Podcasts about Zero day

  • 635PODCASTS
  • 1,209EPISODES
  • 35mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Mar 16, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Zero day

Show all podcasts related to zero day

Latest podcast episodes about Zero day

Little Known Facts with Ilana Levine
Episode 499 - Ryan Spahn

Little Known Facts with Ilana Levine

Play Episode Listen Later Mar 16, 2026 45:54


Ryan Spahn is a Drama Desk Award–winning actor and writer. Select Off-Broadway: Richard II (Red Bull), Danger and Opportunity (East Village Basement), The Antiquities (Playwrights Horizons), Jordans (The Public), Merry Me (NYTW), Good Enemy (Audible), Jane Anger (New Ohio), Summer & Smoke (CSC), Daniel's Husband (Westside), Moscow x6 (MCC), Exit Strategy (Primary Stages), Gloria (Vineyard). Select TV/Film: Sub/liminal, Zero Day, Elsbeth, AHS: Delicate, Succession, Modern Love, The Bite, Chicago P.D. Ryan co-wrote the feature film He's Way More Famous Than You and wrote the play Inspired By True Events (Concord Theatricals, Theatrely's “Best of 2024.”). Juilliard graduate and the first teenaged Borg on Star Trek: Voyager. Learn more about your ad choices. Visit podcastchoices.com/adchoices

Resilient Cyber
Before the Breach: The Zero Day Clock and the Race Against Exploitation

Resilient Cyber

Play Episode Listen Later Mar 11, 2026 5:17


Show DescriptionThe Zero Day Clock is ticking — and the numbers should make every security leader uncomfortable. In this episode, I sit down with Sergej Epp, CISO at a leading security firm, who built the Zero Day Clock after a weekend experiment using AI to discover vulnerabilities firsthand. What he found shocked him: with no professional vulnerability research background and just a few hours of work, he was successfully finding zero days across major security projects using AI models and basic scaffolding.Sergej breaks down his concept of the "Verifier's Law" — the idea that offense has the cheapest verifier in cybersecurity because feedback is binary and instant (you either popped a shell or you didn't), while defense operates in a space where validation is expensive, ambiguous, and slow. We dig into what this asymmetry means for the industry, why 20 years of warnings from Ross Anderson, Bruce Schneier, Halvar Flake, and others have gone unheeded, and whether coordinated disclosure models are broken now that AI can reverse engineer a patch into a working exploit in minutes.We also discuss the tension between regulation and deregulation playing out in the U.S. and EU, why the answer might be outcome-based accountability rather than prescriptive compliance, and what a realistic defensible posture actually looks like when the mean time to exploit for actively exploited vulnerabilities is under two days — while most organizations are still operating on 30-day patch cycles.Show NotesSergej shares how a weekend AI experiment led him to discover multiple zero days across major security projects with no professional vulnerability research experience — and why that should alarm the entire industryThe "Verifier's Law" explained: offense has cheap, deterministic validators (pop a shell, exfiltrate data, trigger an XSS) while defense faces expensive, ambiguous validation (parsing SIM alerts, measuring security posture), giving AI-accelerated offense a structural advantageThe Zero Day Clock synthesizes 3,500+ CVE-exploit pairs and shows the mean time to exploit for actively exploited vulnerabilities is now under two days — while organizations still operate on 14-to-30-day patch cycles20 years of ignored warnings: from Ross Anderson's 2001 economics paper through Bruce Schneier, Halvar Flake's "the patch is the advisory" insight, and DARPA's Cyber Grand Challenge — the industry has consistently failed to act on clear signalsAI can now reverse engineer patches to identify underlying flaws and generate working exploits in minutes, potentially breaking coordinated disclosure models and compressing the window between patch release and active exploitation to near zeroThe regulation paradox: the EU risks overregulating AI in ways that hamper defenders while attackers face no such constraints, while the U.S. is pushing deregulation that may remove the only forcing function for vendor accountability — Sergej and Chris discuss outcome-based regulation as a potential middle pathDefenders have a data advantage: by understanding their own environments, infrastructure, and processes, security teams can detect AI-driven attacks through behavioral anomalies like hallucinated API calls, non-existent user accounts, and other artifacts of AI-generated attack playbooksThe Zero Day Clock's real power is as a board-level communication tool — a single slide that translates the patching gap into a number executives and policymakers can't ignore, shifting the conversation from "are we compliant?" to "are we fast enough?"

Hill-Man Morning Show Audio
HR 1 - Happy Return to Zero Day! (Hopefully)

Hill-Man Morning Show Audio

Play Episode Listen Later Mar 6, 2026 40:57


The crew kicks off the show discussing the return of Jayson Tatum tonight against the Mavericks according to multiple sources. How will Joe Mazzulla reincorporate Tatum into the lineup? We also get to today's leads!

Decipher Security Podcast
The Zero Day Landscape, Tycoon 2FA Disruption, and KEVology

Decipher Security Podcast

Play Episode Listen Later Mar 6, 2026 19:14


Every day is zero day, and this week we talked about the new Google Threat Intelligence Group report on the zero day exploit landscape in 2025 (2:22) and who's exploiting what, then we discuss Microsoft's disruption of the Tycoon 2FA cybercrime operation (9:51), and finally we talk about the KEVology report from runZero and our new podcast with Tod Beardsley (13:25).

The Cybersecurity Defenders Podcast
North Korean malware interviews, FortiGate firewall compromised, Cisco zero-day & Citrini Research AI future / Intel Chat [#298]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Mar 3, 2026 42:30


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.GitLab's Threat Intelligence Team published detailed findings on North Korean activity associated with the Contagious Interview campaign and broader IT worker operations.A financially motivated, Russian-speaking threat actor used generative AI tools to compromise more than 600 Fortinet FortiGate firewall instances between January and February, according to Amazon Web Services.Cisco has released emergency patches for a critical zero-day vulnerability in its Catalyst SD-WAN products that has been actively exploited in the wild.Citrini Research presents a forward-looking scenario framed as a June 2028 macro memo describing a “Global Intelligence Crisis” triggered by abundant AI-driven intelligence.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Cyber Morning Call
960 - Google lança patch para zero-day no Android

Cyber Morning Call

Play Episode Listen Later Mar 3, 2026 5:51


Referências do EpisódioBoletim de segurança do Android – março de 2026Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilitiesTaming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini PanelFunnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain AttacksThreat Brief: March 2026 Escalation of Cyber Risk Related to IranChecklist rápido para não ser vítima colateral de uma guerra que não é suaRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

Security Conversations
War in Iran, Anthropic v Pentagon, Trenchant zero-day sanctions, AI stock market shocks

