POPULARITY
Categories
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.This show is sponsored by Sentry.IO. Sentry wants to help you monitor your environment for problems. They do error tracking, stack tracing, debugging, all so that your developers can diagnose, fix, and optimize the performance of their code. This makes it so developers ship more reliable code faster. Learn more at sentry.io.View all active sponsors.SourcesFull list of sources on the show page: https://darknetdiaries.com/episode/177/
ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/ This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Most security breakthroughs don't come from new technology, they come from finally getting the basics right. As AI accelerates both attacks and the pace of vulnerability disclosure, the organizations that fare best aren't the ones chasing the next big thing, but the ones with the visibility, governance, and segmentation to absorb the shock. In this episode, Raghu Nandakumara sits down with Jason Garbis, founder and CEO of Number Line Security and co-chair of the Zero Trust Working Group at the Cloud Security Alliance, to explore what Zero Trust looks like when threats evolve at machine speed. Jason draws on his path from early software-defined perimeter work to leading Zero Trust strategy at the Cloud Security Alliance, sharing why "right-sizing" a Zero Trust initiative matters more than chasing sweeping transformation, and why even a well-built security capability fails without genuine buy-in from the business. The conversation then turns to AI's effect on the threat landscape: the surge of vulnerabilities and patches enterprises now have to absorb, the widening gap between attacker speed and defender response, and why segmentation remains one of the most effective ways to shrink the blast radius of an attack. Raghu and Jason discuss: How to right-size a Zero Trust initiative for an organization's actual readiness Why "build it and they will come" doesn't work for security adoption Tying Zero Trust investments to business priorities like AI adoption, M&A, and compliance What's genuinely new — and what isn't — about securing AI systems and agents How accelerating vulnerability disclosures are reshaping patch management Why segmentation reduces blast radius even when patching can't keep pace A simple analogy for explaining zero trust to non-security stakeholders Jason closes with his go-to way of explaining Zero Trust to non-technical stakeholders: an analogy involving brakes, oil, and seat belts that reframes security as a shared responsibility rather than a roadblock. Resources Mentioned: Zero Trust Security and Enterprise Guide Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com
Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran "Context Bombing" flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Identity is central to Zero Trust, making it one of the most attractive targets for cyber attackers. While multi-factor authentication has long been a reliable way to ensure identity, traditional MFA has critical gaps. This week on Feds At the Edge, Mark Brennan from the New Jersey Department of Health, and YubiKey's Jeff Frederick, explore how phishing-resistant cryptography and hardware security keys provide stronger protection against modern identity-based threats while improving the user experience. The panel also examines why hardware-backed authentication is recognized in NIST SP 800-63 Revision 4 as a highly secure approach to cryptographic MFA and shares practical guidance for implementation, including starting with a phased rollout, engaging executive leadership early, and continuously refining the program to build user confidence and support long-term Zero Trust success. Tune in on your favorite podcast platform to discover how hardware-backed authentication can help agencies reduce identity-based attacks, strengthen security, and simplify the path to phishing-resistant MFA
Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Managing modern IT infrastructure isn't just about servers and networks anymore; it's about identity.In Part 2 of this five-part series, Paul sits down with Joe Ross, Joe Galvan, Terry Murray, John Parker, and Stephen Sepulveda. Joe Ross takes listeners inside the complexity of supporting more than 400 business units across 180 domains, three cloud platforms, and five Microsoft tenants. As organizations embrace hybrid and multi-cloud environments, identity has become the new security perimeter, and one compromised account can have enterprise-wide consequences.Joe shares why identity management has become one of the toughest challenges facing IT leaders today, discusses lessons learned from high-profile outages like the CrowdStrike incident, and explains why resilience is about more than just recovering systems; it's about maintaining trust, access, and business continuity.Whether you're leading IT operations, cybersecurity, or digital transformation, this episode offers practical insights into navigating today's increasingly complex technology landscape.In this episode, you'll learn:Why identity is the foundation of modern cybersecurityThe challenges of managing large-scale hybrid and multi-cloud environmentsLessons learned from major industry outages and disruptionsHow complexity creates risk—and what IT leaders can do about itStrategies for building a more resilient enterprise
Zero Trust has transitioned from buzzword to basic necessity. As AI has transformed the cybersecurity landscape, becoming a tool for both attack and defence, organisations are being forced to rethink how thy protect themselves, their users, and their networks. Technology Now welcomes back friend of the show Jaye Tillson, CTO Security and HPE Distinguished Technologist to discuss:• The impact of AI on cyber threats as well as cybersecurity• How Zero Trust can contain breeches if they cannot be prevented entirely• Why limited access is more important than ever in a distributed network
In 2026, the biggest identity challenge won't be people - it will be AI agents, machines, and non-human identities. The security landscape is shifting rapidly as automated bots, API tokens, and service accounts become primary attack vectors for modern adversaries. In this forward-looking masterclass episode, InfosecTrain breaks down the expanding risks associated with unmanaged programmatic assets and analyzes why traditional, human-centric security models fail to protect them. The "course titled" SailPoint IdentityIQ Training Program offers an essential foundational framework for security architects racing to close these visibility gaps. We move beyond manual access review spreadsheets to explore automated lifecycle management engineered for the machine-to-machine era. Discover how to deploy intelligent security architectures to defend complex automated pipelines, establish clear human ownership over autonomous agents, and transition your business into a resilient Zero Trust posture.
