Podcasts about Ransomware

Malicious software used in ransom demands

  • 3,072PODCASTS
  • 14,662EPISODES
  • 38mAVG DURATION
  • 2DAILY NEW EPISODES
  • Sep 16, 2026LATEST
Ransomware

POPULARITY

20192020202120222023202420252026

Categories




Best podcasts about Ransomware

Show all podcasts related to ransomware

Latest podcast episodes about Ransomware

The Industrial Talk Podcast with Scott MacKenzie
Antonio Delgado and Ruben Domingo, BCC Global CISO Roundtable

The Industrial Talk Podcast with Scott MacKenzie

Play Episode Listen Later Sep 16, 2026 67:34 Transcription Available


Industrial Talk/BCC is talking to Rubin Domingo and Antonio Delgado, about "CISO Roundtable, Real Threats and Real Decisions impacting the market". Overview The roundtable examined practical cybersecurity risks and emphasized that security is a business responsibility, not solely an IT function. Key Risks Rubenidentified concentration among major service providers and uneven cybersecurity maturity among smaller public bodies as significant threats.Antoniohighlighted ransomware, phishing, social engineering, and third-party risk as more immediate concerns than highly publicized AI attack scenarios. Resilience Priorities Organizations should prepare before an incident through containment plans, crisis communications, tested backups, alternate service instances, and provider redundancy.Manufacturing environments need asset visibility, IT/OT network separation, and controls for legacy systems and connected devices.Leadership should evaluate cyber risk alongside financial and legal risk; cyber insurance increasingly requires evidence of controls such as MFA, backups, incident response, training, EDR, and vulnerability management. Open Questions How can smaller organizations achieve adequate cybersecurity maturity with limited resources?How should organizations adopt AI while protecting sensitive and critical data? Action Items Broadcast from the Barcelona Cybersecurity Congress in Barcelona on November 3–5, 2026. (@Scott Mackenzie) Outline Participants and Roles Ruben: Technology and cybersecurity director for a public organization representing Catalan municipalities and the regional government; advisory board member of the Global CISO Council Spain chapter.Antonio: CISO in an international education group serving schools across Europe, Latin America, and the United States. Real Threats Versus Noise Service-provider concentration can create broad systemic outages.Smaller municipalities and organizations often lack dedicated cybersecurity resources.Ransomware, phishing, social engineering, and third-party weaknesses remain operationally relevant. Incident Preparedness Contain affected systems first, coordinate communications, and restore services from prepared alternate environments.Regulation and frameworks such as ISO 27001 and Spain's National Security Scheme can drive preparedness. Manufacturing and Education Manufacturing requires IT/OT separation, visibility into connected assets, and legacy-system risk management.Schools require layered identity controls, MFA, awareness training, phishing simulations, and protection of minors' data. AI, Leadership, and Insurance AI should be adopted with policies, training, and controls against sensitive-data exposure.CISOs should communicate business impact and risk to boards rather than focusing only on technical controls.Cyber insurance validates organizational maturity and can support recovery after an attack. If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation. Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy! RUBEN CORTES DOMINGO'S CONTACT INFORMATION: Personal LinkedIn:  https://www.linkedin.com/in/rubencortes/ Company LinkedIn: https://www.linkedin.com/company/consorci-aoc-2/home/ Company Website: https://www.aoc.cat/en/ ANTONIO DELGADO'S CONTACT INFORMATION: Personal LinkedIn: https://www.linkedin.com/in/antoniodelgadociso/ Company LinkedIn: https://www.linkedin.com/company/affinitas-education/home/ Company Website: https://www.affinitasedu.com/ PODCAST VIDEO: https://youtu.be/eQThmKVowOY THE STRATEGIC REASON "WHY YOU NEED TO PODCAST": OTHER GREAT INDUSTRIAL RESOURCES: NEOM: https://www.neom.com/en-us Hexagon: https://hexagon.com/ Arduino: https://www.arduino.cc/ Fictiv: https://www.fictiv.com/ Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html Industrial Marketing Solutions:  https://industrialtalk.com/industrial-marketing/ Industrial Academy: https://industrialtalk.com/industrial-academy/ Industrial Dojo: https://industrialtalk.com/industrial_dojo/ We the 15: https://www.wethe15.org/ YOUR INDUSTRIAL DIGITAL TOOLBOX: LifterLMS: Get One Month Free for $1 – https://lifterlms.com/ Active Campaign: Active Campaign Link Social Jukebox: https://www.socialjukebox.com/ Business Beatitude the Book Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES...The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS...

RNZ: Nine To Noon
Tech: Mathspace edutech breach, Storm ransomware explosion

RNZ: Nine To Noon

Play Episode Listen Later Sep 16, 2026 21:52


Cybersecurity expert Tony Grasso looks at how a million records with edutech provider Mathspace were compromised in a relatively simple attack. He will talk about the explosion of Storm Ransomware, a group which has appeared out of nowhere and immediately teamed up with Qillan, a Russian-speaking crime group that's one of the most prolific in the Australasian space. There's been a severe upturn in the number of attacks against medial infrastructure across the region, with targets including dental clinics and medical centres as well as pharmaceutical supply chains - each with amber severity rating which highlights critical risks to patient care and operations. Cybersecurity expert Tony Grasso is Chief Information Security officer at COGENT. He worked at GCHQ in the UK and is a former Intelligence Officer in New Zealand

Easy Prey
Ransomware Evolution

Easy Prey

Play Episode Listen Later Sep 16, 2026 40:32


Ransomware has changed dramatically over the years. What started as criminals locking up individual computers and demanding relatively small payments has grown into a much larger operation involving stolen data, entire networks, third-party vendors, and increasingly sophisticated ways of pressuring victims to pay. Now AI is adding another wrinkle, giving criminals new tools while also creating some unexpected problems for them. Joining me to talk about how ransomware has evolved is Allan Liska, a ransomware researcher and Field CISO at Recorded Future. Allan has more than 30 years of experience in information security and has spent the last 12 years researching ransomware. He has advised major corporations and government agencies, served on national ransomware task forces, and written extensively about ransomware and threat intelligence. We talk about how ransomware became the business it is today, why small businesses can be just as vulnerable as larger organizations, and how attackers are increasingly going after trusted vendors instead of their intended targets directly. We also discuss what happens inside an organization after an attack, why disrupting ransomware groups really can make a difference, how AI is being used by criminals, and some of the mistakes ransomware operators make that ultimately work against them. Show Notes: [01:06] Allan Liska introduces himself and shares how his work at FireEye led him to begin researching ransomware more than a decade ago. [03:10] Growing ransomware problems pushed Allan and other researchers to begin developing better detections for attacks that many security teams were overlooking. [05:22] Ransomware evolved from attacks on individual computers to taking down entire networks and later stealing data to pressure victims into paying. [06:30] Publicly naming victims gave ransomware groups their own form of publicity and made it much harder for organizations to quietly deny an attack. [08:05] Encryption creates technical challenges for criminals, and stealing valuable data can sometimes be just as effective as encrypting an organization's systems. [09:28] Attackers increasingly target vendors and partners, while some groups are now using AI to create fake stolen data and falsely claim organizations as victims. [13:05] Chris and Allan discuss how transparency and regular communication can help organizations manage public trust after a security incident. [14:35] Ransomware response can quickly lead to employee burnout, making outside coordination and basic needs like sleep, food, and scheduling an important part of incident management. [16:14] A major breach may temporarily open security budgets, so organizations should already know which improvements they would prioritize after an incident. [23:29] International law enforcement agencies have become increasingly creative about tracking ransomware operators and waiting for them to make mistakes. [25:48] Being skilled at hacking does not necessarily mean criminals are equally skilled at protecting their identities or activities from intelligence agencies. [28:21] Ransomware groups frequently make technical and strategic mistakes, including faulty AI-generated tools, reused encryption keys, and stealing data nobody considers valuable. [29:36] Fewer ransomware victims are paying, but average payments are increasing, and ransomware remains profitable enough to attract new threat actors. [33:09] Allan explains why simply banning ransom payments may not work and discusses approaches that could give governments better intelligence about where payments go. [39:33] Collaboration remains an important part of ransomware research, and Allan encourages people entering the field to learn from other researchers and security communities. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Allan Liska - SANS Books by Allan Liska Recorded Future Ransomware Live Europol Alerts CISA Alerts

Random but Memorable
AI models can find security vulnerabilities. Can they fix them? with Keith Hoodlet

Random but Memorable

Play Episode Listen Later Sep 10, 2026 62:34


We all know AI models are getting better at finding software vulnerabilities. But can they fix them without creating new problems? In this episode, Wade sits down with Keith Hoodlet, 1Password's Director of Security Research, to discuss new findings from Off-by-1 Labs. Plus, how quickly does good cybersecurity start saving you money?

AZ Tech Roundtable 2.0
AZ TRT 2.0 – Best of Cybersecurity from Business to Government AZ TRT S07 EP14 (296) 9-6-2026

AZ Tech Roundtable 2.0

Play Episode Listen Later Sep 10, 2026 47:30


AZ TRT 2.0 – Best of Cybersecurity from Business to Government AZ TRT S07 EP14 (296) 9-6-2026   What We Learned This Week Cyber and CIO mgmt Common Cyber Issues TRM Labs on security ACTRA - Cyber threats affect everyone from Gov't to business to private & growing Clips from past shows focusing on Cybersecurity and threats to both business and Government. .     Seg. 1 Clips from Related Shows: Cybersecurity, Disruption, Blockchain & Terrorism w Ari Redbord of TRM Labs - BRT S02 EP31 (78) 8-1-2021     What We Learned This Week Cybersecurity is extremely important industry for national security TRM Labs startup in cyber-security, monitors blockchain OFAC - Gov't administers economic and trade sanctions Ransomeware – specific breach, takeover of a computer system, holds data hostage Programatic Money Laundering – bad guys create new addresses, create 'shell' companies   Guest: Ari Redbord, Head of Legal and Government Affairs w/ TRM Labs https://www.linkedin.com/in/ari-redbord-4054381b4/ https://www.trmlabs.com/post/trm-labs-appoints-ari-redbord-as-head-of-legal-government-affairs   Ari is formerly a US Attorney, and worked in the Treasury Department, now advises the Government on cybersecurity, and Blockchain. Cybersecurity is a fast growing and extremely important industry for national security, and corporate interests. There are Nation States acting as bad players in the cyber realm and targeting the US Government and US business. We discuss the advancements in technology on cyber crime, blockchain, crypto, and online fraud. How is the FBI dealing with Ransomware, and other cyber attacks on prime targets like the Colonial Pipeline, or other big corps. What Regulations are coming in banking, and Fintech, with KYC (Know Your Customer), plus the big banks like JP Morgan Chase and Goldman are on board.  What the blockchain ledger can help solve in security, to monitor criminal activity in real time with the help of crypto exchanges like Coinbase.  Lastly, what TRM Labs does for clients, how they advise, operate, and who they work with.   Full Show: HERE     Phishing, Malware & Cybersecurity - Try Not to Get Pwned - BRT S02 EP47 (94) 11-21-2021   What We Learned This Week:   Have I been Pwned? Means have I been breached / hacked – did someone hack my email or website Phishing – most common type of email threat, like when you receive a strange email with a link – Do Not Open – DELETE (and alert other office staff of the email) Ramsonware – hack your website, or data – hold it hostage for an extortion 'ransom' payment Dark Web – where stolen data, & info is being bought & sold VPN Connections – direct and secure   Guests: Vince Matteo, Seven Layer Networks, Inc. https://sevenlayers.com/ Vince Matteo is a certified penetration tester, a security researcher, and a senior consultant at Seven Layers (.com) where he focuses on securing small businesses.  Vince is the author of "Hacking 101 – A Beginner's Guide to Penetration Testing", he's a bug bounty hunter with 17 published critical vulnerabilities, and he's presented talks on offensive hacking at security conferences -- most recently GrrCON in Grand Rapids, MI and BSides in College Station, TX.  Outside of work, Vince is an accomplished endurance athlete, an Ironman age group champion, and in his spare time, you can find him in the desert -- training for the next hundred-mile ultramarathon.    Full Show: HERE     Seg. 2 Cybersecurity Response Plan w/ Frank Grimmelmann of ACTRA   - AZ TRT S06 EP03 (264) 2-9-2025                 What We Learned This Week ACTRA Arizona Cyber Threat Response Alliance Cyber threats affect everyone from Gov't to business to private and growing Companies need to be responsive with speed to be effective + share information of attacks ACTRA has members from both government and private sector ACTRA helped create a state cybersecurity response model that other states can use     Guest: Frank Grimmelmann https://www.actraaz.org/actra/leadership President & CEO/Intelligence Liaison Officer   Mr. Grimmelmann also serves as Co-Chair (together with Arizona's Chief Information Security Officer) for the Arizona Cybersecurity Team ('ACT'), created through the Governor's Executive Order signed in March 2018. He also serves as a Founding Member of the National Leadership Group for the Information Sharing & Analysis Organization Standards Organization ('ISAO SO') at the University of Texas San Antonio (UTSA), created under the President's Executive Order 13691 in February 2015. As ACTRA's leader, Mr. Grimmelmann was invited as the first private sector representative in the Arizona Counter Terrorism Information Center (ACTIC) and served as its first private sector Executive Board representative from 2014-2019. He presently acts as ACTRA's designated private sector liaison to ACTRA's Key Agency and other non-Member Stakeholders.    Full Show: HERE   Seg. 3   Cybersecurity & Compliance w/ Paige Hanson of Secure Labs - AZ TRT S06 EP15 (277) 8-17-2025       What We Learned This Week: A cybersecurity breach can cost more than just data—it can damage infrastructure and destroy client confidence. Even smaller companies (50–100 employees) need structured safeguards, compliance, and often outside MSSPs to stay secure. Secure Labs provides a roadmap for companies to meet regulatory standards like HIPAA, ISO 27001, and SOC 2, helping them win bigger clients. AI-driven threats like voice cloning and deepfakes make personal and business digital security more important than ever. Compliance isn't cheap—outside audits can run $5,000–$50,000 annually, while Big Four audits may exceed $100,000.       Guest: Paige Hanson, Co-Founder of Secure Labs   LinkedIn: https://www.linkedin.com/in/hello-paige-hanson Founder of SecureLabs | Helping businesses meet their security compliance standards | Fractional GRC | 

Security Squawk
LA Metro Hit by Ransomware, 153M Licenses for Sale, AI Breaches a Network in 10 Hours