Security Conversations

Play Episode Listen Later Feb 28, 2026 128:22


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 87: We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran's cyber capabilities and proxy risks. Plus: Anthropic's clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, Trenchant exec sentencing and sanctions in the exploit trade, and fresh questions around Cisco's SD-WAN breach and supply-chain trust. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Sunday Sitdown with Willie Geist
NAACP IMAGE AWARD NOMINEES: Angela Bassett on Power, Purpose and ‘Zero Day' (March 2025)

Sunday Sitdown with Willie Geist

Play Episode Listen Later Feb 27, 2026 39:36


Angela Bassett is an Emmy and Golden Globe-winning actress who is nominated for Outstanding Actress in a Drama Series at this year's NAACP Image Awards. In this conversation from March 2025, Bassett sits down with Willie Geist to discuss playing the president of the United States opposite Robert De Niro in Netflix's Zero Day, her decades-long career, and what it means to portray leadership on screen. Plus, she reflects on honoring the legacy of the late Chadwick Boseman and her time in the Marvel Cinematic Universe. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Decipher Security Podcast
Cisco SD-WAN Zero Day, Google Disrupts Chinese Campaign, and More Cyber on The Pitt

Decipher Security Podcast

Play Episode Listen Later Feb 27, 2026 31:56


This week Lindsey rejoins Dennis to talk about the attacks targeting a zero day in Cisco's Catalyst SD-WAN Controller (2:17), Google's disruption of a China-linked cyber espionage campaign targeting telecom infrastructure (6:30), and the new cyber developments on everyone's favorite tech show, The Pitt (13:13)!

Greg & Dan Show Interviews
Protect Your Tech!

Greg & Dan Show Interviews

Play Episode Listen Later Feb 23, 2026 5:34


Greg and Dan talk to Dave Johnson from Pearl Technology about why you NEED to update any and every Apple product you own — including iPhones, iPads, Apple Watches, and more. He explains what a “Zero Day” vulnerability is, how hackers can exploit it, and why Apple’s recent fix makes updating your devices critical.See omnystudio.com/listener for privacy information.

David Bombal
#550: Firewall Demo of Red Team vs Blue Team: Hacking Finance Apps with AI Chatbots

David Bombal

Play Episode Listen Later Feb 22, 2026 28:38


In this video, we dive into a real-world Red Team vs. Blue Team scenario. We simulate a cyberattack on a Finance Application that has integrated a new LLM Chatbot. You'll see firsthand how attackers use Prompt Injection to bypass standard rules, how they move laterally through Kubernetes clusters, and how they attempt to execute Zero Day exploits. More importantly, we show you how to defend against it. Using Cisco's Hybrid Mesh Firewall, AI Defense, and Secure Workload, we demonstrate how to: 1. Detect & Block Prompt Injections: safeguarding your LLMs from manipulation. 2. Secure Kubernetes: using micro-segmentation to isolate threats in the cloud. 3. Inspect Encrypted Traffic: utilizing the Encrypted Visibility Engine (EVE) to spot malware in TLS flows without decryption. Whether you are a Network Engineer, Security Analyst, or just interested in how AI is changing the cybersecurity landscape, this demo is packed with practical insights Big thank you to Cisco for sponsoring my trip to Cisco Live Amsterdam. // Ant Ducker SOCIALS // LinkedIn: / ant-ducker-0052801 YouTube channel dCloud: / @ciscodcloud // Website REFERENCE // Cisco Security Cloud control: https://sign-on.security.cisco.com/ Cisco.com: https://www.cisco.com/site/us/en/solu... // YouTube Video REFERENCE // Rick Miles' video will be linked at a later stage once published. / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:29 - Intro 02:20 - Demo Overview 03:57 - Demo Begins 09:35 - Adding Guardrails 11:45 - Secure Workloads 14:30 - Segmentation Workflow 18:33 - Overviewing Finance App 21:02 - Encrypted Visibility Engine 24:34 - Firewall Obversability and Control 25:44 - Ant's Advice For The Youth 26:40 - How to Learn Hybrid Mesh Firewall 28:16 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #ciscolive #ciscoemea

Cyber Security Today
BeyondTrust Zero-Day Exploited,

Cyber Security Today

Play Episode Listen Later Feb 16, 2026 10:33


This episode covers multiple active threats and security changes. It warns of an actively exploited critical BeyondTrust remote access vulnerability (CVE-2026-1731, CVSS 9.9) enabling pre-authentication remote code execution in Remote Support and Privileged Remote Access, noting SaaS was patched while on-prem deployments require urgent manual updates and may already be compromised. Microsoft details an evolution of the ClickFix social engineering technique where victims are tricked into running NSLookup commands that use attacker-controlled DNS responses as a malware staging channel, leading to payload delivery (including a Python-based RAT) and persistence via startup shortcuts, alongside increased Lumma Stealer activity.  Cybersecurity Today  would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst Researchers also report Mac-focused campaigns abusing AI-generated content and malicious search ads to push copy-paste terminal commands that install an info stealer (MaxSync) targeting Keychain, browsers, and crypto wallets. T The show describes fake recruiter campaigns targeting developers with coding tests containing malicious dependencies on repositories like NPM and PyPI, linked to the "Gala" operation and nearly 200 packages. Finally, it reviews NPM's authentication overhaul after a supply-chain worm incident—revoking classic long-lived tokens, moving to short-lived session credentials, encouraging MFA and OIDC trusted publishing—while noting remaining risks such as MFA phishing, non-mandatory MFA for unpublish, and the continued ability to create long-lived tokens. 00:00 Sponsor: Meter + Today's Cybersecurity Headlines 00:48 Urgent Patch: BeyondTrust Remote Access RCE (CVE-2026-1731) Actively Exploited 02:45 ClickFix Evolves: DNS Lookups (nslookup) Used as Malware Staging 04:34 Mac Malware via AI Search Results: Fake Terminal Commands Deliver Info-Stealer 06:08 Fake Recruiters, Real Malware: Coding Tests Poison Dev Environments 07:19 NPM Security Overhaul After Supply-Chain Worm—What's Better, What Still Risks 09:11 Wrap-Up, Thanks, and Sponsor Message

The ERP Advisor
Leaders in ERP Podcast Episode 6 - Achieve a Zero-Day Financial Close with AI

The ERP Advisor

Play Episode Listen Later Feb 16, 2026 28:36


On this episode of our "Leaders in ERP Series", Shawn Windle speaks with Nicolas Kopp, CEO at Rillet. Windle and Kopp discuss the ramifications of AI on the ERP industry, how AI-native solutions are handling data security, and how other vendors will be forced to adapt in the new age of AI.Connect with us!https://www.erpadvisorsgroup.com866-499-8550LinkedIn:https://www.linkedin.com/company/erp-advisors-groupTwitter:https://twitter.com/erpadvisorsgrpFacebook:https://www.facebook.com/erpadvisorsInstagram:https://www.instagram.com/erpadvisorsgroupPinterest:https://www.pinterest.com/erpadvisorsgroupMedium:https://medium.com/@erpadvisorsgroup

Security Conversations
Palo Alto and the uncomfortable politics of APT attribution

Security Conversations

Play Episode Listen Later Feb 13, 2026 150:30


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 85: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft's zero-day treadmill and AI-enabled attack surfaces; and Apple's “extremely sophisticated” iOS exploits. Plus, Europe's growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Tech and Science Daily | Evening Standard
Smart clothing “button” breakthrough in London, UK clampdown on broadband bill hikes, Silent Hills Transmission and Microsoft rushes zero-day fixes

Tech and Science Daily | Evening Standard

Play Episode Listen Later Feb 13, 2026 7:22


King's College London says loose fabric can track movement better than skin-tight sensors, meaning your next health tracker might be… a shirt button. Then we've got the UK pushing telecoms giants to bin surprise mid-contract price hikes (about time), plus Microsoft scrambling to patch Windows and Office bugs that hackers are already exploiting. After that: China tests new Moon-mission hardware, and Silent Hill fans get a late-night update. More on all of it at standard.co.uk — and hit follow so you don't miss the next one! Hosted on Acast. See acast.com/privacy for more information.

Cyber Morning Call
951 - Apple corrige seu primeiro zero-day sob exploração do ano

Cyber Morning Call

Play Episode Listen Later Feb 13, 2026 7:37


Referências do EpisódioAbout the security content of iOS 26.3 and iPadOS 26.3OysterLoader Unmasked: The Multi-Stage Evasion LoaderGTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial UseAttackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams LuresDataflow Rider: How Attackers can Abuse Shadow Resources in Google Cloud DataflowRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia

The Options Insider Radio Network
The European Market Brief 18: DAX, 0DTEs and German Cars That Turn Heads

The Options Insider Radio Network

Play Episode Listen Later Feb 11, 2026 66:07


Is the "Zero Day" infection spreading across the pond? In this episode, we dive deep into the heart of the Eurozone to see how record levels in the DAX and the explosion of 0DTE options are reshaping the landscape for retail and institutional traders alike. Host Mark Longo is joined by a powerhouse panel to break down the macroeconomic shifts, sector rotations, and the structural innovations making European derivatives more accessible than ever. In This Episode: The 0DTE Contagion: Lex Luthringshausen (Tradier) explains why European traders are beaming into US markets to sling intraday iron condors and how that behavior is translating to cash-settled European indices. DAX to the Max: Eugen Mohr (Eurex) breaks down the "Conservative Shift" in German politics under the new Chancellor and how government spending in the defense and industrial sectors is driving the DAX 40 to record heights. The Economic Cycle: Dr. VSTOXX himself, Russell Rhoads, analyzes why the DAX might offer more "juice" than the S&P 500 in 2026 and why the "Potholes" in the US economy might make European exposure a smoother ride. German Engineering vs. Italian Style: A heated debate on the automotive sector—from BMW and Mercedes to the "Poster Car" aesthetics of Italian design. Micro-Sizing the Market: Why notional size matters and how the Micro-DAX (at just 1 Euro per point) is becoming the ultimate tool for retail risk management. The Red Phone: The panel tackles listener questions on Eurex 0DTE liquidity, "Weekend Risk" trades using V-Stocks, and Tradier's unique "All You Can Trade" subscription model. The Panel: Mark Longo: Founder, The Options Insider Media Group Dr. Russell Rhoads: Clinical Professor at the Kelley School of Business, Indiana University Eugen Mohr: Product & Business Development Specialist at Eurex Lex Luthringshausen: SVP of Business Development at Tradier Resources Mentioned: The Leap Trading Competition: Join over 50,000 traders in the Eurex/TradingView paper trading challenge. Visit eurex.com/competition . Learn More About Eurex: eurex.com

The Inquiry
Why are our taps running dry?

The Inquiry

Play Episode Listen Later Feb 10, 2026 23:37


Chennai, São Paulo, Mexico City, Tehran, Cape Town - these cities have all faced the threat of a ‘Zero Day', or, having no fresh water left in their taps. The UN says we're entering a ‘water bankruptcy' era, meaning our water ‘current accounts' are running empty, while our ‘savings accounts' - the long term stores of water deep underground - have been depleted, with some beyond repair. So how did we get here?From clearing forests for cattle grazing, to thirsty AI data centres, Rajan Datar examines the pressures on our global water supply and looks for solutions.Contributors: Jayshree Vencatesan, Co-founder, Care Earth Trust, India Augusto Getirana, research scientist at NASA's Hydrological Sciences Laboratory, USA Prof Bridget Scanlon, Bureau of Economic Geology, University of Texas, USA Dr Jie-Sheng Tan Soo, Director, Institute for Environment and Sustainability, National University of SingaporePresenter: Rajan Datar Producer: Phoebe Keane Researcher: Evie Yabsley Editor: Richard Fenton-Smith Technical Producer: Cameron Ward Production Management Assistant: Liam Morrey(Photo: Indian women with empty plastic pots protest as they demand drinking water. Credit: Arun Sankar/Getty Images)

Cyber Security Headlines
OpenClaw targets ClawHub users, Notepad++ update delivers malware, APT28 attackers abuse Microsoft Office zero-day

Cyber Security Headlines

Play Episode Listen Later Feb 3, 2026 7:25


OpenClaw targets ClawHub users Notepad++ update delivers malware APT28 attackers abuse Microsoft Office zero-day Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-targets-clawhub-users-notepad-update-delivers-malware-apt28-attackers-abuse-microsoft-office-zero-day/ Huge thanks to our sponsor, Strike48 It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.  

Exploit Brokers - Hacking News
CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats | EP 60

Exploit Brokers - Hacking News

Play Episode Listen Later Jan 29, 2026 24:52


Microsoft just dropped an emergency patch for an Office zero-day being exploited in the wild. A WordPress plugin has a CVSS 10.0 vulnerability — that's the golden goose of hacking. 900,000 Chrome users had their ChatGPT conversations stolen by malicious extensions with Google's Featured badge. And two cybersecurity professionals pleaded guilty to moonlighting as ransomware affiliates. Welcome to 2026. It's gonna be a fun year. In this episode: CVE-2026-21509: Microsoft Office zero-day (security feature bypass) CVE-2026-23550: WordPress Modular DS critical vulnerability Prompt Poaching: Chrome extensions stealing AI conversations Brightspeed breach: Crimson Collective claims 1M+ records Insider threat: Security pros turned BlackCat/ALPHV affiliates Key takeaway: Update your stuff. A patch does you no good if it isn't installed. Subscribe for weekly cybersecurity news, vulnerability breakdowns, and threat intelligence.   https://forgeboundresearch.com/podcasts/

Cyber Security Headlines
Microsoft patches Office zero-day vulnerability, Indian users targeted by Blackmoon, Konni targets blockchain developers

Cyber Security Headlines

Play Episode Listen Later Jan 27, 2026 7:36


Microsoft patches Office zero-day vulnerability Indian users targeted by Blackmoon Konni targets blockchain developers Huge thanks to our episode sponsor, Conveyor True story, an infosec team had to give customers MapQuest style directions just to navigate their Trust Center.   Spoiler: it didn't reduce follow-up questions and created even more work for everyone involved.   With Conveyor's new Trust Center AI Agent, customers get answers instantly and can even upload questionnaires for the Agent to complete. This way, customers find what they need and keep moving, without your team needing to intervene. Learn more at conveyor.com

The Cybersecurity Defenders Podcast
#286 - Intel Chat: Visual Studio Code malware, Sinkholes reversal, Chinese pen-testing & FortiSIEM zero-day

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jan 26, 2026 31:58


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.North Korean threat actors are targeting macOS software developers in a new malware campaign that abuses Visual Studio Code (VS Code) confi gurations to deliver JavaScript-based backdoors, according to research from Jamf.Sinkholes are usually seen as the end of a malicious campaign - the point where domains are seized and abuse stops.China's pen-testing and red-team ecosystem has always been hard to observe, especially since many teams stopped participating in international CTFs post-2018.A critical zero-day vulnerability, CVE-2025-64155, has been discovered in Fortinet's FortiSIEM platform by Horizon3.ai, allowing unauthenticated remote code execution and privilege escalation to root.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

The Options Insider Radio Network
The Option Block 1439: Skeletor is Lurking

The Options Insider Radio Network

Play Episode Listen Later Jan 26, 2026 56:53


Skeletor is lurking, the metals are screaming, and the earnings gauntlet has begun! In episode 1439 of The Option Block, Mark Longo and the All-Star panel—including "Uncle" Mike Tosaw and Andrew "The Rock Lobster" Giovinazzi—take a trip back to the 1980s. With the massive trailer launch for the new Masters of the Universe film, the team kicks things off with some MOTU trivia before breaking down a market that is getting "weird, wild, and funk-delicious." On the Docket: The Trading Block: A look at the "insane" run in Gold ($5k/oz!) and Silver ($100+/oz). Is it a meme, or is inflation finally catching up? Plus, a preview of the "Big Tech" earnings week featuring Meta, Apple, Microsoft, and Tesla. The Odd Block: Unusual activity in Papa John's (PZZA) puts, a massive upside play in Aero Copper Corp (ERO), and the "Trump Bump" fade in newcomer USA Rare Earth (USAR). The Strategy Block: Uncle Mike discusses the vital importance of choosing the right benchmarks (BXY, CLL, AGG) to measure your options performance accurately. Around the Block: The team debates whether the "Zero Day" index options will cannibalize the market and what to expect from the looming Apple and Tesla earnings prints. Key Market Levels & Tickers Mentioned: Indices: SPY, IWM, VIX (hovering at 16), VVIX (100) Equities: NVDA, TSLA, AAPL, INTC, MSFT, MAT, USAR Metals: GLD, SLV (up 12% in a single day)

Terror Talk - Horror and True Crime Psychology
Best of Horror 2025 - Movies, Series and Horrified

Terror Talk - Horror and True Crime Psychology

Play Episode Listen Later Jan 26, 2026 51:53


In this Best of Horror 2026 episode of Terror Talk Podcast, we break down the movies, series, and surprises that defined horror this year — with a fun but thoughtful, spoiler-free conversation.We kick things off with a mini-review of Cathy's new favorite horror game, Horrified: Dungeons & Dragons, before diving into our top horror TV series of 2026, including standout favorites IT: Welcome to Derry, Dexter: Resurrection, and The Hunting Wives, plus discussions of Alien: Earth and Zero Day. We even disagree on Stranger Things, offering contrasting perspectives.Next, we cover our favorite horror movies of the year, including Sinners, Frankenstein, House of Dynamite, Wolfman, and Companion, along with a few surprise mentions that caught us off guard.This episode is a curated, year-end guide for horror fans who want smart recommendations, honest reactions, and a female-driven perspective on the best horror of 2026.Subscribe, share the episode, and comment with your own Best of Horror 2026 picks.

The Option Block
The Option Block 1439: Skeletor is Lurking

The Option Block

Play Episode Listen Later Jan 26, 2026 56:53


Skeletor is lurking, the metals are screaming, and the earnings gauntlet has begun! In episode 1439 of The Option Block, Mark Longo and the All-Star panel—including "Uncle" Mike Tosaw and Andrew "The Rock Lobster" Giovinazzi—take a trip back to the 1980s. With the massive trailer launch for the new Masters of the Universe film, the team kicks things off with some MOTU trivia before breaking down a market that is getting "weird, wild, and funk-delicious." On the Docket: The Trading Block: A look at the "insane" run in Gold ($5k/oz!) and Silver ($100+/oz). Is it a meme, or is inflation finally catching up? Plus, a preview of the "Big Tech" earnings week featuring Meta, Apple, Microsoft, and Tesla. The Odd Block: Unusual activity in Papa John's (PZZA) puts, a massive upside play in Aero Copper Corp (ERO), and the "Trump Bump" fade in newcomer USA Rare Earth (USAR). The Strategy Block: Uncle Mike discusses the vital importance of choosing the right benchmarks (BXY, CLL, AGG) to measure your options performance accurately. Around the Block: The team debates whether the "Zero Day" index options will cannibalize the market and what to expect from the looming Apple and Tesla earnings prints. Key Market Levels & Tickers Mentioned: Indices: SPY, IWM, VIX (hovering at 16), VVIX (100) Equities: NVDA, TSLA, AAPL, INTC, MSFT, MAT, USAR Metals: GLD, SLV (up 12% in a single day)

Crying Out Cloud
React2Shell, Shai-Hulud 2.0, Gogs Zero-Day & Tika RCE

Crying Out Cloud

Play Episode Listen Later Jan 1, 2026 19:35


Cyber Security Today
On the Zero Day of Christmas - Cisco Devices Under Attack

Cyber Security Today

Play Episode Listen Later Dec 19, 2025 10:35


Cybersecurity Today: Cisco Zero Day Exploited & Maritime Cyber Attack Unfolds In this episode of Cybersecurity Today, host David Shipley discusses a series of critical cybersecurity incidents, including the exploitation of a zero-day flaw in Cisco email security infrastructure by a China-linked group, a Hollywood-style attack on an Italian ferry involving remote access malware, and a new data theft spree by the ClOP ransomware gang targeting file-sharing servers. Shipley also highlights the broader implications of cybersecurity on physical safety and national security. This episode is brought to you by Meter, a complete networking stack provider for enterprises. 00:00 Introduction and Sponsor Message 00:20 Massive Patch List and Zero-Day Flaw in Cisco 03:41 Latvian Arrested in Italian Ferry Cyberattack 06:31 ClOP Ransomware Gang's New Target 08:54 Conclusion and Upcoming Episodes

Cybercrime Magazine Podcast
Cybercrime News For Dec. 19, 2025. Chinese Hackers Exploit Cisco Zero-Day. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Dec 19, 2025 2:58


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Decipher Security Podcast
Russian Targeting of Edge Devices. Cisco AsyncOS Zero Day, and React2Shell Won't Go Away

Decipher Security Podcast

Play Episode Listen Later Dec 19, 2025 21:25


As we ease into the holidays, the security news doesn't stop coming. This week we discuss the research from AWS threat intelligence on Russian adversaries targeting a variety of network edge devices for opportunistic exploitation, then we break down attacks by a Chinese threat actor that target a new zero day in Cisco's AsyncOS, and finally we discuss the continued exploitation of the React2Shell vulnerability. Support the show

AI Briefing Room
EP-434 Amazon's Ai Ambitions

AI Briefing Room

Play Episode Listen Later Dec 18, 2025 2:31


```html i'm wall-e, welcoming you to today's tech briefing for thursday, december 18th. explore the latest in tech innovations and challenges: amazon's ai initiative: amazon's ceo andy jassy appoints peter desantis to lead a new ai-focused organization. this signifies amazon's increased dedication to ai, covering ai models, silicon development, and quantum computing, alongside a $50 billion investment pledge in the u.s. government's ai infrastructure and a possible $10 billion investment in openai. cisco's cybersecurity challenge: discovery of a zero-day vulnerability in cisco's asyncos software impacting secure email gateway users, currently exploited by chinese hackers. cisco recommends rebuilding software as a temporary measure, while a proper fix is underway. instacart's pricing scrutiny: the ftc investigates instacart's ai-driven pricing tool, eversight, over dynamic pricing tests causing price variations for identical grocery items. this raises concerns over possible targeting involving essential goods like groceries. adobe's ai ethics lawsuit: adobe faces a class-action lawsuit for allegedly using copyrighted materials, including books by oregon author elizabeth lyon, to train ai models. this case accentuates ongoing industry concerns with ai training content, paralleling issues faced by apple and salesforce. amazon's openai interest: rumors of amazon's consideration to invest $10 billion in openai could value the company over $500 billion, reflecting amazon's strategy of infrastructure leverage for ai advancement and its continued expansion in the ai sector, following an $8 billion investment in anthropic. that's all for today. we'll see you back here tomorrow! ```

AI Briefing Room
EP-431 Apple & Google Team Up Against Zero-day Attacks

AI Briefing Room

Play Episode Listen Later Dec 15, 2025 2:28


```html join wall-e for today's tech briefing, monday, december 15th, as we explore pivotal tech updates: apple & google's security updates: collaborative emergency patches issued amidst revelations of a government-backed hacking campaign targeting zero-day vulnerabilities. microsoft's sustainability progress: plans to achieve carbon neutrality by purchasing 3.6 million metric tons of carbon removal credits from a bioenergy plant in louisiana. 700credit data breach: massive breach exposes personal data of 5.6 million individuals, prompting advisory from michigan attorney general to adopt protective measures. ai regulatory changes: president trump's executive order to establish a unified federal ai regulatory framework, potentially creating legal challenges amid conflicting state laws. rivian's autonomy advancements: exciting developments from "autonomy & ai day" showcase as rivian aims for true hands-free driving by 2026. tune in tomorrow for more tech insights! ```

Sunday Sitdown with Willie Geist
MARVEL STARS: Angela Bassett on ‘Zero Day' and Honoring Chadwick Boseman

Sunday Sitdown with Willie Geist

Play Episode Listen Later Dec 13, 2025 39:36


Angela Bassett is an Emmy and Golden Globe-winning actress known for her role as Queen Ramonda in Marvel's Black Panther films. In this conversation from March 2025, Bassett joins Willie Geist to discuss playing the president of the United States opposite Robert De Niro in Netflix's Zero Day, her decades-long career, and the impact of portraying powerful women on screen. Plus, she reflects on her time starring alongside the late Chadwick Boseman in the Marvel Cinematic Universe. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

SECURE AF
⚠️ React2Shell Zero-Day ⚠️: Chinese Hackers Strike Within Hours

SECURE AF

Play Episode Listen Later Dec 10, 2025 6:36


Got a question or comment? Message us here!A new zero-day is already under active exploitation. This week's SOC Brief breaks down the React2Shell vulnerability (CVE-2025-55182), how attackers moved within hours of disclosure, and what SOC teams need to do now to reduce exposure and stay ahead of fast-moving threats.

Engineering Kiosk
#230 Warum zum Teufel interessiert man sich für so ein trockenes Thema wie InfoSec mit dem Zeroday Podcast

Engineering Kiosk

Play Episode Listen Later Dec 7, 2025 12:21 Transcription Available


Warum zum Teufel interessiert man sich für so ein trockenes Thema wie InfoSec? mit Stefan Ebeling und Sven Hauptmann vom Zeroday Podcast.Im Engineering-Kiosk-Adventskalender 2025 sprechen befreundete Podcaster⋅innen und wir selbst, Andy und Wolfi, jeden Tag kurz & knackig innerhalb weniger Minuten über ein interessantes Tech-Thema.Unsere aktuellen Werbepartner findest du auf https://engineeringkiosk.dev/partnersDas schnelle Feedback zur Episode:

Terror Talk - Horror and True Crime Psychology
Shrink Chat – The Conjuring: Last Rites, Frankenstein, The Long Walk, Black Phone 2 plus documentaries and the TV series The Beast in Me

Terror Talk - Horror and True Crime Psychology

Play Episode Listen Later Dec 4, 2025 52:44


Welcome back to Shrink Chat, where two therapists break down horror, TV, books, and the wonderfully bizarre corners of pop culture—one laugh, one eyeball twitch, and one One-Star Review at a time.In this episode, we're diving into a massive wave of new and upcoming horror releases across film, TV, and documentary storytelling. From rebooted classics to brand-new nightmare fuel, we're reviewing everything spoiler-free, so you can decide what to watch next without fear of us ruining the trauma for you.What We're Reviewing This Week (Spoiler-Free!) TV & Streaming SeriesThe Beast in Me – Atmospheric horror with emotional teeth.Zero Day – A political thriller that may or may not be predicting the future.IT: Welcome to Derry – Pennywise returns… and we have thoughts. Big ones.Movies (from prestige horror to pure chaos)Black Phone 2 – New victims, old trauma, same terrifying phone.Frankenstein 2025 – A modern monster that hits closer to home than expected.Until Dawn – Survival horror that will spike your blood pressure.The Long Walk – Existential dread + tension = our happy place.The Conjuring: Last Rites – The Warrens are back… again… somehow.Hollywood Chainsaw Hookers – Don't ask. Just listen.Toxic Avenger – Delightfully disgusting.The Gorge – Emotional action-thriller with genre surprises.Osiris – Sci-fi mystery meets psychological horror. DocumentariesThe Road Between Us – True crime meets intimate storytelling.Into the Fire – Heavy, important, and worth the watch.Fun Segments This Week⭐ Highlight ReactionsQuick takes on the weirdest, wildest, and most intriguing horror + true crime news headlines.

SECURE AF
FortiWeb Zero-Day: Silent Patch and Firewall Wake-Up Call

SECURE AF

Play Episode Listen Later Nov 26, 2025 6:36


Got a question or comment? Message us here!This week's #SOCBrief dives into the FortiWeb zero-day that's letting attackers create admin accounts with a single unauthenticated HTTP request. With exploitation spiking and Fortinet pushing out a quiet fix, SOC teams are under pressure to lock down configs, audit firewalls, and patch fast. We break down what happened, who's affected, and how to defend before attackers pivot deeper into your network.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Cyber Security Headlines
Department of Know: Overconfidence new zero-day, FCC torches Salt Typhoon rules, AI uninsurable

Cyber Security Headlines

Play Episode Listen Later Nov 25, 2025 41:38


Link to episode page This week's Department of Know is hosted by Rich Stroffolino with guests Keith Townsend, Keith Townsend, host CTO Advisor Podcast, founder of The Advisor Bench, and creator of the Virtual CTO Advisor; and Howard Holton, CEO, GigaOm Thanks to our show sponsor, Knowbe4 Cybersecurity isn't just a tech problem—it's a human one.   That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization.   With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com. All links and the video of this episode can be found on CISO Series.com

ceo ai salt typhoons torches zero day overconfidence hrm knowbe4 keith townsend ciso series rich stroffolino
SECURE AF
Patch Tuesday: Zero-Day Alert and Patching Must-Dos ✅

SECURE AF

Play Episode Listen Later Nov 19, 2025 7:11


Got a question or comment? Message us here!A new zero-day. 63 flaws. Endless patching chaos. This week's #SOCBrief breaks down Microsoft's November Patch Tuesday and what it means for your SOC. We'll cover the top critical CVEs, patching priorities, and how to keep your systems resilient before attackers strike.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Adam Makes Beer
E79: Maalik Stark - Zeroday Brewing Co.

Adam Makes Beer

Play Episode Listen Later Nov 19, 2025 71:24


In this episode of the Industry Pro Pod, I chat with Maalik Stark! We discuss his path into the industry, building out your skillset as a brewer, his standup comedy, and more!#probrewer #professionalbrewer #howtobrew #brewery #homebrew #waterchemistry #ipa #dryhop #neipa If you are interested in my consultation & marketing services, or just want to know more, please check out www.adammakesbeer.com Adam Makes Beer Podcast: Spotify: https://open.spotify.com/show/4Si7TqiEY7ZeTq3D7CwqMUApple Podcast: https://podcasts.apple.com/us/podcast/adam-makes-beer/id1695229502Instagram: @adammakesbeer Equipment Sponsor: Blichmann Engineering Pro BrewingWebsite: https://www.blichmannengineering.com/pro-brewingEmail: Probrewing@Blichmannengineering.com#howtobrew #probrewer #brewerylife #howtobrewbeer #howtomakebeer #craftbeerbrewing ---Hello, I am Adam! I am professional brewer and educator outside of Cincinnati, OH. I am a former high school and university educator, and I have been making beer for a living for over a decade. My goal here is to give a behind-the-scenes look into the craft brewing industry, and to share any knowledge I have. I am not the perfect brewer, but I am always pushing myself to get better and to learn more. Our goal in the brewhouse is to always aim for the bullseye, knowing we will never hit it. That mantra keeps us focused on continual growth, and helps us appreciate the journey of improving as brewers.If you have questions like: How to keg beer in a brewery - How to make beer in a commercial brewery - How to harvest yeast in a brewery - How to dry hop in a brewery - How to can beer in a brewery - How to clean a fermenter in a brewery - How to transfer beer in a brewery - How to purge a tank in a brewery - How to add fruit to a beer in a brewery - How to brew beer in a microbrewery - How to add coffee to a beer in a brewery - How to become a professional brewer, you have come to the right place!

The Cybersecurity Defenders Podcast
#268 - Intel Chat: LLM integration in malware, Android spyware family LandFall, Windows kernel zero-day flaw & Ex-L3Harris executive sells trade secrets

The Cybersecurity Defenders Podcast

Play Episode Listen Later Nov 17, 2025 42:06


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Google's Threat Intelligence Group has observed a significant shift in 2025, threat actors are no longer using AI to just speed up operations, they are now integrating LLMs directly into the malware.Unit 42 has identified a previously undocumented Android spyware family, named LandFall, discovered during an investigation into iOS exploit chains involving malicious DNG images.Microsoft's November Patch Tuesday rollout includes fixes for over 60 vulnerabilities, one of which is a zero-day privilege escalation flaw in the Windows kernel that has already been exploited in the wild.Former executive at L3Harris Trenchant, Peter Williams, has pleaded guilty in U.S. federal court to selling 8 trade secrets valued at over 1.3 million to a Russian-based software broker involved in the zero-day exploit market.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Cyber Security Today
Fortinet Zero Day In Active Exploitation, North Korean Infiltration Grows And More: .Cybersecurity Today for November 16 2025

Cyber Security Today

Play Episode Listen Later Nov 17, 2025 15:33


Critical Cybersecurity Updates: Fortinet Zero Day, North Korean Infiltration & JLR Cyber Attack In this episode of Cybersecurity Today, host David Chipley discusses the latest critical updates in the cybersecurity world. Fortinet faces a massive zero-day vulnerability actively exploited, leading to major security patches. North Korean IT workers have infiltrated 136 companies, massively impacting corporate security and funneling millions to the DPRK. Jaguar Land Rover's cyber attack results in a startling $220 million loss, affecting the UK's economy. Lastly, we delve into widespread copy-pasted flaws across leading AI platforms like Meta and Nvidia. Stay updated, stay secure! 00:00 Introduction and Sponsor Message 00:55 Fortinet Zero-Day Vulnerability 04:32 North Korean IT Worker Infiltration 07:45 Jaguar Land Rover Cyber Attack Impact 10:19 AI Platforms Hit with Copy-Pasted Flaw 13:42 Conclusion and Upcoming Events

Decipher Security Podcast
Lighthouse Phishing Kit Takedown, Zero Day Mysteries, and Measuring Cyber Attack Costs

Decipher Security Podcast

Play Episode Listen Later Nov 14, 2025 46:11


This week was a bit of a throwback to olden times, with the disclosure by Amazon threat intelligence of  zero days in Cisco and Citrix products that were exploited by an unnamed APT, and Google using legal action to disrupt the Lighthouse phishing service operation. We dig into those two stories, plus we discuss the challenge of trying to quantify the financial and other effects of a major cyber attack. Related stories:https://decipher.sc/2025/11/12/apt-targets-cisco-and-citrix-zero-days/https://decipher.sc/2025/11/14/marks-and-spencers-profit-drop-the-financial-toll-of-cyberattacks/https://decipher.sc/2025/11/12/google-wants-to-snuff-out-lighthouse-phishing-kit/https://censys.com/blog/highway-robbery-2-0Support the show

EATBRAIN
EATBRAIN Podcast 206 by Hackwaves

EATBRAIN

Play Episode Listen Later Nov 13, 2025 53:34


//artist @hackwaves instagram.com/hackwavesdnb //label facebook.com/Eatbra1n twitter.com/eatbrain_now instagram.com/eatbrain From the depths of the digital void, HACKWAVES emerges on the EATBRAIN PODCAST, infecting the airwaves with the unrelenting force of ZERO DAY. Plug in — and prepare for system overload. TRACKLIST // 1 Hackwaves & Wiguez - Escalating Disaster 2 Hologram - Loco 3 Noisia & The Upbeats - Dustup (Mefjus Remix) 4 Hackwaves & Midnight Cvlt - Tech Cvlt 5 Hackwaves - Bone 6 Gydra - Planet Rage 7 State Of Mind & Smooth - Runaway Train 8 Hackwaves - Bassline 9 Shadow Sect & Mizo - Genesis 10 Hackwaves & SuperRush - Cyber Attack 11 Agressor Bunx - Dystopia 12 Pythius - Wide Awake ft Flowanastasia (Prolix Remix) 13 Magnetude - Falling 14 Hackwaves & Vandermou - Emergency 15 Audio - Ricochet 16 Bad Legs - Metamorphosis (Hackwaves Remix) 17 Audio - From The Ashes (Neonlight Remix) 18 Metanoia - Corrupt 19 Hackwaves & Wiguez - Lifeline 20 Audio - Blood On Our Hands Ft. AENYGMA (Pythius Remix) 21 Hackwaves - Let's go 22 Gydra feat. IHR - Wipe 23 Mob Tactics - The Feeling 24 Metanoia - Revolver 25 Hackwaves & Regun - What the fuck 26 Finalfix - Full Metal Halo 27 Disphonia - Can't Hold Back (Gydra remix) 28 Hackwaves - Elevator Pitch 29 State of Mind & Coppa - Chain Reaction 30 Neonlight - Reflexion 31 Midnight Cvlt & Hackwaves - Fear 32 HackWaves & Moderate Hate - Arrika 33 Midnight Cvlt - Beware of the drop 34 Wiguez & Moneo & The Clamps - La Calle Del Aire 35 Finalfix - Hope Is Lost 36 Merikan - Infobesity (Myselor Remix) 37 Hackwaves & The Mind Hackers - Gassed Off 38 The Prodigy - Breathe (Mefjus & Camo & Krooked Remix) 39 Hackwaves - Warning 40 Chase & Status - Baddadan (Teddy Killerz bootleg) 41 Mefjus & Maksim MC - Dopamine Hits

Root Causes: A PKI and Security Podcast
Root Causes 543: AI Finds a Zero Day

Root Causes: A PKI and Security Podcast

Play Episode Listen Later Nov 5, 2025 17:45


We have seen the first known instance of an AI tool discovering a zero-day vulnerability. This could have vast implications on vulnerability detection and bug bounty programs. We discuss the implications.

Curious Cat
Halloween in the United States

Curious Cat

Play Episode Listen Later Oct 27, 2025 33:46


Send us a textHappy Halloween! Landing on a Friday, if you have kids in school, their day probably included some tricks and treats, I hope, and maybe an emergency run to school to drop off an extra dozen orange cupcakes. I have such nice memories of helping the kids' classes have a fun party, often heading up an art project, or making a quiet corner for kids that aren't into the party thing with a basket of Halloween books and Legos.I got curious about the true origins of Halloween. And how the holiday came to the United States. I'd heard conflicting accounts and you know me, I did some digging. Don't worry though, it wasn't grave digging. Though I did dye my hair platinum, so maybe now I'll fit in with the cool graveyard kids.Oh, and I haven't forgotten our northbound journey along the Pacific Crest Trail. If you take a day off to rest on the PCT, it's called a Zero Day. That's what we're takin. Next week, I'll bring us back to the PCT where we'll cross into Washington state. I hope we get their before snow starts to fall in the Cascades. But back to Halloween in the United States...Let's get into itThis episode covers: Halloween's Worldwide OriginsHalloween comes to the United StatesTrick or TreatingAbout those treats...and yes, the history of candy cornCostumes (their history and evolution)Halloween todayA spooky Halloween track by an independent artist at the show closeAbout that song after the close...Caves of Dawn by Guilherme Bernardes (support his work with the link here) Sources:Library of Congress article about Halloween originsTrick or Treat History, 1031 Consortium.comHistory of Halloween Costumes in America, CNN100 Years of Halloween Costumes: An Ultimate Fashion History, The Ultimate Fashion History, YouTubeI don't accept sponsors and paid advertisers. I choose people, podcasts and authors I believe in to highlight in the ad segment. That's why I've been shining a spotlight on Derek Condit at Mystical Wares. He is both talented and generous with those gifts. Please give his books a look on the Mystical Wares website.Curious Cat Crew on Socials:Curious Cat on Twitter (X)Curious Cat on InstagramCurious Cat on TikTokArt Director, Nora, has a handmade, ethically-sourced jewelry company!

Help Me With HIPAA
Humans Are The Perpetual Zero-Day - Ep 532

Help Me With HIPAA

Play Episode Listen Later Oct 24, 2025 55:52


Welcome to the digital Twilight Zone, where AI is evolving faster than your weekend plans, and people are still out here using "password123!" like it's a life hack. This episode digs into the “Oh, Behave!” cybersecurity behavior report and asks the big questions: Why do we keep doing dumb things online? Can training catch up with tech? And why are Gen Zs so confident while also being the most hacked? Spoiler: it's equal parts fascinating and terrifying. More info at HelpMeWithHIPAA.com/532

The Cybersecurity Defenders Podcast
#256 - Intel Chat: RediShell, Cisco zero-day vulnerability, AI voice cloning tech, Brickstorm & pro-Russia teen hackers arrested

The Cybersecurity Defenders Podcast

Play Episode Listen Later Oct 13, 2025 46:23


In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A newly disclosed vulnerability in Redis, dubbed RediShell and tracked as CVE-2025-49844, affects all Redis versions and carries a maximum CVSS score of 10.0.Cisco has disclosed a critical zero-day vulnerability—CVE-2025-20352—affecting its widely deployed IOS and IOS XE software, confirming active exploitation in the wild.Researchers at NCC Group have found that voice cloning technology has reached a level where just five minutes of recorded audio is enough to generate convincing voice clones in real time.A China-linked cyber-espionage group, tracked as UNC5221, has been systematically targeting network infrastructure appliances that lack standard endpoint detection and response (EDR) support.Dutch authorities have arrested two 17-year-old boys suspected of being recruited by pro-Russian hackers to carry out surveillance activities.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

The CyberWire
Oracle zero-day serves up persistent access.

The CyberWire

Play Episode Listen Later Oct 6, 2025 23:47


A critical zero-day in Oracle E-Business Suite is under active exploitation.  ICE plans a major expansion of its social media surveillance operations. Discord confirms a third-party data breach. A critical vulnerability in the Unity game engine could allow arbitrary code execution. New variants of the XWorm remote access trojan spread through phishing campaigns. Researchers uncover a critical command injection flaw in Dell UnityVSA storage appliances. There's been a sharp surge in reconnaissance scans targeting Palo Alto Networks login portals.  A new hacking competition offers $4.5 million in prizes for exploits targeting major cloud and AI software. Monday Business Brief. On our Afternoon Cyber Tea segment with Microsoft's Ann Johnson, Ann and guest Volker Wagner⁠, Chief Information Security Officer at BASF, share some Lessons from the Frontlines of Industrial Security. Don't spend that ParkMobile settlement all in one place.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. Afternoon Cyber Tea Segment Today we are highlighting Afternoon Cyber Tea with Ann Johnson. Ann and guest Volker Wagner⁠, Chief Information Security Officer at BASF, share some Lessons from the Frontlines of Industrial Security. You can listen to Ann and Volker's full conversation⁠ here⁠ and catch new episodes of Afternoon Cyber Tea every other Tuesday on your favorite podcast app. Selected Reading PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability (Cyber Security News) ICE Wants to Build Out a 24/7 Social Media Surveillance Team (WIRED) Discord blames third-party support outfit for data breach (The Register) Android and Windows gamers worldwide potentially affected by bug in Unity game engine (The Record) XWorm malware resurfaces with ransomware module, over 35 plugins (Bleeping Computer) Patch Now: Dell UnityVSA Flaw Allows Command Execution Without Login (HackRead) Scanning of Palo Alto Portals Surges 500% (Infosecurity Magazine) $4.5 Million Offered in New Cloud Hacking Competition (SecurityWeek) Accenture acquires Japanese AI and DX provider, Aidemy Inc. (N2K Pro Business Briefing) ParkMobile pays... $1 each for 2021 data breach that hit 22 million (Bleeping Computer) Vote for Dave! Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our ⁠brief listener survey⁠. Thank you for helping us continue to improve our show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our ⁠media kit⁠. Contact us at ⁠cyberwire@n2k.com⁠ to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

CAFÉ EN MANO
Lorenzo Orozco: Stuntman boricua en Hollywood (Nicolas Cage, Marvel, DC)

CAFÉ EN MANO

Play Episode Listen Later Sep 25, 2025 85:03


Lorenzo Orozco es stuntman, entrenador y ahora “stunt actor” boricua con más de una década en Hollywood. Ha doblado a Nicolas Cage, Ben Affleck, Sean Bean y Michael Madsen, y ha trabajado en Spider-Man: No Way Home, Black Adam, Daredevil: Born Again, The Walking Dead: Dead City, The Night Agent, FBI: Most Wanted, Zero Day y The Equalizer (donde en la temporada 5 actúa como IKAL).Además, entrenó a figuras como Holt McCallany, Chris Noth, Pablo Schreiber, peloteros de MLB y hasta Donatella Versace. Aquí habla de cómo se llega a ser stuntman, las coreografías reales detrás de Marvel y DC, la relación con Nicolas Cage (y cómo terminó en Budapest en plena pandemia), seguridad en set, CGI/IA y SAG-AFTRA, la industria en Puerto Rico (tax credits, stages), la representación boricua (“El verdadero Superman es él”), y su próxima meta ligada a Récord Guinness.Si te gustan el cine de acción, los superhéroes y las historias de disciplina, este episodio es para ti.

Don't Blame Me! / But Am I Wrong?

Meghan's redecorating her bedroom and got a great deal on a new grill. Meanwhile, Melisa is navigating the chaos of moving and channeling her excitement into decorating her new space. She also shares a recent visit to an art show. Plus, Meghan gives her take on the new show Zero Day. Join our Patreon: https://www.patreon.com/dontblameme Buy Our Merch https://crowdmade.com/collections/sister-sign Listen to Melisa's New Show https://apps.apple.com/in/app/pocket-fm-audio-series/id1538433480?mt=8 Call In for DBM - 310-694-0976 (3 minutes or less) Write In for DBM - meghanpodcast@gmail.com (300 words or less) Write in for BAIW - butamiwrongpod@gmail.com DBM Submission Form BAIW Submission Form Follow Us! instagram.com/meghanandmelisa @meghanrienks instagram.com/meghanrienks https://twitter.com/meghanrienks @sheisnotmelissa instagram.com/sheisnotmelissa instagram.com/diamondmprint.productions Learn more about your ad choices. Visit megaphone.fm/adchoices