One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn't right about this letter. It seemed to violate the constitution. So he set out to change the law.Learn more about Nicks work at calyxinstitute.org and phreeli.com.Check out Cindy's book Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance (https://amzn.to/4gXuK2J).SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.View all active sponsors.Sources https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/ https://clearinghouse.net/case/12966/ https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill https://www.aclu.org/documents/national-security-letters https://www.eff.org/cases/re-matter-2011-national-security-letter Cindy's Book: Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.
This episode features Tim Wolf, Senior Solutions Architect at Semperis, and Tim Springston, Principal Product Manager for Recovery Solutions at Semperis.Tim Wolf spent years as a Microsoft Premier Field Engineer helping enterprise customers architect identity solutions at scale. Tim Springston brings 25 years in identity and security and served as Microsoft's product manager for Azure AD recoverability, including direct involvement in building the Entra ID shared responsibility model documentation.In this episode, they walk through what the shared responsibility model actually means for Entra tenant data, how token-based attacks sidestep phishing-resistant authentication, and what happens when a threat actor hard-deletes objects and locks you out.They examine where Microsoft's new Entra ID Identity Resilience Recovery feature stops short, and why planning your recovery before anything goes wrong is the only call to action that matters.Guest BiosTim Wolf Tim Wolf is a Senior Solution Architect at Semperis. Tim's mission is protecting identities. Currently at Semperis, Tim ensures the resilience of Active Directory and Entra ID. Their background includes years as a Microsoft PFE, implementing Zero Trust and modern Authentication like Fido at an enterprise scale. Tim is an active speaker at multiple conferences, advocating for secure and automated identity architectures.Tim Springston Tim Springston is Principal Product Manager for recovery solutions at Semperis. He has over 25 years' identity and security experience with education, government, and Fortune 500 organizations from around the world. In his 25 years at Microsoft, he led services and support for Active Directory and later for Microsoft's cloud identity platform as it evolved from Windows Azure AD to Azure AD. At Microsoft, he was a recurring speaker at internal TechReady conferences and external events. Prior to Semperis, Tim was Microsoft's product manager for Azure AD (now Entra ID) recoverability and Sophos' IAM product manager for the Sophos Central cybersecurity platform.Guest Quotes “The first step in resiliency is not just having a backup plan or a backup tool or capabilities to put things back. You need to know what's important to your organization. If you know what's important, you know what to put back, you know when it's broken.” - Tim Springston “If Entra ID is going down... This is business critical today. You're not available to sign in to Teams, to SharePoint, to Salesforce, to your business critical application. So to really understand Entra ID is business critical.” - Tim WolfTime stamps 0:40 Meet Tim Wolf and Tim Springston 2:32 The Microsoft Shared Responsibility Model for Entra ID 6:22 How Entra ID Tenants Are Being Attacked 8:45 Token-Based Attacks Explained 12:26 What Happens When a Threat Actor Takes Over Your Tenant 19:05 Microsoft's New Entra ID Recovery Solution 25:24 The Difference Between Accidents and Adversaries 28:54 Semperis' Disaster Recovery for Entra Tenant 39:27 Hard Delete and Tenant Cloning Limits 45:30 Resiliency Playbooks and Testing 49:58 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Tim Wolf on LinkedInConnect with Tim Springston on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis
Healthcare organizations face growing pressure to modernize clinical systems while defending against increasingly sophisticated cyber threats. In this episode, host Kim Coombes is joined by Connection Security Center of Excellence experts John Chirrillo and Rob Di Girolamo to discuss Ripple Security Logic, a framework for understanding and managing risk across today's highly connected healthcare environments. The conversation explores the interconnected relationships between endpoints, medical devices, networks, cloud platforms, identities, and clinical workflows. Hear from our experts as they discuss how XDR-powered observability, Zero Trust principles, AI-driven analytics, and resilience-focused strategies can help healthcare organizations reduce risk, strengthen threat detection, and support better patient outcomes. Moderator: Kimberlee Coombes, Security Solution Architect, Connection Guest: John Chirillo, Principal Security Architect, Connection Guest: Rob Di Girolamo, Senior Security Architect, Connection Show Notes (0:00) - Welcome and episode overview: Healthcare cybersecurity and Ripple Security (1:02) - How Ripple Security changes organizational thinking about cybersecurity (2:00) - Interconnected ecosystem of healthcare data and devices (2:57) - Visualizing ripple effects on patient care and organizational risks (3:27) - The number of connected devices per hospital bed (4:26) - Growth of attack surface with connected medical devices (5:24) - Importance of endpoint security and XDR's role in healthcare (6:22) - How XDR correlates telemetry for threat detection (7:20) - The critical role of observability versus simple data collection (8:45) - Distinguishing noise from signals using context-aware observability (10:10) - Significance of XDR in managing healthcare's vast device ecosystem (11:37) - Visibility challenges in healthcare networks and XDR's benefits (13:01) - Faster detection and response through integrated telemetry (14:50) - The importance of east-west traffic monitoring and network segmentation (17:37) - Redefining perimeter security in a remote and cloud-enabled world (20:03) - Combating alert fatigue with AI-driven analytics (21:55) - Security considerations for cloud adoption in healthcare (25:08) - Impact of breaches and costs on healthcare organizations (26:04) - Building resilience as a core component of cybersecurity strategy (28:24) - Aligning security with business resilience and clinical continuity (29:21) - Final thoughts: Trust, resilience, and proactive cybersecurity planning
In this episode of Dr Zero Trust, we dive into how 909 Cyber is revolutionizing the remote interview process to eliminate fraud and save time. Discover the innovative solutions that are changing the game for employers and job seekers alike.Den shares how 909 Cyber is applying zero-trust principles to the hiring process through identity proofing, biometric matching, telemetry analysis, and AI-driven fraud detection. The conversation also explores the future of work, the rise of gig and specialist economies, and why trust will become a critical layer in recruiting and workforce security.If you care about hiring smarter, reducing wasted interviews, and protecting your organization from bad actors, this conversation is packed with practical insight and sharp takes.Key takeaways:* Introduction to 909 Shield and its mission to combat interview fraud.* The importance of identity proofing and biometric matching in hiring.* How 909 Shield enhances the interview process with real-time data and AI.* The impact of remote work on hiring practices and the gig economy.* Insights on the future of work and the rise of specialist roles.Timestamps:00:00 Introduction02:12 Meet Den Jones, CEO of 909 Cyber03:35 The problem of interview fraud06:22 How 909 Shield works08:46 The role of AI in hiring10:23 Addressing deep fakes in interviews12:20 The importance of trust in hiring15:01 The gig economy and its futureWhat's your biggest challenge with remote hiring? Drop it in the comments!Subscribe for weekly insights on cybersecurity and hiring trends!#ZeroTrust #Cybersecurity #RemoteHiring
Ransomware has become a far more serious threat to government than many organizations realize, and it's no longer just about paying a ransom. This week on Feds At the Edge, cybersecurity experts explore what agencies can do to strengthen their defenses, including adopting Zero Trust principles, improving network segmentation, and planning for recovery before an attack occurs. Cesar Gamez from City of Roseville, CA explains how ransomware attacks have evolved, from encrypting files for financial gain to tactics that threaten to expose sensitive data or target victims' customers if demands aren't met. And Travis Rosiek of Rubrik Public Sector, introduces an even more alarming trend: "wiper" attacks. Unlike traditional ransomware, these attacks - often associated with nation-state actors - are designed to permanently destroy or corrupt data, leaving organizations with nothing to recover even if they were willing to pay. Tune in on your favorite podcast platform as our guests also examine the security challenges of hybrid and cloud environments and explain why collaboration and information sharing are essential to staying ahead of increasingly sophisticated cyber threats.
Apply Zero Trust controls to every AI agent in your environment across identity, tool usage, and data access. Extend Conditional Access in Microsoft Entra to evaluate every agent authorization request in real time against the same risk signals as human users. Assign each agent its own managed identity with Entra Agent ID and scope permissions with Access Packages. Govern your MCP catalog as a software supply chain — unapproved tools don't run, and approved servers lock behind Azure API Management. Log every agent tool call, API access, and data lookup into Microsoft Sentinel for continuous anomaly detection. Purview Insider Risk Management auto-assigns risk levels so you can investigate fast or revoke access entirely. DLP and sensitivity labels in Microsoft Purview restrict what agents can reach and auto-inherit to everything they generate, and Data Access Governance maps exactly what each agent can access before a prompt fires. Jeremy Chapman, Microsoft 365 Director, shares how to put these controls into practice across every managed, self-hosted, and shadow agent in your estate. ► QUICK LINKS: 00:00 - How AI changes Zero Trust 01:20 - Zero Trust principles 02:27 - How to apply Zero Trust principles 03:40 - Conditional Access for Agent Identities 04:59 - Entra Agent ID + Access Packages 06:07 - Runtime Observability 06:58 - DLP, Sensitivity Labels + Data Access Governance 07:47 - MCP catalog 08:36 - AI apps & experiences 09:24 - Wrap up ► Link References Watch the rest of this series at https://aka.ms/ZTMechanics For additional resources, check out https://aka.ms/GoZeroTrust ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
In this episode of the Federal Tech Podcast, John Gilroy interviews Justin Fessler, Vice President of Public Sector at LogicMonitor, about the growing role of autonomous AI and observability in federal government IT operations. Fessler explains that autonomous AI is not about replacing people but about automating repetitive operational tasks, correlating complex system events, and helping IT teams make faster, better-informed decisions. Rather than allowing AI to operate without oversight, LogicMonitor focuses on keeping humans "in the loop" while AI handles time-consuming analysis and routine remediation. A central theme is the importance of complete visibility across increasingly complex federal environments. LogicMonitor's agentless monitoring technology discovers devices, cloud resources, applications, and shadow IT without requiring software agents on every endpoint. This broad visibility enables agencies to identify unmanaged assets, reduce blind spots, optimize cloud costs, and strengthen security. The discussion also highlights observability's critical role in Zero Trust. Fessler notes that agencies cannot secure or verify assets they cannot see. By discovering everything connected to the network—including servers, cloud services, IoT devices, cameras, badge readers, and physical infrastructure—LogicMonitor helps agencies build a stronger Zero Trust foundation. Gilroy and Fessler examine the challenges of managing hybrid and multi-cloud environments, emphasizing that agencies require a single operational view regardless of where workloads reside. LogicMonitor integrates information across cloud providers and third-party platforms, including ServiceNow, Splunk, Dynatrace, Datadog, and IBM Watsonx, enabling AI-driven event correlation and faster incident response. The conversation concludes with the future of autonomous IT. Fessler predicts increased automation, AI-assisted self-healing infrastructure, and significantly reduced mean time to identify and resolve incidents. Rather than replacing IT professionals, autonomous AI will eliminate repetitive work, allowing skilled personnel to focus on higher-value mission objectives while improving operational resilience, reducing alert fatigue, and delivering better digital services to citizens. For more information, visit www.logicmonitor.com/solutions/federal-government.
Podcast: Exploited: The Cyber Truth Episode: From Compliance to Resilience: Securing Digital Mission Systems at Military ScalePub date: 2026-06-25Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationIn this episode of Exploited: The Cyber Truth, host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Lt. Gen. (Ret.) Bill Bender, former Chief Information Officer of the U.S. Air Force, to discuss what it takes to build true cyber resilience across some of the world's most complex digital environments. Drawing on his experience overseeing a $17 billion IT portfolio and helping establish the first Chief Information Security Officer (CISO) and Chief Data Officer (CDO) offices within the Department of Defense, Bender explains why organizations must move beyond checklist-driven security and adopt a mission-focused approach to risk management. Together, they explore: Why compliance alone cannot secure mission-critical systemsBuilding cybersecurity leadership, accountability, and culture at scaleManaging technical debt and long-lived systems that cannot easily be replacedThe role of Zero Trust in protecting complex defense environmentsHow software supply chains and SBOMs support mission assuranceWhy public-private collaboration is essential for modernization and innovationThe growing impact of AI on cyber defense and critical infrastructure security From defense acquisition to critical infrastructure protection, this episode examines how organizations can strengthen resilience.The podcast and artwork embedded on this page are from RunSafe Security, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
#TodayinTech Are cybersecurity teams already falling behind in the age of AI? In this episode of Today in Tech, host Keith Shaw chats with Evan Pena, founder and Chief Offensive Security Officer at Armadin, to explore how AI is transforming cyberattacks, cybersecurity defense, and the future of cyber warfare. Evan explains why AI-powered attackers can now find vulnerabilities faster, scale attacks across thousands of systems, and dramatically lower the cost of launching sophisticated cyber campaigns. The conversation also explores Zero Trust security, AI agents, identity management, autonomous cyber defense, ransomware trends, nation-state threats, critical infrastructure attacks, and the rise of AI-driven security operations. Topics include: * Why AI is giving cybercriminals a massive advantage * The rise of autonomous AI-powered attacks * Are Zero Trust security strategies already falling behind? * How defenders can use AI to fight back * What the next three years of cyber warfare could look like Is AI giving hackers an unbeatable advantage, or can defenders use the same technology to fight back?
This week's Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Police clean ups SocGholish-infected sites tied to Evil Corp Klue OAuth breach linked to Icarus Salesforce data theft attacks Warner warns of CISA cuts, staffing gaps in letter to acting chief Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
By Doug Green “Governance is absolutely necessary. It's no longer optional.” In this episode of the Technology Reseller News podcast, Doug Green speaks with Rajesh Kari, Senior Director of Products and Solutions at Versa Networks, about the emerging security challenges created as agentic AI moves into live network and security operations. Kari says Versa Networks is a leader in SASE, offering a unified platform that brings together networking, security and operations across enterprise infrastructure. As AI becomes more embedded in operations, Versa is focused on a new zero trust challenge: controlling not only users and devices, but also the hidden AI-driven sub-actions that can touch production systems. Kari explains that agentic AI is different from traditional AI because it can take action on behalf of users. Rather than simply answering a prompt or returning information, an agent may break a task into sub-queries, call APIs, use credentials, access systems and make changes inside the infrastructure. Those hidden sub-queries can create risk if organizations cannot see, validate and govern what the agent is doing. “People build agents. They know what the objective of the agents are,” Kari says. “But under the hood, what the agent actually deploys, which APIs it accesses, and what kinds of authorization and authentication it leverages can be unknown.” The podcast explores how this creates new exposure for enterprises, MSPs and channel partners. If an AI agent gains access to credentials or production systems, organizations need constant verification, validation and governance around each action. Kari says agentic AI can also hallucinate or generate unnecessary sub-queries, creating additional security and operational risk. Versa is addressing this through Versa Verbo and its Zero Trust MCP architecture. Verbo is designed to help network practitioners gain visibility, management and analytics through natural language interactions. Instead of searching through hundreds of alerts or dashboards, operators can ask questions about outages, performance issues, configuration changes, security incidents and branch health. The Zero Trust MCP architecture extends that capability by applying governance and access control to AI-driven actions. Kari says this enables AI models and agents to query Versa infrastructure securely, while maintaining controls around authentication, authorization, APIs and operational workflows. For MSPs and channel partners, Kari sees an important opportunity. Many organizations want to deploy AI quickly but do not have the internal capability to build governance infrastructure around it. Partners that develop practices around policy architecture, deployment, ongoing governance and human-in-the-loop approval can help customers adopt agentic AI more safely. Kari says AI operations copilots are becoming standard in SASE and network platforms. Network teams, infrastructure managers and executives increasingly want to use natural language to understand the health of their infrastructure instead of relying only on dashboards. But as those tools become more powerful, governance becomes the deciding factor in adoption. “If the agent has gained access into certain files or visuals which has violated any particular compliance standards, it becomes the responsibility of the organization to prove it,” Kari says. For Versa, the message is clear: agentic AI can simplify operations and accelerate decision-making, but it must be governed from the beginning. Zero trust principles need to be built into every AI agent connection. Learn more at www.versa-networks.com
Anthropic tells G7 to cooperate Fortinet VPN leak exposes credentials Crypto Clipper abuses reviews, narrators, and comments Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-tells-g7-to-cooperate-fortinet-vpn-leak-exposes-credentials-crypto-clipper-abuses-reviews/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Athena coalition looks to secure open source Estonia to quarantine Russian email domains Malicious package wave hits Arch Linux Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
For years, cybersecurity leaders have focused on identity as the new perimeter. MFA, Zero Trust, SSO, and identity protection became the center of modern security strategies.But while everyone was focused on identity, attackers never stopped targeting something much older: internet-facing infrastructure.VPNs. Firewalls. Remote access appliances.Recent attacks involving Check Point, Fortinet, Ivanti, SonicWall, and others show that the perimeter never really disappeared.In this episode, Tyler Moffitt discusses why edge devices remain prime ransomware targets, why patch windows matter more than ever, and why vulnerability management remains one of cybersecurity's most important fundamentals.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com
Cyber leaders defend Anthropic's banned models FBI disrupts massive phishing service 1Password acquires Apono Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Feds require Anthropic to ban 'foreign national' access to Fable, Mythos Maine disables data breach notification portal after fake disclosures ShinyHunters extorts universities through exploiting an unpatched Oracle flaw Get the show notes here: Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
As AI agents become more capable and autonomous, they also introduce new security challenges. In this 'Fully Connected' episode, Dan and Chris unpack Anthropic's Zero Trust for AI Agents security framework and what it means for organizations deploying agentic systems. They examine the key security risks facing agentic systems and discuss how organizations can apply Zero Trust principles to deploy AI agents safely. Along the way, they break down practical security controls and discuss how traditional cybersecurity principles must evolve for the age of AI agents.Featuring:Chris Benson – Website, LinkedIn, Bluesky, GitHub, XDaniel Whitenack – Website, GitHub, XLinks: Zero Trust for AI AgentsOWASP GenAI Project Sponsors:Prediction Guard: A self-hosted AI control plane for running agents in high impact environments. predictionguard.com/practicalaiUpcoming Events: Register for upcoming webinars here!Midwest AI Summit 2026
In Episode 106 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Holger Hügel, Chief Technology Officer of SecurityBridge and a global authority on SAP cybersecurity with over 26 years of experience — to address a governance blind spot that exists inside the security perimeters of even the most mature enterprise organizations: the SAP environment.Opening with the August 2024 ransomware attack on Stoli Group USA — where attackers went straight for the company's SAP enterprise resource planning (ERP) system, disrupting financial operations and contributing directly to a bankruptcy filing within three months — Dr. Chatterjee frames the episode's central challenge: organizations can have zero trust architecture, network segmentation, and identity governance fully deployed across their IT landscape, and still be critically exposed, because most CISOs have never formally claimed accountability for SAP security, and most SAP teams do not think of themselves as part of the security function.Hügel explains the structural gap at the heart of this problem. SAP systems are simultaneously the most business-critical and the least security-governed assets in most large organizations. The C-suite depends on them for financial operations, payroll, procurement, and supply chain continuity, yet SAP teams and security teams speak different languages, operate under different budgets, and rarely collaborate. SAP departments typically define "security" as managing user authorizations and privileges — a narrow interpretation that leaves configuration drift, patch backlogs, and monitoring gaps entirely unaddressed.Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) framework, the conversation translates SAP cybersecurity from a technical niche into a governance imperative. The Medtronic case study demonstrates what good looks like: a CISO who crossed the organizational divide, sponsored SAP hardening from the cybersecurity budget, built a continuous patch management process, and created the governance structure that allowed the team to respond to an out-of-band vulnerability within hours rather than weeks.The episode's central message is neither technical nor abstract: the organizations that will survive the next ERP-targeted ransomware attack are not those with the most sophisticated tools — they are the ones that have claimed ownership of the problem, built the processes to address it continuously, and created the cross-functional governance structures that SAP and cybersecurity teams cannot build on their own.To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-106-the-invisible-attack-surface-zero-trust-for-sap-and-erp-environments/Connect with Host Dr. Dave ChatterjeeLinkedIn: https://www.linkedin.com/in/dchatte/ Website: https://dchatte.com/Books PublishedThe DeepFake ConspiracyCybersecurity Readiness: A Holistic and High-Performance ApproachArticles & Cases PublishedChatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024. Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, SwitzerlandChatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.
An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit
An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit
An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit
Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-462
An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit
Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-462
Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-462
An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit
If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »
If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »
If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »
Could a single weak password put your TRS benefit and other accounts at risk? Bad actors and cybercriminals target individuals every day.In this episode of Your Retirement in Focus, host Everett Crockett speaks with Tom McMurry, TRS Chief Information Officer, to break down the real-world risks of scams and how they can impact your identity, credit, and your Teachers Retirement System benefit. Learn about the Zero Trust model and what you can do to protect your money. From creating strong, unique passwords to enabling multi-factor authentication (MFA) and using password managers, this episode delivers the steps to enhance your digital safety.Tom will discuss:Data breaches and the increasing threat of online scams How fraudsters use texts, emails, and spoofed calls to steal informationWhat MFA is and how to use a password managerWhy credit freezes and account alerts are critical for fraud preventionHow to recognize AI scams and deepfakesJoin the conversation to protect your TRS benefit, avoid scams, and strengthen your financial digital security.If you haven't had the chance to meet with us one-on-one in a virtual or in-person format, and are within 2 years of retirement eligibility, be sure to log in to your TRS account online and register for a session today! Are you new to TRS or in the middle of your career? Be sure to designate your beneficiaries as soon as possible in your TRS online account. We want to hear from our members! Please email the show for topic inquiries, questions, and comments! Contact us at podcast@trsga.com. Host: Everett Crockett Guest: Tom McMurry, TRS Chief Information OfficerFor more information visit: www.trsga.com Facebook: https://www.facebook.com/trsgeorgia YouTube: https://www.youtube.com/@trsgeorgia Instagram: www.instagram.com/trsgeorgia#YourRetirementInFocus #FraudProtection #RetirementPodcast This podcast is for information purposes only and should not be considered financial, legal, or tax advice. The views and opinions expressed are those of the speakers and may not reflect the views of the Teachers Retirement System of Georgia.
It started with a fake car listing on eBay.What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea.This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This episode is sponsored by Chainguard. Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We're talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.
(10) Francis Rose explores the security risks of electronic health records, explaining how nation-states like China seek bulk data for espionage and how the government utilizes "zero trust" technology to deter sophisticated machine-speed hacks.1913 GETTYSBURG
Most enterprises have some kind of zero trust strategy, but a lot of them could be better described as good intentions rather than active programs being implemented. Making good on a zero trust strategy and achieving an actual zero trust architecture requires tools that embody the core precept of zero trust thinking: deny access by... Read more »
Most enterprises have some kind of zero trust strategy, but a lot of them could be better described as good intentions rather than active programs being implemented. Making good on a zero trust strategy and achieving an actual zero trust architecture requires tools that embody the core precept of zero trust thinking: deny access by... Read more »
For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls.Was it ethical? Was it effective? They disrupted nine zero-day attacks, exposed who was hacking them, and forced the hackers to change tactics. But at what cost?You have to listen to one of the most audacious corporate cyber defenses ever conducted.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.Support for this show comes from Drata. Drata is the trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses stay audit-ready and scale securely. Learn more at drata.com/darknetdiaries.Sources https://news.sophos.com/en-us/2024/10/31/pacific-rim-timeline/ https://www.justice.gov/archives/opa/pr/seven-hackers-associated-chinese-government-charged-computer-intrusions-targeting-perceived https://www.fbi.gov/wanted/cyber/guan-tianfeng