Security Squawk

Play Episode Listen Later Sep 8, 2026 46:42


LA Metro, the transit system that moves nearly 10 million people in Los Angeles, just appeared on a ransomware gang's extortion site. A dark-web service is selling 153 million scanned driver's licenses. And security researchers watched AI break into a company and steal the master keys in under 10 hours. Three stories, one uncomfortable pattern. *Cybercrime is now an industry, and speed is the whole game.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who can't follow every cyber headline but can't afford to be blindsided. First up: LA Metro. A fast-growing ransomware crew called The Gentlemen posted the country's second-busiest transit system to its leak site, claiming it stole internal data. Here's what most coverage skips: this is a claim on a leak site, not a confirmed breach. There's no ransom demand and no statement from the agency. Bryan explains how to read a scary headline without confusing an allegation for a fact. These crews choose targets based on how much disruption they can cause, and public infrastructure is squarely in their sights. If your business creates real-world chaos when it goes down, you fit the profile. Then Randy tackles the story that should worry every business that scans an ID. A service called Nexus appeared offering searchable access to more than 153 million driver's licenses from the US and Canada. Investigative reporter Brian Krebs traced the data to an identity-verification vendor called IDScan.net. The FBI's New Orleans office opened a case the same day, reportedly after finding IDs belonging to a US Defense Secretary and an FBI Assistant Director in the pile. The vendor runs 21 million ID checks a month for names like Hertz, Target, and FedEx, so a leak there becomes a problem for many other companies. If a business scanned your license, your photo and address may have passed through a vendor you never chose and can't see. Reginald closes with the story that connects everything. Palo Alto Networks' Unit 42 documented a real attack in which a person directed AI agents at a company and let them run the break-in. The agents mapped the network, raided passwords hidden in the company's own code, and grabbed the master credentials in under 10 hours. That work would take a human team about two weeks. One boring control stopped them cold: a basic protection on the code pipeline blocked the backdoor. The lesson for owners is blunt. The fundamentals still work, but your window to catch an attack is now hours, not days. In this episode, we discuss: • A ransomware gang claims LA Metro, and how to tell a claim from a confirmed breach • A dark-web service selling 153 million driver's licenses and the FBI probe into the vendor behind it • AI agents that breached a company and stole root access in under 10 hours • Why cybercrime now scales like a business, and why speed is the whole game • The internet-facing gear and hidden passwords attackers hit first • What to ask every vendor that touches your customers' data Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #LAMetro #DataBreach #FBI #ArtificialIntelligence #VendorRisk #BusinessRisk #SMB #IdentityTheft #MSP Security Squawk

The CyberWire
RMM-ber this ransomware. [Research Saturday]

The CyberWire

Play Episode Listen Later Sep 5, 2026 19:51


Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Research Saturday
RMM-ber this ransomware.

Research Saturday

Play Episode Listen Later Sep 5, 2026 19:51


Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Cybercrime Magazine Podcast
Cybercrime Wire For Sep. 3, 2026. Ransomware Strikes S&P 500 Co. Jack Henry. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Sep 3, 2026 1:17


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Cybercrime Magazine Podcast
Cybercrime News For Sep. 2, 2026. Aurora Ransomware Used Cursor AI In 10 Attacks. WCYB Digital Radio

Cybercrime Magazine Podcast

Play Episode Listen Later Sep 2, 2026 2:51


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Reimagining Cyber
From Ransomware to AI: 15 Years of Cybersecurity - #218

Reimagining Cyber

Play Episode Listen Later Sep 2, 2026 23:33


In this special episode of Reimagining Cyber, Tyler Moffitt hosts the podcast for the final time — looking back on 15 years in cybersecurity, the lessons he's learned from speaking with security practitioners, researchers, MSPs and incident responders, and how dramatically the threat landscape has evolved.Tyler and incoming host Keelin Conant explore the shift from early malware and ransomware to double extortion, data theft and increasingly sophisticated nation-state activity. They also discuss how AI is accelerating the speed at which new exploits and attacks move from proof of concept into the wild.The conversation covers why organizations should report cybercrime to law enforcement, the role cryptocurrency trails can play in investigations, and the increasingly blurred line between financially motivated ransomware groups and nation-state operations.Looking ahead, Tyler shares some practical advice for defenders: treat identity as part of the security perimeter, limit privileges, protect administrative accounts, prepare for AI agents with excessive permissions, test backups, run tabletop exercises and focus on the fundamentals.But this episode is ultimately about more than technology. Tyler and Keelin discuss the importance of people, curiosity and human experience in cybersecurity — and why, despite changing technology and evolving attackers, there will always be a need to understand what is really happening and what defenders should do about it.As Tyler hands over the hosting role to Keelin, the next chapter of Reimagining Cyber begins.In this episode:15 years of cybersecurity lessonsHow ransomware has evolvedAI and the acceleration of cyber threatsWhy organizations should report cybercrimeNation-state attacks and ransomware-for-hireIdentity as the new security perimeterAI agents, permissions and OAuth tokensIncident response and tabletop exercisesWhy cybersecurity fundamentals still matterThe human side of cybersecurityTyler's final episode and Keelin's new chapter as hostAs featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

HLTH Matters
How AI Is Changing the Ransomware Threat in Healthcare

HLTH Matters

Play Episode Listen Later Sep 2, 2026 24:03


Ransomware remains one of the biggest cybersecurity threats facing healthcare, but the threat landscape is changing rapidly. Attackers are becoming more targeted, ransomware-as-a-service is making sophisticated tools more accessible, and artificial intelligence is giving cybercriminals new ways to identify vulnerabilities and craft convincing attacks. In this episode of The Beat's Cybersecurity at ViVE series, Sandy Vance speaks with Dave Bailey, VP of Consulting Solutions & Strategy at Clearwater, about the evolving ransomware threat and what healthcare organizations can do to stay ahead of it. Dave explains why smaller healthcare organizations and specialty practices are increasingly attractive targets, how attackers are using AI to improve social engineering and phishing, and why traditional cybersecurity approaches may not be fast enough for the threats ahead. The conversation also explores why healthcare organizations need to understand their AI risk, establish guardrails, inventory their AI use cases, and prepare defenses that can respond at machine speed. Dave shares practical advice for organizations beginning their AI journey, while emphasizing that cybersecurity can no longer be something organizations assess once a year. It has to become a continuously monitored, evolving process. In this episode, they talk about: Why healthcare continues to be one of the most attractive targets for ransomware How ransomware attacks have shifted toward smaller healthcare organizations and specialty practices Why dental practices and specialty providers can be particularly appealing targets How ransomware-as-a-service has created a more scalable business model for cybercriminals Why cybercriminals increasingly operate like businesses How attackers decide which healthcare organizations to target Why post-COVID healthcare's rapid shift to telehealth changed the threat landscape How AI is making phishing and social engineering attacks more sophisticated Why AI creates new governance and risk-management challenges for healthcare organizations Why healthcare organizations need defenses that can operate at machine speed How frontier AI models could help attackers discover previously unknown software vulnerabilities Why patching needs to become faster as AI-powered attacks evolve Why healthcare organizations need to challenge vendors about their cybersecurity roadmaps How organizations can begin building an AI governance strategy Why organizations should inventory their AI use cases before trying to govern them How healthcare organizations can use a tiered approach to AI risk Why workforce training and communication are essential to responsible AI adoption Why cybersecurity risk assessment can no longer be a once-a-year exercise Why scalability and continuous monitoring will become increasingly important A Little About Dave: Dave Bailey is Vice President of Consulting Solutions & Strategy at Clearwater, where he leads the development and delivery of enterprise-level cybersecurity and risk management services for healthcare organizations nationwide. With more than 24 years of cybersecurity experience, including 14 years focused on healthcare, Dave is a trusted advisor to executive teams navigating complex regulatory, operational, and cyber risk challenges. A recognized authority in cyber risk management and NIST Cybersecurity Framework assessment and implementation, Dave brings a strategic, business-aligned approach to security transformation. He previously served 13 years as a Communications and Information Officer in the United States Air Force, with leadership assignments spanning the Pentagon, domestic bases, and overseas operations. Dave holds an Executive MBA from Quantic School of Business and Technology and is a CISSP, blending executive perspective with deep technical expertise.

Hybrid Identity Protection Podcast
Why Less Than 20% of Ransomware Victims Ever Pay with Marc Jason Grens, President of Chaintrax

Hybrid Identity Protection Podcast

Play Episode Listen Later Sep 1, 2026 40:04


This episode features Marc Jason Grens, President of Chaintrax. Marc has led Chaintrax for twelve years, growing it from a compliance and anti-money-laundering firm in cash-to-crypto services into a licensed blockchain forensics practice after entering the ransomware payment business in 2017. He has since advised on more than 4,000 incidents. In this episode, Marc explains why ransomware victims decide to pay, why that payment can violate US sanctions law if it isn't vetted first, and why tracking the money afterward is how law enforcement works to recover it. This episode makes the case that paying a ransom is only the beginning of a compliance and recovery process, not the end of one. Guest Bio Marc Grens is the President of Chaintrax,  which has been providing cutting-edge financial, technological, and consulting services for the payments and incident response industry for the last 12 years. He is a serial entrepreneur with more than 15 years of experience in the investment industry. Prior to Chaintrax, Marc held senior positions at Charles Schwab, HighTower Advisors, and Alpha Strategies. He received his M.B.A. from the Kellstadt Graduate School of Business at DePaul University in 2010, and a B.A. from Illinois State University. Marc is an active angel investor and serves on multiple advisory boards of companies in the Chicago tech community. Sponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more. Links Connect with Marc on LinkedIn Connect with Sean on LinkedIn Connect with Jeff on LinkedIn Don't miss future episodes Learn more about Semperis HIP Conference 26 is coming to Nashville, September 8–10, 2026. Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments. If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

Cybercrimeology
Whodunit.gov.org: Behaviour and Cyber Attribution

Cybercrimeology

Play Episode Listen Later Sep 1, 2026 24:51


Notes: Ms. Aybar traces her interest in criminal justice, government and politics back to childhood. She recalls her father having her choose a current event from the Sunday newspaper and then discussing it with him, and says she already knew by seventh grade that she wanted to attend John Jay College of Criminal Justice. Her route into cybercrime came through advertising and political campaigns. As digital advertising became increasingly important, she encountered problems with advertisements being directed toward bots rather than people and became involved in applying fraud-prevention techniques to campaigns. This experience sparked a wider interest in cybercrime. After beginning her PhD, Ms. Aybar worked on a research assignment involving USAID and DAI focused on enhancing Ukraine's cybersecurity posture. The work led her further into the national-security side of cybersecurity and into studying nation-state, non-state and other cyber actors. Ms. Aybar and her dissertation chair, Dr. Rob T. Guerette, used environmental criminology and rational choice theory to examine whether state-sponsored and non-state cyber actors demonstrate different behavioural signatures. Rather than focusing only on the tools used in an attack, the approach considers the choices attackers make around risk, reward, effort, visibility, operational security and what they are ultimately trying to accomplish. The study uses data from the European Repository of Cyber Incidents (EuRepoC), allowing the researchers to look for patterns across a large number of publicly documented cyber incidents over time. Ms. Aybar notes that this scale is useful, but also stresses that the data only represent incidents that are visible, recorded and attributable rather than the full universe of cyber activity. Changes in the threat landscape, actor names and APT naming conventions also create challenges for classification and consistency. The clearest distinction in the study was that non-state actors were more associated with high-visibility and immediate-impact activity, including ransomware, disruption, doxxing and publicly confirming responsibility for an attack. State-sponsored or state-affiliated actors were more associated with lower-visibility strategic activity, particularly data theft and reduced operational disruption. From a rational choice perspective, Ms. Aybar suggests these differences reflect different incentives. Non-state actors may benefit from visibility, pressure or immediate financial gain, while state-linked actors may have reasons to preserve access, avoid attention and quietly collect intelligence or strategically valuable data. She emphasizes that, regardless of the category of actor, there are still people behind the screens making these choices. Not all of the study's expectations were supported. The researchers expected state-sponsored actors to be more likely to target state and political systems, but this was not supported in their first theoretically guided model. Ms. Aybar suggests this may reflect strategic indirection: a state-linked actor can pursue a state-level objective by targeting contractors, universities, infrastructure dependencies, supply-chain intermediaries or private companies rather than attacking a government agency directly. Ms. Aybar's planned dissertation consists of three studies. The first will develop behavioural baselines for state-linked cyber operations associated with China, Iran, North Korea and Russia and compare their operational and visibility patterns. The second will examine time to public attribution and whether behavioural characteristics are associated with how quickly an actor is publicly named. Her third dissertation study will examine ransomware crime scripts in the biotechnology and life sciences sector compared with general enterprise cases. The aim is to identify points in the ransomware process where situational crime-prevention techniques could potentially disrupt an attack. This work has also led Ms. Aybar toward the emerging area of cyber biosecurity. She is interested in what happens when cyber threats intersect with biological data, laboratory systems, pharmaceutical research, AI and the wider bioeconomy, approaching these issues from a cybercrime and national-security perspective. About our guest: Priscilla F. Aybar, M.A. Florida International University — International Crime and Justice PhD Program https://ccj.fiu.edu/people/ph.d.-students/ Papers or resources mentioned in this episode: Aybar, P. F., & Guerette, R. T. (2026). Rational choices in cyberspace: Quantitative insights into targeting and attack behavior among cyber offenders. Journal of Criminal Justice, 103, 102621. https://doi.org/10.1016/j.jcrimjus.2026.102621 Pixalate & The Democratic Congressional Campaign Committee (DCCC): How the DCCC used Pixalate to reduce ad fraud A case study featuring Ms. Aybar's work using invalid-traffic detection and advertising analytics to reduce ad fraud in political digital campaigns. https://www.pixalate.com/case-study-dccc-ad-fraud-protection European Repository of Cyber Incidents (EuRepoC) https://eurepoc.eu/database/

The Weekly Reload Podcast
ATF Hacked in Russian Ransomware Attack (Ft. Cybernews' Stefanie Schappert)

The Weekly Reload Podcast

Play Episode Listen Later Aug 31, 2026 65:32


This week, news broke that an extortion group claimed it broke into the Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF). To explain what we know and what may be coming, we have the reporter who broke the story. Stefanie Schappert of Cybernews joins the show to describe how she discovered the hack and what the ATF has said about it. Schappert said a Russian-language hacker group posted news of the hack on a "victim blog," but didn't post any evidence. She noted that the ATF confirmed it had been hacked but didn't say who did it. Still, it did say the hack only impacted a system related to criminal enforcement. While the hacker group did post an announcement that it plans to release data from the hack in the coming days, there's little information on what may be in there to this point. Schappert said the ATF's comments offer clues about what may have been compromised, and the hacker group's history provides further insight into how this may all play out. She said the government's policy on dealing with hackers and this group's background make the threat that the stolen information could become public real.Special Guest: Stefanie Schappert.

DrZeroTrust
The Stanislav Petrov Lesson for AI and Offensive Cyber

DrZeroTrust

Play Episode Listen Later Aug 31, 2026 51:40


In this episode, I dig into a potentially dangerous shift in U.S. cyber policy: allowing private American companies to conduct offensive cyber operations overseas under government authority.I get why the idea is attractive. Ransomware crews, criminal groups, and hostile actors have spent years operating from foreign infrastructure while defenders absorb the damage. At some point, people naturally start asking: why not hit back?The problem is that offensive cyber is not just incident response with more aggression.Attribution is messy. Infrastructure gets reused. Criminal groups overlap with intelligence services. Nation-states deliberately create ambiguity. And a target that looks like “ransomware infrastructure” to a private company could also be tied to an intelligence or military operation that company knows absolutely nothing about.That is where this gets dangerous.Because once an American company acts under U.S. authority, the target may not see a private cybersecurity firm. They may simply see the United States attacking them.So in this episode, I break down the real questions: who makes the attribution call, who understands the broader intelligence picture, who owns the consequences when something goes wrong, and who has the experience and authority to say, “Yes, we can do this technically—but strategically, we should not.”I'm not arguing that we should sit back and let adversaries hammer us.I'm arguing that there is a massive difference between having the capability to launch an offensive cyber operation and having the strategic judgment to do it without accidentally creating a much bigger problem.That distinction matters. A lot.TakeawaysPrivate American companies conducting government-authorized destructive cyber operations overseasThe need for strategic judgment and intelligence in cyber operations Offensive cyber operations exist on a continuum, from minor disruptions to potential international conflict.Private sector expertise in cybersecurity should be leveraged for intelligence and support, but the decision to launch offensive cyber attacks should remain within the government's domain.Chapters00:00 The Consequences of Private Cyber Operations03:38 The Dangerous Policy Idea07:46 The Memorandum and Its Implications10:34 The Most Dangerous Assumption13:49 The Petrov Problem and Strategic Context21:23 The Role of Human Latency in Cyber Operations24:07 The Geopolitical Implications of Private Sector Operations26:04 The Spectrum of Offensive Cyber Operations28:46 Geopolitical Implications and Attribution Challenges36:21 Legal and Ethical Considerations43:02 The Role of Private Sector and Government Collaboration46:18 Strategic Judgment and Human Oversight

Cyber Crime Junkies
Backups Don't REALLY Protect You From RANSOMWARE! What To Do Next

Cyber Crime Junkies

Play Episode Listen Later Aug 31, 2026 52:01


Discover the limitations of backup plans in disaster recovery and learn why they may not be enough to ensure business continuity. Explore the importance of having a comprehensive recovery strategy that goes beyond just backups. Understand the risks and consequences of relying solely on backup plans and find out what you can do to improve your organization's resilience.Chapters00:00 Welcome: Why Having Backups Is Not the Same as Being Recovered02:00 RPO vs RTO Explained: How Much Data Loss Can Your Business Survive04:50 The Real Cost of Cheap IT and Why the CFO Needs to Be in This Conversation06:45 Backup vs Business Continuity: What Leaders Are Actually Paying For09:00 The Gap Nobody Talks About: Blind Trust and Untested Backups11:30 Ransomware Is Organized Crime: Profit Sharing, Shift Changes, and Dark Web Toolkits14:00 City of Florence Alabama: How a $330,000 Ransom Unfolded Step by Step18:00 Same Attack, Different Outcome: Why the Packaging Company Paid Nothing19:30 Immutable Backups Explained: What Happens When Hackers Target Your Backups First22:00 Questions Every Leader Should Ask Their IT Provider About Backup Hardening24:30 AI Has Changed Phishing Forever: Why Old Security Training No Longer Works26:00 Cloud Disaster Recovery in Practice: The Tire Company That Burned to the Ground29:00 WannaCry, Local Hospitals, and the Ransomware Stories Nobody Publicizes32:00 Healthcare on Paper: When Systems Go Down and Nobody Knows the Old Way35:00 What Downtime Actually Costs: Lost Revenue, Idle Staff, Lawsuits, and Reputation39:00 Your 90-Day Recovery Readiness Plan: Assessment, Testing, and Documentation41:30 The Mindset Shift: Making Your IT Provider Part of Your Business StrategyQuestions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.True crime enters our homes and businesses daily. Learn from actual people who fight it daily and show you how in a thriller story. The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) The Moving Target Trilogy. Book 3 to be released September 22nd, 2026. Start with any of them. Be a Moving Target.Special Author pricing (30% off) Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com   Support the showWant to Watch? Subscribe and stop reading about it after it happens: https://www.youtube.com/@CyberCrimeJunkies?sub_confirmation=1Hosted by David Dean Mauro. Former trial lawyer, AI Security Advisor, FBI InfraGard member, VP of Strategic Growth at NetGain Technologies, and author of the Moving Target Trilogy (#1 Amazon Hot New Release, 2026).MOVING TARGET TRILOGY. Nonfiction cybercrime thrillers.

Bricks & Bytes
Site Layout Faceoff, Chinese Hardware Warning, and Largest US Contractor Breached as AI Ransomware Hits Machine Speed

Bricks & Bytes

Play Episode Listen Later Aug 29, 2026 24:02


This week's briefing covers three shifts reshaping jobsite technology, supply chain security, and risk on the ground.For five thousand years, construction has relied on chalk lines and measuring tapes to decide where walls go. While robotic total stations arrived twenty years ago, adoption has stalled near 16%. Now, layout automation is splitting into two clear approaches: printing robots that paint permanent lines and text directly on the slab, and optical projectors that beam designs onto floors, walls, and ceilings. Early data shows the value isn't just labor reduction—it comes from re-sequencing the job. In one hospital build, setting full layout in a single pass let mechanical contractors work ahead of framers, cutting schedule risk and saving $2.5 million. Meanwhile, vendors are pivoting to outcome-as-a-service models rather than pure hardware sales.Next, the pricing shock in physical AI. At the World Humanoid Robot Games in Beijing, Chinese models demonstrated sub-$10,000 price points—with the Unitree R1 starting near $5,900—compared to US equivalents estimated near $250,000. But cheap hardware comes with hidden supply chain dependencies and security exposures. Chinese brands already account for roughly 97% of the commercial construction drone fleet, which now faces looming regulatory freezes, tariffs, and potential data-sharing liabilities on secure sites.Finally, the target on your digital infrastructure. Construction has surged to become the fourth most-targeted industry for ransomware, with 22 distinct cybercrime groups hitting contractors in Q1 alone. Last week, America's largest contractor, Turner Construction, disclosed a breach compromising thousands of personal files and project records. The threat landscape is shifting rapidly: autonomous, AI-driven agents are now conducting reconnaissance and executing automated attacks at machine speed, rendering traditional human-speed incident response obsolete.Drop your answers to this week's questions in the comments of this week's LinkedIn post.

The Raving Patients Podcast
Your Vendors Have the Keys: The Cyber Risk Dental Practices Ignore

The Raving Patients Podcast

Play Episode Listen Later Aug 28, 2026 37:34


The biggest cybersecurity threat to your dental practice may not be a hacker trying to break through your firewall. It could be a vendor you already trust. In this episode of the Raving Patients Podcast, Dr. Len Tau sits down with Anthony Jurjevic, CISSP, founder and CEO of Techspedient, to uncover the cybersecurity risks many dental practices do not realize are already inside their networks. With more than 25 years in healthcare IT and cybersecurity, including over 15 years focused on dental technology, Anthony explains why vendor access, outdated credentials, shared passwords, and poorly managed remote access tools can leave practices vulnerable. Anthony explains how practice management companies, imaging vendors, billing services, patient communication platforms, phone systems, and other vendors may have ongoing access to a practice's network. The problem is not necessarily that these vendors are unsafe. It is that many practices do not know who still has access, how that access is being monitored, or what happens if a vendor's credentials are compromised. The conversation also tackles one of the biggest misconceptions in dental cybersecurity: being in the cloud does not automatically mean your practice is backed up or secure. Anthony shares how attackers can compromise a workstation, use saved credentials to access cloud-based patient information, and quietly steal data without encrypting an entire network. He explains why modern ransomware attacks increasingly focus on data theft and extortion, making traditional backups only one piece of a much larger security strategy. Dr. Len and Anthony also discuss HIPAA compliance, what happens after a ransomware attack, the importance of cyber insurance and forensic investigations, and the practical steps dentists can take right now to identify vulnerabilities. From auditing vendor access and removing former employees to testing backups, enabling multi-factor authentication, and conducting third-party cybersecurity assessments, this episode gives practice owners a practical look at protecting both their patients and their businesses. What You'll Learn Why trusted vendors can become one of your biggest cybersecurity vulnerabilities How unattended remote access can expose your dental practice Why being "in the cloud" does not automatically make your data safe How modern ransomware has shifted from encrypting data to stealing it Why backups cannot protect you once patient data has already been stolen What "HIPAA compliant" software really means for a dental practice What to do immediately after discovering a possible ransomware attack Why individual user accounts are safer than shared passwords How to audit vendor access, administrative permissions, and former employee accounts Why multi-factor authentication should be enabled wherever possible How penetration testing can reveal weaknesses before an attacker finds them — Key Takeaways 02:13 Your Vendors Have the Keys: The Cyber Risk Dental Practices Ignore 03:45 Meet Anthony Jurjevic 05:35 The Hidden Risk of Vendor Access 09:55 Why the Cloud Is Not a Backup 13:12 Ransomware, Data Theft, and Cyber Threats 17:57 What HIPAA Compliance Really Means 19:42 What Happens After a Ransomware Attack 24:54 Simple Ways to Protect Your Practice 26:20 The Danger of Shared Credentials 30:06 Testing Your Practice's Cybersecurity 32:15 Lightning Round 35:55 Connect With Anthony — Connect With Anthony Email: ajurjevic@techspedient.com Phone: 732-275-2708 Company: Techspedient - https://www.techspedient.com/ Anthony is also offering Raving Patients listeners a free simulated phishing attack for their practice. There is no obligation or sales pressure, and practices receive the reports so they can see where their vulnerabilities may be and address them with their IT provider. — Learn proven dental marketing strategies and online reputation management techniques at DrLenTau.com.   This podcast is sponsored by Dental Intelligence. Learn more here.   This podcast is sponsored by CallRail, call tracking & lead conversion software for dentists. Find out more here.   Raving Patients Podcast is your go-to place for the latest and best dental marketing strategies that will help you skyrocket your practice. Follow us for more!  

Daily Tech News Show (Video)
To Pay, or Not to Pay? That is the Question – DTNS Live 5141

Daily Tech News Show (Video)

Play Episode Listen Later Aug 27, 2026 69:12


Ransomware is a looming threat for any business or entity that has an online footprint. But we ask the big question. Should companies pay ransomware or not? We engage each other in a debate for the ages. Plus Walmart began accepting Apple Pay and Google Pay at its Walmart and Sam's Club locations. Robb wants to ask us why aren't more people using tap to pay? Xbox announced its disc-to-digital program that will let owners of physical game discs claim digital copies. You can use those digital copies in Xbox Play Anywhere and Xbox Cloud Gaming. Starring Sarah Lane, Tom Merritt, Robb Dunewood, David Spark, Roger Chang, Joe To read the show notes click here! Support the show on Patreon by becoming a supporter!

news club tech walmart xbox digest ransomware robb apple pay merritt google pay tom merritt xbox play anywhere david spark dtns robb dunewood roger chang
Paul's Security Weekly
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

Paul's Security Weekly

Play Episode Listen Later Aug 26, 2026 67:29


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

Microsoft Threat Intelligence Podcast
JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

Microsoft Threat Intelligence Podcast

Play Episode Listen Later Aug 26, 2026 31:01


In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig's Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure.    In this episode you'll learn:       How Jade Puffer used an LLM to conduct a ransomware attack  Why agentic AI can make cyberattacks faster and more adaptable  How organizations can better protect their growing AI infrastructure  Some questions we ask:      How did you determine an LLM was conducting the attack?  What basic security practices are most important against these attacks?  Does AI allow less-sophisticated threat actors to carry out more advanced attacks?    Resources:   Read the research on JADEPUFFER  View Crystal Morin on LinkedIn   View Michael Clark on LinkedIn   View Elliot Volkman on LinkedIn     Related Microsoft Podcasts:                    Afternoon Cyber Tea with Ann Johnson  The BlueHat Podcast  Uncovering Hidden Risks      Discover and follow other Microsoft podcasts at microsoft.com/podcasts     Get the latest threat intelligence insights and guidance at Microsoft Security Insider    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

Talos Takes
Back-to-school cybersecurity: Protecting education networks from ransomware and threats

Talos Takes

Play Episode Listen Later Aug 26, 2026 23:07 Transcription Available


As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners. How do you strengthen your defenses while managing the delicate balance between security and classroom usability? Here are the most high-priority steps to keep your district safe this semester.Prioritizing patches episode: https://www.buzzsprout.com/2018149/episodes/19360999

Paul's Security Weekly TV
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Dan Bowden, Leslie Nielsen, Brett Stone-Gross - BSW #462

Paul's Security Weekly TV

Play Episode Listen Later Aug 26, 2026 67:30


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Show Notes: https://securityweekly.com/bsw-462

Business Security Weekly (Audio)
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

Business Security Weekly (Audio)

Play Episode Listen Later Aug 26, 2026 67:29


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

Business Security Weekly (Video)
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Dan Bowden, Leslie Nielsen, Brett Stone-Gross - BSW #462

Business Security Weekly (Video)

Play Episode Listen Later Aug 26, 2026 67:30


The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Show Notes: https://securityweekly.com/bsw-462

HeroicStories
Will Ransomware Encrypt Backups?

HeroicStories

Play Episode Listen Later Aug 24, 2026 8:39


Worried that ransomware could sneak past your defenses and encrypt your backups? Most ransomware won't, but it's not impossible. I'll discuss how ransomware picks its targets, why your backup image files are usually safe, and one simple habit to keep your files protected.

Help Me With HIPAA
Connecting the Dots - What the Ransomware Headlines Are Missing - Ep 574

Help Me With HIPAA

Play Episode Listen Later Aug 21, 2026 42:55


Ransomware used to sound like a fairly straightforward nightmare: attackers get in, encrypt your files, demand money, and ruin everyone's week. Unfortunately, the business model has gotten an upgrade. Today's ransomware groups are stealing massive amounts of data, recruiting affiliates with surprisingly competitive revenue splits, disabling security tools, contacting patients directly, and even hijacking social media accounts to turn up the pressure. Meanwhile, regulators are asking harder questions about risk analysis and looking further into the past for answers. Connect those dots, and the picture gets uncomfortable fast. This episode explores what recent ransomware headlines are really telling healthcare organizations, including the small ones still hoping they're too tiny to attract attention. Spoiler alert: the bad guys appear to have misplaced their minimum-size requirement. More info at HelpMeWithHIPAA.com/574

Cyber Security Today
NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

Cyber Security Today

Play Episode Listen Later Aug 21, 2026 14:24


NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts. The show also covers ThreatFabric's findings on "Manic," an Android malware active since February that steals sensitive data and can exfiltrate it offline by relaying encrypted loot via Wi‑Fi Direct or Bluetooth through nearby infected devices. Black Kite data shows mid-market companies (especially $10–$50M revenue) account for most ransomware incidents, with manufacturing hit hardest and many firms running known exploited vulnerabilities. Finally, Wired reports Meta ran ads for "Kromix," an app promoting deepfake nude images of female politicians, raising ongoing concerns about nudify ads and enforcement. 00:00 Sponsor NordLayer 00:37 Headlines Preview 01:05 AI Exploits Hit PLCs 04:06 Android Malware Manic 06:49 Ransomware Targets Midmarket 09:19 Meta Nudify Ads Scandal 12:26 Wrap Up and Weekend Tease 13:23 Sponsor Message NordLayer

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 20, 2026 6:15


Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SECURE AF
Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

SECURE AF

Play Episode Listen Later Aug 20, 2026 5:43 Transcription Available


Got a question or comment? Message us here!Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 19, 2026 8:54


CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Security Conversations
A tiny 12 KB Windows backdoor, one victim, and a dead domain

Security Conversations

Play Episode Listen Later Aug 17, 2026 143:31


(Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.) Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this. Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance. Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade Timestamps: 0:00 Introductory banter 0:58 State of Statecraft, and a late CFP window 3:24 The White House offensive hacking memo 6:37 "Hack back" is the wrong frame for what's being authorized 11:20 Ransomware cases sitting on the shelf 17:01 The million-dollar bond and who can realistically play 22:29 Where DPRK crypto theft falls under the new definitions 28:15 Would TLP Black take a contract? 36:55 Gen Digital's 12 KB backdoor hiding its C2 in desktop.ini whitespace 46:57 Passive DNS, registration patterns, and pivoting on a dead domain 57:32 Feeding a one-off find back into detection engineering 1:02:14 Metador, Mafalda, and the mercenaries who love telcos 1:17:07 Armored Likho and what "Western APT" really means 1:28:16 The IOC market, private reporting, and CTI's matching problem 1:58:10 Google's culture problem, the weekly model churn, and Patch Tuesday math

Cyber Security Today
Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Cyber Security Today

Play Episode Listen Later Aug 17, 2026 9:22


CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July, with a surge in attempts after proof-of-concept code went public. Ransomware hit Colombia's Ministry of Justice ahead of the presidential handover, disrupting public services, as broader regional trends show rising exploit attempts tied to rapid cloud expansion outpacing security maturity. Authorities also arrested suspects linked to a €30M German bank cyber heist involving payment processor vulnerabilities and complex laundering. Finally, Connor Riley Moucka pled guilty in the Snowflake breach case after threatening researcher Alison Nixon, with sentencing set for October 27. 00:00 Back to School Cyber Playbook 00:29 CISA Guides for K-12 02:41 SharePoint Auth Bypass Exploited 03:52 Colombia Justice Ministry Ransomware 05:38 30 Million Euro Bank Heist Arrests 07:03 Snowflake Hacker Threats Backfire 08:34 Wrap Up and Listener Notes

ITSPmagazine | Technology. Cybersecurity. Society
Adversary Behavior Outlasts the Ransomware Brand | A Brand Briefing at Black Hat USA 2026 with Michael DeBolt, President and Chief Intelligence Officer of Intel 471 | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 16:12


Proactive and actionable get used a lot in security, and Michael DeBolt, President and Chief Intelligence Officer at Intel 471, is direct about it. Inside Intel 471, proactive means moving past indicators of compromise, which he describes as temporary, and focusing on adversary behavior instead. Indicators still get blocked. Intent, capability, and motivation are what tell a defender whether they are actually a target. So what is pre-attack intelligence? It is information gathered from inside adversary communities before an attack is launched, built on embedded access to the places where financially motivated actors communicate. DeBolt sets aside the deep and dark web framing, arguing the phrase suggests a space nobody can reach. Mapping it reveals a structured ecosystem of financially motivated cybercrime, with enabling services operating alongside the actors themselves. Why track actors rather than ransomware groups? Because operators move and behaviors stay. Many current groups are staffed by people who ran earlier groups that have since disbanded, and techniques travel with them. A threat hunt built around the behavior holds up whether that person is operating under one banner, another, or on their own. Intel 471 maps techniques to the MITRE framework, which lets a consuming team run threat profiling and decide which actors present more risk than others. The same logic applies to exposure work. An organization scanning its attack surface and finding internet facing vulnerabilities can ask which threat actors are discussing those vulnerabilities, and whether that moves an item to the top of the list. The CISO conversations DeBolt describes land on numbers most security leaders already report on. Mean time to respond, mean time to detect, and alert volume that can absorb half or more of an analyst's day. He uses the phrase decision grade intelligence for intel that informs security operations rather than sitting beside it, with integrations pushing it straight into analyst workflows. Two customer situations show the daily version. Intel 471 helped an organization locate an insider after its own monitoring flagged something unusual. Separately, initial access brokers advertise compromised credentials that feed ransomware operations downstream, and since actors lie and embellish, validating those claims is part of the work. DeBolt closes on a note that sits right next to everyone's AI investment. Credentials, identity, internet facing vulnerabilities, and open remote access tools are still how attackers get in. GUEST Michael DeBolt, President and Chief Intelligence Officer, Intel 471 LinkedIn: https://www.linkedin.com/in/mdebolt/ RESOURCES Black Hat USA 2026 Event Coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Intel 471: https://www.intel471.com/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Michael DeBolt, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, pre-attack intelligence, adversary behavior, ransomware, initial access brokers, insider threat, MITRE framework, threat hunting, decision grade intelligence, compromised credentials, attack surface, cybercrime underground, Black Hat USA 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

CareTalk Podcast: Healthcare. Unfiltered.
Healthcare AI Has a Cybersecurity Problem

CareTalk Podcast: Healthcare. Unfiltered.

Play Episode Listen Later Aug 14, 2026 33:29 Transcription Available


Send us Fan MailA year ago, if you went to a healthcare security conference, AI was still on the horizon. Interesting, a little speculative, maybe useful for writing better phishing emails. But not anymore. There are documented cases where an attacker handed an AI agent stolen credentials and the agent ran the entire attack by itself. It can include hundreds of steps, from breaking in, harvesting credentials, mapping the network, encrypting everything, and leaving the ransom note.David E. Williams, President of Health Business Group, and John Driscoll, Chairman of UConn Health, break it all down, examining what a documented 600-step autonomous AI attack means for health system security teams and why the most effective defense still comes down to fundamentals.

Cyber Security Headlines
The Department of Know: Ransomware gangs, Copilot apps, and drones phone home

Cyber Security Headlines

Play Episode Listen Later Aug 14, 2026 33:20


Read the full stories at CISOSeries.com This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

Cybercrime Magazine Podcast
Ransomware Minute. Ransomware Group Hacks Hospital Facebook Page. Scott Schober, WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 13, 2026 2:42


The Ransomware Minute is a rundown of the latest ransomware attacks & news, brought to you Cybercrime Magazine, Page ONE for Cybersecurity. Listen to the podcast weekly and read it daily at https://ransomwareminute.com. For more on cybersecurity, visit us at https://cybercrimemagazine.com.

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 12, 2026. Ransomware Group Hijacks Hospital's Facebook. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 12, 2026 1:15


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Reimagining Cyber
The Attack Is Over. Now Comes the Hard Part - #214

Reimagining Cyber

Play Episode Listen Later Aug 12, 2026 24:45


Ransomware recovery doesn't end when the malware is removed and the servers come back online.In this episode of Reimagining Cyber, Tyler Moffitt is joined by Keelin Conant, a cybersecurity professional with firsthand experience of ransomware restoration, to explore what happens after the immediate crisis is over.They look beyond restoring systems to the human and business consequences that can linger for weeks, months and even years. Keelin shares stories of exhausted IT teams, leadership pressure, employee trauma, reputational damage and the danger of falling back into old habits once the immediate crisis has passed.The conversation also examines why organizations can be more vulnerable to another attack after the first one, the importance of fixing the vulnerabilities that allowed attackers in, and why backups and incident response plans aren't enough if they aren't regularly tested.From ransomware-as-a-service and repeat attacks to communication, leadership and the psychological impact on the people involved, this episode asks a fundamental question: when has an organization really recovered from a cyberattack?The answer may have less to do with getting the technology running again—and much more to do with whether the business and its people can genuinely move forward.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 11, 2026 6:21


Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013 Gunra Ransomware https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf Neo4J/GraphQL Vulnerability CVE-2026-5423 https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Cybercrime Magazine Podcast
Cybercrime Wire For Aug 11, 2026. Ransomware Attack On Big Canadian Hospital. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 11, 2026 1:21


The Cybercrime Wire, hosted by Scott Schober, provides boardroom and C-suite executives, CIOs, CSOs, CISOs, IT executives and cybersecurity professionals with a breaking news story we're following. If there's a cyberattack, hack, or data breach you should know about, then we're on it. Listen to the podcast daily and hear it every hour on WCYB. The Cybercrime Wire is brought to you Cybercrime Magazine, Page ONE for Cybersecurity at https://cybercrimemagazine.com. • For more breaking news, visit https://cybercrimewire.com

Resources Risk & Insurance Podcast
Cyber Insurance, AI & Rising Threats- What Agents Need to Know in 2026

Resources Risk & Insurance Podcast

Play Episode Listen Later Aug 11, 2026 32:44


Ready to build expertise in one of the fastest-growing areas of insurance? Explore the Risk & Insurance Education Alliance's Cyber RiskPRO® program and gain the knowledge you need to identify cyber exposures, explain coverage solutions, and serve clients with confidence in today's rapidly evolving cyber environment. Artificial intelligence is transforming the insurance industry, but it's also reshaping the cyber threat landscape. In a recent episode of Alliance Insights, Lisa Gardner spoke with Adam Connor, Area Executive Vice President at Risk Placement Services, about the current state of the cyber insurance market and what insurance professionals should expect over the next 12 to 18 months. One of Connor's key observations is that AI is rapidly becoming an everyday business tool. He described today's AI adoption as similar to the early days of online dating services. What once felt unfamiliar is quickly becoming mainstream. Insurance agencies are already using secure AI tools to analyze books of business, identify growth opportunities, improve retention strategies, and automate administrative tasks. At the same time, cyber criminals are leveraging AI to increase the speed and scale of attacks. According to Connor, social engineering and ransomware remain leading causes of cyber claims. AI lowers the technical barriers for threat actors, making sophisticated attacks easier to launch than ever before. Despite rising claims activity, the cyber insurance market remains competitive. Connor noted that many organizations continue to see flat renewals or even rate reductions due to new carrier entrants and strong marketplace competition. However, he expects the market to gradually harden as losses continue to accumulate. Connor also challenged a common misconception that smaller organizations are unlikely cyber targets. Many attacks use a broad, automated approach rather than targeting specific companies. Businesses that fail to maintain software updates, security controls, and employee awareness programs remain vulnerable regardless of size. Another important takeaway is the need for adequate cyber insurance limits. Connor cautioned that minimal coverage may create a false sense of security. With cyber losses often reaching millions of dollars, organizations should carefully evaluate whether their limits align with their exposure. As cyber threats continue to evolve, insurance professionals have an opportunity to help clients better understand both risk management and insurance solutions. While technologies may change, Connor's message was clear: cyber risk isn't going away, and organizations that embrace both cybersecurity and cyber insurance will be better positioned for the future. Cyber threats are evolving faster than ever, and clients are looking to insurance professionals for guidance. Build the expertise needed to identify cyber exposures, evaluate coverage options, and confidently navigate today's cyber risk landscape with the Risk & Insurance Education Alliance's Cyber RiskPRO® program. Learn more and take the next step in advancing your cyber risk knowledge. Focusing exclusively on risk management and insurance professional development, the Risk & Insurance Education Alliance provides a practical advantage at every career stage, positioning our participants and their clients for confidence and success.

The CyberWire
Now with extra vulnerabilities.

The CyberWire

Play Episode Listen Later Aug 10, 2026 27:34


Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber ambassador. Meta ordered to pay an additional $567 million in child safety case. Water sector cyberattacks expand to new states. We got your Monday Business Briefing. On our Industry Voices, Dave Bittner sits down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat discussing AI Speed Cyber Defense. And scammers set sail on The Odyssey. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, Dave Bittner sat down with Mujtaba Hamid, EVP, Product and Strategy at Booz Allen Hamilton at Black Hat USA, discussing AI Speed Cyber Defense. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading More than half of AI-generated patches are broken (CyberScoop) China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns (The Record) Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) US cyber ambassador nominee Cassady confirmed in Senate (The Record) Meta Ordered to Pay $567 Million in New Mexico Child Safety Case (New York Times) New Jersey, Alabama Join States Targeted in Water Cyberattacks (Securityweek) Business Breakdown (N2K) ‘Watch The Odyssey for free online': scam targets film fans with fake streaming sites (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

HeroicStories
How to Avoid Ransomware

HeroicStories

Play Episode Listen Later Aug 10, 2026 5:51


Ransomware can lock up every file on your computer and hold it hostage until you pay. I'll discuss defenses that work, why backups are your best insurance, and why you should never, ever pay the ransom.

Farm4Profit Podcast
The Biggest Cybersecurity Mistakes Farmers Make

Farm4Profit Podcast

Play Episode Listen Later Aug 3, 2026 36:07


Today's farms rely on technology more than ever. From grain dryers and irrigation pivots to livestock systems, security cameras, accounting software, and smartphones, nearly every part of a modern farming operation is connected. That also makes agriculture one of the fastest-growing targets for cybercriminals. Chris from Tech Support Farm returns to Farm4Profit to discuss how farms can better protect themselves from ransomware, phishing scams, compromised credit cards, malware, and attacks on connected equipment. The conversation covers real-world examples—including Tanner's own experience with fraudulent credit card charges—and explains how remote monitoring, endpoint detection, password management, secure business email, mobile device management, and network monitoring work together to reduce risk. The episode also explores: Business email security Password managers Public Wi-Fi risks Phishing scams Credit card fraud Remote monitoring Endpoint detection (EDR) Mobile device management Irrigation and grain dryer security Data backups Disaster recovery Cyber insurance Farm technology infrastructure AI and digital threats Whether you operate a family farm or a multi-location business, this episode offers practical advice that could save your operation from significant financial loss and downtime. Want Farm4Profit Merch? Custom order your favorite items today!https://farmfocused.com/farm-4profit/ Don't forget to like the podcast on all platforms and leave a review where ever you listen! Website: www.Farm4Profit.comShareable episode link: https://intro-to-farm4profit.simplecast.comEmail address: Farm4profitllc@gmail.comCall/Text: 515.207.9640Subscribe to YouTube: https://www.youtube.com/channel/UCSR8c1BrCjNDDI_Acku5XqwFollow us on TikTok: https://www.tiktok.com/@farm4profitllc Connect with us on Facebook: https://www.facebook.com/Farm4ProfitLLC/Farm4Profit Media is not a financial, legal, or tax advisor. Content is provided for informational purposes only, and we serve solely as a platform for third-party opinions. Any actions taken based on this content are at your own risk. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
The driver's seat to ransomware. [Research Saturday]

The CyberWire

Play Episode Listen Later Aug 1, 2026 23:52


This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs

Security Now (MP3)
SN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

Security Now (MP3)

Play Episode Listen Later Jul 22, 2026 167:29


Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update. Lots of interesting listener feedback. And new ways AI is being used by bad guys Show Notes - https://www.grc.com/sn/SN-1088-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT zscaler.com/security adaptivesecurity.com joindeleteme.com/twit-biz arcticwolf.com/trends

The CyberWire
Behind the friendly face.

The CyberWire

Play Episode Listen Later Jul 20, 2026 29:19


Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple's App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop discussing election integrity and the Trump administration's waning influence. You can read more here.  Selected Reading AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign (Security Affairs) Ernst & Young Data Breach Affects Personal, Financial Information (SecurityWeek) Critical ServiceNow code execution flaw now exploited in attacks (Bleeping Computer) How ransomware tactics against law firms are changing (Wisconsin Law Journal) Capital One Open Sources AI-Powered ‘VulnHunter' Security Tool (SecurityWeek) AI spam filters are getting suckered by old-school text salting (The Register) Investigation reveals dozens of disguised gambling apps on the App Store in Brazil (9to5Mac) FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (Hackread) Israeli identity management startup Oak emerges from stealth with $60 million in seed funding. (N2K Pro Business Briefing) AI-altered images on birdwatching forums putting research at risk | AI (artificial intelligence) (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices