti ransomware gang, translation quirks and all, and gives his take on recent AI-driven hacks, including the Hugging Face/OpenAI incident and the Cold Card wallet exploit — plus why he's skeptical of confident claims about how much AI is actually being used in phishing today.This episode is brought to you by FirstRead — the AI-powered contract and document tool built for lawyers. Use code BYNDTHECODE10 for 10% off, or sign up here: https://first-read.com/signup?ref=BEYOND2026In this episode, we cover:00:00 – Intro: who is Geoff White04:14 – From balloon modeler to investigative journalist09:25 – Going freelance and the leap into book writing11:05 – How book deals and advances actually work13:39 – Researching and writing Crime.com15:05 – Meeting Brett Johnson, the "OG of hacking"17:36 – Books vs. podcasts: what changes in the storytelling24:00 – What the reader knows and when: crafting a true-crime narrative26:18 – Rinsed: has crypto made money laundering easier, or just different?35:37 – Inside The Conti Files: leaked chats, translation chaos, and "the grandmas"42:30 – Personal safety and the risks of covering hackers directly44:22 – Revisiting AI: Friend or Foe, written in 201948:05 – The Hugging Face/OpenAI hack, the Cold Card exploit, and self-custody risk50:45 – Why Geoff won't say "AI phishing is worse" without the dataConnect with Geoff :https://geoffwhite.tech/ (podcast and audiobook links, book purchases and contact details)
Podcast: Industrial Cybersecurity InsiderEpisode: Your Most Critical Network May Be Your Least ProtectedPub date: 2026-08-11Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationThe air gap you're counting on probably isn't there. Dino Busalacchi sits down with cybersecurity veteran and Tulane University Cybersecurity Professor Joshua Copeland, to talk about the realities of protecting industrial environments, where uptime, safety, and production come first. They dig into why legacy systems can't be secured like IT, how routine security tasks can disrupt physical operations, the leadership gap between IT and OT, and why cybersecurity needs to be treated as digital safety. A practical listen for CISOs, CIOs, engineering leaders, and plant operators.Chapters:(00:00:00) Why operational technology is critical to everyday life(00:03:00) Legacy systems and the hidden opportunity in OT security(00:07:00) Ransomware, AI, and attacks designed for physical outcomes(00:10:00) How standard IT security tools can stop production(00:13:00) What cybersecurity events get wrong about OT(00:16:00) The leadership gap and the myth of isolated systems(00:20:00) Why cybersecurity should be treated as digital safety(00:23:00) Compliance, asset inventory, and aging industrial equipment(00:27:00) Building the next generation of OT security professionals(00:31:00) Why every part of modern life depends on OTLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityJosh Copeland on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you'd like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
Ransomware recovery doesn't end when the malware is removed and the servers come back online.In this episode of Reimagining Cyber, Tyler Moffitt is joined by Keelin Conant, a cybersecurity professional with firsthand experience of ransomware restoration, to explore what happens after the immediate crisis is over.They look beyond restoring systems to the human and business consequences that can linger for weeks, months and even years. Keelin shares stories of exhausted IT teams, leadership pressure, employee trauma, reputational damage and the danger of falling back into old habits once the immediate crisis has passed.The conversation also examines why organizations can be more vulnerable to another attack after the first one, the importance of fixing the vulnerabilities that allowed attackers in, and why backups and incident response plans aren't enough if they aren't regularly tested.From ransomware-as-a-service and repeat attacks to communication, leadership and the psychological impact on the people involved, this episode asks a fundamental question: when has an organization really recovered from a cyberattack?The answer may have less to do with getting the technology running again—and much more to do with whether the business and its people can genuinely move forward.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com
A six-billion-dollar brand got breached this week, and the attackers never wrote a line of code. They called three employees and pretended to be IT. Every business owner should sit with this: the same phone call works even better on a company your size. *Every breach is won or lost before it begins.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who do not have time to keep up with cyber news but cannot afford to be blindsided. The good news first. The City of Coweta, Oklahoma, a town of about ten thousand people, got hit with a ransomware attack that locked up every computer in City Hall. Permits, transactions, and in-person card payments stopped cold. But 911 never went down because police and fire systems run on separate off-site servers the attack could not reach. Coweta is refusing to pay the ransom for one reason: its backups actually work. That is the whole lesson in one town. Levi Strauss told the SEC that attackers stole corporate data after socially engineering just three employees. No malware. No exploit. Someone called pretending to be the internal help desk, led employees to a fake login page, and captured their passwords and live sessions in real time. Then they registered their own login devices, removed the real ones, and deleted security alerts so nobody got a warning. Google's threat team says the crew behind this style of attack built tools to hit more than two hundred companies in about five weeks. If they will call Levi's, they will call your front desk. LockBit is back. Law enforcement broke up the ransomware crew in 2024, but its 5.0 version has already listed more than two hundred victims. The latest is Microphase, a Connecticut company that has made radio and radar parts for the defense world since 1955. This is double extortion: they steal your data first, then threaten to publish it unless you pay. Backups alone will not save you. If they will hit a specialty parts shop, "we're too small to be a target" is not a plan. Three stories, one thread. Coweta survived because of decisions made long before the attack. Levi's got hurt in a single moment of misplaced trust. LockBit proves attackers are coming whether you are a household name or a shop nobody has heard of. The outcome was decided long before the attack. In this episode, we discuss: • How the City of Coweta kept 911 online while ransomware locked up City Hall • Why refusing to pay a ransom only works when your backups actually do • How attackers breached Levi Strauss with three phone calls and no malware • Why regular text-message MFA did not stop the Levi's attackers, and what does • LockBit's return and why a 1955 defense parts maker landed on its leak site • Why "we're too small to be a target" is the most expensive assumption in business • The one habit that shuts down the fake-IT phone call for free Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #DataBreach #LeviStrauss #LockBit #SocialEngineering #Vishing #SmallBusiness #BusinessRisk #MSP #Backups
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013 Gunra Ransomware https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf Neo4J/GraphQL Vulnerability CVE-2026-5423 https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
Ready to build expertise in one of the fastest-growing areas of insurance? Explore the Risk & Insurance Education Alliance's Cyber RiskPRO® program and gain the knowledge you need to identify cyber exposures, explain coverage solutions, and serve clients with confidence in today's rapidly evolving cyber environment. Artificial intelligence is transforming the insurance industry, but it's also reshaping the cyber threat landscape. In a recent episode of Alliance Insights, Lisa Gardner spoke with Adam Connor, Area Executive Vice President at Risk Placement Services, about the current state of the cyber insurance market and what insurance professionals should expect over the next 12 to 18 months. One of Connor's key observations is that AI is rapidly becoming an everyday business tool. He described today's AI adoption as similar to the early days of online dating services. What once felt unfamiliar is quickly becoming mainstream. Insurance agencies are already using secure AI tools to analyze books of business, identify growth opportunities, improve retention strategies, and automate administrative tasks. At the same time, cyber criminals are leveraging AI to increase the speed and scale of attacks. According to Connor, social engineering and ransomware remain leading causes of cyber claims. AI lowers the technical barriers for threat actors, making sophisticated attacks easier to launch than ever before. Despite rising claims activity, the cyber insurance market remains competitive. Connor noted that many organizations continue to see flat renewals or even rate reductions due to new carrier entrants and strong marketplace competition. However, he expects the market to gradually harden as losses continue to accumulate. Connor also challenged a common misconception that smaller organizations are unlikely cyber targets. Many attacks use a broad, automated approach rather than targeting specific companies. Businesses that fail to maintain software updates, security controls, and employee awareness programs remain vulnerable regardless of size. Another important takeaway is the need for adequate cyber insurance limits. Connor cautioned that minimal coverage may create a false sense of security. With cyber losses often reaching millions of dollars, organizations should carefully evaluate whether their limits align with their exposure. As cyber threats continue to evolve, insurance professionals have an opportunity to help clients better understand both risk management and insurance solutions. While technologies may change, Connor's message was clear: cyber risk isn't going away, and organizations that embrace both cybersecurity and cyber insurance will be better positioned for the future. Cyber threats are evolving faster than ever, and clients are looking to insurance professionals for guidance. Build the expertise needed to identify cyber exposures, evaluate coverage options, and confidently navigate today's cyber risk landscape with the Risk & Insurance Education Alliance's Cyber RiskPRO® program. Learn more and take the next step in advancing your cyber risk knowledge. Focusing exclusively on risk management and insurance professional development, the Risk & Insurance Education Alliance provides a practical advantage at every career stage, positioning our participants and their clients for confidence and success.
In today's episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: 1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years. 2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors. 3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: 1 Geoff's investigation into Conti, one of the world's most notorious ransomware gangs (7:33) 2 The impact of AI on ransomware attacks (13:52) 3 How money laundering is changing (17:03)Standout Quotes: 1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff WhiteRead the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.
Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online': scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Ransomware can lock up every file on your computer and hold it hostage until you pay. I'll discuss defenses that work, why backups are your best insurance, and why you should never, ever pay the ransom.
The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com
The risk of ransomware is real - are you ready? Richard talks with Heather Renze about her experiences dealing with a ransomware attack and how to get prepared when it happens to you. Heather talks about how ransomware has evolved into a business that has operators, affiliates, and even tech support. Making a plan is essential - involving finance, legal, and IT. Cyberinsurance plays a big role, as do regulatory bodies - it depends on the business you're in. But your plan needs to know three essential things: what breaks first, how long your company can function with it broken, and who can decide on what to do next in the first hour of the event. The plan may or may not work perfectly, but not having a plan is far worse. Get ready! Links Ransomware Guidance from NIST Recorded June 25, 2026
Today's farms rely on technology more than ever. From grain dryers and irrigation pivots to livestock systems, security cameras, accounting software, and smartphones, nearly every part of a modern farming operation is connected. That also makes agriculture one of the fastest-growing targets for cybercriminals. Chris from Tech Support Farm returns to Farm4Profit to discuss how farms can better protect themselves from ransomware, phishing scams, compromised credit cards, malware, and attacks on connected equipment. The conversation covers real-world examples—including Tanner's own experience with fraudulent credit card charges—and explains how remote monitoring, endpoint detection, password management, secure business email, mobile device management, and network monitoring work together to reduce risk. The episode also explores: Business email security Password managers Public Wi-Fi risks Phishing scams Credit card fraud Remote monitoring Endpoint detection (EDR) Mobile device management Irrigation and grain dryer security Data backups Disaster recovery Cyber insurance Farm technology infrastructure AI and digital threats Whether you operate a family farm or a multi-location business, this episode offers practical advice that could save your operation from significant financial loss and downtime. Want Farm4Profit Merch? Custom order your favorite items today!https://farmfocused.com/farm-4profit/ Don't forget to like the podcast on all platforms and leave a review where ever you listen! Website: www.Farm4Profit.comShareable episode link: https://intro-to-farm4profit.simplecast.comEmail address: Farm4profitllc@gmail.comCall/Text: 515.207.9640Subscribe to YouTube: https://www.youtube.com/channel/UCSR8c1BrCjNDDI_Acku5XqwFollow us on TikTok: https://www.tiktok.com/@farm4profitllc Connect with us on Facebook: https://www.facebook.com/Farm4ProfitLLC/Farm4Profit Media is not a financial, legal, or tax advisor. Content is provided for informational purposes only, and we serve solely as a platform for third-party opinions. Any actions taken based on this content are at your own risk. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Hackers got inside America's drinking water controls. In one Minnesota town, the tower called for water while the well sat dead. This wasn't a data leak. Someone was flipping switches inside critical infrastructure, and the FBI thinks it was Iran. *Your attacker isn't malware anymore. It's a voice you decided to trust.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who can't afford to be blindsided. First, the water. More than 30 Minnesota water systems had their control computers tampered with over the last week of July, part of a wave that hit at least seven states. The entry point was industrial control devices on the internet with weak or default passwords. Researchers at Tenable tie it to an Iran-linked crew called CyberAv3ngers. Nobody demanded a ransom, and that's the chilling part. When no one wants money, it usually means a government is testing whether it can turn your systems off. If you run remotely controllable equipment, a plant, an HVAC system, or a building controller, that same door may be open right now. Then, the healthcare giant. Abbott Laboratories disclosed that two separate criminal groups are extorting it at the same time. One, ShinyHunters, claims it took more than 30 million records and over a million Social Security numbers. The entry point was a phone call. Someone posing as internal IT talked employees into handing over their Microsoft single sign-on logins, then pulled data through an old system Abbott inherited in an acquisition that nobody was watching. No virus. No zero-day. Just a convincing voice and one over-trusted login. Finally, the one you'll feel in your own office. Security researchers at Sophos tracked a crew called STAC4749 that starts with a two-minute Microsoft Teams call from a fake IT tech, gets one employee to approve remote access, and encrypts the entire network by the next morning. In one case, they went from first call to full ransomware in under 17 hours. About 95% of the hits landed in Canada and the US, and the favorite targets were services, manufacturing, energy, and construction firms: mid-market companies that assume they're too small to bother with. Real internal IT does not cold-call and ask you to approve access. That one rule would have stopped every one of these. Three different targets. One common thread: the door wasn't kicked in. Someone opened it by trusting a device, a voice, or a message. • Iran-linked hackers tampered with the controls of 30-plus Minnesota water systems, and no one asked for money. • Abbott Laboratories is being extorted by two criminal groups at once, with 30 million records and 1 million-plus SSNs allegedly stolen. • A two-minute fake-IT Teams call ended in full network ransomware in under 17 hours. • The way in for all three was trust, not clever code. • Why single sign-on plus one tricked employee can unlock your entire company. • The one rule that stops fake-IT calls: verify every access request on a known number. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #DataBreach #Abbott #MicrosoftTeams #SocialEngineering #Vishing #CriticalInfrastructure #SmallBusiness #BusinessRisk #MSP
Send us Fan MailJonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.Articles referenced:Ransomware Doesn't Have to Hit Like a Hurricane (Myota): https://www.myota.io/articles/ransomware-doesnt-have-to-hit-like-a-hurricaneWhy We Need an AI Agent Taxonomy Right Now But We Can't Have One (42 Notions): https://blog.42notions.com/why-we-need-an-ai-agent-taxonomy-right-now-but-we-cant-have-one/Chapters:00:00 – Catch-up with Sander14:30 – The hurricane analogy: why Myota built resilience instead of a wall20:30 – What actually makes Myota different from standard backup/cyberstorage22:15 – Why you can't build a clean AI agent taxonomy (and the six dimensions Sander landed on instead)28:50 – The hybrid agent problem: acting "on behalf of" vs. "for the benefit of"45:10 – Sander's one takeaway: get the basics right before chasing the AI hypeSupport the show
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
Ransomware attacks have become more prominent in recent years, with major breaches of hospitals, like Toronto's Hospital for Sick Children in 2022, and companies like Indigo in 2023. In 2025, damages from ransomware attacks were expected to reach US$57-billion dollars worldwide. Alongside the rise of ransomware attacks came the emergence of a new kind of industry: ransomware negotiators. They communicate with attackers to try to convince them to lower the ransom fee. Today, the Globe's financial and cybercrime reporter, Alexandra Posadzki, joins us to talk about what it takes to hack the hackers, and what's at risk in these kinds of engagements.This episode originally aired April 16, 2026.Questions? Comments? Ideas? Email us at thedecibel@globeandmail.com Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead to Chaos ransomware attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
A non-profit puts a $22,000 bounty on the INC ransomware group, hackers breach the UK Department for Education, Russia charges Telegram founder Pavel Durov, and the FCC bans foreign robots and power inverters. Show notes Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group
In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.Send us Fan MailSupport the show
The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.
What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects? Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti's 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the Moscow movie studio the gang's leader used to launder money years previously, to the Ukraine war leak that brought the whole Conti empire down, this one plays like true crime… because it is. Geoff makes the case that defenders should think the same way: you're not buying security tools to fend off a hoodie in a basement, you're investing to outcompete a rival business. For anyone trying to integrate a better incident response plan, this episode reframes the whole conversation. Impactful Moments 00:00 - Introduction 01:45 - The Rewind: Colonial Pipeline and the week the East Coast ran dry 03:50 - How Geoff went from tech news to cybercrime reporting 05:10 - The difference between threat groups, APTs, and crime gangs 07:25 - Inside the Conti leaks: 300,000 messages 08:55 - Meet the gang: Stern, Mango, and Target 13:20 - Stern's origin story: Zeus malware, money mules, and the 25th Floor front company 16:50 - Ransomware gangs vs. the mafia: where's the protection? 18:10 - The money: $2.5M single payouts and 400 years of wages 19:30 - The Conti member arrested on a layover in Miami 20:35 - The downfall: the Ukraine war and the leak that ended it all 23:05 - What businesses can learn from Conti: recruitment, retention, reputation 27:45 - Advice for defenders: response waves, segmentation, and negotiating down 31:05 - Ron's takeaway: belonging and the thin line between operator and criminal Links Connect with Geoff White on LinkedIn: https://www.linkedin.com/in/geoffwhitetech/ Get your own copy of Geoff's books (Crime Dot Com, The Lazarus Heist, Rinsed): https://geoffwhite.tech/book/ Want more information on Conti? Check out Geoff's BBC podcast series, Cyber Hack: The Conti Files, available on BBC Sounds, Spotify, and Apple Podcasts – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements — U.S. Government Accountability Office & 70% of federal cybersecurity reporting rules are duplicated, GAO finds — CyberScoop • ANCHOR-CI could fix 20 years of broken government-industry collaboration — CyberScoop • Project Pilot: Can AI models fly drones? — Anthropic — • OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI — • Bluesky Thread: OpenAI and Hugging Face incident demonstrates both autonomous cyber risk and defensive potential — Pwnallthethings • Hugging Face CISO Post Mortem — Cloud Security Alliance Main Topics:1 dead, 16 injured after car ramming at Berlin CSD Pride event — DW — 25 Jul 2026. One person was killed and 16 others were injured after a vehicle was driven into people attending Berlin's CSD Pride event. Authorities investigated the circumstances and potential motive behind the incident as emergency personnel treated victims and secured the area. The attack underscores the vulnerability of large public gatherings to vehicle-based violence and the potential for mass casualties within seconds. • The suspect in the deadly Berlin Pride attack is killed in a confrontation with police • Car Plows Into Crowd at Berlin Pride Event in Suspected Terror Attack ‘Integrated' cyber and physical attacks concerned FIFA planners — StateScoop — 20 Jul 2026. Security planners for the 2026 FIFA World Cup prepared for blended attacks combining cyber disruption, physical violence, disinformation, swatting, infrastructure attacks, and interference with emergency communications. • The Gate 15 Interview EP 60 – Sasha Larkin: “I like the chaos, chaos makes sense to me.”2026H1 Threat Review: Vulnerabilities Up 51% Year Over Year — Forescout — 20 Jul 2026. Forescout reports a 51 percent year-over-year increase in vulnerabilities during the first half of 2026 as organizations contend with accelerating disclosure volumes across IT, Internet of Things, operational technology, and connected devices. Email threat landscape: Q2 2026 trends and insights — Microsoft Security — 23 Jul 2026. Microsoft detected approximately 7.6 billion email-based phishing threats during the second quarter, while monthly volumes declined modestly from April through June. Quick Hits:• Weekly ransomware & data leak landscape — eCrime.ch — 27 Jul 2026. eCrime.ch recorded 236 public ransomware and data-leak claims involving 45 active groups during the seven-day period ending 27 July, with 63 events showing public evidence of data leakage. Qilin led with 37 claims, followed by Gentlemen and Global Secret Group with 31 each, while construction was the most frequently targeted sector with 17 incidents. The United States accounted for 103 claims, and healthcare recorded 10 incidents among the 88 sectors represented. • Pay up or not? Ransomware surge has victims facing tough choices — Ars Technica • If you pay a hacker's ransom, chances are that they'll come back for more • Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) — Ransom-ISAC — 22 Jul 2026. Ransom-ISAC, eCrime.ch, and DEFUSED warn that Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM systems. • Black Kite's 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly
Ransomware lateral movement is exactly what it sounds like — once an attacker's inside your network, they start crawling around looking for more to encrypt, and stopping that crawl is often the difference between a bad day and a catastrophe. In this encore episode, part four of our seven-episode series pulling the best of the archives back into your feed, W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to break down exactly how attackers move once they're in, and what you can actually do about it.This one's back because listeners didn't just download it — they stuck with it, and a fair number of you came back for a second listen. That kind of engagement told us this conversation was worth surfacing again, especially with ransomware attacks as common as they are right now.Tom walks through the fundamentals of network segmentation — VLANs, air gaps, and why a "flat" network (where everything can talk to everything) is a gift to any attacker who gets in. From there the conversation moves into Zero Trust Network Architecture, what it actually takes to implement it at scale, and why flipping the switch from "allow everything" to "deny by default" is both the right move and the one that generates a thousand help desk tickets on day one. There's a good stretch on how schools, stadiums, and hotels handle network isolation differently than a typical enterprise, plus a practical rundown of incident response — locking down external access, isolating infected segments, keeping communication running when your own network is down, and why every kill switch needs to actually be wired to something.If you've ever wondered how much of this is built into your existing networking gear versus something you have to buy separately, or you just want a clearer mental model for how ransomware spreads once it's past the perimeter, this is a great one to revisit.Chapter Markers:00:00:00 - Intro and why ransomware lateral movement matters right now00:01:25 - Welcome back, meet Tom Hollingsworth00:04:06 - Why isolating the network is step one after a ransomware attack00:06:07 - Networking basics: how ransomware exploits flat networks00:09:31 - VLANs, air gaps, and network segmentation00:14:12 - Zero Trust Network Architecture explained00:19:02 - Managing zero trust at scale across teams00:25:48 - Special cases: schools, stadiums, and hotels00:34:31 - Blocking newly registered domains to stop command and control00:38:01 - Incident response: locking down the network00:42:12 - Keeping communication running during an attack00:44:54 - A real-world story: isolating infected devices00:50:01 - Building segmentation in from the start
Send us Fan MailAI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.
On this episode of Kill Chain, we go straight to the source with someone who spends his career trying to break into cars, trucks, and the chargers that power them. Kamel Ghali is an automotive cybersecurity researcher, penetration tester, and educator, and VP of International Operations for DEF CON's Car Hacking Village — the group that's been teaching the world to hack vehicles safely since 2017.Kamel walks us through a real exploit chain that hands over root access to an aftermarket infotainment system with nothing but a USB stick and a few taps on a touchscreen, the 2015 Jeep hack that changed the industry's culture overnight, and a wireless attack called Brokenwire that can knock a charging session offline from a passing car in about five seconds. If your fleet has a single electric vehicle charging overnight, this is the episode that explains exactly what's at stake.In this episode:What actually happens inside DEF CON's official car hacking masterclassA live walkthrough of rooting an aftermarket infotainment system with a USB stickWhy Tesla's from-scratch build gives it a security edge the legacy OEMs can't matchThe origin story of Car Hacking Village, and how it went globalThe SDR attack that let a researcher mess with a semi-truck's trailer brakes for a couple hundred dollars in hardwareWhy EV chargers are full computers, and most are running insecure protocolsThe wireless "Brokenwire" attack that can disrupt EV charging without touching the vehicleA real car theft that used CAN injection through a headlight, no key requiredWhat ISO 21434 and UN R155 actually require of automakers nowChapters: 0:00 Cold Open 2:24 Inside the Car Hacking Masterclass 8:19 Root, No Password 12:25 Pwn2Own & Why Tesla Leads 16:42 The Car Hacking Village Origin Story 23:47 Village Sponsors 26:25 Why Villages Matter 31:16 Ground Zero 36:20 The Weak Link 37:54 What to Expect at Car Hacking Village 41:11 What Kamel's Working On Now 43:39 Plugged In, Wide Open 47:36 The Tesla Wall Connector Hack 49:18 Broken Wire 51:39 Why This Matters 59:09 Ransomware & Cybercrime Motives 1:01:56 Real-World Car Theft: The RAV4 Case 1:04:03 Hollywood vs. Reality 1:05:35 Final Thoughts: The Next Ten Years 1:09:46 Outro / Car Hacking Village PlugNew episodes of the Kill Chain Podcast — like, comment, and subscribe. Learn more at fleetdefender.comWant to learn more about securing your fleets, platforms, or mission critical systems? Contact us at FleetDefender.com.
The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends
A ransomware attack against Coca-Cola-owned Fairlife forced the company to temporarily suspend production across the United States. Product safety was not affected, but production-related systems were.How does a cyberattack stop a physical product from being manufactured? Why would a company shut down production when there is no evidence that the product itself was compromised? And what does this tell us about the difference between restoring technology and restoring a business?Ben interviews Tyler Moffitt about operational ransomware, manufacturing dependencies, containment decisions, and what organizations should learn from Fairlife's response.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com
Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here. Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Could the disaster recovery plan designed to protect your company make a ransomware incident even worse? In this episode, I speak with Darren Thomson, Vice President and Chief Technology Officer for EMEA at Commvault, about Resilience Operations, commonly known as ResOps, and why cyber recovery now requires security, infrastructure, identity and data teams to work from one coordinated plan. Darren argues that many companies are accepting a difficult reality. Even with considerable investment in prevention and detection, a breach may eventually succeed. That does not make cybersecurity controls any less necessary, but it means recovery can no longer be treated as a secondary activity managed by another department. The problem is that security operations and infrastructure teams have traditionally worked toward different objectives. Security specialists concentrate on identifying and stopping threats. Infrastructure teams protect data, maintain backups and restore systems after outages. During a cyberattack, a successful recovery requires both sets of expertise. A backup administrator may be able to restore data quickly, but a forensic specialist must establish whether that data is clean. Without that confirmation, the company risks restoring malware and restarting the incident. Darren explains why a conventional disaster recovery plan may be particularly dangerous during ransomware. These plans were commonly designed for physical failures such as a lost data center. Data would be copied from one location to another so operations could continue. If the source data is infected, however, fast replication can carry the malware into the recovery environment. This is where ResOps enters the discussion. Darren describes it as an operating model rather than a product. It combines established practices from security and infrastructure management into a continuous program for testing, learning and improving recovery. Individual technology projects may come from the program, but resilience itself never reaches a final completion date. AI adds pressure on both sides. Criminals can use it to create faster and more effective attacks, while defenders can use machine learning to inspect large volumes of information, detect patterns and identify the newest clean recovery point. Companies must also protect AI systems as they would any other business application, including the models, data repositories and identities connected with them. Darren offers one practical starting point for CIOs and CISOs: Mean Time to Clean Recovery, or MTCR. This measures how long it takes to restore an application and its data with evidence that both are free from compromise. Before measuring MTCR, leaders must define their minimum viable company. These are the systems and services the business cannot operate without. Once that list exists, teams can test how long a verified clean recovery would take and replace assumptions with evidence. The initial answer may be uncomfortable. Teams may know how to restore an application without knowing whether the backup is clean. Security may know how to inspect the system but lack an established workflow with the recovery team. Darren sees those gaps as the starting point for a useful ResOps program because they provide everyone with a shared problem and a measurable objective. If your most important systems disappeared today, how long would it take to bring the minimum viable company back using verified clean data? Listen to the episode and share your answer with me.
This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack.This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back.Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one.They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact.Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from.Chapter Markers:00:00 – Encore intro & episode setup00:01:37 – Show intro and banter00:06:21 – Preventing the breach: phishing, droppers, and whitelisting00:14:46 – Blocking lateral movement, RDP/SSH lockdown00:20:28 – Detecting exfiltration and honeypot files00:24:19 – What to do once you've been hit00:25:58 – Building your incident response plan00:30:43 – Decryption, ransom payments, and why it's not over yet
News sources: https://lmg.gg/L8hqh Timestamps: 0:00 Linus Torvalds welcomes AI coding 1:14 Lenovo's inkjet-printed OLED laptop 2:32 EU forces Google to open Android 4:04 QUICK BITS INTRO 4:13 Ransomware halts Fairlife production 4:44 Samsung foldable specs leak 5:20 Moonshot unveils Kimi K3 5:56 23andMe settles its data breach 6:30 OpenAI sells a $70 basketball 7:04 Credits Learn more about your ad choices. Visit megaphone.fm/adchoices
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs
Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud's Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Tech over child safety. SAP patches critical bugs. CISA flags an actively exploited Cisco flaw. And the federal government accelerates AI investments. Our guest is Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, talking about Cyberthreats to Journalists and Influencers. AI costs savings come at a price. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Bogdan Botezatu, Senior Director, Threat Research and Reporting at Bitdefender, is talking about "Targeting the Messengers: Cyberthreats to Journalists and Influencers," their awareness campaign designed to address the escalating digital and reputational risks faced by media professionals in hostile environments. Selected Reading US sanctions VPN, malware providers for enabling ransomware attacks (Bleeping Computer) Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense) Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking | brief (SC Media) Estée Lauder Companies Reports Data Breach Exposing Health Records and SSNs (Beyond Machines) US military targeted in Iran war phone-tracking campaign (Financial Times) Australia finds serious gaps in Big Tech response to online child sexual abuse (Reuters) SAP warns of critical flaws in NetWeaver and Commerce Cloud (Bleeping Computer) CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog | brief (SC Media) Federal AI Projects Get Priority in TMF Funding Dash (GovInfo Security) Companies Are Throttling Employees' AI Use Because It's Too Expensive (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices