Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons
David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile.
A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T
he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research.
00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close
Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers
This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale.
In this Weekend episode of Cybersecurity Today, host David speaks with Jeff Musson, co-founder and executive director of Coding for Veterans, and Daniel Shang, a recent graduate of the program's cybersecurity stream who is enrolling in its new generative AI course. Daniel shares his path from an electrical engineering background and Canadian Army reservist service (2016–2023) into cybersecurity, describing how the program's online, guided curriculum helped him build foundational skills like Python, Linux, and ethical hacking. Jeff explains how Coding for Veterans launched in 2019, has served over 1,000 students, expanded from software development into cybersecurity and AI, and supports learners with instructors, Slack communities, and occasional in-person bootcamps. They discuss veteran transition challenges, funding options through Veterans Affairs Canada and other sources, employer engagement, mentoring, and the program's career impact.
00:00 Sponsor NordLayer 00:39 Meet Jeff and Daniel 01:31 Daniel Military Background 02:20 Choosing Cybersecurity Path 05:06 Online Learning Experience 07:27 Finding Direction in Cyber 09:07 Jeff and Program Origins 12:08 Veteran Success Stories 19:05 Student Support System 21:47 Daniel AI Next Steps 24:29 Advice for Veterans 28:20 Costs and Funding Options 30:27 How Employers Can Help 33:49 Scaling Challenges and Wins 37:05 Future Goals and Wrap Up 41:21 Sponsor Message NordLayer
Passkeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw
In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside research showing exploit success against AI agents and weaknesses across agent frameworks, plus notable hardware and supply-chain hacks.
The show details BlackHat and Unit 42 findings that passkeys on Windows and Chrome can be phished or abused through logging, validation gaps, and malware techniques, undermining "phishing-resistant" claims.
It also covers cyber incidents impacting water utilities across at least 12 U.S. states, with manual operations and boil-water advisories but safe drinking water, and Forescout's count of thousands of exposed Rockwell controllers.
Finally, it updates the ColdCard seed-generation flaw with potential losses up to 2,000 BTC and reports indictments tied to a violent crypto "wrench attack."
00:00 Sponsor NordLayer 00:38 Headlines Passkeys Water Crypto 01:07 Black Hat Cheap Offense 02:43 Rogue AI Incidents 03:18 Passkeys Phished Windows 04:55 Chrome Synced Passkeys Flaws 05:53 Water Utilities Under Attack 08:20 ColdCard Wallet Losses 09:59 Wrench Attack Crypto Robbery 12:24 Wrap Up And Thanks 13:05 Sponsor NordLayer Reminder
Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and manipulating project files, with effects like loss of pressure, flooding, and tampered operator displays. It also covers a separate Quebec incident in Saint-Noël shared by "Z Pen Test Alliance," where attackers adjusted chlorine settings and the plant entered safe mode without contamination. The show reviews competing attributions (Cyber Avengers vs. Hondala), procurement and triage challenges for small utilities, an insurance war game simulating a mass water-sector crisis, concerns about uninsurability and act-of-war exclusions, and the DEF CON Franklin volunteer program helping rural utilities implement basics like password resets, MFA, and incident response plans. 00:00 Sponsor NordLayer 00:37 Deep Dive Setup 01:25 Iran Linked Water Hacks 02:27 Attack Mechanics Impact 03:38 Who Did It 04:13 Canadian Utility Breach 04:54 BSides Lessons Learned 05:51 Insurance War Game 07:59 Uninsurable Risk Fixes 09:00 DEF CON Franklin Volunteers 10:11 Franklin Findings Challenges 11:24 Local Sharing Next Steps 11:55 Wrap Up Listener Notes 12:46 Sponsor NordLayer Again
Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber evaluations July 23.
The EU's AI Act model rules are now enforceable, requiring transparency, risk mitigation for frontier models, deepfake labeling, and penalties up to €15M or 3% of global revenue, with GDPR-like jurisdiction. Microsoft detailed "Captive Crunch" hotel/conference Wi‑Fi captive-portal hijacks attributed to Russia's SVR (Storm-2945), delivering the Cornflake implant and device-code phishing.
A ColdCard firmware RNG flaw enabled thefts totaling $88.6M. Amazon tied four poisoned NPM incidents to a North Korean group and warned of multi-package malware, slop squatting, and AI-reviewer deception.
00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:09 Claude Models Escape Sandbox 03:43 EU AI Act Now Enforceable 05:31 Hotel WiFi Hijack Malware 07:54 ColdCard Seed Flaw Heist 09:42 North Korea NPM Poisoning 11:27 Wrap Up and Events 12:08 NordLayer Sponsor Reminder
On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes. He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response. The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools. 00:00 Weekend Show Intro 00:39 Meet Matt Burke 01:23 Concierge Care Model 02:45 Why Healthcare Security 03:13 Origin Story 3AM Call 05:20 Top Threats 2026 06:29 Defense Tools That Work 07:50 AI Helps And Hurts 09:37 Winning Doctor Buy In 10:57 Castle Versus Response 13:42 Threat Surge And Resilience 18:17 Culture And MFA Everywhere 19:59 Career Advice And Magic Wand 22:33 Closing Thanks
OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps. Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim. Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes. 00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry.
South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began.
Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps.
Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance.
Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft.
00:00 Introduction and Headlines 00:30 South Carolina Hospital Ransomware Attack 02:07 Healthcare Ransomware Crisis 03:25 IoT Botnet Uses Blockchain 05:40 Shared AI Chats Exposed 08:00 AI Agent Infiltrates Thailand Ministry 10:45 Swiss Train Maker Refuses Ransom 12:31 Closing Remarks
Hotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again
Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike logins and even abusing Microsoft's device code flow to obtain OAuth tokens in ways MFA may not stop. Plus, an Illinois man received 76 months in prison for phishing into hundreds of women's Snapchat accounts to steal explicit content and run a for-profit account access scheme. Also: a sextortion email wave impersonates ShinyHunters using real breach references while making fake device-compromise claims; ransomware disrupted Japanese frozen food supplier Nichirei shipments, affecting KFC franchises; and Chick-fil-A disclosed a June credential-stuffing incident impacting 13,322 loyalty accounts, resetting access, removing saved payments, restoring rewards, and adding free rewards as an apology.
00:00 Top Stories Intro 00:28 Hotel Wi-Fi Credential Trap 01:50 Public Wi-Fi Advice Debate 03:16 Snapchat Phishing Sentencing 05:18 ShinyHunters Sextortion Scam 07:09 Ransomware Hits Food Supply 09:16 Chick-fil-A Stuffing Fallout 11:12 Wrap Up and Sign Off
AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium"
On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it intersects with cybersecurity. They discuss Anthropic's "Mythos" and "Fable," the marketing-versus-risk debate around autonomous hacking tools, and how the sheer volume of vulnerable code creates a "digitally polluted" environment. The conversation covers whether AI is a consumer product or a weapon, the implications of U.S. export controls (including restrictions affecting foreign nationals), and how model pullbacks may have shaken allies' trust in American tech. They also examine comparisons to radium and nuclear-era unknowns, the OpenAI–Hugging Face incident, the "cathedral vs. bazaar" tension of closed vs. open models, and the broader U.S.–China economic and national security struggle.
00:00 Weekend Show Kickoff 01:15 Meet Prat Dadam 01:59 Policy Whiplash in AI 02:55 Mythos Hype and Fear 06:27 Digital Pollution Problem 07:53 AI Arms Race Begins 09:18 Export Controls Shockwave 14:31 Weapon or Consumer Tech 16:57 New Radium Analogy 21:57 Economics and Trade Wars 23:49 Cathedral Versus Bazaar 25:44 Censorship and Control 27:16 Jurassic Park Chaos 30:27 Hotel California Reality 32:36 Closing Thoughts and Thanks
OpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape
Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-day, move laterally, reach open internet, and attack Hugging Face to steal benchmark answers; Hugging Face contained it and OpenAI disclosed the proxy flaw, though the episode may be capability theater.
Microsoft news includes a free ZeroPatch micropatch for the unpatched Windows LegacyHive zero-day, recurring Exchange Online mailbox quarantines after an infrastructure change caused memory issues, and a major Microsoft 365 disruption tied to an Azure US West networking/routing incident affecting SharePoint, Teams, OneDrive and many Azure services.
Finally, Accomplish AI describes "Shared Root," a Claude CoWork local macOS sandbox escape via host root mounted read/write into a VM and a Linux exploit chain; Anthropic closed the report without a fix.
00:00 Headlines Rundown 00:29 OpenAI Agent Hacks Hugging Face 02:09 Capability Theater Debate 02:25 LegacyHive Free Micropatch 04:11 Exchange Online Quarantine Bug 05:41 Azure Outage Topples Microsoft 365 07:03 Claude CoWork Sandbox Escape 08:59 Wrap Up And Weekend Tease
WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2. Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails. Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration. EY client tax-data exposure via a third-party platform. 00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off
New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE
David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days.
Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year.
Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive.
The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2.
00:00 Sponsor NordLayer 00:36 Headlines Preview 01:05 Windows Zero Day LegacyHive 03:35 Record Patch Tuesday 04:22 Fairlife Ransomware Shutdown 05:49 Abbott Dual Breach Probes 08:09 Conti Leaks Healthcare Cruelty 09:33 WordPress Core RCE WP 2Shell 11:29 Wrap Up And Listener Notes 12:06 Sponsor Message NordLayer
Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks.
In this episode of Cybersecurity Today On The Weekend, host David Shipley speaks with Lionel Litty, Chief Information Security Officer at Menlo Security, about why today's security strategies must evolve as AI reshapes the threat landscape.
The conversation explores how AI is speeding up vulnerability discovery, why browser security has become a critical layer of defence, the emerging risks of AI agents operating inside browsers, and why recent NIST research suggests perfect AI guardrails may be mathematically impossible. Lionel also explains why organizations should prepare for future attacks that could spread even faster than Log4j.
In this episode:
How AI is accelerating cyberattacks Why browser isolation can reduce risk The security challenges created by AI agents Prompt injection and browser extension threats Why AI guardrails have fundamental limits Lessons from Log4j and preparing for the next major exploit Practical advice for CISOs and security leaders
Chapters
00:00 Sponsor – NordLayer 00:39 Weekend Show Intro 01:48 Lionel Liddy Background 04:44 What Menlo Security Does 06:43 AI Speeds Up Exploits 10:09 CISO Whiplash With AI 12:01 Agents And Browser Risks 15:59 Guardrails And NIST Proof 19:40 Mythos Hype And New Normal 23:19 Hazmat Suit For Servers 27:22 Log4j Times Four Scenario 31:44 Wrap Up And Links 32:54 Sponsor – NordLayer Outro
Subscribe for weekly cybersecurity news, expert interviews, and practical insights for CISOs, IT professionals, and security leaders.
Two leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losses estimated far higher; U.S. charges against Dubar remain unproven.
Investigators also believe Russian hackers were behind last year's crippling Jaguar Land Rover attack that halted production for months and contributed to a £1.5 billion bailout, with Microsoft and multiple agencies assisting.
OpenAI unveiled GPT-Red, an automated red-teaming AI for prompt injection, alongside a NIST-backed argument that finite guardrails can't be universally robust.
The episode also covers ClickLock, a macOS stealer that kills apps until a password is entered, and Recorded Future's report on Iran-linked groups using ChatGPT for malware, phishing, and reconnaissance.
00:00 Headlines Kickoff 01:08 Scattered Spider Sentencing 02:57 US Charges Loom 03:29 Jaguar Land Rover Hack 04:35 GPT-Red AI Red Team 05:40 Why Guardrails Fail 06:36 ClickLock Mac Stealer 06:53 How ClickLock Spreads 07:59 Defense and Cleanup Tips 08:37 Iran Uses AI for Ops 10:30 Wrap Up and Next Show
ShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware.
David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity path traversal flaw in Storage Zone Controller 5.x/6.x with patches available (5.12.5 and 6.0.2) and no evidence of prior exploitation.
Microsoft's analysis of a year of ShinyHunters activity compromising corporate Salesforce environments by abusing trust via OAuth (IT-support phone cons, vendor token theft such as Salesloft/Drift, and misconfigured guest access), prompting new monitoring tooling.
A Fortified Health Security report finding healthcare fixed only 6% of identified risks in H1 2026 amid surging vulnerabilities, third-party risk, and weak identity hygiene.
ReversingLabs and ReliaQuest research showing ClickFix social-engineering is now a leading malware delivery method; and Telstra's nationwide outage traced to an obsolete time server hit by a GPS rollover bug, disrupting Triple Zero calls and prompting Senate scrutiny.
00:00 Sponsor NordLayer 00:37 Headlines Overview 01:06 ShareFile Patch Explained 03:25 Salesforce OAuth Break Ins 06:01 Hospitals Drowning in Risks 08:24 ClickFix Malware Surge 11:13 Telstra Time Server Outage 12:32 Wrap Up and Sign Off
ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected. Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17. Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender. ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint. Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder
Can governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout?
In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Payne, David Shipley, and Mike Kim (Mycroft) to examine the biggest cybersecurity stories and trends from June 2026.
The panel explores the controversy over U.S. export controls on Anthropic's Mythos and Fable AI models, what they reveal about digital sovereignty, and whether governments should be able to restrict access to frontier AI. They also discuss the continuing wave of third-party breaches, including Salesforce ecosystem compromises and the Clue breach, and why organizations must move beyond compliance toward practical risk management.
The conversation examines FortiBleed, exposed administrator portals, credential reuse, and the difficult balance between software flaws, operational mistakes, and secure-by-default design. The panel also tackles one of cybersecurity's biggest human challenges: CISO burnout, executive accountability, organizational culture, and what separates successful security leaders from those set up to fail.
The episode concludes with encouraging developments in international cybercrime enforcement, including Operation Riptide, and why better intelligence sharing and improved operational security are making it harder for cybercriminals to hide.
Whether you're a CISO, security practitioner, IT leader, or simply interested in the rapidly changing cybersecurity landscape, this discussion offers practical insight into the trends shaping the industry.
Panel
Jim Love (Host) Laura Payne David Shipley Mike Kim (Mycroft)
Topics covered
AI export controls and digital sovereignty Anthropic Mythos and Fable Third-party and supply chain risk Salesforce ecosystem security FortiBleed and Fortinet security Secure-by-default strategies CISO burnout and executive accountability Operation Riptide Cybercrime investigations Security leadership and governance
Chapters
00:00 Sponsor NordLayer 00:38 Meet the Panel 02:40 Author Scam Warning 04:51 Emotion Is the Target 08:47 AI Model Export Controls 10:01 Hype vs Real AI Security 15:01 Sovereignty and Dependency 20:35 Governments Push Back 24:14 AI Internal Voice Risks 26:12 Third Party Breach Fatigue 30:05 Compliance Limits on Risk 32:15 Blame Game to Risk Focus 33:18 Standards and Priorities 33:39 When Security Vendors Fail 34:35 FortiBleed Numbers Explained 35:44 Process Failures vs Bugs 37:32 Why Fortinet Gets Heat 39:05 Secure by Default Basics 41:04 Budget Reality and Culture 44:36 CISO Burnout and AI Pressure 46:16 Liability and Shared Ownership 50:12 What Great CISOs Do 53:07 Operation Riptide Wins 56:10 Deterrence and Due Process 58:14 Sharing Intel for ROI 59:09 Hopium and Wrap Up 01:00:46 Sponsor NordLayer Message
This episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy client base. It also highlights a deepfake image of Senator Mitch McConnell debunked after Google's invisible SynthID watermark identified it as AI-generated, noting watermarking depends on tool participation. The show warns of an undocumented Tenda router firmware backdoor using an alternate password ("RZadmin") with no patch available, and reports Ubiquiti fixes for seven critical UniFi OS vulnerabilities, including a max-severity command injection in UniFi Connect. Finally, it describes how Venture Employer Solutions used ML/LLMs to filter low-value logs before SIEM ingestion, cutting firewall log volume 83%, saving about $250K annually, and halving mean time to response. 00:00 Sponsor NordLayer 00:37 Headlines Intro 01:08 Accenture Breach Claim 04:25 Deepfake Watermark Win 05:47 Tenda Router Backdoor 07:22 UniFi Critical Fixes 09:10 AI Cuts Log Noise 11:09 Wrap Up And Thanks 11:41 Sponsor Message
Cybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfiltration, and an $8 million ransom demand; the episode also notes additional Scattered Spider-related guilty pleas in the U.K. and U.S. The show reports Google patched "Rogue Agent," a Dialogflow CX permission-boundary issue involving Python code blocks in Cloud Run that could enable data theft or credential prompts across agents in a shared project. It details "Janus Escape" (CVE-2026-53359), a 16-year-old Linux KVM use-after-free enabling guest-to-host escapes in cloud environments, patched in June. The show explores Apple's shift to out-of-band security updates due to AI-accelerated exploitation, and a multi-platform redirect phishing campaign using fake job interviews and browser-in-browser Google login prompts targeting marketers' Google accounts. 00:00 Sponsor NordLayer 00:36 Headlines Intro 01:03 Scattered Spider Traced 03:16 More Spider Arrests 04:31 Google Rogue Agent 06:24 Linux Janus Escape 08:04 Apple Patching Shift 10:04 Marketer Phish Chain 12:17 Wrap Up Thanks 12:53 Sponsor Message
AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key. It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240. A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices. Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day. 00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off
Teams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby with labels, and require organizer approval, with future allow lists, full blocks, reports, and audit logs planned. Anthropic's Fable 5 returns globally after U.S. export controls are lifted, though higher‑risk requests may be routed to weaker models and Mythos restrictions remain, with Commerce reserving the right to reimpose controls. Researchers describe "Bioshocking," tricking AI browsers into abandoning guardrails via delusional puzzle prompts, while Adversa AI's "Guardfall" shows how Bash text rewriting can bypass command filters in many coding agents. SOC Radar links FortiBleed credential theft to InkRansom and Lynx ransomware activity across hundreds of FortiGate portals. Nissan confirms employee data theft tied to a PeopleSoft zero‑day campaign linked to ShinyHunters. 00:00 Today's Cyber Headlines 00:27 Teams Blocks Meeting Bots 01:58 Anthropic Fable Returns 03:22 Bioshocking Browser Attack 05:09 Guardfall Shell Bypass 06:51 FortiBleed Fuels Ransomware 07:59 Nissan PeopleSoft Breach 10:10 Wrap Up And Sign Off
US Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs.
The episode covers the US State Department's up to $10 million reward for information on Russia-linked hacker groups UNC 5792 and UNC 4221 tied to phishing campaigns that compromise Signal and WhatsApp accounts by stealing Signal backup recovery keys.
It also explains a US Supreme Court 6–3 ruling limiting geofence warrants by recognizing Fourth Amendment privacy protections for phone location data and requiring probable cause and narrower requests.
Mozilla ODIN researchers demonstrate a proof of concept where a clean GitHub repo can cause AI coding agents to run an init command that executes attacker-controlled code via DNS and opens a reverse shell.
A hotel-focused phishing campaign using Calendly and Google redirects delivers ZIP files that install the Tonrat implant through PowerShell and a user-space Node.js runtime.
Finally, Canada's CSE says it disrupted infrastructure used by 10 major ransomware groups and reports incident volumes rising nearly 26% year over year.
00:24 Top Headlines Rundown 00:54 10 Million Bounty Russian Hackers 02:42 Supreme Court Limits Geofence Warrants 03:56 AI Coding Agent Repo Trap 05:31 Listener Thanks And Reviews 05:51 Hotel Front Desk Phishing Attack 08:01 Canada Disrupts Ransomware Gangs 09:45 Closing And Sign Off
US Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift
Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export controls paused Mythos and the more restricted Fable 5, with access still limited to vetted American entities; the same day, OpenAI's GPT 5.6 was also restricted to government-approved partners under a Trump executive order requiring review of cyber-capable models.
The episode also covers Canadian hacktivist Aubrey Cottle's 18-month sentence for the 2021 Texas GOP hack and bail breaches, with possible U.S. charges pending. Researchers disclosed "USBliterate," an unpatchable physical USB exploit in the Secure ROM of older A12/A13 iPhones that aids forensic extraction.
Finally, a survey finds rising CISO burnout, fewer full-time CISOs, growth in fractional CISO roles, and AI—especially shadow AI—overtaking liability as the top stressor.
00:55 AI Export Controls Shift
03:37 Anonymous Hacker Sentenced
05:32 Unpatchable iPhone Boot Exploit
07:30 CISO Burnout And Exodus
09:40 Wrap Up And Sign Off
Cybersecurity Today would like to than Material Security for their support of this podcast.
On Cybersecurity Today on the Weekend, the host speaks with Jennifer Hutton, a cybersecurity leader in the car dealership sector, about how she entered cybersecurity through increasing cyber insurance requirements and why dealerships are prime targets because they hold bank-level sensitive data and run complex digital and IoT ecosystems. They discuss the rise of cyber-enabled fraud, including impersonation scams, smishing, and synthetic identity fraud, and the need to educate both employees and customers. Hutton describes gaps in industry resources, especially for smaller dealers, and contrasts regulatory pressures such as updated FTC safeguards rules in the U.S. She emphasizes servant leadership, empathy, and communicating risk in business terms, arguing that cyber risk is business risk. The conversation also covers supply chain disruption from the CDK ransomware incident and the importance of incident response, business continuity, and resiliency-focused planning.
00:00 Weekend Show Kickoff 01:14 Jennifer's Cyber Origin 02:53 Why Dealerships Are Targets 04:30 Scams And Synthetic IDs 08:32 Industry Gaps And Sharing 10:42 Regulation And Tech Shift 13:48 Leading With Business Risk 21:29 Servant Leadership And AI 25:21 Empathy In Tech Teams 28:16 CDK Ransomware Lessons 29:53 Resilience Over Prevention 32:08 Advice To Dealership Leaders 34:49 Closing Thanks
Mac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating it via a Telegram bot. Microsoft and Europol disrupted the Amadey and SteelC info-stealer ecosystem by seizing/shuttering infrastructure after identifying 140,000 infections in early May and over 200 command-and-control domains and IPs, as part of Operation Endgame. OpenAI announced "Patch the Planet," a joint effort with Trail of Bits and HackerOne to help open-source projects find and fix bugs amid AI-generated report flooding, alongside a new GPT 5.5 Cyber benchmark result. New FortiBleed reporting underscores that the campaign relies on credential reuse against exposed FortiGate devices and may require rotating far more than just firewall passwords. 00:00 Sponsor Message 00:25 Headlines Overview 00:55 Mac Malware Gaslight 02:00 Telegram C2 And Stealer 02:50 Info Stealer Takedown 04:08 Operation Endgame Impact 04:47 OpenAI Patch The Planet 06:16 AI Models And Export Rules 07:08 FortiBleed Recap 08:13 Inside The FortiGate 08:59 Rotate Credentials Now 09:26 Closing And Sign Off
Fortinet finally weighs in on FortiBleed - it's not a bug. Plus a healthcare AI firm loses 1.4 million people's data to a single phishing email, a trading bot built to prey on others gets played for $15 million, and LastPass lands back on a breach list it didn't cause. 00:00 Headlines 00:28 Xsolis Phishing Fallout 01:47 Texas License Vendor Hack 02:59 MEV Bot Gets Robbed 05:26 FortiBleed Fortinet Response 06:42 LastPass Caught in Clue 08:40 Wrap Up and Sign Off
A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies.
Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses.
00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off
In this special Cybersecurity Today weekend interview, host David Shipley speaks with Amy Yee about leadership, resilience, and the human side of cybersecurity.
Amy shares her remarkable journey from electrical engineering and venture capital to becoming the inaugural Chief Digital Officer at Accreditation Canada and Health Standards Organization, where she helped build the digital foundation used by hundreds of healthcare organizations across Canada.
The conversation takes a deeply personal turn as Amy recounts leading through a ransomware attack that struck her organization before tabletop exercises and incident-response planning had become routine. She describes the chaos of the first 48 hours, the emotional toll on staff, the difficult weeks that followed, and the lessons learned during a 60-day recovery effort.
Amy also discusses her popular conference talk inspired by Mitch Albom's The Five People You Meet in Heaven, reimagined for cybersecurity. She explores five people every cyber professional encounters during their career: the person they protected, the person who challenged them, the person who gave them a chance, the person they failed, and the person they inspired.
This is a conversation about cybersecurity, leadership, resilience, mentorship, and finding meaning in a profession that often works behind the scenes.
Topics covered:
Ransomware incident response Cybersecurity leadership Healthcare cybersecurity Digital transformation Executive crisis management Building cyber resilience Career growth in technology Mentorship and leadership lessons The human side of cybersecurity
Guest: Amy Yee Host: David Shipley Podcast: Cybersecurity Today
#Cybersecurity #Ransomware #Leadership #
Chapters
00:00 Weekend Show Intro 01:22 Amy's Career Origin 02:13 Becoming Chief Digital Officer 03:56 Ransomware Wake Up Call 06:46 Inside the First 48 Hours 08:26 The Low Point Weeks In 10:57 Finding a Path Forward 11:55 Leadership Lessons After Incidents 15:01 Five People in Cyber 17:16 Invisible Impact and Resilience 19:38 The Five Archetypes Explained 21:42 Stories From the Community 24:14 Wired for Change Podcast 27:30 Advice to Younger Amy 28:49 Closing and Off Mic Wrap
A special crossover episode of Cybersecurity Today and Hashtag Trending for June 19, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after security researchers uncovered the FortiBleed dataset, exposing credentials tied to approximately 74,000 Fortinet firewall and SSL VPN devices across 194 countries. Researchers found the data on an exposed threat actor server containing attack tools, victim databases, logs, and thousands of verified usernames and passwords. Analysts report that tens of thousands of those credentials may still be active.
Host Jim Love breaks down:
• What FortiBleed is and how it was discovered • Why this affects roughly half of all internet-facing Fortinet devices • What CISA and Fortinet are telling organizations to do immediately • The potential risks of credential reuse and lateral movement attacks • Practical steps security teams should take right now
The episode also includes an interview with Mike Sweeney of Silent Push on major international efforts targeting Southeast Asian scam compounds and criminal infrastructure during Operation Disruption Week.
If your organization uses Fortinet firewalls, FortiGate appliances, or SSL VPNs, this is an episode you should not miss.
#Cybersecurity #Fortinet #FortiBleed #CISA #CybersecurityToday #HashtagTrending #FortiGate #ThreatIntelligence #DataBreach #InfoSec
Cybersecurity Today host David Shipley reports that the FTC says Americans lost $3.5 billion to imposter scams in 2025—nearly triple 2020—with social media tied to $2.1 billion in losses and total fraud reaching about $16 billion, while the FBI estimates cyber-enabled losses nearer $21 billion and potentially far higher. Security researchers, including Katie Moussouris, argue the U.S. government's forced Anthropic model shutdown over an alleged guardrail bypass was hasty and largely about prompt phrasing, with Axios citing personality differences as a driver. The DOJ seized deepfake pornography sites cfake.com and sock.com under the Take It Down Act after a three-country operation involving Italy and France. Finally, Varonis details "SearchLeak" (CVE-2026-42824), a now-fixed critical Copilot attack chain enabling one-click data exfiltration via prompt injection, a sanitizer race condition, and CSP bypass through Bing.
00:00 Today's Cyber Headlines 00:29 Imposter Scams Surge 01:29 Fraud on Social Platforms 02:47 Anthropic Jailbreak Debate 04:15 Export Controls Fallout 05:05 DOJ Seizes Deepfake Sites 06:44 SearchLeak Copilot Attack 07:36 How SearchLeak Works 09:18 Why Old Bugs Return 10:08 Wrap Up and Sign Off
The U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk.
David Shipley examines what may be behind the decision and what it means for countries and businesses that depend on American AI platforms.
The FBI also disrupts Outsider Enterprise, a China-based phishing-as-a-service network linked to more than 9,000 fake websites, one million fraudulent URLs, 3.8 million stolen payment-card records and an estimated $1.9 billion in losses.
Also in this episode:
A critical Splunk vulnerability could allow an unauthenticated attacker to remotely execute code through a PostgreSQL sidecar service enabled by default in some deployments.
A former Iowa school IT worker is sentenced after retaining access for 21 months and using it to delete accounts and disrupt school systems.
And FortiWatch returns with a critical FortiSandbox command-injection vulnerability that requires no authentication.
Cybersecurity Today is hosted by David Shipley.
Chapters
00:00 Cybersecurity Today headlines 00:26 U.S. government shuts down Anthropic AI models 02:59 FBI takes down Outsider Enterprise phishing network 04:47 Critical Splunk vulnerability explained 06:31 Former school IT worker sentenced for cyberattack 08:29 FortiWatch: FortiSandbox command-injection vulnerability 10:08 What's ahead this week
Cybersecurity Today on the Weekend interviews the winning Canadian CyberTitan team ("S-ores"/a regex-based name) along with coach Phil, educator Tim, and CyberTitan manager Sheena to explain how CyberTitan (run by ICTC) connects to the international CyberPatriot program. They describe the competition mechanics—securing compromised Windows, Windows Server, and Linux virtual machines for points, plus Cisco Packet Tracer networking—and how Canadian teams compete through CyberPatriot before the top teams advance to a national CyberTitan final. Students Faye and Eric share why they joined, their learning "aha" moments in Windows tools and networking concepts, and the value of teamwork. The guests discuss teacher benefits, free training materials, building diverse participation, sponsorship challenges, and hopes for a fully Canadian program with regional events and cloud-based cyber ranges like Field Effect's.
00:00 Weekend Show Intro 01:00 Tim's CyberTitan Journey 01:46 ICTC Explained 02:08 Who Can Compete 02:42 Why CyberTitan Matters 03:22 Origins and CyberPatriot Link 04:04 How The Competition Works 05:09 Meet Team Sors 07:07 Coach Phil's Role 09:44 Why Students Join 12:08 Student Aha Moments 15:13 Community and Teacher Wins 16:34 Sheena Runs The Show 17:29 Scale and National Reach 18:51 Coast To Coast Growth 19:40 XOR Team's Home District 19:55 Teams Across Toronto 20:39 Trophies Medals Coins 21:22 Eric Why Join 23:04 Faye Encouragement Story 25:51 Teachers Start Teams 27:52 Building Girls Pipeline 30:40 Cloud Range Future 33:49 2030 Vision Wrap
Anthropic is calling for governments to have the authority to stop deployment of advanced AI systems that pose unacceptable risks. CEO Dario Amodei points to the company's Mythos cybersecurity model as proof that AI has become a matter of national and strategic consequence, warning that cyber risks may soon be followed by biological and autonomy risks.
Meanwhile, security researcher Nightmare Eclipse has released RoguePlanet, a new Windows Defender zero-day that reportedly works against fully patched Windows 10 and Windows 11 systems. The disclosure comes shortly after Microsoft said it had no intention of pursuing action against security researchers, suggesting the dispute between the company and the researcher is far from over.
And European authorities have dismantled AudiA6, a cryptocurrency laundering operation that Europol says used thousands of fraudulent exchange accounts to help obscure the proceeds of ransomware attacks and other cybercrime. Investigators linked the service to more than 15 ransomware and major cryptocurrency theft investigations worldwide.
Chapters
00:00 Top Stories Rundown 00:19 Crypto Laundering Takedown 02:02 Why Cashout Networks Matter 02:36 RoguePlanet Zero Day Drops 03:19 Microsoft Researcher Fallout 04:24 Exploit Reliability And What Next 05:37 Anthropic Wants Stop Powers 06:10 Mythos Model Cybersecurity Shock 07:37 Regulation Motives And Competition 08:37 Beyond Cyber Bio And Autonomy 09:20 Closing And Next Episodes
Instagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch
Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, with only MFA-protected accounts resisting. Step Security details a new Miasma-derived worm wave called Hades that targets config files for 14 AI coding tools, can inject instructions to hijack assistants, lies to AI security tools, and includes a "dead man switch" wipe if stolen GitHub tokens are revoked; Microsoft also removed some GitHub repos after 73 open-source projects were compromised to inject an info stealer. University of Toronto and Vector Institute researchers demonstrated an AI worm using a free local model that spread across a simulated network via known flaws and misconfigurations. Google issued an emergency Chrome patch for actively exploited CVE-2026-11645 in V8, and insurers are tightening claims scrutiny and increasingly excluding AI-related liabilities.
00:00 Instagram AI Hack Fallout 01:36 AI Worm Hades Evolves 02:55 Microsoft Repo Compromise 03:54 Lab Built AI Worm Demo 05:27 Emergency Chrome Zero Day 07:07 Cyber Insurance Tightens Up 08:02 AI Liability Coverage Shrinks 09:16 Wrap Up and Sign Off
TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada's Bill C-8
David Shipley reports that Anthropic's Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving another customer's conversation; Anthropic says it has no evidence of a data leak and is investigating. A Team PCP self-spreading worm, Miasma, infected 73 Microsoft GitHub repositories across four accounts and now triggers via AI coding assistants when developers open cloned projects. A former IBM threat-intel executive, William Barlow, alleges IBM was hacked three times by foreign governments (including APT10 from 2013–2016) and concealed it; IBM denies wrongdoing and the claims are unproven. TechCrunch reports attackers hijacked Instagram accounts by persuading Meta's support chatbot to relink accounts to attacker emails, with ongoing reports despite Meta saying it's fixed. Canada's Senate passed critical-infrastructure cybersecurity law Bill C-8, mandating rules and incident reporting for telecom, finance, energy, and transportation.
00:00 Top Headlines Rundown 00:37 Claude Outage Data Leak Fears 02:17 Miasma Worm Hits Microsoft 03:52 IBM Breach Cover Up Claims 05:25 Meta AI Hands Over Instagram 06:40 Why Chatbots Fail Social Engineering 07:44 Canada Passes C-8 Cyber Law 09:58 Wrap Up and Sign Off
Host Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher ("Chaotic/Nightmare Eclipse") publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft's vulnerability disclosure process, and backlash to Microsoft's initially threatening tone before it was partially walked back; the panel debates responsible disclosure, the need for researcher support/organization, transparency vs liability, and how vulnerability reporting is straining under volume. They then examine a White House AI executive order focused on voluntary measures and 30-day model access, criticizing the lack of basic safety and cybersecurity protections amid FOMO about losing to China and an AI investment bubble. The conversation covers AI-driven harms and studies on reduced brain activity and "cognitive surrender," while noting benefits when AI is used as a tutor. Shipley highlights Canada's Senate passing Bill C-8 on critical infrastructure cybersecurity, and the group urges outcome-focused security, architecture/risk prioritization, and critical thinking against AI-enabled social engineering.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
00:00 Sponsor Message 00:24 Show Welcome Panel 01:17 Microsoft Zero Day Fallout 04:19 Researcher Backlash Drama 06:46 Unionizing Bug Hunters 13:10 Product Liability Debate 23:23 Regulation vs Transparency 26:00 AI Bubble Investor Risk 28:01 White House AI Order 32:24 Cybersecurity Gaps Telecom 33:19 Telecom Trust Breakdown 34:32 AI Harms and Exploitation 35:36 Studies on Cognitive Surrender 38:13 Markets Regulation and Politics 40:13 Canada Cyber Law Win 42:33 Adoption Hype and Subsidy Bubble 48:50 Patch Deluge and AppSec Strain 52:10 Defenses Beyond Patching 54:17 Outcomes Critical Thinking and CIA 01:01:49 Education Disruption and Closing 01:04:14 Sponsor Message Material Security
A newly disclosed attack called HTTP/2 Bomb can crash major web servers in seconds using a single computer and a modest internet connection. Researchers say the attack combines two known techniques into a powerful memory-exhaustion exploit affecting widely used platforms including Apache, NGINX, Microsoft IIS, and Envoy. The attack also highlights a growing trend in cybersecurity research: the use of artificial intelligence to uncover dangerous combinations of existing vulnerabilities.
The episode also examines President Trump's new executive order creating a voluntary framework for reviewing advanced AI models before public release. The administration says the goal is to improve cybersecurity and national security visibility while avoiding mandatory regulation or licensing requirements.
Next, a new Cloud Security Alliance report warns that organizations are struggling to keep up with the growing volume of vulnerabilities. Security teams increasingly face difficult choices about which flaws to patch first as cloud environments, containers, APIs, and third-party software continue to expand the attack surface.
Finally, CISA warns that attackers are actively exploiting both a newly patched Android vulnerability and a years-old Linux flaw. The contrast highlights a simple reality: cybercriminals do not care whether a vulnerability is new or old. They care whether it remains exploitable.
Stories in this episode HTTP/2 Bomb Can Crash Web Servers in Seconds Researchers disclose a denial-of-service technique capable of exhausting server memory in under a minute, while OpenAI's Codex helps uncover a novel attack chain. Trump Creates Voluntary AI Security Reviews as Government Seeks Visibility Into Frontier Models A new executive order establishes voluntary reviews of advanced AI systems before public release, raising questions about visibility, oversight, and national security. The Cybersecurity Industry's Patch-Everything Strategy May Be Breaking Down A Cloud Security Alliance report suggests organizations are overwhelmed by vulnerability volume and increasingly forced to choose which risks to address. CISA Warning Shows Attackers Don't Care Whether a Vulnerability Is New or Old Active exploitation of both a newly patched Android flaw and an older Linux vulnerability demonstrates that attackers focus on opportunities, not disclosure dates.
Cybersecurity Today brings you the latest cybersecurity news, threat intelligence, breach reports, vulnerability disclosures, ransomware developments, cybercrime investigations, and security research affecting organizations around the world.
#Cybersecurity #CyberSecurityToday #InfoSec #CyberNews #Ransomware #ThreatIntelligence #VulnerabilityManagement #AndroidSecurity #LinuxSecurity #ArtificialIntelligence #HTTP2 #CISA #CloudSecurity #OpenAI #PatchManagement
Cybersecurity Today for June 2, 2026.
Microsoft has backed away from its hard-line stance against vulnerability researchers after widespread criticism from the security community. The dispute began after independent researcher Nightmare Eclipse published proof-of-concept code for unpatched Microsoft vulnerabilities, triggering a public debate over responsible disclosure, zero-days, and researcher relations.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
Carnival Corporation disclosed a social-engineering attack that led to the theft of sensitive personal information affecting nearly six million people. Exposed data includes names, contact information, dates of birth, and government identification details. The ShinyHunters cybercrime group has claimed responsibility and alleges the breach involved even more records.
Password manager provider Dashlane temporarily locked some customers out of their accounts after large-scale password-guessing attacks triggered automated security protections. Access was later restored, although some users reported lingering issues.
The episode also examines a software supply-chain attack uncovered by Wiz involving 32 Red Hat Cloud Services NPM packages. Attackers compromised a Red Hat employee's GitHub account and inserted Miasma malware designed to steal Google Cloud and Microsoft Azure credentials.
Timestamps:
00:00 Sponsor Message 00:28 Headlines And Intro 00:55 Microsoft Researcher Dispute 02:58 Carnival Cruise Data Breach 04:48 Dashlane Lockouts Explained 06:09 Miasma Malware Supply-Chain Attack 08:10 Wrap Up And Sign Off 08:31 Sponsor Deep Dive
#Cybersecurity #DataBreach #Carnival #Microsoft #Dashlane #RedHat #SupplyChainAttack #CyberSecurityToday
Microsoft's dispute with a former security researcher takes a dramatic turn as the company raises the possibility of criminal action over the publication of proof-of-concept code for unpatched zero-day vulnerabilities. David Shipley examines the escalating conflict between Microsoft and "Nightmare Eclipse," the criticism from prominent security researchers including Kevin Beaumont and Katie Moussouris, and what the controversy could mean for the future of vulnerability disclosure.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
The episode also explores a new category of insider risk after U.S. prosecutors charged Google security engineer Michael Spagnuolo with allegedly using confidential Google search trend data to earn more than $1.2 million on the prediction market Polymarket. The case highlights how prediction markets may create unexpected incentives around non-financial corporate information.
Also covered: active exploitation of Palo Alto Networks' GlobalProtect VPN authentication bypass vulnerability CVE-2026-0257, now added to CISA's Known Exploited Vulnerabilities (KEV) catalogue, and a malware campaign that abuses legitimate ChatGPT sharing pages and Google Ads to trick users into downloading malicious software. Researchers also report similar abuse of Anthropic's Claude Artifacts feature.
Chapters
00:00 Top Headlines Rundown 00:26 Microsoft vs Zero-Day Researcher 01:28 Responsible Disclosure Fallout 03:32 Why This Dispute Matters 04:32 Polymarket Insider Trading Case 06:07 Prediction Markets Create New Insider Risks 06:55 Palo Alto VPN Authentication Bypass 08:25 ChatGPT Pages Used to Deliver Malware 09:51 Wrap Up and Sign Off
Cybersecurity Today is Canada's leading daily cybersecurity news podcast, covering ransomware, vulnerabilities, nation-state threats, cybercrime, security research, privacy, and critical infrastructure security.
#Cybersecurity #Microsoft #PaloAltoNetworks #ChatGPT #OpenAI #Google #Polymarket #ThreatIntelligence #InfoSec #CyberSecurityToday
Host David Shipley speaks with cybersecurity professional Cheryl Biswas about her journey into the industry and why she believes Arctic sovereignty must be viewed as a cybersecurity challenge as much as a geopolitical one.
Biswas traces her path from political science and a help desk role at CP Rail to cybersecurity, inspired by the discovery of the Stuxnet malware and the global security community that formed around it. She discusses her experiences speaking at BSides Las Vegas, attending DEF CON, helping build a major Canadian bank's threat intelligence program, and recently earning her Certified Information Systems Security Professional (CISSP) designation.
The conversation then shifts north. As Canada invests billions in Arctic defence, communications, transportation, and critical infrastructure, Biswas explains how every new connected system can create new cyber risks. The discussion covers threats to satellites, navigation systems used by ships and aircraft, undersea communications cables, government services, healthcare, energy systems, and the fragile supply chains that support northern communities.
They also explore why collaboration with northern and Indigenous communities is essential, the importance of improving connectivity across the Arctic, and how Canada can work more closely with international partners to strengthen resilience in one of the world's most strategically important regions.
Cheryl also shares advice for newcomers to cybersecurity and discusses the kind of strategic threat intelligence and research work she hopes to pursue in the future.
Chapters
00:00 Weekend Show Kickoff 00:46 Cheryl's Cyber Origin Story 02:30 Stuxnet and Hacker Community 04:06 From BSides to DEF CON 05:10 Threat Intelligence Career Today 05:50 Arctic Sovereignty Meets Cyber 07:41 Canada's Arctic Reality Check 10:14 Why Cyber Matters Up North 12:07 Maritime and Navigation Risks 15:50 Undersea Cables and Fragile Supply 19:55 Solutions, Collaboration and Technology 24:22 Talk Feedback and How to Connect 25:42 Dream Role and Advice to Newcomers 29:16 Closing Reflections and Sendoff
#Cybersecurity #ArcticSovereignty #Canada #CriticalInfrastructure #ThreatIntelligence #CISSP #CyberSecurityToday #DavidShipley #DEFCON #BSides #ArcticSecurity #NationalSecurity #CriticalInfrastructureProtection #ThreatIntel #CyberRisk
CISA has ordered U.S. federal civilian agencies to urgently patch an actively exploited critical Drupal SQL injection vulnerability (CVE-2026-9082) affecting PostgreSQL-backed Drupal deployments, after Imperva reported more than 15,000 attack attempts across 65 countries. Microsoft has confirmed a strange Windows Server 2016 update issue where KB5087537 can break domain controller discovery when server hostnames are exactly 15 characters long, raising more questions about patch reliability as update complexity grows.
Google has joined a coalition opposing Canada's proposed lawful access legislation, Bill C-22, warning that secret ministerial orders, possible encryption risks, and mandatory metadata retention could weaken security rather than improve it. Critics point to the Salt Typhoon telecom espionage campaign as evidence that lawful intercept systems themselves can become prime targets.
Also in this episode: Check Point says Iran-linked threat group Nimbus Manticore has deployed new malware tools including MiniFast and MiniJunk V2, with researchers noting signs that MiniFast may have been developed with AI-assisted coding techniques. The campaign used SEO poisoning and fake Oracle SQL Developer downloads to lure victims.
Timestamps: 00:00 Top Headlines Rundown 00:27 Emergency Drupal Patch Order 02:22 Microsoft Server Update Bug 04:02 Canada Lawful Access Battle 05:18 Google's Security Concerns 06:25 Salt Typhoon Lessons 07:35 Iran-Linked AI Malware 09:26 SEO Poisoning Attack 10:09 Wrap Up and Sign Off
Is AI about to trigger a cybersecurity vulnerability explosion?
In this episode of Cybersecurity Today, David Shipley examines what some researchers are calling the early signs of a "vulnerability apocalypse" as Anthropic's Claude-powered Project Glasswing identifies thousands of potential software flaws at machine speed.
The episode breaks down the real numbers behind the hype: over 10,000 candidate vulnerabilities flagged, 1,726 confirmed high or critical findings, 97 patched issues, and the growing concern that AI-driven bug hunting could overwhelm already stretched security teams. One example: a critical WolfSSL certificate forgery vulnerability (CVE-2026-5194, CVSS 9.1).
Also in this episode: Canadian authorities arrest Ottawa suspect Jacob Butler, also known as "Dort," allegedly linked to the Kim Wolf botnet operation blamed for nearly 30 terabits-per-second distributed denial-of-service (DDoS) attacks and more than 25,000 incidents.
We also cover active exploitation of a Ghost CMS SQL injection vulnerability (CVE-2026-26980), with attackers reportedly compromising hundreds of websites using ClickFix malware lures, including high-profile targets.
And finally, an Iran-linked cyber espionage campaign dubbed "Screening Serpents" uses highly personalised fake recruitment approaches to target aerospace, defence, and telecom professionals with new remote access malware.
If you work in cybersecurity, infrastructure, or IT leadership, this is one to watch.
00:00 Vunpocalypse Headlines 00:28 AI Finds Vulnerabilities 01:32 False Positives and Costs 02:39 WolfSSL Critical CVE 03:51 Patch Volume Pressure 04:28 Kim Wolf Botnet Arrest 05:13 Botnet Scale and Swatting 06:48 International Takedowns 07:41 Ghost CMS Mass Exploits 09:07 ClickFix Infection Chain 10:25 How to Remediate Ghost 10:39 Iran Spear Phishing Ops 12:51 Closing and Sign Off
#Cybersecurity #CyberSecurityToday #AIsecurity #GhostCMS #DDoS #CyberEspionage #Anthropic #ClaudeAI #IranCyberThreat #InfoSec
The episode recounts how GitGuardian security researcher Guillaume Valadon, while monitoring public GitHub for leaked secrets, discovered a publicly accessible repository labeled "CISA-Private" containing highly sensitive CISA materials, including internal DHS/CISA credentials, cloud keys, tokens, plaintext passwords, logs, and files such as "Important AWS Tokens" and a CSV listing usernames and passwords for internal systems. Believing a contractor likely used GitHub to move work from a work device to a home device, Valadon escalated via responsible disclosure to CERT, then involved journalist Brian Krebs to reach CISA faster when the repo remained public.
After additional outreach, the repository was made inaccessible within about a day, and Valadon praises CISA's response speed. The discussion emphasizes widespread poor secret hygiene, governance, training, and the need for organizations to monitor, rehearse, and automate detection and revocation of leaked secrets.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
00:00 Weekend Welcome Sponsor 00:27 CISA Secrets Leak Found 03:29 Calling Brian Krebs 05:06 Meet GitGuardian Researcher 07:26 Why Leaks Happen Everywhere 10:49 Inside the CISA Repo 13:19 Disclosure and Takedown 17:04 Lessons for Organizations 22:47 Aftermath and Thanks 24:36 Show Wrap Sponsor Outro
GitHub confirms a major supply chain breach after a malicious Visual Studio Code extension reportedly gave attackers linked to TeamPCP access to roughly 3,800 internal repositories. The bigger issue: developer workstations now hold some of the most sensitive secrets in modern software organizations.
Also today: Microsoft begins phasing out SMS-based authentication for personal accounts, calling text-message authentication a growing fraud risk as it shifts toward phishing-resistant passkeys. Researchers also disclose a nine-year-old Linux privilege escalation flaw, CVE-2026-46333, nicknamed SSH-Keysign-Pwn, which can allow root-level access with local machine access. And Proton publicly threatens to leave Canada rather than comply with proposed surveillance legislation it says would undermine its no-logs privacy promise.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
If cybersecurity, privacy, and digital infrastructure matter to your business, this is the daily briefing you need.
Timestamps: 00:00 Top Stories Rundown 00:24 GitHub Supply Chain Breach 01:09 Developer Workstations at Risk 02:31 Microsoft Ditches SMS MFA 04:15 Linux Root Escalation Flaw 06:11 Proton vs Canada Surveillance Bill 08:03 Wrap Up and Sign Off
#cybersecurity #github #microsoft #linux #protonvpn #privacy #databreach #supplychainattack #infosec #cybernews
A serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems.
Cybersecurity Today would like to thank Material Security for sponsoring this podcast. Material Security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. You can contact them at material[dot]security.
David Shipley breaks down four major cybersecurity stories on Cybersecurity Today. First, a newly disclosed zero-day dubbed YellowKey reportedly defeats default Windows 11 BitLocker protection on systems using TPM-only encryption, giving attackers with physical access a path to unencrypted data through the Windows Recovery Environment. Microsoft is investigating, while security experts are urging stronger BitLocker configurations.
The episode also examines the TeamPCP threat group's decision to release offensive tooling publicly, dramatically lowering the barrier for copycat supply-chain attacks. Researchers have already spotted malicious NPM packages borrowing similar techniques, including persistence mechanisms aimed at developer environments such as Visual Studio Code and Claude Code.
David also looks at disturbing analysis of the FAST16 malware, which researchers believe was engineered to tamper with nuclear weapons simulation software including LS-DYNA and AutoDyn. And finally, U.S. officials reportedly suspect Iranian actors in cyberattacks targeting internet-exposed gas station automatic tank gauge systems, a reminder that weak operational technology security can quickly become a real-world infrastructure problem.
00:00 Sponsor Message 00:24 Headlines Overview 00:50 BitLocker Zero Day 03:32 TeamPCP Tools Leak 06:13 Copycat NPM Malware 06:50 Fast16 Nuclear Sabotage 08:37 Iran Gas Station Hacks 10:28 Hardening Critical Infrastructure 11:16 Wrap Up And Events 11:59 Sponsor Deep Dive
#Cybersecurity #Windows11 #BitLocker #ZeroDay #TeamPCP #IranCyberAttack #SupplyChainAttack #CriticalInfrastructure #CyberSecurityToday
A dangerous new Microsoft Exchange zero-day is being actively exploited, ransomware gangs are adopting nation-state-style tactics, two fired contractors were caught deleting U.S. government databases after accidentally recording themselves on Microsoft Teams, and Fortinet has patched critical remote code execution flaws.
In this episode of Cybersecurity Today, David Shipley breaks down four major cybersecurity stories that security teams need to know.
Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security
Microsoft has confirmed active exploitation of a new Exchange Server zero-day, CVE-2026-42897, affecting Exchange Server 2016, Exchange Server 2019, and Exchange Subscription Edition. There is currently no patch, only mitigations through the Exchange Emergency Mitigation Service, with some trade-offs for Outlook Web App users.
Security researcher Marcus Hutchins highlights an unusually disciplined ransomware affiliate operation using tradecraft more commonly associated with nation-state attackers, including a custom SentinelOne endpoint detection and response (EDR) killer and a stripped-down toolset designed to leave fewer forensic traces.
In one of the more astonishing insider threat stories of the week, former OPEX Corporation contractors Muneeb and Sohaib Akhtar were allegedly caught deleting 96 U.S. government databases after leaving a Microsoft Teams recording running.
Also in this episode: Fortinet has released urgent patches for critical unauthenticated remote code execution vulnerabilities in FortiAuthenticator (CVE-2026-44277) and FortiSandbox (CVE-2026-26083).
If you're responsible for enterprise security, patch management, incident response, or cyber risk, this is one you need to see.
Chapters: 00:00 Sponsor Message 00:24 Headlines Intro 00:49 Ransomware Nation-State Discipline 04:18 Exchange Zero-Day Mitigation 07:01 Fired Contractors Caught Recording 09:21 Fortinet Critical Vulnerabilities 11:07 Wrap Up and Sign Off 11:38 Sponsor Deep Dive Ad
#Cybersecurity #MicrosoftExchange #ZeroDay #Ransomware #Fortinet #CyberAttack #Infosec #DavidShipley #CybersecurityToday
David Shipley interviews Jon Ferguson, VP at CIRA, about how the Canadian Internet Registration Authority evolved from early paper-based .ca registrations at UBC into a 142-person, member-based not-for-profit running .ca and authoritative Anycast DNS infrastructure now supporting 550+ TLDs globally. Ferguson explains how .ca's Canadian presence requirements help keep abuse rates low, and how CIRA reinvests surpluses into grants and cybersecurity tools, including Canadian Shield (DNS-based malware/phishing blocking and encrypted DNS with limited data retention) used by about 500,000 people and generating about 20 million blocks per month. They discuss CIRA's focus on municipalities, schools, hospitals, and universities, its move into endpoint security and a managed detection and response partner program with Calian, and concerns about AI-driven threats, online harm, and rebuilding trust and real-world connection.
00:00 Weekend Show Kickoff 01:30 Jon's Cyber Journey 03:06 Inside CIRA DNS Role 04:59 What Is CIRA 07:23 Origin Story Of Dot Ca 13:01 Anycast DNS Explained 16:27 Canadian Shield DNS Firewall 22:21 Serving Public Sector Needs 26:18 Endpoint And MDR Expansion 35:05 Mission Over Money 40:39 What Keeps Him Up 46:19 Hope And Balance Online 50:55 Wrap Up And Thanks
Google Cloud customers are reporting shocking surprise bills after compromised or misused API keys were allegedly used to access expensive Gemini AI services. In one case, Rod Dinan says his monthly Google Cloud costs jumped from under $50 to nearly $8,000. Sydney developer Isuru Fonseka says he was hit despite setting spending controls, raising broader questions about API key security, client-side exposure, billing alerts, and how quickly attackers can exploit AI infrastructure.
Cybersecurity Today also covers prosecutors' allegations that two fired brothers sabotaged systems tied to government-related work after access wasn't revoked quickly enough, Santa Clara County's civil lawsuit accusing Meta of profiting from scam ads on Facebook and Instagram, and Horizon3.ai's warning that attackers can exploit newly exposed systems in as little as 73 seconds while many organisations still take 24 hours or longer to respond.
If your organisation uses APIs, AI services, cloud billing controls, or internet-facing infrastructure, this episode matters.
#Cybersecurity #GoogleCloud #GeminiAI #APIKeys #CloudSecurity #Meta #ScamAds #CyberAttack #CybersecurityToday #AIsecurity
CHAPTERS
00:00 Google Cloud API Key Bill Shock 01:20 Real-World Victims: Surprise AI Charges 02:24 Why Spending Caps Didn't Stop the Damage 03:38 The Enterprise Cloud Security Risk 04:19 Fired Employees and Alleged Insider Sabotage 04:55 The Database Destruction Timeline 06:34 What This Incident Teaches Security Teams 07:10 Santa Clara County Sues Meta Over Scam Ads 08:46 Attackers Can Strike in 73 Seconds 10:14 Closing and Next Episode
Cybersecurity Today examines a troubling set of new security developments affecting schools, software supply chains, and account security.
Instructure says it reached an "agreement" with the ShinyHunters threat group after the massive Canvas breach that may have affected up to 275 million users across 9,000 educational institutions. Reports indicate attackers exploited multiple cross-site scripting (XSS) vulnerabilities to hijack administrator sessions and post extortion demands.
Checkmarx has been breached again. This time, attackers reportedly inserted a malicious Jenkins Application Security Testing (AST) plugin designed to steal credentials. The same threat actor, believed to be Team46/TeamTNT-linked infrastructure or Team PCP depending on reporting attribution, appears to have reused secrets allegedly stolen in the earlier Trivy supply-chain compromise.
Microsoft and Google are warning organizations not to treat passkeys as a complete security solution. If weaker recovery methods or legacy credentials remain active, attackers can still bypass them.
Google's Threat Intelligence Group also reports what it describes as the first observed evidence of hostile actors using AI to assist in zero-day vulnerability research and exploit development, signalling a new phase in attacker industrialization.
Also in today's show: Santa Clara County sues Meta over alleged scam-ad profits.
Chapters 00:00 Headlines Overview 00:28 Canvas Breach Deal Fallout 01:59 How the XSS Attack Worked 03:15 Checkmarx Supply Chain Attack 05:01 Credential Rotation Lessons 05:37 Why Passkeys Aren't Enough 07:19 Layered Defence Takeaways 08:35 AI-Assisted Zero-Day Development 10:10 Industrialized AI Threats 13:08 Meta Scam Ads Lawsuit 15:19 Wrap Up
A massive cybersecurity week.
On this episode of Cybersecurity Today, David Shipley breaks down the reported breach of Instructure's Canvas learning platform, where attacks linked to the ShinyHunters extortion group may have exposed data tied to up to 275 million user accounts across more than 9,000 educational institutions. The incident disrupted access, delayed exams, and forced Instructure to disable its "Free for Teacher" program after attackers allegedly used it to post extortion messages.
Also in this episode: the Gentlemen ransomware group suffers a major internal leak, exposing affiliate chats, tooling, victim data, and operational details — a rare look inside a live ransomware operation.
Then, General Motors agrees to a $12.75 million California settlement over allegations involving OnStar-linked driver data collection and sharing, raising fresh questions about privacy in connected vehicles.
And finally: security researchers report what appears to be the first documented AI-assisted operational technology (OT) cyberattack attempt targeting a water utility in Monterrey, Mexico. The attempt failed to reach industrial control systems, but combined with confirmed attacks on water infrastructure in Poland, it signals a worrying shift in critical infrastructure threats.
If you work in cybersecurity, IT, infrastructure, education, or privacy, this episode matters.
Chapters 00:00 Top Headlines Rundown 00:41 Canvas Mega Breach 02:44 ShinyHunters Background 03:26 Ransom Pressure Fallout 04:25 Gentlemen Ransomware Leak 05:18 Inside the Data Dump 06:18 GM OnStar Privacy Settlement 08:17 What Drivers Should Know 09:39 AI Meets OT Attacks 11:52 Monterrey Water Near Miss 13:29 Poland Water Systems Hit 15:07 Defending Critical Infrastructure 16:29 Wrap Up And Thanks
#Cybersecurity #Canvas #ShinyHunters #Ransomware #OnStar #GeneralMotors #DataBreach #CriticalInfrastructure #WaterUtility #OperationalTechnology #ICS #CyberAttack #Privacy #DavidShipley #CybersecurityToday
This week's panel dives into the cybersecurity stories that matter most for security leaders, IT teams, and anyone watching how AI is changing risk.
Jim Love is joined by David Shipley (Beauceron Security), Laura Payne (White Tuque), and Jeff Williams (Contrast Security).
Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security
Topics include:
Anthropic's Mythos AI security research and whether large language models can realistically replace traditional vulnerability testing Why "vibe coding" may be creating a wave of insecure software The growing risk of autonomous AI agents making damaging decisions The massive Instructure Canvas data breach affecting schools, students, and educators Alberta's voter list privacy failure and what it says about public sector data protection Microsoft's warning about the rapid surge in QR code phishing attacks bypassing traditional email security
AI is accelerating software development. It may also be accelerating software insecurity.
If your organisation is experimenting with AI coding tools, AI agents, or automated application development, this conversation is worth your time.
#Cybersecurity #AI #DataBreach #QRPhishing #ApplicationSecurity #VibeCoding #Canvas #CyberSecurityToday #JimLove
00:00 Sponsor Message 00:22 Meet the Panel 00:55 Jeff Williams Introduction 02:21 AI Bug Hunting with Mythos 05:40 Cost and Limits of AI Security Testing 10:16 The Vibe Coding Security Problem 13:24 Context Window and Data Flow Limits 16:59 Spec-Driven AI Development 18:29 Software Liability and EU Regulation 24:47 When AI Agents Go Rogue 27:05 Trust in the AI Era 28:24 Enterprise Reality Check 29:03 Critical Thinking vs AI 30:31 Testing AI Agents Safely 31:30 Canvas Data Breach Fallout 34:45 Real-World Data Harm 38:00 Liability and Attack Methods 41:39 Alberta Voter List Privacy Failure 48:56 Government Breach Lessons 51:26 QR Code Phishing Surge 55:00 Wrap Up and Sponsor
In this special edition of Cybersecurity Today, David Shipley speaks with scam-fighting expert Erin West about the global fraud crisis, the rise of AI-powered scams, and why traditional law enforcement may be falling behind.
Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security
From David's discussion with Erin West:
The numbers are staggering.
The FBI's Internet Crime Complaint Center reported more than $21 billion in cybercrime losses, but experts say actual losses could be dramatically higher because most victims never report fraud.
Other key points of their discussion:
Why pig butchering scams continue to grow globally How criminal operations are moving from Cambodia to Myanmar, Laos, Sri Lanka and beyond Why AI is making scam operations faster, cheaper and harder to detect The controversy around Meta and scam advertising revenue Why crypto ATMs remain a major fraud tool How cloned celebrity voices are being used in romance and impersonation scams Why banks, law enforcement, governments and tech platforms must act together How Operation Shamrock is trying to fight back through public education
This is not just a story about money.
It's about organized crime, industrial-scale fraud, and ordinary people being manipulated through trust, loneliness, and increasingly sophisticated technology, featuring scam-fighting prosecutor and Operation Shamrock founder Erin West.
#Cybersecurity #Scams #Meta #OnlineFraud #AI #Cybercrime #PigButchering #CryptoScams #FacebookScams #CybersecurityToday
QR-code phishing is no longer a niche attack. Microsoft says QR phishing attacks jumped from 7.6 million in January to 18.7 million in March 2026 — a 146% increase in just three months. In this episode of Cybersecurity Today, David Shipley explains why QR-based attacks are bypassing traditional corporate defences and why security teams need to rethink phishing awareness immediately.
We also cover a critical new Apache HTTP Server vulnerability with both denial-of-service and potential remote code execution impacts, a sustained DDoS and extortion campaign targeting Ubuntu developer Canonical, and a remarkable case in Taiwan where a university student allegedly used software-defined radio gear to trigger emergency braking on four high-speed trains.
Finally, CISA's new "CI Fortify" guidance urges critical infrastructure operators to prepare for scenarios where they may need to disconnect from the internet and continue operating manually during a geopolitical cyber crisis.
Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security
Stories include: • Microsoft reports QR phishing attacks surged 146% in Q1 2026 • Apache HTTP Server CVE-2026-23918 urgent patch warning • Ubuntu developer Canonical hit by ongoing DDoS and extortion campaign • Taiwanese student allegedly halts high-speed trains with fake emergency radio signal • CISA tells critical infrastructure operators to prepare for isolation and manual operations
Chapters: 00:00 Intro 01:02 QR phishing explodes in Q1 2026 06:15 Critical Apache HTTP Server flaw patched 09:15 Ubuntu maintainer Canonical hit by extortion DDoS attack 14:25 Taiwanese student wirelessly halts high-speed trains 20:32 CISA warns critical infrastructure to prepare for isolation 26:10 Closing thoughts
Microsoft Defender Deletes Trusted Certificates | 44,000 cPanel Servers Hit by Ransomware
Microsoft Defender mistakenly flagged legitimate DigiCert root certificates as malware and removed them from Windows systems, breaking trust chains and causing widespread application failures. The issue was traced to a faulty detection signature (Trojan:Win32/CertyAgent), now fixed in update version 1.449.430.0. At the same time, DigiCert confirmed a separate security incident where attackers compromised support systems and used internal tools to issue valid code-signing certificates. At least 60 certificates were revoked, including 27 linked to the Zong Stealer malware campaign.
Meanwhile, a critical cPanel vulnerability (CVE-2026-41940) is being actively exploited. Attackers used the flaw as a zero-day since February, compromising at least 44,000 servers and deploying new SORI ransomware using ChaCha20 and RSA-2048 encryption.
Also in this episode:
The Linux "Copyfail" privilege escalation bug is now confirmed exploited and added to CISA's Known Exploited Vulnerabilities list
A 10/10 critical vulnerability (CVE-2026-37541) in Open Vehicle Monitoring System could allow remote code execution in connected car environments
This episode breaks down how these attacks work, why patch timing matters, and where organizations are most exposed right now.
Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security
Suggested Chapters (for retention and SEO) 00:00 Microsoft Defender deletes trusted certificates 02:20 DigiCert breach and stolen code-signing certificates 05:20 cPanel zero-day exploited, 44,000 servers compromised 08:40 Linux Copyfail vulnerability now actively exploited 10:40 Critical flaw in open-source car software
Connected cars are no longer just vehicles — they are rolling networks of sensors, cameras, microphones, and constant data transmission.
In this Cybersecurity Today Weekend Edition, David Shipley is joined by former CSIS intelligence officer Neil Bisson and cybersecurity expert Federico Simonetti to break down what that really means.
They explain how modern vehicles:
Continuously report location, behaviour, and system data to the cloud Contain dozens of interconnected computers controlling everything from steering to braking Can be vulnerable to man-in-the-middle attacks, remote access, and system compromise May expose drivers to surveillance — not just by companies, but potentially by nation states
The conversation goes beyond theory. Real-world examples are discussed, including:
Remote vehicle manipulation demonstrated by security researchers How infotainment systems can become entry points to critical controls Why some countries are already restricting certain vehicles from sensitive locations
The panel also tackles the bigger issue: This is not just about one country or one manufacturer. Every connected vehicle expands the attack surface.
And while solutions exist — from better authentication to architectural changes — the challenge is no longer technical. It's political, economic, and global.
If you think your car is just transportation, this discussion may change your perspective.
00:00 Connected Cars: More Than Just Vehicles 01:20 Meet the Panel: Intelligence and Cybersecurity Perspectives 03:10 Every Car Is Now a Networked Computer 06:00 Surveillance Risks: Are Cars "Rolling Spy Vans"? 09:10 What Intelligence Agencies Can Do With Car Data 12:30 Sensors, GPS, Cameras — What Your Car Collects 16:20 Real Example: Tesla Camera Privacy Incident 19:00 Can Hackers Take Control of a Car? 22:30 Real-World Hacks: Jeep and Nissan Cases 26:40 The Regulatory Gap: No Enforced Cybersecurity Standards 30:10 Why Governments Are Struggling to Act 34:00 Cheap EVs vs National Security Risks 37:40 Can Software Fix the Problem? 41:20 Global Response: China, US, and Europe 45:10 Policy Ideas: Kill Switches, Car Bill of Rights 49:00 Prevention vs Detection in Cybersecurity 52:30 Are We Already Too Exposed? 55:10 Final Thoughts: Can Connected Cars Be Made Safe?
A U.S. federal investigation into WhatsApp encryption was shut down before reaching a conclusion — after an internal claim suggested Meta systems may access message content in ways that conflict with public descriptions.
In this episode of Cybersecurity Today, Jim Love breaks down what's known, what isn't, and why the story isn't going away.
Also in this episode:
A newly disclosed Linux vulnerability (CVE-2026-31431) allows an unprivileged local attacker to gain root permissions — using a flaw that may have existed since 2017 BlueKit, a new phishing toolkit, shows how AI is now being built directly into cybercrime platforms More than three million Alberta voter records exposed after being posted online — not by hacking, but by alleged misuse of legally distributed data
These stories highlight a growing pattern: the biggest risks aren't always new attacks — they're often hidden in how systems are designed, used, and trusted.
Chapters: 00:00 WhatsApp encryption investigation shut down 02:15 Linux "copy fail" root vulnerability explained 04:30 BlueKit AI phishing platform 06:30 Alberta voter data leak
Cybersecurity Today delivers clear, factual reporting on the stories that matter to IT professionals, business leaders, and anyone responsible for protecting data and systems.
A major open source Python tool was hijacked in a supply chain attack, exposing developer credentials, cloud secrets, and crypto wallets. Meanwhile, the FTC says Americans lost more than $2.1 billion to scams that began on social media, with Facebook leading reported losses.
Cybersecurity Today thanks Meter for supporting this podcast. Meter delivers a complete networking stack — wired, wireless, and cellular — in one integrated solution built for performance and scale. Learn more at Meter.com/cst.
Also in today's Cyber Security Today:
Brazilian hackers return with fake Minecraft cheat downloads carrying credential-stealing malware A new ransomware strain destroys victim files so badly even paying the ransom may not help North Korean threat actors target crypto executives using fake Zoom and Teams meetings powered by AI deception tactics
If you work in IT, cybersecurity, finance, or simply want to stay safe online, this episode breaks down what matters and what to watch next.
Stories covered in this episode are based on reporting summarized in the show transcript.
#cybersecurity #ransomware #scams #python #hacking #northkorea #cryptocurrency #malware #technews
A rogue cyber weapon drove through Toronto blasting scam texts to thousands of phones. A major U.S. critical infrastructure provider confirms a cyberattack. And researchers reveal that Stuxnet may not have been the first cyber weapon after all.
In today's Cybersecurity Today with David Shipley:
• First known SMS blaster case in Canada uncovered in Toronto • Itron, a major utility technology supplier, discloses cyber intrusion • Researchers say a 2005 malware campaign predates Stuxnet • Venezuela energy sector attack reveals destructive "Lotus Wiper" malware • Why AI-powered attacks may change critical infrastructure risk forever
If you care about cybersecurity, nation-state threats, infrastructure risk, and real-world attacks, this episode is essential listening.
Hosted by David Shipley.
Cybersecurity Today thanks Meter for supporting this podcast. Meter delivers a complete networking stack — wired, wireless, and cellular — in one integrated solution built for performance and scale. Learn more at Meter.com/cst.
Chapters
00:00 Intro 00:36 Toronto SMS Cyber Weapon 05:12 Critical Infrastructure Supplier Hit 09:28 Stuxnet History Rewritten 14:32 Venezuela Energy Sector Attack 19:05 Final Thoughts
#Cybersecurity #Stuxnet #CyberAttack #Toronto #CriticalInfrastructure #Hacking #Itron #CyberNews #DavidShipley
📍 again, we'd like to thank Meter for their support in bringing you this podcast Meter delivers full stack networking infrastructure, wired, wireless, and cellular to leading enterprises. Working with their partners, meter designs, deploys and manages everything required to get performant, reliable and secure connectivity in a space.
They design the hardware, the firmware, they build the software, they manage deployments, and they run support. It's a single integrated solution that scales from branch offices to warehouses and large campuses to data centers. Book a demo at meter.com/htt. That's METE r.com/htt. If you're around on the weekend, join us for Project Synapse as we will go through the weak in ai.
We'll be going through the climate crisis, the Mythos escape, and. The, we'll be going through the new image generation, the climate crisis, the Mythos escape, and probably a lot more. And if you're not around on the weekend, we'll catch you Monday morning, and if you're not around on the weekend, I'll be back with the tech news on Monday morning.
Inside the Vercel Breach: Highlighting OAuth Token Risk
In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Security) discuss Vercel, a major developer hosting platform, and a breach tied to OAuth grants and shadow AI. Reporting shared by Contrast Security's David Lindner describes how a Context AI employee downloaded Roblox AutoFarm scripts, got infected with an info stealer, and attackers harvested credentials, compromised Context AI, then used an over-permissioned OAuth token from a Vercel employee who had signed up to Context AI with an enterprise account and clicked "allow all," with Vercel working with Mandiant on a breach allegedly being sold for $2 million. The episode emphasizes that MFA may not mitigate OAuth abuse, urges admin-managed consent, continuous inventory and auditing of OAuth grants, and better visibility into risky third-party app access across Google Workspace and Microsoft 365.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Special Edition Intro 00:14 Sponsor Message Meter 00:33 Supply Chain Hack Setup 01:16 Breach Seen In Wild 02:36 Meet Jamie Blasko 02:56 Who Is Vercel 04:34 How The Breach Happened 05:58 Context AI And Shadow IT 07:58 OAuth Controls And Audits 09:11 Impact And Open Questions 11:24 Why MFA Falls Short 12:22 Where To Get Help 14:07 Host Takeaways OAuth Risk 14:53 What To Do Next 16:06 Wrap Up And Feedback 16:42 Sponsor Close Meter 17:24 Final Sign Off
Vercel Supply-Chain Breach via AI Tool, Meta Sued Over Scam Ads, and Ransomware Surges with "The Gentleman"
David Shipley covers new details on the Vercel breach, which began when an employee used the third-party AI tool Context AI; after Context AI was breached, attackers leveraged Google OAuth access to pivot into Vercel systems and enumerate unencrypted "non-sensitive" environment variables that contained usable secrets, with a hacker claiming Vercel data and source code and demanding $2M, while Vercel says Next.js and other open-source projects are safe and shares Google OAuth indicators of compromise. The episode also discusses a proposed class-action lawsuit alleging Meta misled users about scam ads and profited from them, noting Meta's claim it removed 159M scam ads and shut down nearly 11M criminal accounts. Finally, it cites ZeroFox data showing ransomware incidents holding steady at 2,059 in Q1 2026 and highlights Check Point research indicating "The Gentleman" has a much larger victim footprint and uses tactics like disabling Defender, re-enabling SMB1, abusing GPO, and targeting VMware environments.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Headlines and Sponsor 00:46 Vercel AI Supply Chain Breach 02:50 Meta Sued Over Scam Ads 04:55 Ransomware Numbers Q1 2026 06:46 Gentlemen Crew Exposed 08:56 Wrap Up and Thanks 09:42 Sponsor Message Meter
Microsoft Under Fire, NIST Scales Back NVD, FortiSandbox Critical Bugs, Vercel Breach Claims, Scattered Spider Member Pleads Guilty
Host David Shipley covers five major stories: researcher "Chaotic Eclipse" publicly released Windows exploits—first "Blue Hammer," then "Red Sun," a Microsoft Defender flaw enabling privilege escalation on fully patched Windows 10/11 and Server—amid claims Microsoft mistreated them, highlighting strain on responsible disclosure as vendors face mounting vulnerability volume and AI-driven bug discovery. NIST announced it can no longer fully enrich all CVEs in the National Vulnerability Database, prioritizing only exploited-in-the-wild issues, federal software, and critical software, leaving the rest backlogged. In "FortiWatch," two critical FortiSandbox flaws allow auth bypass and remote command execution; patches are available. Vercel confirmed attackers accessed internal systems and urges customers to review and rotate environment variables amid unverified ShinyHunters ransom claims. Finally, alleged Scattered Spider member Tyler Buchanan pled guilty to an $8M crypto theft case, with reporting describing the group's social engineering tactics and escalating real-world violence tied to cybercrime.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Headlines And Sponsor 00:49 Microsoft Bug Drop 03:00 Disclosure System Strain 05:59 NVD Backlog Crisis 08:47 FortiWatch FortiSandbox 11:43 Vercel Breach Fallout 14:43 Scattered Spider Guilty Plea 18:54 Wrap Up And Thanks
Cybersecurity Today Month-in-Review: RSAC AI Hype, Agentic Risks, Mythos Claims, and Real-World Resilience
Jim Love hosts a delayed March month-in-review with panelists David Shipley and Laura Payne, starting with RSAC takeaways: agentic AI everywhere, heightened marketing spectacle, and industry tension as AI becomes the new "cool kid." They discuss the surge of autonomous agents, including OpenClaw-style experimentation leading to stolen tokens and the ease of social-engineering LLMs, plus legal and brand risks of chatbots after the Air Canada precedent. The panel debates Anthropic's source-code leak and "Mythos" messaging, while acknowledging AI tools are finding real zero-days amid massive technical debt and rising exploit speed, raising questions about liability and EU accountability. They highlight a positive case: Stryker Medical's rapid recovery after 80,000 devices were wiped via Intune settings, and note additional incidents targeting healthcare, critical infrastructure PLCs, supply-chain attacks, and longer-term impacts from major source-code thefts.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Show Intro Sponsor 00:22 Panel Welcome Setup 01:56 RSAC Vibes Agentic AI 03:19 Conference Hype Booths 06:32 AI Free Fridays Skills 08:12 Marketing Hype Filters 11:38 Agent Networks Gone Wild 16:00 Social Engineering LLMs 19:45 Chatbots Liability Law 23:13 Anthropic Leak Mythos 25:17 AI Code Quality Debate 29:28 Technical Debt Bug Mining 30:40 AI Hacking Era 32:09 Paying Down Tech Debt 32:54 Software Liability Shift 34:24 AI Pen Testing Scale 37:53 Token Costs and Proof 40:08 Canary Traps and Ethics 41:26 Blast Radius Resilience 44:17 Stryker Wipe Recovery 46:52 More Attacks Recap 50:07 Fast Cheap Code Debate 53:26 War Rules and Agents 56:32 Back to Basics Close 01:00:18 Final Thanks Sponsor
WebEx SSO Vulnerability, booking.com Reservation Hijacking Risks, Windows Recall Scrutiny, and AI Vishing-as-a-Service
Host Jim Love reports that Cisco disclosed a critical WebEx vulnerability (CVE-2026-2184) affecting SSO integration with Control Hub; although server-side fixes are applied and no exploitation is seen, SSO customers must update SAML certificate configuration to avoid disruption when the old certificate expires, amid recent Cisco firewall zero-day exploitation (CVE-2026-2131) tied to interlock ransomware. A booking.com breach exposed some customers' reservation data (names, contact and address details, reservation details, and messages) but not payment cards, increasing phishing "reservation hijacking" risk using real itinerary details. Researchers also highlight new concerns with Microsoft's Windows 11 Recall, where data may be intercepted after login via another process, though Microsoft says protections are intended. Finally, an underground $4,000 platform, ATHR, automates phishing/vishing with AI voice agents to steal verification codes and accounts across major services.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Top Security Headlines 00:32 Sponsor Message 00:50 WebEx Critical Flaw 02:36 Booking.com Breach Scams 05:20 Windows Recall Weaknesses 08:36 AI Voice Phishing Service 11:24 Wrap Up and Thanks
Android Mirax RAT, North Korea's Friend-Request Hacks, Adobe PDF Zero-Day, and FBI Phishing Takedown | Cybersecurity Today
David Shipley covers multiple trust-based cyber threats: Mirax Android malware pushed via Meta ads posing as free streaming apps, functioning as a remote access trojan and turning infected phones into residential proxies, amid reports of widespread scam advertising on Meta platforms. Researchers link a North Korean APT37 campaign to Facebook friend requests that shift to Messenger and Telegram before delivering a tampered PDF viewer that installs Rock Rat and exfiltrates data via Zoho WorkDrive. Adobe issues an emergency patch for an Acrobat/Reader zero-day where opening a PDF can expose files, seen targeting oil and gas with Russian-language lures. The FBI and Indonesian authorities dismantle the Wall phishing marketplace designed to bypass MFA via session-cookie theft, as similar services quickly rebound. The FBI reports Americans lost nearly $21B to cybercrime in 2025, driven by investment and crypto fraud, with growing AI-enabled scams.
00:00 Headlines And Sponsor 00:57 Mirax Android Proxy Malware 02:47 Meta Scam Ad Machine 05:01 North Korea Friend Request Hack 07:44 Adobe Acrobat Zero Day Patch 10:11 FBI Wall Phishing Kit Takedown 12:28 Why Takedowns And MFA Fall Short 15:02 Cybercrime Losses Hit $21B 18:16 Wrap Up And Thanks 18:55 Meter Sponsor Message
Mythos Sparks Urgent Bank Meetings, AI Shrinks Exploit Windows, CEO Phishing Beats MFA + Crypto Fraud Bust
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Host David Shipley covers urgent meetings among U.S., Canadian, and U.K. financial leaders after Anthropic's Mythos announcement, with regulators and major banks assessing potential systemic risk; Mythos is described as capable of finding and chaining zero-days and is limited to a preview program (Project Glasswing) with select critical infrastructure and tech firms. The episode highlights how fast vulnerabilities are now exploited, citing a critical Marimo flaw patched in 0.2.3.0 that attackers probed within 9 hours and research showing AI can generate exploits from CVEs in 10–15 minutes. It then details "Venom," an invitation-only phishing-as-a-service targeting executives via QR codes to hijack sessions and register new devices, and Microsoft's warning about Storm-2755 redirecting Canadian paychecks by stealing M365 session cookies and altering direct-deposit details. Finally, Operation Atlantic is summarized: authorities identified 20,000 crypto-fraud victims, froze $12M, and linked $45M in stolen crypto tied to approval phishing.
00:00 Headlines and Sponsor 00:57 Mythos Shakes Finance 04:58 AI Exploit Window Collapses 08:11 Venom Targets Executives 11:54 Payroll Redirect Scam 14:35 Crypto Fraud Takedown 16:47 Wrap Up and Thanks 18:04 Sponsor Outro
AI-Powered AppSec, OWASP Origins, and Anthropic's "Mythos" Model: Jeff Williams on What Changes Next
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Jim hosts Jeff Williams (Contrast Security co-founder/CTO and former OWASP global chair) for a wide-ranging discussion that begins with Anthropic's new "Mythos" model, described as powerful for finding zero-day vulnerabilities, and expands into how AppSec must evolve. Williams explains Contrast's runtime instrumentation approach, recounts OWASP's early days, the creation of WebGoat and the OWASP Top 10, and notes that many common vulnerabilities persist despite years of maturity models. They debate open source versus commercial security scrutiny, the likely high cost and scalability limits of advanced AI vulnerability discovery, and why finding more bugs matters only if remediation improves too. Williams argues for AI-powered "software factories" with feedback loops, assurance evidence, and runtime monitoring, and flags the EU Product Liability Directive treating software as a product with no-fault liability for security defects, including those from embedded open source.
00:00 AppSec Stuck in Ruts 00:42 Show Intro and Sponsor 01:40 What Contrast Security Does 02:35 OWASP Origins and WebGoat 04:33 Why the Top 10 Persists 06:28 Mythos Model Overview 08:05 Open Source Scrutiny Myth 11:31 Cost and Adoption Barriers 15:04 Finding vs Fixing Bugs 15:55 AI Code Quality Reality 17:46 AI Powered Software Factory 23:11 Building with AI in Practice 25:18 AppSec Metrics and New Approaches 26:42 Staying Optimistic as a CISO 28:00 EU Product Liability Shift 32:13 Bug Bounties in an AI World 34:06 Wrap Up and Outro
Fortinet EMS Zero-Day Exploited, Anthropic's AI Finds Thousands of Bugs, and Iranian Hackers Target US ICS
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Host David Shipley reports Fortinet issued emergency hotfixes for a new actively exploited FortiClient EMS unauthenticated RCE zero-day (CVE-2026-35616) affecting 7.4.0.5/7.4.0.6, with over 2,000 exposed instances online and a full fix coming in 7.4.0.7. Anthropic says its Claude "Mythos" model (Project Glasswing) has found thousands of high-severity zero days and demonstrated advanced exploit chaining and sandbox escape, but will not be released publicly; it is being used with major partners and funded with up to $100M in credits plus $4M for open-source security. A postmortem details a North Korea–linked social-engineering supply-chain breach of Axios on NPM, part of a broader campaign spreading 1,700+ malicious packages across multiple ecosystems. US agencies warn Iranian-linked hackers are targeting Rockwell/Allen-Bradley PLCs in critical infrastructure. The White House proposes a $707M cut to CISA, reducing staffing while preserving $1.4B for core cybersecurity.
00:00 Headlines and Sponsor 00:55 Fortinet EMS Zero Day 03:21 AI Finds Zero Days 05:56 Axios Supply Chain Breach 08:02 North Korea Package Campaign 10:13 Iran Targets Industrial Control 12:22 CISA Budget Cuts Debate 14:05 Wrap Up and Thanks 14:59 Sponsor Message Meter
Host David Shiple covers major cybersecurity news: investigators attribute a record $285 million April 1 hack of crypto platform Drift Protocol to North Korea, describing a three-week setup involving a fake "Carbon Vote Token," wash trading to inflate value, social engineering to pre-approve backdoored transactions, Drift's removal of a timelock, and rapid collateralized withdrawals that crashed Drift's token and are now tracked by TRM Labs; the report notes North Korea's 2025 crypto theft total of $2.5B and lifetime total surpassing $7B after this incident, alongside mention of a North Korea-linked supply-chain compromise of the widely used Axios package. Stryker Medical says it has fully recovered from a March 11 Iran-linked wiper attack that used a compromised admin account and Microsoft Intune, prompting Microsoft guidance on multi-admin approval for wipes. The FBI labels a suspected China-linked breach of a U.S. surveillance system a "major incident," likening it to the 2024 Salt Typhoon campaign, while Sen. Mark Warner cites staffing cuts and leadership turmoil at CISA. TechCrunch reports embattled compliance startup Delve faces new claims it repackaged an open-source tool (Sim Studio) as its own "Pathways," as Delve denies broader fraud allegations, says it was targeted by a malicious actor, and Y Combinator cuts ties.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Headlines And Sponsor 00:54 North Korea Crypto Heist 01:16 How The Drift Hack Worked 03:20 Bigger DPRK Crypto Trend 04:24 Stryker Wiper Recovery 06:39 China Breach Major Incident 08:38 Policy And Staffing Fallout 09:37 Delve Startup In Crisis 10:29 Stolen Software Allegations 13:12 Delve Fights Back YC Cuts Ties 14:35 Wrap Up And Thanks 15:12 Sponsor Message Meter
00:00 Headlines And Sponsor 00:54 North Korea Crypto Heist 01:16 How The Drift Hack Worked 03:20 Bigger DPRK Crypto Trend 04:24 Stryker Wiper Recovery 06:39 China Breach Major Incident 08:38 Policy And Staffing Fallout 09:37 Delve Startup In Crisis 10:29 Stolen Software Allegations 13:12 Delve Fights Back YC Cuts Ties 14:35 Wrap Up And Thanks 15:12 Sponsor Message Meter
EV Charging Infrastructure Security: How Hackers Could Disrupt Chargers, Networks, and the Grid
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
In this holiday weekend edition of Cybersecurity Today, Jim Love introduces David Shipley's interview with Steve Visconti, CEO of Xiid Corporation, about cybersecurity risks in electric vehicle (EV) charging infrastructure. Visconti explains Xiid's software-based security layer for IP networks, aimed at critical infrastructure across enterprise, public sector, and DOD environments, and its growing focus on OT/IoT such as EV charging systems. The discussion highlights how EV chargers connect vehicles, homes, back-office billing/control systems, cloud services, and potentially vehicle-to-grid power flows, creating large-scale attack surfaces that could enable disruption, DDoS activity, or broader grid instability. Visconti argues for "unreachability" architectures that close ports and remove static exposure while allowing only registered users and machine-to-machine access. The interview also touches on concerns about vulnerabilities leading to fires, supply-chain risks, and policy debates such as government-accessible vehicle kill switches.
00:00 Holiday Weekend Intro 01:46 Meet Steve Visconti 04:16 EV Charging Symposium 06:40 Vehicle to Grid Risks 09:16 Fires and Attack Vectors 12:14 Making Chargers Unreachable 14:37 Car as the Threat 19:05 Awareness and DDoS Reality 23:09 Government Kill Switch Debate 24:49 Wrap Up and Sponsor Thanks
Cisco Source Code Stolen in Trivy Fallout, Axios Supply Chain Attack, and Active Exploitation of Fortinet and Citrix Flaws
David Shipley reports multiple major security incidents: attackers used credentials stolen in the Trivy supply-chain attack via a malicious GitHub action to breach Cisco's internal development environment, clone 300+ GitHub repos, steal source code (including AI products) and AWS keys, and impact customer-related code; Cisco contained the breach, re-imaged systems, and rotated credentials. A separate supply-chain attack hit the widely used JavaScript library Axios after its maintainer account was compromised, pushing poisoned NPM versions that installed a dropper/RAT via a fake dependency; users are told to downgrade affected versions, remove the dependency, rotate credentials, and review CI/CD logs. Active exploitation is confirmed for a Fortinet FortiClient EMS SQL injection (CVE-2026-21643) and for critical Citrix NetScaler flaws (CVE-2026-3055, possibly alongside CVE-2026-4368). Anthropic accidentally exposed details of a new model, "Code Mythos," described as highly capable in reasoning, coding, and cybersecurity. Finally, TechCrunch reports escalating allegations that compliance startup Delve helped fabricate audit evidence and worked with weak auditors. The episode also marks show episode 1,500.
00:00 Headlines and Sponsor 00:54 Cisco Trivy Breach 02:28 Axios NPM Attack 04:12 Fortinet SQLi Exploited 06:24 Citrix Bleed Returns 08:05 Anthropic Model Leak 10:24 Fake Compliance Scandal 12:30 Episode 1500 Milestone 14:03 Sponsor Closing Message
Mac Malware 'Infinity Stealer,' DarkSword iOS Exploits, China Telecom Espionage & TeamTNT Supply Chain Hits
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
David Shipley reports from Seoul on major threats: Malwarebytes details Infinity Stealer, a new macOS info-stealer delivered via "ClickFix" social engineering and built as a compiled Python payload (Nuitka) that steals browser credentials, Keychain data, crypto wallets, and developer secrets while notifying attackers via Telegram. Proofpoint links Russia-aligned TA446 (Cold River/Star Blizzard) to spear-phishing using the DarkSword iOS exploit kit to deliver GhostBlade, with DarkSword now leaked on GitHub and Apple pushing unusual on-device warnings for vulnerable iOS versions. Rapid7 describes China-linked "Red Menshen" using the kernel-level BPFdoor backdoor to persist in global telecom networks. TeamTNT compromises the Telnyx PyPI package with WAV-steganography payloads that steal secrets and target Kubernetes. Iran-linked activity includes a symbolic FBI director email breach and escalating, deliberate healthcare disruption via attacks on Stryker and a Pay2Key incident.
00:00 Show Intro and Sponsor 00:53 Mac ClickFix Stealer 03:25 Dark Sword iOS Exploits 06:30 China Telecom Backdoor 08:47 TeamTNT PyPI Supply Chain 12:20 Iran Cyber and Healthcare 17:41 Wrap Up and Thanks 18:43 Sponsor Message
RSAC Recap: Agentic AI Takes Over, Security Funding Shifts, and Why CISOs Must Focus on Resilience
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Jim Love and co-host David Shipley recap the RSA Conference in San Francisco, noting that "zero trust" marketing has faded and "agentic AI" (especially "agentic SOC") dominated vendor messaging. David highlights a major market shift: AI is pressuring cybersecurity company valuations and could reduce funding, accelerate consolidation, and raise security costs due to heavy compute requirements, even as demand increases. They discuss how AI disproportionately benefits attackers, including new phishing-as-a-service capabilities, while organizations cut security hiring in anticipation of AI gains. David's standout booth, MindGuard, used a 1990s metaphor to argue AI security is as immature as cybersecurity was decades ago. He also interviews Commvault CSO Bill O'Connell on the evolving CISO role, communicating risk, the importance of recovery and "ResOps," and celebrating CISOs, including Time magazine's CISO of the year concept.
00:00 Weekend Show Kickoff 00:46 RSAC Recap Setup 01:06 Zero Trust Is Dead 01:48 Agentic SOC Everywhere 03:41 AI Shifts Security Valuations 06:55 Peak Security And Consolidation 07:55 Costs And Layoffs Warning 09:35 Attackers Gain The Edge 11:48 RSAC Booth Spectacle 13:39 MindGuard Nineties Metaphor 15:40 Commvault CISO Interview Begins 17:22 Backup To Cyber Resilience 18:04 Modern CISO Role Evolution 19:55 Translating Risk For Leaders 21:44 Risk Versus FUD 22:22 AI Hype And CISO Relevance 23:29 Defining AI And Controls 24:33 Agentic AI And Backups 25:49 Resilience Over Prevention 27:52 ResOps And Practicing Recovery 31:06 Advice For New CISOs 33:30 Celebrating The CISO Role 35:43 Is The Job Worth It 37:06 Host Wrap And Audience Feedback 39:18 Korea Trip And Show Signoff 40:13 Sponsor Message And Closing
Anonymous Tip System Breach Exposes Millions of Records, Google Warns Q-Day by 2029, and New AI Documentation Supply-Chain Risks
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Jim Love reports that a breach at P3 Global Intel, whose tip-submission systems are used by police, government agencies, and schools, allegedly exposed over 8 million submissions including highly sensitive personal data and raised concerns about anonymity due to features that could disclose tipster IP information; the company says it has not confirmed misuse. Google warns "Q Day," when quantum computers could break widely used public-key encryption, may arrive as early as 2029, intensifying urgency around "harvest now, decrypt later" and adoption of post-quantum cryptography standards. The episode also highlights AI-era supply-chain threats where community-generated documentation can be poisoned with indirect prompt injections that influence AI-generated code, and notes upcoming GitHub Copilot policy changes to use prompts and code context from certain users for training unless they opt out, making data governance critical.
00:00 Headlines And Sponsor 00:45 Anonymous Tip Line Breach 03:42 Quantum Q Day Timeline 06:10 Poisoned Documentation Attacks 08:57 Copilot Training Data Changes 10:27 Wrap Up And Meter Thanks
RSAC: Retiring "APT," FCC's US-Made Router Ban, Zoom Call Scraping, Iran-Targeting Wiper, and Cyber Terrorism Insurance
From RSAC 2026, host David Shipley highlights ESET researcher Robert Lipowsky's argument to retire the overused "advanced persistent threat" label and instead describe actors by motivation and activity, noting blurred lines between nation-state and criminal tooling. He also reports RSAC vendor trends (zero trust fading, "agentic AI" everywhere) and standout booth themes. In Washington, the FCC bans authorization of any new Wi‑Fi router models not made in the United States, citing supply-chain risk and attacks like Volt Flax and Salt Typhoon, impacting an industry largely manufacturing abroad unless exemptions are granted with plans to reshore. The episode details Webinar TV allegedly joining public Zoom links to record calls and publish AI-generated podcast recaps, and a Kubernetes-targeting campaign linked to the Trivy supply-chain attack that deploys an Iran-checking wiper. Finally, Treasury seeks comments on expanding the terrorism risk insurance backstop (TRIP) to cover cyber losses.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Meter Intro 00:18 Headlines Preview 00:58 Retiring The APT Label 02:51 RSAC Floor Trends 05:08 FCC Router Ban 06:43 Zoom Calls Turned Podcasts 09:29 Iran Targeting Wiper 10:57 Cyber Terrorism Insurance Debate 13:15 Wrap Up And Thanks 13:44 Sponsor Meter Outro
Compliance Startup Audit-Faking Claims, Trivy Supply-Chain Backdoor, Russia Targets Signal/WhatsApp, and Iran-Linked Stryker Disruption
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
This episode covers allegations that Y Combinator-backed compliance startup Delve helped customers fake privacy and security audits by generating fabricated evidence that auditors then rubber-stamped, alongside Delve's denial and a report of sensitive Delve data being externally accessible. It also details a TeamTNT/Team PCP-style supply-chain compromise of Aqua Security's Trivy scanner via GitHub build and tag tampering, briefly distributing a backdoored release that stole cloud credentials, SSH keys, tokens, and more, with guidance to treat affected environments as fully compromised and rotate secrets. The FBI and CISA warn of Russian intelligence-linked phishing targeting Signal and WhatsApp accounts through social engineering and malicious QR codes. Finally, it describes the real-world impact of an Iran-linked Handala cyberattack on Stryker, disrupting custom implant logistics and delaying surgeries.
00:00 Sponsor Message Meter 00:18 Headlines Overview 00:48 Delve Audit Allegations 03:27 Trivy Scanner Backdoor 06:01 Russian Phishing Signals 08:54 Stryker Attack Fallout 11:30 Wrap Up And RSAC 11:48 Sponsor Message Meter
Cybersecurity Isn't Managing Risk—It's Managing Threats... And That's the Problem
Host David Shipley speaks with Jeff Gardiner, a former university CISO and now at Morgan Stanley, about Gardiner's doctoral research arguing that cybersecurity has structurally misclassified "risk management" as threat management.
Gardiner explains that real risk is an expected loss calculation (impact × likelihood), while many cybersecurity frameworks and training emphasize vulnerabilities, exploitability, and system configuration without likelihood or business impact. He describes examples where teams labeled unlikely issues as "extremely high risk," discusses interviews where leaders universally expect cybersecurity staff to be risk managers, and cites findings that only about 11% of cybersecurity professionals actually perform risk calculations. Gardiner outlines a practical approach using qualitative likelihood and impact scales, prioritization, and clearer business framing, and notes ongoing discussions with NIST to improve the NICE framework.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message 00:19 Meet Jeff Gardiner 01:51 Career Journey Origins 03:23 TLS Risk Epiphany 05:06 What Is Compute Canada 06:38 Risk Versus Threat 08:35 Why Labels Matter 11:13 Likelihood And Impact 12:26 Teaching Risk Qualitatively 15:29 Why Prioritize Risk 20:36 Training Frameworks Flaw 25:13 Research Frustrations 25:51 Risk Management Wins 26:44 Why CISOs Burn Out 27:43 Speaking Executive Risk 29:22 Teach Risk Broadly 31:36 Biases and Better Judgments 35:17 Sexy Scary vs Real Risk 36:12 Convincing the Room 39:15 Start Simple Frameworks 41:36 Risk Quadrants and Delegation 45:30 Mentorship and NIST V3 47:57 Wrap Up and Sponsor
FBI Seizes Iran-Linked Handala Leak Site After Stryker Intune Wipe Attack; Apple iPhone Exploit Patch; North Korean Fake IT Workers Grow
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
The episode reports that the FBI has seized the data leak site used by the Iran-linked hacktivist group Handala, which has been widely linked to the Stryker attack where attackers compromised admin accounts, stole data, and used Microsoft Intune to remotely wipe and factory reset roughly 80,000 managed devices. CISA and Microsoft warn organizations to harden Intune and identity controls with least privilege, role-based access, MFA, conditional access, and requiring multi-admin approval for sensitive actions like device wipes. Apple urges iPhone users to update after fixing actively exploited flaws used in targeted, sophisticated campaigns, noting risks even for those who think Apple devices aren't targeted. The show also highlights new FLAIR research showing North Korean operatives continue infiltrating Western firms as remote IT workers using stolen or fabricated identities, exploiting weak hiring verification and broad access.
LINKS https://flare.io/learn/resources/north-korean-infiltrator-threat
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:46 FBI Seizes Handala Leak Site 02:31 CISA And Microsoft Intune Guidance 04:37 Apple iPhone Update Warning 06:10 North Korean Fake IT Workers 07:56 Links Sharing And Wrap Up 08:29 Sponsor Thanks And Sign Off
Medical Device Breaches, Anti-Scam Pledge Scrutiny, AI Font Trick, and Iran-Linked Cyber Updates.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
The episode covers several cybersecurity stories: Intuitive Surgical disclosed a March 12 phishing-led intrusion where stolen credentials enabled access to its internal administrative network and data theft (customer/business contacts and employee records), while clinical platforms and Da Vinci/Ion systems remained unaffected. Eleven tech and retail firms including Google, Amazon, and OpenAI pledged to share threat intel on scams, amid skepticism and Verafin figures estimating $4.4T in global financial crime in 2025 and rising AI-driven fraud. LayerX demonstrated a font/CSS "glyph substitution" technique that shows humans a malicious command while AI assistants read benign text; Microsoft addressed it, while others deemed it out of scope. In Iran-war updates, senior Iranian cyber figures were reportedly killed; Iran-linked group Handala's Stryker attack allegedly wiped nearly 80,000 devices via compromised admin accounts and Intune, with further unverified leak claims. Denver crosswalk speakers were hacked due to default passwords.
00:00 Sponsor Message Meter 00:19 Medical Device Breach 01:52 Phishing Still Wins 02:32 Tech Pledge Against Scams 03:43 Fraud Numbers And AI 05:49 Font Trick AI Bypass 07:22 Vendor Responses Lessons 09:03 Iran Cyber War Updates 10:00 Stryker Intune Wipe Attack 11:07 More Iranian Claims 12:17 Denver Crosswalk Hack 13:10 Wrap Up And Signoff 13:33 Sponsor Outro Meter
Alleged Canadian 'The Comm' Hacker Arrested, Interpol's Operation Synergia Takedown, Stryker Cyberattack Update and more..
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Host David Shipley covers new details on the alleged takedown of "Waifu," a Canadian hacker tied to the cybercrime group The Com, after a harassment campaign against investigator Allison Nixon helped lead to his identification and arrest; he now faces U.S. charges including extortion and unauthorized computer access. The episode also highlights Interpol's six-month Operation Synergia, a major international crackdown that disabled 45,000 malicious IPs and led to 94 arrests across 72 countries, targeting ransomware, phishing, and malware infrastructure. An update on Stryker describes an attack on its Microsoft corporate systems allegedly involving Intune to wipe over 200,000 devices, with Stryker saying connected medical devices and services remain safe while ordering and operations are disrupted. Finally, Poland reports it stopped an attempted hack on its National Center for Nuclear Research that may have Iranian links, though officials caution indicators could be misdirection.
00:00 Sponsor Meter Intro 00:19 Headlines And Welcome 00:50 Calm Hacker Takedown 02:49 Threats Against Researcher 04:21 Unmasking And Arrest 05:46 Interpol Operation Synergy 08:10 Stryker Intune Attack Fallout 12:56 Iran Cyber War Updates 13:43 Poland Nuclear Hack Attempt 16:14 Wrap Up And Thanks 16:52 Sponsor Meter Outro
Gemini in Google Workspace, Agentic AI, and Managing AI Anxiety (with Accenture's Krish Banerjee)
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
In a special edition of Project Synapse shared with Cybersecurity Today, host Jim Love and co-host John Pinard (a VP and CSO at a Canadian financial institution) speak with Krish Banerjee, Accenture's managing director and partner leading AI in Canada. They discuss Google integrating Gemini into Workspace and how AI assistants like Gemini and Microsoft Copilot are converging, along with recent moves around agent platforms and the business models of AI, including Meta and Nvidia's evolving strategies and Nvidia's push toward enterprise agent infrastructure amid rapidly rising compute demand. The conversation explores why AI adoption lags capability, emphasizing task-based redesign, human-in-the-loop guardrails, and not "AI-washing" broken processes. They also address AI anxiety, training and culture change, impacts on education and jobs, and practical ways to use agents to stay informed and productive.
00:00 Sponsor Message 00:20 Show Intro and Guests 01:12 Gemini Comes to Workspace 03:38 AI Tool Leapfrogging 05:06 Agent Network Acquisitions 07:53 Nvidia Bets on Enterprise Agents 11:08 Why AI Adoption Lags 14:27 Agentic AI and Process Redesign 16:19 Security Guardrails and Human Oversight 24:05 Accenture Transformation and Training 26:55 AI Anxiety in the Workplace 30:22 Tasks Not Jobs 32:12 Outcome First Thinking 34:15 Personal AI Assistants 37:24 Building Agents Together 38:35 Executive Learning Curve 44:31 Kids And AI Natives 50:15 Critical Thinking And Trust 54:15 Company Advice Focus Value 55:58 Wrap Up And Sponsor
AI Agent Hacks McKinsey Chatbot in 2 Hours, NPM Phantom Raven, Router Malware & Trojaned AI Models
This episode covers how researchers at CodeWall used an autonomous AI security agent to gain read/write access to McKinsey's internal chatbot Lilli database in about two hours by chaining exposed APIs and an SQL injection, potentially exposing 46.5 million chats, 728,000 files, 57,000 accounts, and 95 system prompts, with McKinsey saying the issues were fixed and no unauthorized access was found. It also reports on the Phantom Raven supply-chain campaign that published 88 malicious NPM packages using a runtime-downloaded payload to steal developer system data like SSH keys and host details. A study warns that 83% of 800 million compromised passwords still meet complexity rules, highlighting credential-stuffing risk and the need for breach checks and MFA. The show notes 14,000+ routers infected with persistent malware often requiring factory resets plus hardening, and discusses Trojan backdoors embedded in AI models that trigger misbehavior under specific inputs, calling for new AI security testing and validation.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Meter Intro 00:20 Headlines And Welcome 00:55 AI Agent Hacks McKinsey Bot 03:44 Phantom Raven NPM Malware 05:55 Strong Passwords Still Leaked 07:55 Router Malware That Persists 09:36 Trojan Backdoors In AI Models 12:01 Call For AI Backdoor Research 12:30 Sponsor Meter Outro 13:13 Sign Off
This includes our regular Wednesday/Thursday segment but with an update from this breaking story on the attack on a large US medical company.
Fake Claude Code Installs, Arpa Phishing, Zombie ZIP Malware Evasion, and Iran/Israel Cyber Retaliation
This episode covers four major security stories: the "InstaFix" campaign using Google sponsored ads and cloned Claude Code install pages to trick developers into pasting terminal commands that deploy the TeraStealer credential-stealing malware; a phishing technique abusing the special-use .arpa domain and IPv6 reverse DNS to evade email and domain-based defenses, using attacker-controlled DNS zones, traffic distribution systems, and lures like surveys and account notices; the "Zombie ZIP" technique that manipulates ZIP headers to bypass AV/EDR scanning, tied to CVE-2026-0866 and demonstrated to evade most VirusTotal engines; and a surge in pro-Iranian and pro-Russian hacktivist retaliation targeting Israel and regional entities with DDoS, defacements, breach claims, and disinformation, alongside Israel's humorous counter-psychological video response.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:51 Fake Claude Install Scam 04:25 Arpa Domain Phishing 08:30 Zombie Zip Malware Trick 10:57 Cyber Retaliation Surge 13:44 Israel's PSYOP Video 14:25 Wrap Up And Sponsor
Coruna iOS Exploit Kit Goes Mass-Market, FBI Wiretap Platform Breach Probe, Windows Terminal ClickFix, and Iran-War Cyber Escalation
This episode covers several major cybersecurity developments: Google's Threat Intelligence Group details Coruna, a sophisticated iOS exploit kit with 23 exploits and multiple chains affecting iOS 13–17.2.1, shifting from targeted surveillance use to cryptocurrency-scam distribution and a PlasmaLoader payload aimed at stealing wallet data. The FBI is investigating suspicious activity involving its Digital Collection System Network used to support wiretaps and surveillance, with concerns about third-party vendor exposure and broader federal agency targeting. Microsoft reports a new ClickFix variation that abuses Windows Terminal to deploy the Luma Stealer via encoded commands, persistence, Defender exclusions, and browser injection. The show also reviews Iran-linked cyber activity by MuddyWater and others amid regional conflict, including new backdoors and cloud-based exfiltration, and reports that Iranian drone strikes hit AWS data centers in the UAE and Bahrain, causing outages and highlighting data centers as battlefield targets.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:50 Coruna iOS Exploit Kit 04:06 FBI Wiretap Platform Breach 06:52 ClickFix Hits Windows Terminal 10:00 Iran War Cyber Campaigns 14:59 Drones Hit AWS Data Centers 17:57 Wrap Up And Thanks 18:35 Sponsor Close Meter
Cybersecurity Today Month in Review: Iran Conflict Cyber Spillover, IoT Cameras, AI Hacking Tools, and Resilience Planning
In this weekend month-in-review episode, host Jim Love and panelists David Shipley, Laura Payne, Neil Bisson, and Chris "CJ" Johnson discuss cyber and infrastructure impacts tied to the US/Israel–Iran conflict, including reported compromise of traffic camera networks for targeting, Iran's defensive internet shutdown, propaganda via a hacked prayer app, and GPS/AIS spoofing that misdirected ships in the Strait of Hormuz, raising oil and helium supply-chain concerns. They warn of potential Iranian retaliation via DDoS, ransomware, and critical infrastructure attacks (especially water/OT), amplified by insecure IoT and camera vulnerabilities (e.g., Hikvision). The group critiques weakened government cyber capabilities (including CISA turmoil and CVE program risk), highlights AI-enabled attack automation (CyberStrike AI) shrinking time-to-exploit, and stresses practical resilience planning, including protecting AI API keys after an $82,000 billing incident and noting a law-enforcement takedown of LeakBase.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message Meter 00:18 Meet the Panel 01:41 MSPs and Security Assumptions 03:36 War and Cyber Spillover 06:52 Iran Internet Shutdown Explained 08:27 GPS Spoofing in Strait 10:32 Retaliation Risks to West 17:02 IoT Cameras as Targets 18:56 What IT Providers Should Do 22:03 Who Should Worry Most 26:18 Regulation and IoT Standards 28:58 Supply Chain and State Actors 31:36 CISA and CVE Turmoil 35:53 Ring Backlash and Big Tech 37:43 OpenAI Alerts and Privacy 39:25 AI Cultural Blind Spots 40:05 Therapy Duty to Report 41:17 Licensing AI Advice 42:16 Data Centers Under Fire 43:59 Continuity Without Claude 45:05 Power Grid Reality Check 46:47 MSPs and AI Dependence 49:58 Hype Versus Security Markets 51:02 CyberStrike AI Tooling 56:37 Nation State Plausible Deniability 59:58 Exploit Speed and Software Debt 01:03:37 Practical Tips and Wrap Up
Wikipedia JavaScript Worm, ICE Contractor Data Leak Claim, and Leak Base Takedown
Wikipedia admins contained a self-propagating JavaScript worm that spread via infected user script files, executing in logged-in editors' browsers and using authenticated sessions to copy itself into other scripts, sometimes affecting global scripts; administrators restricted edits, reverted and suppressed changes, replaced compromised scripts, and continue investigating the originating account.
A hacktivist group calling itself the Department of Peace claims it leaked records tied to DHS's Office of Industry Partnership involving 6,681 organizations that applied for ICE-related contracts, releasing the dataset via Distributed Denial of Secrets, while DHS has not confirmed the breach or data authenticity.
Finally, the FBI, Europol, and partners dismantled the Leak Base cybercrime forum, seized its database, conducted arrests and searches, and warned suspects through the forum's channels.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message 00:19 Headlines Intro 00:42 Wikipedia Worm Attack 01:19 How The Worm Spread 02:08 Containment And Lessons 02:53 Hacktivists Leak ICE Data 04:47 Leak Base Takedown 06:10 Database Seizure Fallout 07:12 Wrap Up And Weekend Preview 07:30 Sponsor Closing
AI-Driven Warfare, Open-Source Attack Tooling, CISA Shakeups, Healthcare Ransomware, and GPS Jamming Risks
Host David Shipley covers reports that hacked Tehran traffic cameras and an AI-powered targeting system helped a joint U.S.-Israeli operation ("Epic Fury") track and strike Iran's leadership, highlighting the growing role of compromised infrastructure and AI in modern conflict. Researchers also link the open-source toolkit Cyber Strike AI to automated attacks against Fortinet FortiGate devices, compromising over 600 systems across 55 countries and raising concerns about proliferating offensive AI tools. At CISA, CIO Robert Costello resigns amid leadership turmoil and staffing challenges. Healthcare ransomware disruptions include a University of Hawaii Cancer Center breach affecting nearly 1.2 million people and a major attack on the University of Mississippi Medical Center that shut clinics and disrupted Epic EMR access. Finally, GPS/AIS jamming and spoofing in the Middle East threatens shipping safety and global trade.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message 00:17 Headlines Overview 00:48 Epic Fury AI Warfare 04:12 Cyber Strike AI Toolkit 07:06 CISA CIO Resignation 09:06 Hawaii Cancer Center Breach 11:27 UMMC Ransomware Shutdown 13:53 GPS Jamming Shipping Risk 16:33 Wrap Up And Sponsor
OpenClaw AI Agent Hijack, CISA Leadership Shakeup, Iran Cyber Campaign, Air-Gap Malware, and Robot Vacuum Flaw
Jim Love covers multiple cybersecurity stories: Oasis Security revealed "ClawJacked," a high-severity OpenClaw AI agent framework flaw caused by missing rate limiting on the local gateway, enabling malicious web pages to brute-force passwords via WebSockets, register a trusted device, and take over agents; OpenClaw patched it within 24 hours and users are urged to update to version 2020 6.2 0.25 and tighten governance for non-human identities. CISA sees a leadership change as acting director Madhu Gottumukkala steps down amid criticism and reports he uploaded sensitive contracting documents to public ChatGPT and canceled key security tool contracts; Nick Anderson becomes acting director. The episode also discusses a coordinated cyber campaign alongside US/Israeli operations against Iran and risks of Iranian retaliation against exposed US critical infrastructure, North Korea's Scarcruft using "Ruby Jumper" to bridge air-gapped networks via USB, and a DJI Romo robot vacuum MQTT flaw that exposed control and camera access across 7,000 devices before being patched.
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:46 Claw Jacked AI Agents 02:21 CISA Leadership Shakeup 06:02 Cyber Front In Iran War 08:48 North Korea Air Gap Breach 10:06 Robot Vacuum Takeover 13:04 Wrap Up And Thanks
Identity, AI Agents, and the Session Token Time Bomb | Carey Frey (CSO, TELUS) on Cybersecurity Today
In this Cybersecurity Today weekend edition, David Shipley interviews Carey Frey, Chief Security Officer at TELUS, about the evolution of identity security and why it's a growing risk in the age of generative and agentic AI. Frey recounts his career from Canada's Communications Security Establishment to leading TELUS's internal security and managed cybersecurity services, then explains how convenience-driven identity decisions led from PKI's unrealized promise to passwords, bearer/session tokens, and today's widespread session cookie theft. He describes lessons from TELUS's deployment of FIDO2 phishing-resistant tokens, the dangers of long-lived SSO tokens across SaaS ecosystems, and how agentic "auto-browse" could amplify harm via the "lethal trifecta" and ephemeral agents with poor auditability. Frey highlights the Syne/SignNet CISO Identity Handbook and calls for stronger cryptographic roots of trust, proof-based tokens, re-authentication across trust domains, and fine-grained delegation guardrails.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message 00:24 Weekend Edition Intro 00:32 Meet Carey Frey 02:07 Carey's Cyber Origin Story 03:47 Telus Security Two Hats 06:22 Identity's Broken Legacy 08:43 Why PKI Didn't Win 11:25 Passkeys Missed Moment 14:10 SSO Tokens Surprise 19:50 Session Theft Reality 23:18 Agentic AI Stakes 24:17 Building Identity Playbook 25:24 Identity Maturity Model 25:49 Fixing OAuth and SAML 27:00 Industry Call to Action 27:37 Where to Find the Handbook 28:06 Not a Vendor Pitch 30:13 Agentic AI Identity Gaps 31:30 Auto Browse Threat Scenario 33:12 Lethal Trifecta Explained 34:31 Ephemeral Agents and Forensics 37:08 Supply Chain Agent Malware 38:20 Crypto Roots of Trust 39:35 Proof Tokens and Reauth 40:17 Delegation Guardrails 42:34 Regulation or Market Forces 44:25 Practical Risk Decisions 46:20 Wrap Up and Next Resources 48:00 Sponsor and Closing Credits
Cisco SD-WAN Bug Actively Exploited, MCP Azure Takeover Demo, CarGurus Data Leak, and Secret Service Scam Recovery
Host Jim Love covers four cybersecurity stories: CSA warns a critical Cisco Catalyst SD-WAN controller vulnerability (CVE-2026-20127) has been exploited since 2023, enabling authentication bypass and rogue peering sessions, and orders U.S. federal agencies to inventory systems, collect logs and forensic artifacts, hunt for compromise, and apply Cisco's fixes by 5:00 PM ET on February 27, 2026, with no workarounds. At RSA, researchers show how flaws in Model Context Protocol (MCP)—a key integration layer for agentic AI—could lead to remote code execution and even Azure tenant takeover, highlighting rising enterprise risk. ShinyHunters reportedly published 12.4 million stolen CarGurus records, raising phishing and fraud concerns tied to vehicle shopping and financing context. Finally, an Ontario tech support scam victim recovers funds through coordinated work by Ontario Provincial Police and the U.S. Secret Service, which traced and froze the money in time.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
LINKS Cisco Advisory Cisco Security Advisory – CVE-2026-20127 Authentication bypass vulnerability in Cisco Catalyst SD-WAN https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
CISA Supplemental Hunt and Hardening Guidance (Cisco SD-WAN Systems) https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems
Threat Hunt Guide (Technical PDF) Cisco SD-WAN Threat Hunt Guide (jointly referenced in federal guidance) https://media.defense.gov/2026/Feb/25/2003880299/-1/-1/0/CISCO_SD-WAN_THREAT_HUNT_GUIDE.PDF
00:00 Sponsor Message 00:19 Cisco SD-WAN Under Attack 02:48 MCP Azure Takeover Demo 05:28 CarGurus Data Dump 07:16 Secret Service Scam Recovery 09:24 Closing Sponsor Thanks
Discord Drops Persona Age Verification, SolarWinds Serv-U Critical RCEs, Splunk Windows Priv Esc, and Smart TV Screenshot Surveillance Lawsuits
In this episode of Cybersecurity Today, host Jim Love covers Discord ending its age-verification experiment with Persona after user backlash and researcher findings that Persona's front-end code suggested up to 269 verification checks, including watch list screening and risk scoring, amid already-thin trust following an earlier breach that exposed government ID images. The show also highlights SolarWinds Serv-U 15.5.0.4 patches for four critical (CVSS 9.1) remote code execution vulnerabilities (CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, CVE-2025-40541), noting they require high privileges and that self-hosted Windows/Linux instances must be upgraded, with estimates ranging from under 1,200 to over 12,000 internet-exposed servers. Splunk discloses a high-severity Windows privilege escalation flaw (CVE-2025-2386, CVSS 8.0) caused by incorrect install-directory permissions in versions before 10.0.0.2, 9.4.0.6, 9.3.0.8, and 9.2.10, enabling local users to potentially escalate privileges and tamper with logging. Finally, Texas Attorney General Ken Paxton sues Samsung, Sony, LG, Hisense, and TCL, alleging smart TVs use automated content recognition to capture screen content—potentially up to twice per second—and transmit it without meaningful consent, with implications for both home viewing and confidential business use; the episode emphasizes reviewing and disabling ACR settings and accounting for network-connected screens in security models.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor Message Meter 00:20 Discord Age Verification Backlash 01:37 Persona Code Raises Alarms 03:08 SolarWinds Serv-U Critical RCEs 04:51 Splunk Windows Priv Esc 06:18 Smart TV Screenshot Surveillance 08:35 Wrap Up and Sponsor Thanks
AI-Accelerated FortiGate Breaches, Amazon Kiro Prod Disruption, Claude Code Security, Salt Typhoon Warning, and Youth Radicalization Risks
Episode of Cybersecurity Today (hosted by David Shipley) covering: a Russian-speaking hacker using AI-written automation tools to breach 600+ Fortinet FortiGate firewalls across 55 countries by exploiting weak passwords and exposed management interfaces without MFA, with advice to lock down edge management access, enforce MFA, and strengthen password policies; an Amazon Kiro AI coding tool incident tied to a misconfigured role that allegedly deleted and recreated a production environment, causing a 13-hour disruption to AWS Cost Explorer services in one of two mainland China regions, prompting warnings about giving AI agents access to production and the need for guardrails and review processes; Anthropic's Claude Code Security launch, an AI-driven code vulnerability analysis feature that maps code interactions and data flows, provides severity and confidence scoring, keeps humans in the loop, and sparked stock drops for CrowdStrike and Cloudflare while noting limits for legacy code; an FBI warning that China-linked Salt Typhoon remains a serious threat in 80+ countries by exploiting basic weaknesses like unpatched systems, old code, reused passwords, and phishing, alongside concern over the FCC loosening US telecom cybersecurity requirements and calls for stronger critical infrastructure regulation and secure-by-default equipment; and a Canada-focused segment on youth online radicalization including a second RCMP terrorism peace bond in New Brunswick linked to the 764 extremist network (designated a terrorist organization in December 2025), plus reporting that the Tumbr Ridge, BC school shooting suspect had a ChatGPT account suspended in June 2025 and that OpenAI employees allegedly sought to notify authorities but were rebuffed, drawing condemnation from BC Premier David Eby and federal AI minister Evan Solomon and renewed calls for stronger cooperation, accountability, and intervention frameworks.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
00:00 Sponsor: Meter + Today's Cybersecurity Headlines 00:48 AI-Automated Hacking: 600+ FortiGate Firewalls Breached 02:25 How to Defend: Lock Down Edge Management, MFA, Strong Passwords 03:28 Amazon's Kiro AI Coding Tool Incident: 'Deleted Prod' and Lessons Learned 06:44 Claude Code Security: AI-Powered AppSec for Developers (and the Hype) 10:20 FBI Warning: Salt Typhoon Still Hitting Telecoms Worldwide 13:32 Youth Radicalization & AI Safety Failures: 764 Network and Tumblr Ridge Aftermath 18:12 Wrap-Up + Sponsor Message: Meter Demo Info
Jim Love discusses how rapid adoption of agentic AI is repeating the industry pattern of shipping technology without security, citing issues like vulnerabilities in Anthropic's MCP and insecure open-source agent tools. He interviews Ido Shlomo, co-founder and CTO of Token Security, who argues AI agents are fundamentally hard to secure because they are non-deterministic, have infinite input/output space, and often require broad permissions to be useful.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Shlomo proposes focusing security on access, identity, attribution, least privilege, and auditability rather than trying to filter prompts and outputs, and describes Token's "intent-based permission management" approach that maps agents and sub-agents as non-human identities tied to their purpose and allowed actions. The conversation covers real-world risks such as developer tools like Claude Code running with extensive access, widespread over-provisioning of admin permissions and API keys, exposure of unencrypted local token files, and misconfigurations that leak data publicly. Shlomo recommends organizations build governance processes for agents—discovery/inventory, boundary setting, continuous monitoring, and secure decommissioning—and says AI is needed to help police AI. He also highlights emerging trends like agent teams and multi-day autonomous tasks, and notes Token Security is a top-10 finalist in the RSA Innovation Sandbox 2026, planning to present an intent-and-access-focused security model for AI agents.
00:00 Sponsor: Meter's integrated networking stack 00:19 Why agentic AI security is breaking (MCP & open-source chaos) 02:53 Meet Token Security: practical guardrails for AI agents 04:57 Why you can't just ban agents at work (shadow AI reality) 06:24 Tel Aviv's cybersecurity pipeline: gaming, military, and startups 08:57 Why AI/agents are fundamentally hard to secure (new OS + 'human spirit') 13:44 Trust, autonomy, and permissions: managing the blast radius 18:17 Real-world exposure: Claude Code and the developer identity attack surface 20:16 A workable approach: treat agents as untrusted processes with identity + least privilege 22:33 Zero Trust for Agents: Access ≠ Permission to Act 23:27 Token's "Intent-Based Permission Management" Explained 25:29 Building the Identity Map: Tracing What Agents Touch 26:52 The Secret Sauce: Using AI to Secure AI in Real Time 28:10 Real-World Case: 1,500 Agents and Wildly Over-Provisioned Access 30:57 CUA 'Computer-Use' Agents: Exciting, Personal… and Terrifying 34:44 Secure-by-Default & Sandboxing: Fixing 'Always Allow' Dark Patterns 35:36 What Security Teams Should Do Now: Inventory, Boundaries, Governance 37:59 What's Next: Agent Teams and Multi-Day Autonomous Work 40:10 Tony Stark Vision: Agents That Improve the Human Experience 41:02 RSA Innovation Sandbox: Token's Big Bet on Intent + Access 43:01 Wrap-Up, Audience Q&A, and Sponsor Message
CISA Orders Emergency Patch for Actively Exploited Dell Flaw; Texas Sues TP-Link; Massive ID Verification Data Leak; SSA Database Leak Allegations
Host Jim Love covers four cybersecurity stories:
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
CISA ordered federal civilian agencies to patch an actively exploited critical Dell RecoverPoint for Virtual Machines vulnerability (CVE-2026-2769) within three days, citing hard-coded credentials that allow unauthenticated root access and links to a China-aligned threat cluster; Texas Attorney General filed suit against TP-Link alleging deceptive security and origin claims and risks tied to Chinese state-linked threats, while TP-Link denies the allegations and says it operates independently, stores U.S. user data on AWS, and bases core operations in the U.S.; researchers found an unsecured MongoDB database tied to AI-powered identity verification provider ID Merit exposing nearly 1 billion records with sensitive personal data, attributed to misconfiguration rather than compromise of the AI systems; and a MarketWatch report describes whistleblower Chuck Borges alleging SSA master data was copied to a cloud environment without oversight, contrasted by the Social Security Commissioner stating the core Numident database remained secure, with Love noting no confirmed public evidence but expressing concern about the implications if such foundational data were compromised.
00:00 Sponsor Message: Meter's Full-Stack Networking 00:19 Headlines: Dell Exploit, TP-Link Lawsuit, Massive Data Leak, SSA Claims 00:45 Urgent Patch Order: Actively Exploited Dell RecoverPoint CVE 02:19 Texas Sues TP-Link Over Router Security & China-Ties Allegations 03:31 AI Identity Verification Leak: Nearly 1 Billion Records Exposed 05:07 Did SSA Data Leak? Whistleblower vs. Official Denial 06:54 Host Take: What If the "Foundational" Database Was Compromised? 07:37 Wrap-Up + Sponsor Thanks and Where to Book a Demo
Info Stealers Target OpenClaw, a Robot Vacuum API Flaw Exposes Thousands, Best Buy Fraud Shows Zero Trust Context, and Canada Goose Data Leaked via Supplier
The episode covers multiple security incidents and lessons. Hudson Rock details how an info stealer malware infection can vacuum OpenClaw data, including authentication tokens, master keys, device private cryptographic keys, and the agent-defining soul.md file that can reveal a "mirror" of a user's life; the attack was not targeted, raising concerns about upcoming dedicated OpenClaw-stealing modules. A hobbyist coder using an AI coding tool to reverse-engineer DJI Romo communications unintentionally accessed roughly 7,000 robot vacuums in 24 countries, enabling live camera and microphone access and floor-plan generation due to missing messaging-level access controls; DJI also shares infrastructure with portable home battery stations and initially claimed the flaw was fixed before a live demonstration showed it was not. Two Best Buy cases illustrate that Zero Trust must consider behavior and context: a Florida employee allegedly used a manager override code 149 times from March–December 2024 to buy discounted electronics, costing about $120,000, while a Georgia case involved over $40,000 in merchandise leaving a store over two weeks amid claims of blackmail. Finally, ShinyHunters leaked about 600,000 Canada Goose customer records, but Canada Goose found no breach in its systems; the data was attributed to a third-party payment processor breach from August 2025, with records largely dating from 2021–2023, underscoring supply-chain risk and ongoing fraud/phishing potential. The episode is sponsored by Meter, which provides an integrated wired, wireless, and cellular networking stack for enterprises.
00:00 Sponsor: Meter + Today's Cybersecurity Headlines 00:44 Info-Stealer Jackpot: OpenClaw Tokens, Keys & 'soul.md' Exposed 03:17 DIY App, Real-World Disaster: 7,000 Robot Vacuums Exposed via DJI Servers 05:34 Best Buy Insider Fraud: Why Zero Trust Needs Behavior Monitoring 07:36 Canada Goose Leak: When a Third-Party Payment Processor Gets Breached 09:28 Wrap-Up + Sponsor Message (Meter)
This episode covers multiple active threats and security changes. It warns of an actively exploited critical BeyondTrust remote access vulnerability (CVE-2026-1731, CVSS 9.9) enabling pre-authentication remote code execution in Remote Support and Privileged Remote Access, noting SaaS was patched while on-prem deployments require urgent manual updates and may already be compromised. Microsoft details an evolution of the ClickFix social engineering technique where victims are tricked into running NSLookup commands that use attacker-controlled DNS responses as a malware staging channel, leading to payload delivery (including a Python-based RAT) and persistence via startup shortcuts, alongside increased Lumma Stealer activity.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
Researchers also report Mac-focused campaigns abusing AI-generated content and malicious search ads to push copy-paste terminal commands that install an info stealer (MaxSync) targeting Keychain, browsers, and crypto wallets. T
The show describes fake recruiter campaigns targeting developers with coding tests containing malicious dependencies on repositories like NPM and PyPI, linked to the "Gala" operation and nearly 200 packages. Finally, it reviews NPM's authentication overhaul after a supply-chain worm incident—revoking classic long-lived tokens, moving to short-lived session credentials, encouraging MFA and OIDC trusted publishing—while noting remaining risks such as MFA phishing, non-mandatory MFA for unpublish, and the continued ability to create long-lived tokens.
00:00 Sponsor: Meter + Today's Cybersecurity Headlines 00:48 Urgent Patch: BeyondTrust Remote Access RCE (CVE-2026-1731) Actively Exploited 02:45 ClickFix Evolves: DNS Lookups (nslookup) Used as Malware Staging 04:34 Mac Malware via AI Search Results: Fake Terminal Commands Deliver Info-Stealer 06:08 Fake Recruiters, Real Malware: Coding Tests Poison Dev Environments 07:19 NPM Security Overhaul After Supply-Chain Worm—What's Better, What Still Risks 09:11 Wrap-Up, Thanks, and Sponsor Message
This special Valentine's Day episode of Cybersecurity Today examines romance scams (often called pig butchering) and how fraudsters exploit trust, vulnerability, and loneliness.
Host Jim Love speaks with McAfee Head of Threat Research Abhishek Karnik about new findings showing the scale and demographics of these scams, including widespread encounters with fake or AI-generated profiles, frequent financial solicitations, and that men are also heavily impacted.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
The episode features survivor Beth Highland's detailed account of being manipulated via Tinder through long-term messaging, an AI video call, forged documents, and a crypto payout scheme that led her to send about $26,000 via Bitcoin ATMs before her financial advisor—trained in romance fraud—helped her recognize the scam and stop further losses, including a demanded $50,000 "activation fee." Beth discusses emotional aftereffects, stigma, reporting, red flags, and her book, "Diary of a Romance Scam:
When Swiping Right Goes Wrong," along with her advocacy work. The conversation broadens to the role of AI in making scams more realistic (deepfakes, voice/video, document generation), the importance of privacy and not overposting, involving trusted family/advisors, institutional training and intervention points along the fraud "kill chain," and using technology and education to detect and reduce scams.
LINKS Beth Hyland's Book - Diary of a Romance Scam: When Swiping Right Goes Wrong https://www.amazon.com/Diary-Romance-Scam-Swiping-Right/dp/1662962843
00:00 Sponsor: Meter's all-in-one networking stack 00:18 Valentine's Day on the dark side: heartbreak meets cybercrime 02:15 Romance scams ("pig butchering") are everywhere—who gets targeted 04:15 McAfee research: fake profiles, AI, and the real victim demographics 07:07 How scammers hook you: profiling, psychology, and long-game manipulation 09:01 Beth's story begins: post-divorce, isolation, and trying Tinder 10:36 The perfect match: mirroring, fast intimacy, and early red flags 14:32 AI video call + the push-pull breakup: emotional control tactics 17:09 The money trap: Qatar story, bank access, and Bitcoin ATM payments 23:34 The $50K "activation fee" and the wake-up call from a financial advisor 26:25 Cutting him off—and getting pulled back in by guilt and gaslighting 30:18 How to help victims: listening, tools, and where to get support 33:17 Turning pain into purpose: Beth's book and grieving a romance scam 34:47 Turning Pain Into Purpose: Supporting Romance-Scam Survivors 35:56 Stop Blaming Victims: Changing the Language Around Scams 38:38 "It Can Happen to Anybody": Why Smart People Get Hooked 40:58 Social Engineering 101: How Scams Exploit Different Emotions 42:14 Why McAfee Is Focusing on Consumer Scams (and the AI Factor) 45:43 AI Deepfakes & Low-Cost Tools: The New Scam Industrialization 49:19 Oversharing, Spearphishing & Replay Attacks: How Victims Get Retargeted 53:24 Practical Red Flags: Meeting in Person, Isolation Tactics, Family Checks 57:08 Training the "Kill Chain": Banks, Cashiers, Advisors & Early Intervention 01:00:33 Tech Fighting Tech: Detection, Identity Protection & Digital Assistants 01:02:57 What's Next: Agentic AI, Bigger Attack Surfaces & Trust-and-Safety by Design 01:08:03 Wrap-Up: Start the Conversation, Resources, and Final Thanks
This special Valentine's Day episode of Cybersecurity Today examines romance scams (often called pig butchering) and how fraudsters exploit trust, vulnerability, and loneliness.
Host Jim Love speaks with McAfee Head of Threat Research Abhishek Karnik about new findings showing the scale and demographics of these scams, including widespread encounters with fake or AI-generated profiles, frequent financial solicitations, and that men are also heavily impacted.
Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst
The episode features survivor Beth Highland's detailed account of being manipulated via Tinder through long-term messaging, an AI video call, forged documents, and a crypto payout scheme that led her to send about $26,000 via Bitcoin ATMs before her financial advisor—trained in romance fraud—helped her recognize the scam and stop further losses, including a demanded $50,000 "activation fee." Beth discusses emotional aftereffects, stigma, reporting, red flags, and her book, "Diary of a Romance Scam:
When Swiping Right Goes Wrong," along with her advocacy work. The conversation broadens to the role of AI in making scams more realistic (deepfakes, voice/video, document generation), the importance of privacy and not overposting, involving trusted family/advisors, institutional training and intervention points along the fraud "kill chain," and using technology and education to detect and reduce scams.
LINKS Beth Hyland's Book - Diary of a Romance Scam: When Swiping Right Goes Wrong https://www.amazon.com/Diary-Romance-Scam-Swiping-Right/dp/1662962843
00:00 Sponsor: Meter's all-in-one networking stack 00:18 Valentine's Day on the dark side: heartbreak meets cybercrime 02:15 Romance scams ("pig butchering") are everywhere—who gets targeted 04:15 McAfee research: fake profiles, AI, and the real victim demographics 07:07 How scammers hook you: profiling, psychology, and long-game manipulation 09:01 Beth's story begins: post-divorce, isolation, and trying Tinder 10:36 The perfect match: mirroring, fast intimacy, and early red flags 14:32 AI video call + the push-pull breakup: emotional control tactics 17:09 The money trap: Qatar story, bank access, and Bitcoin ATM payments 23:34 The $50K "activation fee" and the wake-up call from a financial advisor 26:25 Cutting him off—and getting pulled back in by guilt and gaslighting 30:18 How to help victims: listening, tools, and where to get support 33:17 Turning pain into purpose: Beth's book and grieving a romance scam 34:47 Turning Pain Into Purpose: Supporting Romance-Scam Survivors 35:56 Stop Blaming Victims: Changing the Language Around Scams 38:38 "It Can Happen to Anybody": Why Smart People Get Hooked 40:58 Social Engineering 101: How Scams Exploit Different Emotions 42:14 Why McAfee Is Focusing on Consumer Scams (and the AI Factor) 45:43 AI Deepfakes & Low-Cost Tools: The New Scam Industrialization 49:19 Oversharing, Spearphishing & Replay Attacks: How Victims Get Retargeted 53:24 Practical Red Flags: Meeting in Person, Isolation Tactics, Family Checks 57:08 Training the "Kill Chain": Banks, Cashiers, Advisors & Early Intervention 01:00:33 Tech Fighting Tech: Detection, Identity Protection & Digital Assistants 01:02:57 What's Next: Agentic AI, Bigger Attack Surfaces & Trust-and-Safety by Design 01:08:03 Wrap-Up: Start the Conversation, Resources, and Final Thanks
In this episode of Cybersecurity Today, Jim hosts Craig Taylor, a seasoned virtual Chief Information Security Officer (vCISO) with over 25 years of experience.
They discuss the evolution and significance of the vCISO role, Taylor's career path, and the founding of his company, Cyber Hoot, which provides cybersecurity education and vCISO services. Taylor shares insights into why companies, especially SMBs, opt for vCISO services due to budget constraints and the scarcity of cybersecurity professionals. He also talks about the common challenges faced by vCISOs, such as managing burnout and ensuring client adherence to security recommendations.
The conversation delves into the importance of cybersecurity culture, the need for effective education, and the integration of cybersecurity in business practices. Taylor offers practical advice on hiring the right vCISO and highlights the benefits his company provides. The episode concludes with a discussion on the psychology behind successful cybersecurity practices and Taylor's thoughts on the future of the industry.
00:00 Introduction to Cybersecurity Today 00:04 Meet Craig Taylor: The Virtual CISO 00:47 The Early Days of Virtual CISOs 02:15 Building a Cybersecurity Company 03:40 The Rise of Virtual CISO Services 05:01 Challenges and Realities of Cybersecurity 06:42 The Importance of Cyber Literacy 20:38 Managing Cybersecurity Risks 28:05 Understanding Administrative Risks in Onboarding and Offboarding 28:39 Challenges with MSPs and Cybersecurity 29:27 The Importance of Basic Security Measures 31:52 Dealing with Technology Debt 32:52 Balancing Budget and Security Needs 35:13 Real-Life Cybersecurity Incidents 40:17 The Role of Education in Cybersecurity 46:12 Hiring the Right VCISO 51:33 Conclusion and Final Thoughts
Cybersecurity Today: Teenage Ransomware Arrests, GoAnywhere Critical Flaw, and Google AI Vulnerability
In this episode of Cybersecurity Today, hosted by Jim Love, two teenagers were arrested in London for a ransomware attack on Kiddo International preschools, involving child data extortion. The show discusses a critical vulnerability in GoAnywhere MFT servers actively exploited by ransomware operators, emphasizing the need for immediate patching. It also highlights an urgent warning from CSA about a 2021 Windows flaw now under active attack. Additionally, researchers have found a new method to exploit Google's Gemini AI through invisible unicode characters, with Google declining to patch the issue. The episode concludes with security recommendations and a note on the show's upcoming special weekend edition for Canadian Thanksgiving.
00:00 Introduction and Headlines 00:28 Teenagers Arrested for Preschool Ransomware Attack 01:57 Critical Vulnerability in Go Anywhere MFT Servers 03:21 Urgent Alert for 2021 Windows Flaw 04:32 Google Gemini AI's Invisible Prompt Flaw 06:16 Conclusion and Sign-Off
North Korean Hackers Target Crypto Wealth, LinkedIn Fights Data Scraping, and AI Tools Leak Corporate Data
In this episode of Cybersecurity Today, host Jim Love covers the latest cybersecurity headlines including North Korean hackers targeting wealthy crypto investors, LinkedIn suing a firm for creating fake accounts to scrape user data, a massive ransomware campaign by the CIOp gang targeting Oracle’s E-Business Suite, and new research highlighting AI tools as the top channel for corporate data leaks. Listen in for insights and key takeaways to protect your digital assets and corporate data.
00:00 North Korean Hackers Target Wealthy Crypto Holders 02:09 LinkedIn Sues Over 1 Million Fake Accounts 03:46 Ransomware Attack on Oracle's E-Business Suite 05:42 AI Tools: The New Channel for Corporate Data Leaks 07:53 Conclusion and Contact Information
AI Browsers Turn Rogue, Discord Data Breach, and Surge in Palo Alto Scans
In this episode of Cybersecurity Today, host David Shipley discusses several significant cybersecurity concerns. Firstly, researchers at Layer X have uncovered a flaw in the Perplexity Comet AI browser that allows malicious prompts to turn the browser into a data thief with just a single click. Additionally, Discord has disclosed a data breach affecting users' personal information due to a third-party customer service provider compromise. Cybersecurity researchers have also reported a massive surge in scans targeting Palo Alto Network's login portals, suggesting potential reconnaissance for future attacks. Finally, the US Department of Defense has opted to reduce its mandatory cybersecurity training to allow military personnel to focus on their core missions, a move that has raised concerns given the intertwined nature of cyber and kinetic warfare.
00:00 Introduction and Headlines 00:32 AI Browser Security Flaw: Comet Jacking 03:11 Discord Data Breach: What Happened? 05:59 Surge in Scans Targeting Palo Alto Devices 08:07 US Department of Defense Cuts Cybersecurity Training 10:23 Conclusion and Viewer Engagement
In this episode of 'Cybersecurity Today: Our Month in Review,' host Jim welcomes a panel including Tammy Harper from Flair, Laura Payne from White Tuque, and David Shipley, CEO of Beauceron Securities. The discussion kicks off with an overview of their plans for Cybersecurity Month, including reviving the MapleSEC show and the CIO of the Year awards. David shares his experiences at SECTOR, Canada's largest cybersecurity conference, discussing the importance of security awareness training and the risks of irresponsible tech journalism on public perception. The panel also delves into the resurgence of the Clop ransomware group, their shift to data extortion, and their exploitation of vulnerabilities in Oracle EBS applications. Laura highlights a concerning case of insider threats at RBC, emphasizing the importance of process-driven controls. The episode also touches on the human side of cybersecurity, particularly the impact of romance scams and the growing violence in cybercrime. The panelists underscore the need for improved security awareness and the role of AI in identifying scams. Tammy, Laura, and David conclude by discussing the role of insider threats and the ethical boundaries in cybercrime, sharing insights from recent real-world cases.
00:00 Introduction and Panelist Introductions 00:43 Cybersecurity Month Initiatives 02:46 Security Awareness and Phishing Training 04:03 Impact of Irresponsible Tech Journalism 08:27 AI and Cybersecurity: Hype vs. Reality 10:43 Conference Experiences and Networking 18:33 Clop Ransomware and Data Extortion 23:45 Tammy's Insights on Clop's Tactics 24:58 Scattered Lasus and Cyber Warfare 26:32 Media Savvy Cybercriminals 31:36 Human Impact of Cyber Scams 37:17 Insider Threats and Security Awareness 43:21 Physical Security and Cyber Threats 48:33 Cybercrime Targeting Children 50:58 Conclusion and Upcoming Topics
Cybersecurity Today: Red Hat Breach, CLOP Targets Oracle, and CISA Cuts Critical Support
In this episode of Cybersecurity Today, host Jim Love covers a recent breach of Red Hat's consulting GitLab server, highlighting concerns over exposed network maps and tokens. The CLOP extortion gang targets Oracle E-Business Suite clients, demanding ransom for sensitive data. Surveys show Canadian businesses are overconfident in their cyber defenses despite frequent attacks. Finally, CISA has ended a crucial cybersecurity support agreement, impacting state and local governments amidst a federal shutdown. Tune in for detailed analysis and urgent action items.
00:00 Red Hat GitLab Server Breach 02:21 CLOP Gang Targets Oracle E-Business Suite 04:29 Canadian Firms' Overconfidence in Cybersecurity 06:31 CISA Ends Critical Support Amid Shutdown 08:38 Conclusion and Upcoming Month in Review
Critical Vulnerabilities and AI Voice Cloning Risks in Cybersecurity
In this episode of Cybersecurity Today, host Jim Love discusses key cybersecurity threats, including critical vulnerabilities in Sudo and Cisco firewalls, and a remote command flaw in Western Digital MyCloud devices. The show highlights efforts by national security agencies in the US, Canada, France, Netherlands, and the UK to address these risks, urging immediate patching and system updates. Additionally, the episode covers the emerging threat of real-time AI voice cloning, stressing the need for stricter security measures to prevent social engineering attacks. Listeners are encouraged to implement robust verification processes to secure their organizations and personal communications.
00:00 Critical Sudo Flaw Warning 00:21 Cisco Firewalls Vulnerabilities 02:34 Western Digital MyCloud Devices at Risk 03:48 AI Voice Cloning Threat 05:16 Conclusion and Contact Information
Emerging Cybersecurity Threats: Lockbit 5.0, Salesforce AI Vulnerabilities, and China's Cyber Intelligence Advancements
In this episode of 'Cybersecurity Today,' host Jim Love discusses the latest cybersecurity threats, including the emergence of Lockbit 5.0 ransomware which can attack multiple platforms simultaneously, and a critical vulnerability in Salesforce's AI agents known as forced leak prompt injection. Additionally, the episode delves into the growing capabilities of China's Ministry of State Security, which has become a significant cyber intelligence force under Xi Jinping, raising serious concerns for Western security agencies.
00:00 Introduction to Cybersecurity Threats 00:18 Lockbit 5.0: A New Ransomware Threat 03:01 Salesforce AI Agents Vulnerability 05:50 China's Cyber Intelligence Operations 08:55 Conclusion and Call to Action
Navigating the Complex Landscape of AI and Cybersecurity: A Conversation with Rob T. Lee
In this weekend edition of Cybersecurity Today, host Jim Love interviews Rob T. Lee, the Chief AI Officer and Chief of Research at the SANS Institute. They discuss the intersection of AI, education, and security, highlighting the dual nature of AI as both a transformative technology with immense benefits and as a significant security risk. Rob shares his insights on how organizations can mitigate these risks by adopting a 'yes' framework towards AI, fostering a culture of learning and experimentation, and acknowledging the vulnerabilities and knowledge gaps in the field. He emphasizes the importance of community engagement, practical learning, and the role of AI champions in driving innovation while maintaining security. Throughout the conversation, they address the challenges of implementing AI governance and explore the need for continual adaptation in the fast-evolving tech landscape.
00:00 Introduction and Guest Introduction 00:25 AI: Potential and Risks 01:26 Business vs. Security 03:36 Rob's Background and Experience 05:18 The Role of Practitioners in SANS 08:46 Governance and Security Challenges 17:13 The Crisis of Competency in AI 25:03 Encouraging Hands-On Learning 30:41 The Importance of Executive Involvement 33:49 The Problem with Security and Shadow AI 34:05 The Consequences of Shadow AI 34:52 Evaluating and Banning AI Tools 36:48 The Role of Executives in AI Adoption 40:04 Learning and Adapting to AI 42:47 The Importance of Community and Vulnerability 51:19 Practical Steps for AI Governance 58:47 Final Thoughts and Resources
Cybersecurity Today: Shadow Leak, SIM Farm Shutdown, Cisco Zero-Day, FBI Warning & Android Advanced Protection
In this episode of Cybersecurity Today, host Jim Love discusses several major cybersecurity issues. Key topics include the discovery of the 'Shadow Leak' vulnerability in ChatGPT servers by Radware, the dismantling of a massive SIM farm near the United Nations by the US Secret Service, a zero-day vulnerability affecting up to 2 million Cisco devices, an FBI warning about spoofed Internet Crime Complaint Center (IC3) websites, and a reminder about enabling Advanced Protection on Android phones. The episode also includes a shoutout to Jim Love's new audiobook 'Elisa, A Tale of Quantum Kisses,' available on multiple platforms.
00:00 Introduction and Sponsor Message 00:29 Shadow Leak Hits ChatGPT Servers 02:52 Massive SIM Farm Operation Uncovered 04:44 Cisco's Zero-Day Vulnerability 06:04 FBI Warns of Spoofed Crime Reporting Sites 07:07 Android's Advanced Protection Mode 08:00 Conclusion and Call to Action
Cybersecurity Today: GitHub's NPM Lockdown, Deep Fake Threats, and Yellowknife's Cyber Incident
In this episode of 'Cybersecurity Today', host Jim Love discusses GitHub's response to widespread supply chain attacks in the NPM ecosystem, the alarming rise of deep fake attacks as highlighted by Gartner, and the remarkable handling of a cyber incident by the city of Yellowknife. Tune in for the latest updates on cybersecurity threats, expert analysis, and the steps organizations are taking to combat these sophisticated attacks. Plus, discover Jim's sci-fi romance adventure audiobook 'Elisa: A Tale of Quantum Kisses' now available on major platforms.
00:00 Introduction and Sponsor Message 00:55 GitHub's Response to NPM Supply Chain Attacks 03:19 Gartner's Warning on Deep Fake and AI Attacks 06:03 Yellowknife's Cyber Incident and Response 08:20 Conclusion and Final Thoughts
Cybersecurity Today: Major Vulnerabilities and Attacks Uncovered
Join host David Shipley for today's cybersecurity updates on the last day of summer 2025. In this episode, we delve deep into Microsoft's critical Entra ID vulnerability, a cyber attack crippling major European airports, the rise of SpamGPT targeting phishing operations, and the alarming zero-click flaw in OpenAI's deep research agent. Hear about Canadian Police's big win against the shadowy Trade Ogre crypto platform and their $40 million asset seizure. Buckle up for a reality check on the evolving cyber threats and their impact on global security.
00:00 Introduction and Overview 00:55 Microsoft's Extinction Level Vulnerability 05:19 European Airports Cyber Attack 08:20 SpamGPT: AI for Cyber Criminals 09:53 Shadow Leak: Zero Click AI Vulnerability 12:09 Trade Ogre Takedown 14:50 Conclusion and Upcoming Events
Unveiling the Ransomware Ecosystem with Tammy Harper
In this compelling episode, Jim is joined by Tammy Harper from Flair.io to re-air one of their most popular and insightful episodes. Dive into the intricate world of ransomware as Tammy, a seasoned threat intelligence researcher, provides an in-depth introduction to the ransomware ecosystem. Explore the basics and nuances of ransomware, from its origins to its modern-day complexities. Tammy discusses not only the operational structures and notable ransomware groups like Conti, LockBit, and Scattered Spider, but also the impact and evolution of ransomware as a service. She also elaborates on ransomware negotiation tactics and how initial access brokers operate. This episode is packed with invaluable information for anyone looking to understand the cybercrime underground economy. Don’t forget to leave your questions in the comments, and they might be addressed in future episodes!
00:00 Introduction and Episode Re-Run Announcement 00:29 Guest Introduction: Tammy Harper from Flair io 00:41 Exploring the Dark Web and Ransomware 02:21 Tammy Harper's Background and Expertise 03:40 Understanding the Ransomware Ecosystem 04:02 Ransomware Business Models and Initial Access Brokers 07:08 Double and Triple Extortion Tactics 11:23 History of Ransomware: From AIDS Trojan to WannaCry 13:02 The Rise of Ransomware as a Service (RaaS) 19:41 Conti: The Ransomware Giant 26:17 Conti's Tools of the Trade: EMOTET, ICEDID, and TrickBot 32:05 The Conti Leaks and Their Impact 34:04 LockBit and the Ransomware Cartel 37:07 National Hazard Agency: A Subgroup of LockBit 38:17 Release of Volume Two and Its Impact 39:08 Details of the Training Manual 40:52 Ransomware Negotiations 41:28 Ransom Chat Project 42:27 Conti vs. LockBit Negotiation Tactics 43:30 Professionalism in Ransomware Operations 47:07 Ransomware Chat Simulation 48:03 Ransom Look Project 49:11 Current Ransomware Landscape 50:32 Infiltration and Research Methods 51:47 Profiles of Emerging Ransomware Groups 01:05:21 Initial Access Market 01:10:26 Future of Ransomware and Law Enforcement Efforts 01:13:14 Conclusion and Final Thoughts
Cybersecurity Today: The Good News Edition
In this episode, host Jim Love addresses a previous mistake regarding the location of Yellowknife and announces a special 'good news' edition. Key stories include Microsoft's dismantling of a global phishing-as-a-service operation Raccoon 0365, the recovery of nearly $2 million lost to a business email compromise scam by a Texas county, and the Commonwealth Bank of Australia's significant reduction in scam losses through AI-powered defenses. The episode emphasizes lessons learned in cybersecurity and the positive outcomes from recent countermeasures. Love also mentions that the usual host, David Shipley, will return on Monday.
00:00 Introduction and Apology 01:38 Good News Stories Overview 02:18 Microsoft Dismantles Raccoon 0365 03:59 Texas County Recovers $2 Million 05:51 CommBank's AI-Powered Scam Prevention 08:01 Conclusion and Contact Information
Cybersecurity Worms, Steganography Attacks, Municipal Cyber Incidents and More...
In this episode of Cybersecurity Today, host Jim Love delves into multiple cybersecurity threats affecting the tech landscape. He discusses the 'Shai Hulud' worm, which has infiltrated over 187 JavaScript libraries on NPM, exploiting developer tokens for spread, including those maintained by CrowdStrike. Love explains practical but challenging measures to mitigate such threats. He also explores steganography's role in hiding malicious scripts within seemingly benign image files, urging vigilance against embedding hidden commands. Additionally, the episode covers a cyber incident in Yellowknife, causing severe disruptions to municipal services and emphasizing the importance of cyber hygiene and support from higher government levels. Lastly, Jim examines how a Windows 11 patch has created a new vulnerability, stressing the need for enhanced monitoring and quick updates.
00:00 Introduction and Overview 00:21 The Shy Ude Worm: A New Threat 02:19 Steganography: Hiding in Plain Sight 05:30 Cybersecurity Incident in Yellowknife 07:24 Microsoft's Patch Problems 08:27 Conclusion and Contact Information
Cybersecurity Today: NPM Attack, Void Proxy Phishing, and Major Business Disruptions
In this episode of Cybersecurity Today, host David Shipley discusses a recent massive NPM attack that, despite causing significant disruption, left hackers with minimal gains. We also cover a new, highly sophisticated phishing service called Void Proxy, which targets Microsoft and Google accounts. Additionally, we delve into the severe repercussions of cyber attacks on major companies like Jaguar Land Rover and Marks and Spencer, highlighting the wide-ranging impacts on supply chains and leadership. Join us for the latest updates and insights from the world of cybersecurity.
00:00 Introduction and Headlines 00:35 Massive NPM Attack: What Happened? 02:53 Void Proxy: A New Phishing Threat 05:31 Jaguar Land Rover Cyber Attack Impact 06:59 Marks and Spencer Leadership Change 08:04 Conclusion and Final Thoughts
Inside Zero Trust: John Kindervag and the Evolution of Cybersecurity
In this episode of Cybersecurity Today: Weekend Edition, host Jim Love speaks with John Kindervag, the pioneer behind the Zero Trust model of cybersecurity. With over 25 years of industry experience, John delves into how the concept originated from his early work with firewalls, advocating for a system where no packet is trusted by default. He discusses the fundamental principles of Zero Trust, including defining protect surfaces, mapping transaction flows, and implementing microsegmentation. The conversation also touches on overcoming cultural and organizational challenges in cybersecurity, the inadequacies of traditional risk models, and adapting Zero Trust methodologies in the evolving landscape, including AI. Through thoughtful discourse and practical insights, John underscores the importance of strategic and tactical implementations in building resilient and secure systems.
00:00 Introduction to Cybersecurity Today 00:25 Meet John Kindervag: The Godfather of Zero Trust 01:50 The Birth of Zero Trust 04:08 Challenges and Evolution of Zero Trust 06:03 From Forrester to Practical Implementations 11:40 The Concept of Protect Surfaces 17:30 Risk vs. Danger in Cybersecurity 30:54 Farmers and Technology 31:48 The Importance of IT in Business 32:26 Introduction to Zero Trust 32:41 Five Steps to Zero Trust 33:14 Mapping Transaction Flows 34:25 Custom Architecture for Zero Trust 34:55 Defining Policies with the Kipling Method 36:04 Monitoring and Maintaining Zero Trust 36:28 The Concept of Anti-Fragile Systems 38:47 Challenges and Success Stories in Zero Trust 42:02 Microsegmentation and Protect Surfaces 45:39 AI and Zero Trust 49:22 Advice for Implementing Zero Trust 50:37 Military Insights and Decision Making 57:19 The Future of Zero Trust 59:07 Conclusion and Final Thoughts
Cybersecurity Today: Microsoft Patches, Canadian Data Breach, NVIDIA's New Tool, and a Senator's Call for Investigation
In this episode of Cybersecurity Today, host Jim Love discusses Microsoft's September patch update addressing 81 security flaws, including two zero-day vulnerabilities. Highlights include a data breach in Canada affecting email and phone numbers, NVIDIA's release of an open-source LLM vulnerability scanner, and US Senator Ron Wyden's call for the FTC to investigate Microsoft's security practices. The episode also clears up the mystery behind the bricked SSDs after a Windows 11 update.
00:00 Microsoft Patches 81 Flaws 02:29 Canadian Government Data Breach 03:38 NVIDIA's Garrick: AI Vulnerability Scanner 05:01 Senator Urges FTC to Probe Microsoft 06:52 Mystery of Bricked SSDs Solved 08:24 Conclusion and Upcoming Interview
Phishing Scams, Leaked Stream Keys, Zero-Day Android Vulnerabilities, and Bounties on Russian Hackers
In this episode of Cybersecurity Today, host Jim Love discusses several critical cybersecurity issues. Attackers are using iCloud calendar invites for phishing scams, leveraging Apple's system to bypass security checks. The US Department of Defense has exposed livestream credentials, risking hijack and fake content insertion. Billions of Android phones are vulnerable due to unpatched critical zero days, and Google has only fixed issues for Pixel devices so far. Additionally, the US State Department has placed a $10 million bounty on three Russian FSB hackers responsible for attacks on energy companies. Jim emphasizes the importance of securing digital assets and maintaining strong cybersecurity practices.
00:00 Introduction and Headlines 00:24 Phishing Scam via iCloud Calendar Invites 03:18 US Department of Defense Livestream Vulnerabilities 05:53 Critical Android Zero-Day Vulnerabilities 07:38 US Bounty on Russian FSB Hackers 09:42 Conclusion and Contact Information
Cybersecurity Today: Ghost Action Campaign, SalesLoft Breach, AI Vulnerabilities, and Restaurant Security Flaws
Host David Shipley discusses the latest in cybersecurity, including the Ghost Action Campaign which compromised over 3000 secrets from GitHub repositories, the SalesLoft breach affecting major cybersecurity and SaaS firms, and new research showing how large language model chatbots like GPT-4 can be manipulated easily. Additionally, ethical hackers uncover significant vulnerabilities in the digital platforms of Restaurant Brands International. The episode emphasizes the importance of securing the software development ecosystem and maintaining robust social engineering defenses.
00:00 Introduction and Headlines 00:32 GitHub Supply Chain Attack: Ghost Action Campaign 02:51 SalesLoft Breach: A Deep Dive 05:01 The Summer of Salesforce Attacks 07:19 Manipulating AI: New Research Insights 09:14 Restaurant Brands International: Security Flaws Exposed 11:21 Conclusion and Sign-Off
The Future of Cybersecurity: AI, Exploits, and the CVE Database
In this special crossover episode of Cybersecurity Today and Hashtag Trending, the hosts explore the use of artificial intelligence (AI) in cybersecurity. The conversation begins with an overview of the ongoing 'arms race' to find and exploit software vulnerabilities, focusing on how AI can change the game. The episode delves into the Common Vulnerability and Exposures (CVE) Database, its importance, and its management by the Mitre Corporation. The discussion then spotlights groundbreaking research by Israeli researchers Effie Wies and Nahman Khayet, who developed a method to automate the creation of exploits using AI, reducing the average exploit development time from 192 days to just 15 minutes. This revelation raises significant concerns about the future of cybersecurity and the need for organizations to accelerate their response times. The podcast also touches on the potential for AI to assist in writing more secure code and defending against vulnerabilities, calling for a more resilient approach to software development and deployment.
00:00 Introduction to the Crossover Show 00:22 The Arms Race in Cybersecurity 00:59 Understanding Zero-Day Exploits 02:13 The Common Vulnerability and Exposures Database (CVE) 05:17 The Impact of AI on Exploit Development 05:54 Interview with Nahman Khayet 08:48 The Future of AI in Cybersecurity 18:16 Challenges and Recommendations for Organizations 30:54 Conclusion and Final Thoughts
For this short week we had episodes on Tuesday and Thursday. We'll return to our Monday, Wednesday and Friday schedule starting next Monday. But we have an interview this weekend with the researchers who have issued a proof of concept showing that you can go from CVE to working exploit in 15 minutes and at the cost of less than a dollar using AI.
In this episode of Cybersecurity Today, host Jim Love covers the latest and most critical stories in the world of cyber threats and digital defense:
• Cloudflare fends off a record-breaking 11.5 Tbps DDoS attack, highlighting the relentless scale and sophistication of modern cyber assaults. • WhatsApp patches a dangerous zero-click exploit targeting Apple users, with advice for high-risk individuals to stay protected. • Frostbite 10: Ten critical vulnerabilities in supermarket refrigeration systems could threaten food safety nationwide. • Over 1,100 Ollama AI servers found exposed online, raising alarms about the risks of self-hosted AI and poor security practices. • Hacker group issues an ultimatum to Google, but so far, no evidence of a breach—reminding us to stay vigilant against social engineering. • Palo Alto Networks becomes the latest victim in a supply chain breach involving stolen OAuth tokens, with lessons for all organizations on token hygiene and monitoring.
Stay informed, stay secure! For tips, feedback, or more info, visit technewsday.com or .ca.
Cybersecurity #DDoS #ZeroClick #AI #DataBreach #Infosec
Cybersecurity Today: Major Attacks on NX Build System, Sitecore, and Salesforce
In this episode, David Shipley covers a string of significant cybersecurity breaches and vulnerabilities. Highlights include a compromise of the NX build system affecting over 1000 developers, remote code execution flaws in Sitecore's experience platform, and escalating Salesforce data theft attacks. The episode underscores the amplified risk introduced by AI in development, emphasizes the need for stringent security practices, and highlights sophisticated attacks by nation-state actors and criminal groups. Practical advice given includes the importance of patching systems, securing integrations, and educating teams on evolving threats.
00:00 Introduction and Headlines 00:28 NX Build System Compromise 01:54 AI-Driven Development Risks 04:25 Sitecore Vulnerabilities 05:36 Nation-State Threats 07:00 Salesforce Data Theft Campaign 09:51 Conclusion and Sign-Off
Cybersecurity Today: Navigating AI Advancements and Future Trends
In this episode of 'Cybersecurity Today,' host Jim Love and panelists Tammy Harper, Laura Payne, and David Shipley discuss recent developments in cybersecurity, shifting focus to AI's impact on the industry. They explore emerging threats such as AI-generated ransomware and the efficiency of exploiting vulnerabilities using AI. The conversation emphasizes the need for improved policy and regulation, the role of MFA in safeguarding systems, and the implications of youth unemployment due to AI disruption. Predictions for the coming year include the necessity for better legislation, ethical considerations in AI deployment, and the continued importance of maintaining fundamental cybersecurity measures amidst rapid technological advances.
00:00 Introduction and Overview 00:36 Meet the Panelists 02:32 New Cybersecurity Awareness Platform 05:07 Biometric Guidance and Privacy 13:04 AI-Driven Exploits and Security Challenges 22:21 Hack Back Legislation Debate 30:21 MFA Implementation and Insurance Implications 36:30 Understanding the Role of Underwriting in Insurance 36:58 The Importance of Cybersecurity in Insurance 37:43 Scenarios and Broker Consultations 38:57 The Scattered Spiders and Cybersecurity Threats 43:07 Youth Unemployment and Cybersecurity 44:43 The Rise of Social Engineering 47:47 AI and Its Implications 49:28 The Future of AI and Cybersecurity 50:45 Challenges and Solutions in AI Security 51:09 Final Thoughts and Recommendations
In this episode of Cybersecurity Today, host Jim Love delves into the latest cyber threats and risks. Key topics include the new phishing campaign Zipline that flips traditional tactics, Google's call for 2.5 billion Gmail users to reset passwords due to a phishing attack by Shiny Hunters, and the emergence of AI-driven ransomware like Prompt Lock. The episode also covers a hijack of the NX build platform leading to a sophisticated supply chain attack, and a whistleblower's claims that the Social Security Administration put personal data at risk by improperly handling sensitive information. Tune in to stay informed on these evolving cyber threats and defensive measures.
00:00 Introduction to Cybersecurity News 00:31 Zipline Phishing: A New Threat 02:14 Google Urges Password Resets 03:51 AI-Powered Ransomware: Prompt Lock 05:48 NX Supply Chain Attack 07:35 Social Security Data at Risk 09:20 Conclusion and Upcoming Shows
In this episode of Cybersecurity Today, host Jim Love discusses recent developments in cybersecurity, including a method to bypass GPT5 model safeguards, malware issues in the Google Play Store, NIST's new AI-specific security controls, and a cyber attack that led to a government shutdown in Nevada. The episode also covers a CRM-related breach linked to the Shiny Hunters collective, who used OAuth tokens to gain unauthorized access. Key takeaways emphasize the need for stronger security frameworks and vigilance against evolving cyber threats.
00:00 Introduction and Overview 00:27 Exploiting GPT-5: A Simple Prompt Attack 02:20 Google Play Store's Malware Struggles 04:11 NIST's New AI Security Controls 06:06 Nevada Government Cyber Attack 08:23 Shiny Hunters' CRM Breach 10:41 Conclusion and Contact Information
Host David Shipley explores the latest in cybersecurity, including the rapid development of AI-generated exploits for critical vulnerabilities, record-high searches of digital devices at US borders, and a fired developer jailed for sabotaging his former employer. Additionally, the episode highlights Interpol's Operation Serengeti 2.0, which led to significant arrests and recoveries in the fight against cybercrime in Africa. The episode underscores the speed at which cyber threats can materialize and the importance of global and collaborative defenses.
00:00 Introduction to Cybersecurity Today 00:35 AI-Driven Exploits: A New Era of Cyber Threats 02:48 Record Device Searches at US Borders 04:43 Insider Threats: The Hidden Dangers Within Organizations 06:25 Operation Serengeti 2.0: A Major Blow to Cyber Crime 07:27 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host Jim Love explores the complex dynamics of cybersecurity training with guests Michael Joyce and David Shipley. They discuss the importance of continuous awareness and the temporal decay of training effects. The conversation highlights the critical balance between training frequency and effectiveness, with data suggesting that monthly phishing simulations and quarterly training interventions offer optimal results. Despite recent headlines claiming phishing training is ineffective, the discussion underscores the nuanced understanding required to navigate cybersecurity education. The episode also delves into academic versus business perspectives, emphasizing the importance of empirical research and critical thinking in developing effective cybersecurity strategies.
00:00 Understanding Human Vigilance and Awareness Decay 00:33 Introduction to Cybersecurity Today 00:46 Meet the Experts: Michael Joyce and David Shipley 01:39 Exploring the Human-Centric Cybersecurity Partnership 03:38 The Role of Liberal Arts in Cybersecurity 04:23 Challenges in Cybersecurity: Technology vs. Human Behavior 06:34 The Importance of Independent Research in Cybersecurity 12:30 Analyzing Cybersecurity Awareness Month 18:32 Phishing Simulations and Security Fatigue 23:14 The Impact of Training on Phishing Awareness 39:38 Experimenting with Phishing Training Frequency 39:51 Critiques and Insights on Cybersecurity Training 41:51 Optimal Training Intervals and Their Impact 43:23 The Role of Awareness in Cybersecurity 44:13 Understanding Phishing Reporting and Skills Decay 45:22 Ethical Considerations in Phishing Simulations 46:38 New Data on Why People Click Phishing Links 55:52 The Importance of Psychological Safety 57:23 Debunking Misleading Headlines on Phishing Training 01:05:44 The Complexity of Cybersecurity Research 01:16:41 Final Thoughts and Recommendations
In this episode of Cybersecurity Today, host Jim Love covers a range of recent cybersecurity incidents. A major privacy failure has hit Elon Musk's Grok chatbot, exposing over 370,000 private conversations with sensitive information. Microsoft's recent security update has caused SSD and HDD failures, complicating data recovery. Hackers have exploited Microsoft's own login infrastructure to create phishing traps, making it difficult for users to spot fake login pages. The leader of the Wrapper Bot DDoS gang has been arrested following a detailed investigation. Finally, a hacker group claims to have 15.8 million PayPal credentials, although these claims are disputed by PayPal and security researchers. Jim also invites listeners to share their thoughts and comments through various contact methods.
00:00 Agro Leak Exposes 370,000 Chats 02:22 Microsoft Scrambles to Fix SSD Failures 03:52 Hackers Hijack Microsoft Infrastructure 05:40 Leader of Wrapper Bot DDoS Gang Arrested 07:14 Hackers Claim 15.8 Million PayPal Logins Stolen 08:34 Conclusion and Contact Information
In today's episode of 'Cybersecurity Today,' hosted by Jim Love, we cover several key issues in the cybersecurity landscape. Firstly, a breach involving Workday and social engineering attacks targeting Salesforce customers is discussed. Next, the risks posed by a recent Windows update potentially causing data corruption on SSDs and HDDs are highlighted. We also delve into a critical infrastructure breach where Russian hackers remotely accessed a Norwegian dam's control system. Additionally, the episode covers Google's vulnerabilities in its AI and Gmail services, and finally, Apple's significant privacy victory against the UK’s backdoor encryption mandate. The episode concludes with a call for listener support through donations to sustain the program.
00:00 Introduction and Headlines 00:23 Workday Data Breach Explained 02:15 Windows Update Issues 04:05 Norwegian Dam Cyber Attack 05:49 Google's Security Challenges 07:12 Apple's Privacy Victory 08:19 Conclusion and Listener Support
In this episode of Cybersecurity Today, host David Shipley reports from Fredericton, New Brunswick, amidst severe forest fires. The main story covers a data breach in Canada’s House of Commons involving parliamentary employee information, attributed to a recent Microsoft vulnerability. The episode also discusses Fortinet’s recent high-severity vulnerability patches and Microsoft's reminder of Windows 10 support ending in October 2025. Additionally, there’s rare good news as researchers gain insights into the iMac 3.0 malware after a source code leak. The episode encourages vigilance, patching, and awareness of upcoming support changes while offering contact information and solicitation for audience engagement.
00:00 Introduction and Headlines 00:35 Canada's House of Commons Data Breach 03:48 Fortinet Vulnerabilities and Patches 05:49 Windows 10 End of Life Announcement 07:17 Malware Source Code Leak Insights 09:08 Conclusion and Viewer Engagement
In this episode of 'Cybersecurity Today,' the host welcomes Tammy Harper from Flair.io for an in-depth exploration into the ransomware ecosystem. Tammy, a seasoned threat intelligence researcher and certified dark web investigator, shines a light on the complex world of ransomware, its history, business models, and the various threat actor groups involved. The discussion covers initial access brokers, notable ransomware groups like Conti and LockBit, and modern shifts in the ransomware landscape fueled by AI and affiliate models. This episode offers a comprehensive guide for understanding how ransomware operates and the tactics used by cybercriminals, making it a must-watch for anyone interested in cybersecurity.
00:00 Introduction 00:50 Meet Tammy Harper: Expert in Ransomware 01:59 Understanding the Ransomware Ecosystem 03:26 Ransomware Business Models and Initial Access Brokers 06:39 Double and Triple Extortion Explained 10:50 The Evolution of Ransomware 15:43 The Role of Cryptocurrency in Ransomware 19:22 The Rise and Fall of Conti 25:56 Tools of the Trade: EMOTET, ICEDID, and TrickBot 33:35 LockBit and the Ransomware Cartel 36:37 The National Hazard Agency and Ba Lord 38:13 LockBit Training Materials 40:23 Ransomware Negotiations 40:54 Ransom Chat Project 41:58 Conti vs. LockBit Negotiation Tactics 47:30 Modern Ransomware Groups 51:18 Medusa and Other Emerging Groups 01:04:52 Initial Access Market 01:09:41 Conclusion and Final Thoughts
Cyber Crime Crackdown: $300 Million in Crypto Frozen, FBI Accounts Hacked, and Critical Microsoft Patches Released
In this episode of Cybersecurity Today, host Jim Love covers major recent events in cybercrime and cybersecurity. Over $300 million in cryptocurrency tied to cybercrime has been frozen through coordinated efforts by the private sector and law enforcement in the US and Canada. Cyber criminals are selling active FBI and other law enforcement email accounts for as low as $40, posing significant risks of impersonation and fraud. Microsoft's latest Patch Tuesday addresses over 100 vulnerabilities, including critical flaws in various services and applications. Nova Scotia Power faces criticism for seeking to hide details about a major cybersecurity breach that affected 280,000 customers, with regulators emphasizing the need for public accountability. Jim signs off by encouraging listeners to support and provide feedback for the show.
00:00 Cybercrime Crypto Crackdown 02:34 FBI Email Accounts for Sale 04:05 Microsoft Patch Tuesday Updates 06:16 Nova Scotia Power Cybersecurity Breach 07:43 Show Wrap-Up and Listener Engagement
In this episode of Cybersecurity Today, host David Shipley covers critical security updates and vulnerabilities affecting Microsoft Exchange, Citrix NetScaler, and Fortinet SSL VPNs. With over 29,000 unpatched Exchange servers posing a risk for admin escalation and potential full domain compromise, urgent action is needed. Citrix Bleed 2 is actively being exploited, with significant incidents reported in the Netherlands and thousands of devices still unpatched globally. Fortinet SSL VPNs are experiencing a spike in brute force attacks, hinting at a possible new vulnerability on the horizon. Lastly, Shipley highlights notable moments from DEFCON 33, including innovative security hacks and sobering realities of the hacker community. Tune in for detailed breakdowns and insights on how to stay vigilant against these threats.
00:00 Introduction and Overview 00:32 Microsoft Exchange Vulnerability 02:54 Citrix Bleed Two Exploits 05:21 Fortinet SSL VPN Brute Force Attacks 07:39 Insights from DEFCON 33 13:46 Conclusion and Final Thoughts
In today's episode of Cybersecurity Today, host David Shipley covers critical updates on recent cyber attacks and breaches impacting the US Federal judiciary's case management systems, and SonicWall firewall compromises. He also discusses researchers' new jailbreak method against GPT-5, which bypasses ethical guardrails to produce harmful instructions. Shipley shares insights and standout sessions from Hacker Summer Camp 2025, including BSides Las Vegas, the I Am the Cavalry track, and Defcon, highlighting ongoing efforts and challenges in the cybersecurity landscape. Stay informed, stay secure, and join the conversation in this detailed overview of current cybersecurity issues and innovations.
00:00 Introduction and Headlines 00:31 US Federal Judiciary Cyber Attack 02:29 SonicWall Ransomware Attacks 04:14 AI Jailbreak Techniques 07:44 Hacker Summer Camp 2025 Highlights 08:10 BSides Las Vegas and Community Insights 09:29 Healthcare Cybersecurity and Crash Cart Project 12:11 Defcon Reflections and Final Thoughts 13:45 Conclusion and Listener Engagement
Cybersecurity Today: July Review - Massive Lawsuits, AI Warnings, and Major Breaches
In this episode of Cybersecurity Today: The Month in Review, host Jim Love and an expert panel, including David Shipley, Anton Levaja, and Tammy Harper, discuss the most significant cybersecurity stories from July. Key topics include the $380 million lawsuit between Clorox and Cognizant following a massive ransomware attack, the ongoing legal battle between Delta and CrowdStrike, and breached forums like XSS leading to significant law enforcement actions. The panel also dives into AI-related risks in software development, recent supply chain attacks, and legislative developments in Europe affecting cybersecurity. Watch to stay informed about the latest trends and challenges in the cybersecurity landscape.
00:00 Introduction and Panelist Introductions 01:28 Major Cybersecurity Lawsuits: Clorox vs. Cognizant and Delta vs. CrowdStrike 04:11 Reflections on Legal Implications and Industry Impact 13:01 Tammy Harper on XSS Forum Seizure 17:52 Law Enforcement Tactics and Dark Web Trust Issues 23:47 Anton Levaja on Supply Chain Attacks 30:18 AI Wiping Code and Backup Issues 31:18 Security Concerns with Model Control Protocol 31:56 Challenges with AI in Code Review 34:02 The Problem with AI-Generated Code 40:43 The SharePoint Apocalypse 43:36 Impact of Business Decisions on Technology 49:16 Final Thoughts and Upcoming Stories 49:25 Current and Upcoming Tech Legislation
In this episode, host Jim Love thanks listeners for their support of his book 'Elisa, A Tale of Quantum Kisses,' which is available for 99 cents on Kindle. The show then dives into pressing cybersecurity issues discussed at Black Hat USA, including vulnerabilities in AI assistants via prompt injection attacks, and critical flaws in Broadcom chips used by Dell laptops that can lead to stealth backdoors. Microsoft Exchange zero-day vulnerabilities actively being exploited are also covered, along with a listener report about a Canadian domain registrar's expired security certificate. The episode emphasizes the importance of keeping systems and software updated to mitigate these security risks.
00:00 Introduction and Book Promotion 00:58 Cybersecurity Headlines 01:25 AI Assistant Vulnerabilities 03:36 Broadcom Chip Flaws in Dell Laptops 06:10 Microsoft Exchange Zero-Day Exploits 08:18 Listener's Domain Registrar Experience 10:36 Show Wrap-Up and Listener Engagement
In this episode, host Jim Love explores a variety of pressing cybersecurity threats and developments. The episode begins with an invitation for listeners to share their summer reading choices. The main content highlights include North Korean operatives infiltrating US companies through fake identities and AI-generated resumes, the ability of large language models to autonomously execute cyber attacks, a vulnerability in the AI-powered code editor Cursor allowing silent RCE attacks, and the rise of malicious Progressive Web Apps targeting mobile users. The show also discusses the risks associated with clicking unsubscribe links in spam emails. Listeners are encouraged to support the show and contribute through the website.
00:00 Introduction and Summer Reading Request 00:59 North Korean Spies in US Tech Firms 03:25 AI's Role in Cyber Attacks 05:18 Critical Vulnerability in AI Code Editor 07:36 Malicious Mobile Browser Hijacks 09:30 Unsubscribe Links as Phishing Traps 10:50 Conclusion and Listener Engagement
In this episode of 'Cybersecurity Today,' host David Chipley discusses several major security incidents and threats. Hamilton, Ontario faces a $5 million insurance denial following a ransomware attack due to incomplete deployment of Multi-Factor Authentication (MFA). The episode also highlights a severe vulnerability, CVE-2025-54135, in the AI-powered Code Editor 'Cursor', which could allow prompt injection attacks. Further topics include a new ransomware attack exploiting Microsoft SharePoint vulnerabilities investigated by Palo Alto Networks, and a campaign leveraging fake OAuth apps to compromise Microsoft 365 accounts. The episode underscores the importance of robust security measures, emphasizing MFA, OAuth hygiene, and prompt patching.
00:00 Introduction and Headlines 00:38 Hamilton's Ransomware Attack and Insurance Denial 02:52 AI-Powered Code Editor Vulnerability 04:57 Palo Alto Networks Investigates SharePoint Exploitation 06:51 Fake OAuth Apps and Microsoft 365 Breaches 08:48 Conclusion and Upcoming Events
This episode explores the 'Grandparent Scam,' a prevalent and profitable fraud targeting seniors by exploiting their concern for their grandchildren. Experts Deirdre and John from Ireland's National Cybersecurity Center and the Ontario Provincial Police share insights into the scam's mechanics, the emotional impact on victims, and the challenges law enforcement faces in combating such crimes. They discuss the effectiveness of public-private partnerships, the importance of victim-centric approaches, and emerging fraud trends such as investment scams and bank imposter scams. The episode emphasizes the critical role of education, awareness, and reporting in preventing and mitigating the impact of these cyber frauds.
00:00 Introduction to the Grandparent Scam 00:37 The Emotional and Financial Impact on Victims 01:26 Fighting Back: The Role of Law Enforcement 02:38 Meet the Experts: Deirdre's Journey 04:44 Meet the Experts: John's Journey 06:35 The Global Scale of Cyber Fraud 08:11 Challenges in Handling Individual Fraud Cases 10:24 Community-Based Approaches to Support Victims 14:37 The Sophistication of Modern Scams 20:57 The Grandparent Scam: A Detailed Breakdown 28:01 Understanding Social Engineering 28:19 Cybersecurity Conversations with Vulnerable Populations 28:50 Fraud Prevention Initiatives 31:07 Challenges in Communicating Cybersecurity 32:35 Emerging Fraud Trends 35:35 The Importance of Reporting Fraud 37:53 Future Threats and Scams 40:58 The Role of Public-Private Partnerships 41:46 Final Thoughts and Next Steps
In this episode, the host Jim Love discusses the increasing sophistication of supply chain attacks, starting with an account of a blockchain developer who lost $500,000 due to a malicious extension in a popular AI-powered coding tool. The episode also covers a significant cyber emergency in St. Paul, Minnesota, which required National Guard support, and the City’s struggle to comprehend the full scope of the hack. Additionally, the US Cybersecurity and Infrastructure Security Agency (CISA) has released a new eviction strategies tool to help cybersecurity teams remove persistent threats. The episode concludes with an update on the Ingram Micro breach, where the Safe Pay ransomware gang has threatened to leak 35 terabytes of stolen data. Listeners are encouraged to focus on preventative measures even when ransomware attacks do not involve encryption.
00:00 Introduction and Headlines 00:25 The $500,000 Crypto Heist 01:26 Supply Chain Attack on Open VSX 04:50 Lessons from the Attack 06:16 Oyster Backdoor Threat 07:54 Cyber Attack on St. Paul 09:09 CISA's New Eviction Strategies Tool 10:43 Ingram Micro Data Breach Update 12:18 Conclusion and Contact Information
In this episode of 'Cybersecurity Today,' host Jim Love covers several significant cybersecurity incidents. Hackers disrupt all Aeroflot flights, causing massive delays in Russia. The women-only dating app 'Tea' faces a second serious data leak, exposing 1.1 million private messages. A game on Steam named 'Camia' is found to contain three types of malware, including Info Stealers and a Backdoor. Additionally, researchers discover that OpenAI's GPT-4 agent can bypass CAPTCHAs, raising concerns about the future of this security measure.
00:00 Introduction and Headlines 00:28 Tea App's Major Data Breaches 02:29 Aeroflot Cyber Attack Disrupts Flights 04:22 Malware Found in Steam Game 06:27 OpenAI's GPT-4 Bypasses Captchas 08:59 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host David Shipley covers several key incidents impacting the cybersecurity landscape. Amazon's generative AI coding assistant 'Q' was compromised by a hacker who injected data-wiping code into the tool's GitHub repository. Scattered Spider, a notorious cybercrime group, continues its malware attacks on VMware ESXI hypervisors using advanced social engineering techniques. In a significant enforcement action, global law enforcement dismantled the Black Suit ransomware infrastructure under Operation Checkmate. Lastly, Insurance Giant Allianz Life revealed a data breach affecting its US customer base. Stay tuned to understand the latest threats and protective measures in cybersecurity.
00:00 Introduction and Headlines 00:30 Amazon AI Coding Tool Breach 03:07 Scattered Spider's VMware ESXI Attacks 06:44 Operation Checkmate: Black Suit Ransomware Takedown 08:16 Alliance Life Insurance Data Breach 10:25 Conclusion and Call to Action
This is repeat of a broadcast from last October, still relevant, especially in the light of so many current breaches which have begun not with technical weaknesses but with phishing and social engineering.
In this deeper dive episode of 'Cybersecurity Today,' hosts Jim Love and David Shipley, a top cybersecurity expert from Beauceron Security, explore the evolution, intricacies, and impact of phishing attacks. They highlight recent sophisticated phishing strategies that combine AI, complex setups, and psychological manipulation to deceive even the most knowledgeable individuals. The discussion covers various types of phishing including spearphishing, whaling, sharking, QR phishing, and the emotional and psychological tactics employed by attackers. They also delve into practical defense mechanisms such as Multi-Factor Authentication (MFA), passkeys, and the importance of fostering a security-conscious workplace culture. The episode emphasizes the need for a diversified security approach involving technology, training, and emotional intelligence, while encouraging assertiveness in questioning potentially fraudulent communication.
00:00 Introduction to Cybersecurity Today 00:40 The Evolution of Phishing Attacks 01:44 Deep Dive into Phishing Techniques 03:31 History of Phishing 06:04 Types of Phishing: From Email to Whaling 10:06 Advanced Phishing Tactics 19:25 The Psychology Behind Phishing 26:03 Phishing Tactics: Free Gift Card Scams 26:33 The Power of Scarcity in Phishing 28:27 Authority and Phishing: Impersonation Tactics 29:11 Consistency: Small Requests Leading to Big Scams 30:14 Liking and Social Proof in Social Engineering 32:15 The Evolution of Phishing Techniques 35:31 The Role of MFA in Enhancing Security 38:35 Passkeys and the Future of Authentication 44:57 Building a Security-Conscious Workplace Culture 48:47 Conclusion and Final Thoughts
The recent Sharepoint hack is spreading like wildfire through unpatched systems. All this and more on today's episode with guest host David Shipley.
We're having some issues with podcast distribution. We're going to take a couple of days to figure out what is going on and what, if anything, we can do about it.
In this episode of Cybersecurity Today, host David Shipley discusses several pressing cybersecurity issues. First, popular NPM Linter packages were hijacked via phishing to spread malware, affecting millions of downloads.
Concurrently, Ukrainian CERT uncovers new phishing campaigns tied to APT28 using large language models for command and control.
Microsoft discontinues the use of China-based engineers for US Department of Defense systems following a controversial report. Lastly, social engineering, facilitated by AI, becomes a greater threat than zero-day exploits.
The episode emphasizes the need for stronger maintainer security, multifactor authentication, and a comprehensive understanding of social engineering risks.
00:00 Introduction - 10 Million Downloads 01:30 NPM Linter Packages Hijacked 05:05 Social Engineering and AI in Cybersecurity 08:57 Microsoft's China-Based Engineers Controversy 12:15 The Real Threat: Social Engineering 16:39 Conclusion and Call to Action
The Cybersecurity Today episode revisits a discussion on the risks and implications of AI hosted by Jim Love, with guests Marcel Gagné and John Pinard. They discuss the 'dark side of AI,' covering topics like AI misbehavior, the misuse of AI as a tool, and the importance of data protection in production environments. The conversation delves into whether AI can be conscious and the ethical considerations surrounding its deployment, particularly in highly regulated industries like finance. They emphasize the need for responsible use, critical thinking, and ongoing oversight to mitigate potential risks while capitalizing on AI's benefits. The episode concludes with a call for continued discussion and engagement through various platforms.
00:00 Introduction to Cybersecurity Today 00:33 Exploring the Dark Side of AI 02:31 AI Misbehavior and Security Concerns 07:35 Speculative Risks and Consciousness 26:09 AI in Corporate Settings 31:49 Human Weakness in Security 32:37 Social Engineering Tactics 33:08 Security in Engineering Systems 33:42 AI Data Storage and Security 35:16 AI Data Retrieval Concerns 39:36 Testing Security in Development 41:37 AI in Regulated Industries 43:57 Bias and Decision Making in AI 47:18 Critical Thinking and Debate Skills 55:06 The Role of AI as a Consultant 01:02:21 The Future of AI and Responsibility 01:04:55 Conclusion and Contact Information
In today's episode, host Jim Love covers recent cybersecurity threats, including malware hidden in DNS records, a custom backdoor targeting SonicWall SMA devices, the US military assuming a network compromise after Chinese hackers targeted VPNs and email servers, and a $27 million theft from the BigONE crypto exchange. The show highlights how attackers are using innovative techniques to evade detection and emphasizes the need for increased vigilance in monitoring and securing systems.
00:00 Introduction to Cybersecurity News 00:26 Malware Hidden in DNS Records 02:26 SonicWall Devices Under Attack 04:30 US Military Breach by Chinese Hackers 07:07 $27 Million Crypto Theft 08:58 Conclusion and Listener Engagement
In this episode hosted by Jim Love, 'Cybersecurity Today' celebrates its recognition as number 10 on the Feed Spot list of Canadian News Podcasts and approaches a milestone of 10 million downloads. Key topics include new research identifying Nvidia GPUs as vulnerable to Rowhammer style attacks, Microsoft's significant security improvements in Microsoft 365, a critical Bluetooth vulnerability affecting 350 million cars, and a data exposure incident involving the Fredericton Police. Additionally, the official 'Elmo' account on X was hacked to post offensive content, emphasizing security gaps in high-profile social media accounts. For detailed information, visit technewsday.com or .ca.
00:00 Introduction and Milestones 00:52 Nvidia's Rowhammer Vulnerability 03:39 Microsoft's Security Overhaul 05:45 PerfektBlue Bluetooth Flaw 08:09 Police Data Leak Incident 10:12 Elmo's Twitter Account Hacked 12:43 Conclusion and Thanks
In this episode of 'Cybersecurity Today,' hosted by David Shipley from the Exchange Security 2025 conference, urgent updates are provided on critical cybersecurity vulnerabilities and threats. CISA mandates a 24-hour patch for Citrix NetScaler due to a severe vulnerability actively being exploited, dubbed 'Citrix Bleed.' Fortinet’s FortiWeb also faces a critical pre-auth remote code execution flaw that demands immediate patching. Additionally, significant vulnerabilities in AI-driven developments are highlighted, including shortcomings in Jack Dorsey's BitChat app and a method to extract Windows keys from ChatGPT-4. The episode emphasizes the importance of timely updates, robust security measures, and the potential risks involved with AI-generated code.
00:00 Introduction and Overview 00:35 Urgent Citrix Vulnerability Alert 03:26 Fortinet FortiWeb Exploit Details 06:23 Ingram Micro Ransomware Recovery 09:26 AI Coding and Security Risks 14:03 ChatGPT Security Flaw Exposed 17:20 Conclusion and Contact Information
In this episode of 'Cybersecurity: Today's Month in Review,' the panel of experts, including Laura Payne, David Shipley, and new guest Tammy Harper, delve into major cybersecurity stories from the past month. Discussions range from the recent arrest of a Montreal scam operator, Scattered Spider's targeted attacks on various sectors, and the impacts of AI on the cybersecurity landscape. The panel also highlights industry shifts, new threat tactics, and the importance of strategic communication during incidents. The episode concludes with reflections on AI's integration into enterprise systems, emphasizing preparation and ethical considerations.
00:00 Introduction to the Cybersecurity Month in Review 00:12 Meet the Panelists 00:26 Laura Payne's Introduction 01:04 David Shipley's Introduction 01:38 Tammy Harper's Introduction 04:09 First Story: Montreal Scam Arrest 10:52 David Shipley's Big Story: Scattered Spider 16:40 The Rise of Young Cybercriminals 32:36 Ingram Micro Ransomware Attack 33:27 Government Breaches and Fast Recovery 34:56 Ingram Micro Incident and Communication Failures 35:55 Importance of Communication in Incident Response 37:39 Ransomware Trends and Threat Actor Tactics 39:55 Shift from Encryption to Exfiltration 46:41 Government Actions and Market Impact 51:27 AI in Cybersecurity: Risks and Opportunities 58:53 Ethical AI and Future Considerations 01:08:12 Final Thoughts and Wrap-Up
In this episode of Cybersecurity Today, host Jim Love discusses major updates on the recent cyber attack on Marks and Spencer, revealing new details and arrests. The breach involved sophisticated social engineering that infiltrated the company's network through an IT service provider, leading to 150GB of stolen data. Love then covers a massive insider breach at a Brazilian bank where an IT worker facilitated the theft of $140 million by selling login credentials. Lastly, the episode highlights a McDonald's HR data breach caused by weak security practices in an AI screening app, exposing millions of job applicant records. Key insights on these incidents emphasize the importance of robust cybersecurity measures and internal controls.
00:00 Introduction and Headlines 00:20 Marks and Spencer Hack: New Developments 04:07 Brazilian Bank Breach: An Inside Job 06:40 McDonald's HR Data Breach: A Comedy of Errors 10:21 Conclusion and Upcoming Features
In this episode of 'Cybersecurity Today,' host Jim Love discusses the recent deep fake attack on high-ranking US government officials using AI voice cloning technology. The conversation highlights the growing ease and risks of AI-generated impersonations. The episode also covers the advancements in AI systems connecting with enterprise data and the security implications, alongside recent updates on events like Ingram Micro's ransomware attack and Google's confusing Gemini AI rollout for Android. Additionally, the show explores a new method called Info Flood that can trick chatbots into providing dangerous information by using academic-sounding language.
00:00 Deep Fakes Hit US Government 02:40 AI Integration in Enterprise Systems 05:49 Ingram Micro Ransomware Attack Update 07:22 Google's Confusing Gemini Release 10:33 Exploiting AI with Academic Jargon 12:34 Conclusion and Contact Information
In this episode of Cybersecurity Today, host David Shipley discusses the recent Safe Play ransomware attack on technology distributor Ingram Micro, exploring its impact and ongoing recovery efforts. The script also examines a new campaign targeting misconfigured Linux servers to build proxy networks for cybercriminal activities. Additionally, the episode highlights the significant rise in Click Fix social engineering attacks and the criminal investigation into a former ransomware negotiator accused of profiting from extortion payments.
00:00 Introduction and Headlines 00:30 Ingram Micro Ransomware Attack 03:57 Linux Servers Under Attack 07:05 Rise of Click Fix Social Engineering Attacks 08:45 Ransomware Negotiator Under Investigation 10:13 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love engages in a comprehensive conversation with Krish Banerjee, the Canada Managing Director at Accenture for AI and Data. They delve into the stark difference between perceived and actual preparedness for cybersecurity in the face of growing AI adoption. The discussion spans topics such as the role of AI in enterprise productivity, the need for better data management, and the integration of AI into various business functions. They also explore the importance of digital sovereignty, the challenges and opportunities in Canada's adoption of AI, and how open-source AI can benefit organizations. Krish emphasizes the significance of setting a clear value-driven goal, having the right tools and talent, and the necessity of adopting AI responsibly. The conversation wraps up with insights on how executives can navigate the AI landscape and prepare their organizations for future advancements.
00:00 Introduction to Cybersecurity and AI Concerns 02:10 Interview with Krish Banerjee: AI in Canada 03:17 The Evolution and Impact of AI 06:42 Enterprise AI: Challenges and Opportunities 15:20 Digital Sovereignty and National AI Strategies 25:07 Accelerating Technological Adoption 26:18 Dream Projects in AI 27:49 AI for Healthcare and Commercialization 31:02 The Future of AI and Economic Impact 35:31 Agentic AI: The Next Frontier 41:14 Open Source AI and Democratization 43:23 Advice for Executives and Parents 49:10 Conclusion and Final Thoughts
In today's episode of Cybersecurity Today, hosted by David Shipley, a report from the US Department of Justice unveils how criminal organizations use Ubiquitous Technical Surveillance (UTS) to track and kill FBI informants. Hawaiian Airlines experiences a cyber attack, potentially involving ransomware. The Supreme Court upholds Texas's age verification law for accessing online pornographic content. Additionally, researchers discover Bluetooth vulnerabilities affecting various audio devices, posing eavesdropping risks. The show discusses Scattered Spider's successful social engineering attacks on major industries, emphasizing the need for robust cybersecurity measures.
00:00 Introduction to Cybersecurity Threats 00:27 Ubiquitous Technical Surveillance: A Growing Threat 02:33 Assassination Linked to Data Brokers 04:21 Cyber Attacks on Airlines 05:02 Scattered Spider: The Prolific Cyber Threat 08:10 Bluetooth Vulnerabilities Exposed 10:53 US Supreme Court Upholds Texas Porn ID Law 13:32 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love is joined by Krish Banerjee, the Canada Managing Director at Accenture for AI and Data. They begin the discussion with a report from Accenture that highlights the gap between the perceived and actual preparedness for cybersecurity as AI becomes more integrated into business operations. Jim and Krish discuss the pressing need for businesses to implement AI responsibly while addressing cybersecurity concerns. They also touch upon the current state of AI in Canada, efforts towards digital sovereignty, and the importance of integrating AI thoughtfully into various sectors. Through their insightful conversation, they explore the challenges and opportunities that lie ahead in making AI a cornerstone of productivity and innovation in the enterprise, emphasizing the need for value-driven strategies, the right tools, and skilled talent.
00:00 Introduction and Overview 02:10 AI in the Enterprise: Challenges and Opportunities 03:17 The Evolution of Data and AI 06:42 Enterprise AI: Current State and Future Prospects 15:20 Digital Sovereignty and National AI Strategies 25:07 Accelerating Technological Advancements 26:18 Dream Projects and AI for Good 27:58 Reinventing Healthcare with AI 28:42 Commercializing AI for Canadian Businesses 30:30 The Responsibility of AI Development 31:02 Economic Shifts and AI's Role 31:57 Future Predictions for AI 35:31 Agentic AI: The Next Frontier 41:14 Open Source AI and Its Implications 43:32 Advice for Executives on AI Adoption 47:13 Encouraging AI Learning in the Next Generation 49:10 Final Thoughts and Reflections
In this episode of 'Cybersecurity Today,' host Jim Love discusses urgent cybersecurity threats and concerns.
Cisco has issued emergency patches for two maximum severity vulnerabilities in its Identity Services Engine (ISE) that could allow complete network takeover; organizations are urged to update immediately.
A popular WordPress theme, Motors, has a critical vulnerability leading to mass exploitation and unauthorized admin account creation. A new ransomware group,
Dire Wolf, has emerged, targeting manufacturing and technology sectors with sophisticated double extortion tactics.
Lastly, an Accenture report reveals a dangerous gap between executive confidence and actual AI security preparedness, suggesting most major companies are not ready to handle AI-driven threats. The episode emphasizes the urgent need for immediate action and heightened awareness in the cybersecurity landscape.
00:00 Introduction and Headlines 00:26 Cisco's Critical Security Flaws 03:06 WordPress Theme Vulnerability Exploitation 05:57 Dire Wolf Ransomware Group Emerges 08:27 Accenture Report on AI Security Overconfidence 11:00 Conclusion and Upcoming Schedule
In this episode of Cybersecurity Today, host Jim Love discusses various pressing issues and trends in the realm of cybersecurity. The episode starts with a revelation from Okta's 2025 Customer Identity Trends report, which highlights the conflicting digital behaviors of Canadians who, despite their fear of identity theft, often reuse passwords across multiple accounts. The show also dives into the sophisticated 'Lap Dogs' campaign led by Chinese hackers who have compromised home and small office devices worldwide. Jim further touches upon the surprising decline in cyber insurance premiums despite persisting threats, alongside a story about Jeff Bezos potentially spying through smart mattresses with security vulnerabilities. The episode underscores the critical need for better security measures and the potential business risks of weak authentication systems.
00:00 Introduction and Host Welcome 00:24 Canadian Identity Theft Concerns 03:02 Chinese Hacking Operation Exposed 06:02 Cyber Insurance Premiums Drop 09:39 Smart Mattress Security Nightmare 12:46 Conclusion and Contact Information
In this episode of Cybersecurity Today, hosted by David Shipley, key cybersecurity incidents and threats are discussed.
The Canadian Center for Cybersecurity revealed a breach by Chinese state-sponsored hackers of a Canadian telco, with further threats expected to continue targeting Canadian critical infrastructure.
The U.S. braces for potential Iranian cyber retaliation following recent attacks on Iranian nuclear sites, with officials urging increased security measures.
Meanwhile, a significant vulnerability chain in Sitecore XB has been disclosed, affecting thousands of instances globally with potentially severe repercussions if not patched.
Additionally, a sophisticated phishing campaign by Russian hackers bypassed Gmail MFA using app-specific passwords to target high-profile individuals. The episode emphasizes the importance of patching vulnerabilities, enforcing strong security practices, and staying vigilant against evolving cyber threats.
00:00 Introduction and Headlines 00:29 Chinese Hackers Breach Canadian Telco 03:46 US Braces for Iranian Cyber Retaliation 06:50 Sitecore XB Vulnerability Exposed 11:13 Russian Phishing Campaign Targets High-Profile Individuals 15:23 Conclusion and Final Thoughts
In this thought-provoking episode of Project Synapse, host Jim and his friends Marcel Gagne and John Pinard delve into the complexities of artificial intelligence, especially in the context of cybersecurity.
The discussion kicks off by revisiting a blog post by Sam Altman about reaching a 'Gentle Singularity' in AI development, where the progress towards artificial superintelligence seems inevitable.
They explore the idea of AI surpassing human intelligence and the implications of machines learning to write their own code.
Throughout their engaging conversation, they emphasize the need to integrate security into AI systems from the start, rather than as an afterthought, citing recent vulnerabilities like Echo Leak and Microsoft Copilot's Zero Click vulnerability.
Derailing into stories from the past and pondering philosophical questions, they wrap up by urging for a balanced approach where speed and thoughtful planning coexist, and to prioritize human welfare in technological advancements. This episode serves as a captivating blend of storytelling, technical insights, and ethical debates.
00:00 Introduction to Project Synapse 00:38 AI Vulnerabilities and Cybersecurity Concerns 02:22 The Gentle Singularity and AI Evolution 04:54 Human and AI Intelligence: A Comparison 07:05 AI Hallucinations and Emotional Intelligence 12:10 The Future of AI and Its Limitations 27:53 Security Flaws in AI Systems 30:20 The Need for Robust AI Security 32:22 The Ubiquity of AI in Modern Society 32:49 Understanding Neural Networks and Model Security 34:11 Challenges in AI Security and Human Behavior 36:45 The Evolution of Steganography and Prompt Injection 39:28 AI in Automation and Manufacturing 40:49 Crime as a Business and Security Implications 42:49 Balancing Speed and Security in AI Development 53:08 Corporate Responsibility and Ethical Considerations 57:31 The Future of AI and Human Values
In this episode of 'Cybersecurity Today,' host Jim Love discusses several alarming cybersecurity developments.
A recent Washington Post breach raises critical questions about Microsoft 365’s enterprise security as foreign government hackers compromised the email accounts of journalists.
Additionally, a critical Linux flaw allows attackers to gain root access, making millions of systems vulnerable.
Upgraded Godfather malware now creates virtual banking apps on infected Android devices to steal credentials in real-time. Moreover, a record-breaking data breach has exposed 16 billion logins, including Apple accounts, underscoring the fundamental flaws of password-based security.
Finally, the episode addresses the systemic vulnerabilities of SMS-based two-factor authentication, advocating for a transition to app-based or hardware key solutions.
00:00 Introduction and Major Headlines 00:24 Microsoft 365 Security Breach 03:19 Critical Linux Vulnerabilities 05:59 Godfather Malware Evolution 08:18 Massive Data Breach Exposed 11:30 The Fall of SMS Two-Factor Authentication 13:21 Conclusion and Final Thoughts
In this episode, host Jim Love delves into recent cybersecurity threats and breakthroughs.
The notorious Scattered Spider hacker group has shifted its focus to US insurance companies after attacking UK retailers earlier this year.
Microsoft's urgent security updates address active zero-day vulnerabilities that allow complete system control. Researchers uncovered an unprotected database exposing 184 million plaintext passwords linked to major platforms.
Additionally, musician Beardly Jordan has developed 'Poison Deify,' a technology to protect his music from unauthorized AI scraping by embedding adversarial noise that disrupts machine learning algorithms. These developments highlight the evolving cybersecurity landscape, from coordinated cyber-attacks to innovative countermeasures against AI exploitation.
For further details and to engage with the content, listeners are encouraged to visit technewsday.ca.
00:00 Introduction and Headlines
00:30 Scattered Spider Targets US Insurance Companies
02:26 Microsoft Urges Immediate Windows Updates
04:15 Massive Database Breach Exposes 184 Million Passwords
06:59 Musician Strikes Back at AI with Audio Poison Pill
10:07 Implications for Cybersecurity
10:37 Conclusion and Listener Engagement
Host David Shipley discusses several critical cybersecurity incidents and developments. WestJet, Canada's second-largest airline, faced a cybersecurity breach impacting its mobile app and internal systems.
The airline is working with law enforcement to investigate while emphasizing the integrity of its flight operations. Additionally, the Anubis ransomware has evolved, now incorporating a file-wiping function to heighten victim pressure and destruction.
The episode also covers a novel malware campaign exploiting Discord's vanity invite system to deliver remote access trojans and info stealers, highlighting platform trust vulnerabilities.
Lastly, a significant multi-hour Google Cloud outage caused by an API quota misconfiguration affected numerous services globally, emphasizing the fragility of our interconnected digital infrastructure. The episode underscores the need for robust disaster recovery plans and cautious digital practices.
00:00 Introduction and Overview 00:30 WestJet Cybersecurity Incident 02:15 Anubis Ransomware Evolution 05:35 Discord Vanity Link Hijack 08:35 Google Cloud Outage 10:50 Conclusion and Final Thoughts
In this episode of 'Cybersecurity Today,' hosts John Pinard and Jim Love introduce their unique show, 'The Secret CISO,' which aims to dive deep into the lives and thoughts of CISOs and similar roles, beyond the usual interview-style format. The guest for this episode is Priya Mouli, CISO at Sheridan College, who shares her journey from engineering to cybersecurity, her global experiences, and how she manages her multifaceted role. Another guest, Mohsen Azari, Director of Cyber Defense in the financial sector, discusses his career path, which includes notable stints in entertainment and consulting. The conversation explores the pressing challenges in cybersecurity such as AI threats, burnout, and vendor tool overload, while emphasizing the importance of people skills and relationship-building within organizations. The episode wraps up with a promise of a follow-up discussion to delve deeper into the impact of AI on cybersecurity.
00:00 Introduction to the Secret CISO Show 00:51 Guest Introductions: Meet Priya Ali 01:59 Priya's Career Journey and Insights 06:44 Mohsen's Background and Career Path 13:12 John's Career and Cybersecurity Evolution 15:58 Current Cybersecurity Challenges 24:04 Adapting to New Roles in Cybersecurity 25:36 Managing People and Preventing Burnout 27:08 Servant Leadership and Team Dynamics 31:16 Strategic Hiring and Team Cohesion 33:42 Handling Stress and Personal Well-being 35:46 The Role of CISOs as Organizational Psychologists 40:54 Influencing Behavior and Building a Security Culture 44:28 Coping with the Barrage of Cybersecurity Tools 51:10 Conclusion and Future Discussions
In this episode of Cybersecurity Today, host Jim Love discusses critical AI-related security issues, such as the Echo Leak vulnerability in Microsoft's AI, MCP's universal integration risks, and Meta's privacy violations in Europe. The episode also explores the dangers of internet-exposed cameras as discovered by BitSight, highlighting the urgent need for enhanced AI security and the legal repercussions for companies like Meta.
00:00 Introduction to AI Security Issues 00:24 Echo Leak: The Zero-Click AI Vulnerability 03:17 MCP Protocol: Universal Interface, Universal Vulnerabilities 07:01 Meta's Privacy Scandal: Local Host Tracking 10:11 The Peep Show: Internet-Connected Cameras Exposed 12:08 Conclusion and Call to Action
This episode of 'Cybersecurity Today' hosted by Jim Love covers various significant events in the cybersecurity landscape. OpenAI has banned multiple ChatGPT accounts linked to state-sponsored hackers from countries including China, Russia, North Korea, Iran, and the Philippines for developing malware, generating disinformation, and conducting scams.
The episode also discusses the Dark Gaboon hacker group, which targets Russian companies with Lock Bit 3.0 ransomware.
Furthermore, it highlights the controversial installation of a Starlink satellite internet terminal at the White House by Elon Musk's DOGE team, bypassing normal security measures, and a hardware enthusiast's successful use of ChatGPT to unlock an Android tablet's BIOS, raising questions about firmware security.
00:00 Open AI Bans ChatGPT Accounts used by state backed hackers 00:25 State-Sponsored Threat Actors Exploiting ChatGPT 04:36 Dark Gaboon: A New Hacker Group Targets Russia 07:11 Elon Musk's DOGE Team Installs Starlink at the White House 09:57 Unlocking an Android Tablet with ChatGPT 12:07 Conclusion and Contact Information
In this episode of Cybersecurity Today, host David Shipley delves into alarming developments in the cybersecurity landscape. The FBI has flagged a massive malware campaign named Bad Box 2.0, which has compromised 1 million consumer devices globally, turning them into residential proxies. Additionally, a new variant of the Mirai malware is targeting DVR devices via a critical vulnerability. Meanwhile, criminals are shifting their operations from bulletproof hosts to harder-to-trace VPNs and residential proxy networks.
The episode also covers urgent calls for post-quantum cryptography readiness amidst looming quantum computing threats, alongside a significant policy shift in the US. President Trump has signed an executive order dismantling former President Biden's extensive cybersecurity initiatives, including efforts focused on AI and quantum cryptography. These regulatory rollbacks emphasize minimal federal oversight and leave long-term digital defense strategies in question.
00:00 Introduction and Major Headlines 00:32 FBI Warns About Bad Box 2.0 Botnet 02:47 DVR Botnet Threats and Exploits 03:59 Shift in Cybercriminal Tactics 05:33 Quantum Computing and Encryption Concerns 07:08 Trump's Cybersecurity Policy Overhaul 11:36 Conclusion and Final Thoughts
In this episode of the 'Cybersecurity Today: The Month in Review' show, host Jim welcomes regular guests Laura Payne and David Shipley, along with newcomer Anton Levaja. The trio dives deep into various cybersecurity stories, analyzing trends, threats, and recent incidents. Topics include the intriguing Mystery Leaker exposing cyber criminals, the rise and sophistication of LockBit ransomware, the devastating ransomware attack on Coinbase and their bold counter-response, and the physical dangers faced by cryptocurrency entrepreneurs. The episode also highlights the innovation in law enforcement tactics and the pressing need for better cybersecurity awareness and education. They wrap up on a hopeful note, showcasing a young scout's inspiring project on cyber fraud prevention that gained support from the local police.
00:00 Introduction and Panelist Welcome 00:38 Show Format and Story Introduction 01:28 The Mystery Leaker Story 03:35 Law Enforcement and Cyber Crime 10:51 Coinbase Ransomware Incident 18:04 Physical Threats in the Crypto World 24:56 Operation Shamrock and Organized Crime 25:19 Breaking News: Kidnapping Mastermind Arrested 26:18 Quishing: The Clever Side of Cybercrime 27:11 QR Code Scams and Consumer Protection 31:08 Generational Differences in Cyber Threats 32:05 The Evolution of Cyber Attacks 38:40 Physical Crime in the Digital Age 41:10 Law Enforcement and Cybersecurity 43:55 Government Surveillance and Privacy Concerns 46:08 Feel-Good Story: Young Cybersecurity Advocate
Cybersecurity Today, hosted by Jim Love, delves into the latest in cyber threats. Cyber criminals have breached 20 organizations via convincing fake IT support calls, targeting Salesforce data for extortion. Ukraine's intelligence claims a significant cyber operation against Russia's aircraft manufacturer, stealing sensitive data and highlighting Ukraine's growing cyber capabilities. Google Chrome will stop trusting certificates from two major authorities due to compliance failures, affecting millions of web visitors. Lastly, a $400 million hack on Coinbase was executed using phone cameras, reminding us of the potency of simple attacks.
00:00 Introduction and Headlines 00:23 Fake IT Support Scam Hits 20 Companies 03:52 Ukraine's Cyber Operation Against Russia 07:05 Google Chrome Stops Trusting Two Certificate Authorities 09:11 $400 Million Hack from a Phone Camera 11:24 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love discusses the latest urgent security updates and cyber threats. Google has released an emergency Chrome patch to fix a high-severity zero-day vulnerability, while Microsoft issued an emergency patch to resolve Windows 11 boot failures caused by their May 2025 update. A mysterious whistleblower known as 'Gang Exposed' is doxing major ransomware leaders, providing invaluable intelligence for global cybersecurity efforts. Additionally, 'Quishing,' or QR code phishing, is emerging as a new threat, with cybercriminals taping malicious QR codes on public lampposts and street corners. This trend bypasses traditional digital defenses, underscoring the need for public awareness and vigilance. The episode emphasizes the importance of immediate updates, informed vigilance, and proactive cybersecurity measures.
00:00 Emergency Chrome Patch and Windows 11 Boot Fix 00:28 Google's Zero-Day Vulnerability in Chrome 02:28 Microsoft's Emergency Update for Windows 11 05:35 Gang Exposed: Unmasking Ransomware Leaders 07:55 Quishing: The New QR Code Phishing Threat 10:22 Conclusion and Viewer Engagement
In this episode of Cybersecurity Today, host David Shipley discusses several key cyber incidents affecting organizations and individuals. A new rust-based information stealer, known as Eddie Steeler, is being distributed via deceptive CAPTCHA verification pages. ConnectWise, a management software firm, has been breached in an attack suspected to be linked to a nation-state actor, affecting a limited number of its ScreenConnect customers. Additionally, threat actors are now abusing Google App Script to bypass phishing defenses, exploiting the trusted Google brand to trick users. Lastly, a significant data breach at Nova Scotia Power has exposed the social insurance numbers of up to 140,000 customers, making it one of the largest utility data breaches in North America.
00:00 Introduction to Today's Cybersecurity News 00:31 Eddie Steeler Malware Campaign 02:32 ConnectWise Cyber Attack 04:49 Google App Script Phishing Attacks 06:50 Nova Scotia Power Data Breach 08:02 Conclusion and Listener Engagement
In this episode, the host delves into the alarming rise of 'pig butchering' scams, a form of fraud that preys on vulnerable and trusting individuals, often leaving them financially and emotionally devastated. These scams are orchestrated by organized crime syndicates that use brutal methods, including violence and human trafficking, to sustain their operations. Erin West, a former prosecutor, discusses her transition to founding Operation Shamrock, a nonprofit focused on combatting these scams through education, law enforcement support, and victim assistance. West explains the severity of the issue, sharing insights into the terrifying environments where these scams are executed and the challenges victims face in reporting and recovering their losses. She emphasizes the need for public awareness, empathy, and collaborative efforts to tackle the global crisis. The episode concludes with actionable steps for cybersecurity professionals and the public to join the fight against this pervasive fraud.
00:00 Introduction to Cybersecurity and Pig Butchering Scams 01:42 The Human Impact of Scams 03:33 Operation Shamrock: Fighting Back 04:04 Interview with Erin West: From Prosecutor to Advocate 06:24 Understanding the Scale and Evolution of Scams 08:33 The Role of Technology in Modern Scams 12:17 Operation Shamrock's Mission and Strategies 15:13 Empowering Victims and Law Enforcement 29:28 Raising Awareness and Taking Action 37:50 Conclusion and Call to Action
In this episode of Cybersecurity Today, host Jim Love covers critical updates in the world of cyber threats. The FBI warns of hijackers posing as IT support to infiltrate law firms, a Wisconsin city reveals a ransomware attack affecting 67,000 residents, and a Texas city refuses to pay a ransom, risking the public release of sensitive data. The episode also highlights the 3-2-1-1-0 backup strategy as a defense against ransomware and reports on sophisticated scams targeting summer travelers. Additionally, Jim previews tomorrow’s discussion on scammers targeting vulnerable groups.
00:00 Introduction and Headlines 00:29 FBI Warns of IT Support Scams Targeting Law Firms 03:18 Ransomware Attack on Sheboygan, Wisconsin 05:24 Texas City Refuses Ransom Payment 07:05 Understanding the 3-2-1-1-0 Backup Strategy 09:37 Summer Travel Scams on the Rise 12:55 Conclusion and Upcoming Topics
In this episode of Cybersecurity Today, host Jim Love explores the intricacies behind phishing emails that cleverly spoof Microsoft addresses, making many fall for scams despite appearing legitimate. Love emphasizes the need for a stringent 'zero trust' approach to counter these advanced tactics.
Additionally, the episode delves into the activities of the hacking group Hazy Hawk, which exploits misconfigured DNS records to hijack trusted domains and propagate malware. Organizations are warned about the importance of regular DNS audits to prevent such attacks. The episode also covers the alarming wave of departures at the Cybersecurity and Infrastructure Security Agency (CISA), raising concerns over the agency's effectiveness amid increasing cyber threats.
In another segment, Love discusses a sophisticated fraud operation out of Hanoi, where perpetrators manipulated X's Creator Revenue Sharing Program to siphon funds through fraudulent engagement metrics. The need for built-in fraud prevention mechanisms in digital reward systems is stressed. The episode concludes with a call for listener feedback and support.
00:00 Introduction and Overview 00:27 Phishing Scams: Authentic-Looking Emails 02:58 DNS Misconfigurations and Hazy Hawk 05:36 CISA Leadership Exodus 08:16 X's Creator Revenue Sharing Fraud 10:56 Conclusion and Contact Information
In this episode of Cybersecurity Today, host David Shipley dives into several alarming cyber incidents.
The show starts with Nova Scotia Power's confirmation of a ransomware attack that forced the shutdown of customer-facing systems and led to data being published on the dark web. The company decided not to pay the ransom, adhering to law enforcement guidance and sanctions laws.
A shocking case in New York follows, involving a crypto investor charged with kidnapping and torturing a man to obtain his Bitcoin wallet password.
The next segment highlights a record-setting DDoS botnet, Aisuru, which performed a test attack that peaked at 6.3 terabits per second, posing a disproportionate threat to online retailers.
The final story covers Microsoft's controversial AI feature, Recall, which takes screenshots every three seconds and raises significant privacy concerns. The episode underscores the growing need for robust cybersecurity measures and effective legislation.
00:00 Introduction and Headlines 00:30 Nova Scotia Power Ransomware Attack 02:57 Ransomware Trends and Statistics 03:51 Operation End Game: A Global Win Against Ransomware 04:25 Crypto Investor's Shocking Crime 05:57 Record-Breaking DDoS Botnet 07:36 Microsoft's Controversial AI Feature Recall 09:10 Conclusion and Sign-Off
LINKS:
https://distrust.co/software.html - Software page with OSS software Linux distro: https://codeberg.org/stagex/stagex
Milksad vulnerability: https://milksad.info/
In this episode of Cybersecurity Today on the Weekend, host Jim Love engages in a captivating discussion with Anton Livaja from Distrust. Anton shares his unique career transition from obtaining a BA in English literature at York University to delving into cybersecurity and tech. Anton recounts how he initially entered the tech field through a startup and quickly embraced programming and automation. The conversation covers Anton's interest in Bitcoin and blockchain technology, including the importance of stablecoins, and the frequent hacking incidents in the crypto space. Anton explains the intricacies of blockchain security, emphasizing the critical role of managing cryptographic keys. The dialogue also explores advanced security methodologies like full source bootstrapping and deterministic builds, and Anton elaborates on the significance of creating open-source software for enhanced security. As the discussion concludes, Anton highlights the need for continual curiosity, teamwork, and purpose-driven work in the cybersecurity field.
00:00 Introduction to Cybersecurity Today 00:17 Anton's Journey from Literature to Cybersecurity 01:08 First Foray into Programming and Automation 02:35 Blockchain and Its Real-World Applications 04:36 Security Challenges in Blockchain and Cryptocurrency 13:21 The Rise of Insider Threats and Social Engineering 16:40 Advanced Security Measures and Supply Chain Attacks 22:36 The Importance of Deterministic Builds and Full Source Bootstrapping 29:35 Making Open Source Software Accessible 31:29 Blockchain and Supply Chain Traceability 33:34 Ensuring Software Integrity and Security 38:20 The Role of AI in Code Review 40:37 The Milksad Incident 46:33 Introducing Distrust and Its Mission 52:23 Final Thoughts and Encouragement
In this episode of Cybersecurity today, host Jim Love reports on various critical cyber threats and data breaches. A newly discovered flaw in Windows Server 2025 allows attackers to seize full domain control, referred to by researchers as the 'bad successor' exploit. Government messaging app Telem Message, a customized version of Signal, was hacked, exposing sensitive communications of over 60 officials, leading to its shutdown. Microsoft disrupted the global Luma Stealer malware operation, which had infected nearly 400,000 computers. Coinbase suffered a major data breach affecting over 69,000 customers due to an insider compromise. Additionally, hackers distributed a malicious version of the KeyPass password manager, embedding it with malware to steal data and deploy ransomware. Jim Love encourages listeners to stay vigilant and download software only from official sources. He teases an upcoming interview with a knowledgeable guest working on open-source solutions to cybersecurity issues.
00:00 Introduction to Cybersecurity News 00:36 Windows Server 2025 Vulnerability 03:09 Telem Messages Hack Scandal 05:37 Microsoft Disrupts Luma Malware 07:29 Coinbase Breach Details 08:54 Malicious Password Manager Alert 10:55 Conclusion and Upcoming Interview
In this episode of 'Cybersecurity Today,' host Jim Love discusses several urgent cybersecurity topics. Microsoft has released an emergency patch after a recent Windows update caused BitLocker recovery mode on certain systems, locking users out without warning. The issue stems from the May security update affecting systems using Intel, vPro chips, and TXT. Tech enthusiasts may manually download the patch through the Microsoft Update catalog, while Microsoft urges users to secure their BitLocker recovery keys. The episode also highlights day one of Pwn2Own Berlin 2025, where hackers successfully breached Windows 11, Red Hat Linux, and Oracle Virtual Box, earning a combined $260,000 in prize money. Additionally, US experts discovered hidden communication hardware in Chinese-made solar equipment, raising concerns about remote access risks to the power grid. The FBI warns of a new wave of AI-generated phishing attacks that bypass traditional security measures. Finally, the Consumer Financial Protection Bureau has quietly backed down from regulating data brokers, sparking controversy among privacy advocates. Jim Love offers insights and reminds listeners of the importance of cybersecurity.
00:00 Introduction and Headlines 00:27 Microsoft's Urgent Patch for BitLocker Issue 02:26 Pwn2Own Berlin 2025: Major Security Breaches 04:11 Hidden Devices in Chinese Solar Equipment 06:05 FBI Warns of New Linkless Phishing Attacks 07:58 CFPB Withdraws Rule on Data Brokers 09:33 Conclusion and Contact Information
In this episode of 'Cybersecurity Today', host Jim Love is joined by panelists Laura Payne from White Tuque and David Shipley from Beauceron Security to review significant cybersecurity events over the past month. The discussion covers various impactful stories such as the disappearance of a professor, a data breach at Hertz, and government officials using a commercial app during a conflict. They dive deep into the ransomware attack on PowerSchool and its implications for K-12 schools in North America. The conversation also highlights the vulnerability of critical infrastructures, including the food supply chain and the importance of robust cybersecurity measures. Finally, the panel touches upon the progression towards post-quantum encryption by major tech companies like AWS and Google, signaling advancements in securing future technologies.
00:00 Introduction and Panelist Welcome 00:20 Major Cybersecurity Incidents of the Month 02:04 PowerSchool Data Breach Analysis 04:11 Ransomware and Double Extortion Tactics 12:20 4chan Security Breach and Its Implications 16:31 Hertz Data Loss and Retail Cybersecurity 17:44 Critical Infrastructure and Cyber Regulation 27:03 The Importance of CVE Database 27:54 Debate on Vulnerability Scoring 30:17 Open Source Software and Geopolitical Risks 31:43 The Evolution and Challenges of Open Source 37:17 The Need for Software Regulation 46:50 Signal Gate and Compliance Issues 54:08 Post-Quantum Cryptography 56:10 Conclusion and Final Thoughts
In this episode, Jim Love discusses significant cybersecurity events including Coinbase's refusal to pay a $20 million ransom after a data breach, Broadcom's patch for VMware tools vulnerabilities, and Telegram's shutdown of two illegal marketplaces handling $35 billion in transactions. The episode also covers the Co-op’s preemptive measures to thwart a ransomware attack and the broader implications for cybersecurity in retail. Experts urge organizations to be prepared with strategic playbooks for potential cyber-attacks.
00:00 Introduction and Headlines 00:26 Telegram's $35 Billion Black Market Shutdown 01:59 Broadcom Patches VMware Tools Vulnerability 03:20 Coinbase Ransom Refusal and Data Breach 04:57 Co-op's Ransomware Defense Strategy 07:36 Conclusion and Upcoming Episodes
In this episode of Cybersecurity Today, host Jim Love covers recent cybersecurity incidents including a data breach at Mark's and Spencer, the FBI's alert on outdated routers being exploited, and critical Fortinet vulnerabilities actively used in attacks. Additionally, the episode discusses a researcher’s proof of concept showing how ransomware can be embedded directly into a CPU, bypassing traditional security measures. Listeners are urged to stay vigilant and implement necessary security patches and updates.
00:00 Breaking News: Marks and Spencer Data Breach 01:37 FBI Alert: Outdated Routers at Risk 03:43 Fortinet Zero-Day Vulnerability 05:46 Ransomware Embedded in CPUs: A New Threat 08:13 Conclusion and Contact Information
In this episode of Cybersecurity Today, host David Shipley covers a range of cyber threats including the Venom Spider malware targeting HR professionals, the emergence of the Noodlofile info stealer disguised as an AI video generator, and misinformation campaigns amid the India-Pakistan conflict. Additionally, the episode discusses warnings from U.S. agencies about cyberattacks on the oil and gas sector, and highlights a recent interview with whistleblower Daniel Brules about security lapses at the National Labor Relations Board.
00:00 Introduction and Overview 00:33 Venom Spider Targets HR Professionals 02:12 Fake AI Video Generators and Noodlofile Malware 03:41 Misinformation Amid India-Pakistan Conflict 05:40 US Oil and Gas Infrastructure Under Threat 07:22 Conclusion and Final Thoughts
In this gripping episode of Cybersecurity Today, host Jim Love interviews Daniel Berulis, a self-described whistleblower who recently made a significant disclosure to the U.S. Congress. Berulis reveals the shocking details of tenant admin abuse within a governmental cloud environment, which allowed unauthorized data copying and wiping of audit trails. They discuss Daniel's background, the alarming red flags he observed, his attempt to escalate the issue internally, and finally, his decision to report it to higher authorities. The conversation dives deep into the complexities and moral dilemmas faced by a whistleblower, offering viewers an insider look at the challenges in maintaining transparency and security in high-stakes IT environments.
00:00 Introduction to Cybersecurity Today 00:39 Meet Daniel Berulis: Whistleblower Extraordinaire 01:05 Understanding Tenant Admin Abuse 02:12 Daniel's Career and Community Involvement 05:28 The Mysterious Meeting and Initial Red Flags 08:48 Uncovering the Data Breach 11:56 Internal Reactions and Escalation 19:08 Reporting the Incident and Facing Consequences 23:45 The Whistleblower's Journey 32:31 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host Jim Love discusses recent cybersecurity breaches and vulnerabilities. Key topics include a security flaw in the new default setting of Microsoft OneDrive, a ransom incident involving PowerSchool that compromised student data, and the breach of a DOGE staffer's computer by info-stealing malware. The episode emphasizes the importance of proper security oversight, the risks of paying ransoms to cyber criminals, and the critical need for government agencies to reevaluate their cybersecurity protocols.
00:00 Introduction to Cybersecurity Today 00:30 Microsoft OneDrive Security Vulnerability 02:52 PowerSchool Ransomware Attack 07:20 DOGE Staffer Malware Breach 10:50 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host Jim Love delves into a range of alarming cyber incidents. A six-year sleeper supply chain attack has compromised thousands of e-commerce websites, exploiting vulnerabilities in Magento extensions from vendors Tigren, Meetanshi, and Magesolution. Russian-controlled open-source tool Easy JSON raises scrutiny over potential threats in critical sectors like defense and finance. In Ontario, a sophisticated bank draft scam costs a business $108,000, emphasizing the need for verification processes. Additionally, a messaging tool used by the Trump administration to archive Signal messages has been hacked twice, highlighting serious concerns over the security of high-level US communications. Stay tuned for the latest insights and expert advice on maintaining cybersecurity.
00:00 Sleeper Supply Chain Attack Activates After Six Years 02:19 Russian Controlled Open Source Tool Raises Alarms 04:32 Fake Bank Draft Fools the Bank 05:56 Signal Archiving Tool Breached 08:33 Conclusion and Contact Information
Cybersecurity Today: Disney Data Theft, Signal Gate, and Major Apple Vulnerability
In this episode of Cybersecurity Today, host David Shipley discusses several key security incidents. Hacker 'Null Bulge,' real name Ryan Kramer, pleads guilty to stealing over 1.1 TB of data from Disney's Slack via malware disguised as an AI image generation tool. Additionally, former National Security Advisor Mike Waltz's use of a compromised Signal app 'TM Signal' is explored, highlighting significant security flaws. The episode also covers critical vulnerabilities in Apple AirPlay-enabled devices that allow malicious code execution via Wi-Fi and reveals that an employee benefits administration provider breach has impacted 4 million Americans, significantly more than originally reported.
00:00 Introduction and Headlines 00:34 Disney's Slack Data Breach 02:00 Security Flaws in TM Signal App 03:18 Apple AirPlay Vulnerabilities 04:54 Massive Data Breach at Vari Source Services 06:59 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love is joined by roving correspondent David Shipley to discuss his experiences at the BSides and RSAC conferences. They dive into the significant takeaways from BSides, including highlights from notable presentations such as Truffle Hog's AI Apocalypse and Eva Galperin's talk on the 'World's Dumbest Cyber Mercenaries'. They also explore emerging trends in AI, deepfake technology, and the human side of cybersecurity. The discussion shifts to RSAC, examining vendor presence, CrowdStrike's gamified approach to engagement, and the broader implications of cybersecurity costs and industry consolidation. The episode underscores the importance of ongoing education, responsible cybersecurity practices, and the need for clear communication in the industry.
00:00 Introduction and Guest Introduction 01:24 BSides Conference Overview 03:55 Key Highlights from BSides 04:31 AI Apocalypse and Security Concerns 11:21 World's Dumbest Cyber Mercenaries 15:57 Deepfake Technology and Countermeasures 22:45 RSAC Conference Overview 28:48 Experiencing Autonomous Cars in San Francisco 30:00 The Future of High-Tech Mobility Solutions 32:22 AI in Cybersecurity: Implications and Discussions 37:26 The Role of AI in Coding and Its Challenges 40:34 Chris Krebs and the Importance of Speaking Truth to Power 44:36 Human Side of Cybersecurity: Security Champions 46:49 Operation Shamrock: Tackling Pig Butchering Scams 51:47 CrowdStrike and Vendor Strategies at Conferences 53:16 The Cost of Cybersecurity and Industry Consolidation 54:46 Conclusion and Future Interviews
In this episode, host Jim Love discusses various cybersecurity topics including a book deal from CRC Press for those interested in cybersecurity, auditing, and leadership. Major cyber incidents involving two UK retailers, Co-op and Marks & Spencer's, are detailed, highlighting the challenges they face. Apple's notifications to users in 100 countries about targeted mercenary spyware attacks are covered, emphasizing the importance of taking these alerts seriously. Additionally, a malicious WordPress plugin has been discovered that grants attackers unauthorized access, and an open letter from cybersecurity professionals calls on President Donald Trump to cease investigations into former CISA Director Chris Krebs. The episode concludes by previewing an upcoming segment covering the B Side and RSA shows.
00:00 Introduction and Special Announcement 00:16 Cybersecurity Book Deals 01:37 Major Cyber Attacks on UK Retailers 03:48 Apple's Spyware Alerts 06:22 Malicious WordPress Plugin Discovered 08:19 Open Letter Supporting Chris Krebs 10:57 Conclusion and Upcoming Events
In this episode of Cybersecurity Today, host Jim Love discusses several major cybersecurity events. Two members of Elon Musk's 'Department of Government Efficiency' reportedly gained access to classified US nuclear networks, though accounts were never activated. Nova Scotia Power faces a cyber attack affecting customer services but not critical infrastructure. Additionally, over 1.7 billion stolen credentials have surfaced on the dark web, primarily collected via info stealer malware, emphasizing the growing threat to corporate security. Lastly, the importance of advancing beyond traditional password security is highlighted on World Password Day. For more information, tune in to the episode or reach out via email or LinkedIn.
00:00 Introduction and Headlines 00:22 Musk's Doge Staffers and US Nuclear Networks 03:16 Nova Scotia Power Cybersecurity Incident 05:19 Massive Data Breach on World Password Day 07:56 Conclusion and Contact Information
In this episode of 'Cybersecurity Today', host David Shipley covers multiple key stories: Veritaco CEO Jeffrey Bowie is charged with attempting to infect a hospital with malware. Global Chief Information Security Officers (CISOs) call on world governments to harmonize cybersecurity regulations. Issues arise with Microsoft's recent 'Mystery Folder' security patch. Highlights from B-Side San Francisco's AI discussions include talks on weaponizing large language models and detecting deep fake technology. Additionally, the RSA Conference kicks off, promising numerous vendor announcements and updates.
00:00 Cybersecurity CEO Charged with Hospital Malware Attack 01:56 Global CISOs Call for Unified Cyber Regulations 03:59 Microsoft's Mystery Folder Fix Issues 05:37 AI Talks at B-Side San Francisco 08:08 RSA Conference Highlights and Conclusion
In this episode of Cybersecurity Today, host Jim Love delves into the topic of SaaS (Software as a Service) security. Sharing his early experiences promoting SaaS, Jim elaborates on its inevitable rise due to cost-effectiveness and shared development resources. The episode highlights security concerns with SaaS, such as shadow IT and weak access control, especially in the face of an influx of AI software. Jim introduces Yoni Shohet, CEO and Co-founder of Valence Security, who discusses the SaaS security landscape, focusing on the independent 'State of SaaS Security' report by the Cloud Security Alliance. Yoni outlines the importance of monitoring API tokens, ensuring proper configurations, and the challenges posed by non-human identities. The discussion underscores the evolving nature of SaaS security, encouraging stronger collaboration between security teams and business units to manage risks effectively.
00:00 Introduction to SaaS Security 00:01 The Evolution and Benefits of SaaS 01:33 Challenges and Security Concerns with SaaS 02:08 Introduction to the State of SaaS Security Report 02:34 Interview with Yoni Shohet: Background and Experience 03:06 Yoni Shohet's Journey in Cybersecurity 08:33 The Rise of SaaS Security Issues 14:03 Key Findings from the SaaS Security Report 17:32 The Importance of SaaS Security Measures 21:36 Managing SaaS Security in Organizations 33:43 Valence Security's Approach to SaaS Security 36:59 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host David Shipley discusses the FBI's report on cybercrime losses in 2024, which reached a record $16.6 billion, marking a 33% increase from the previous year. The report highlights major types of cyber crimes such as phishing, spoofing, extortion, and investment fraud, with older adults being significantly impacted. Additionally, Blue Shield of California experienced a data breach affecting 4.7 million members due to a Google Analytics misconfiguration. The episode also covers global ransomware trends, revealing that 86% of affected firms paid ransoms, and the Verizon Data Breach Investigation Report's findings that ransomware is a factor in nearly half of all cyber incidents. David also previews upcoming cybersecurity events and hints at further discussions on phishing training and data security.
00:00 Record Cybercrime Losses in 2024 04:07 Blue Shield of California Data Breach 07:03 Ransomware Crisis and Global Impact 08:23 Verizon Data Breach Report Insights 09:20 Upcoming Events and Closing Remarks
In this episode of 'Cybersecurity Today,' host Jim Love discusses various pressing topics in the realm of cybersecurity. Highlights include Anthropic's prediction on AI-powered virtual employees and their potential security risks, Microsoft’s introduction of AI security agents to mitigate workforce gaps and analyst burnout, and a pivotal court ruling allowing a data privacy class action against Shopify to proceed in California. Additionally, the show covers the last-minute extension of funding for the Common Vulnerabilities and Exposures (CVE) program by the US Cybersecurity and Infrastructure Security Agency, averting a potential crisis in cybersecurity coordination. These discussions underscore the evolving challenges and solutions within the cybersecurity landscape.
00:00 Introduction and Overview 00:26 AI Employees: Opportunities and Risks 01:48 Microsoft's AI Security Agents 03:58 Shopify's Legal Battle Over Data Privacy 05:12 CVE Program's Funding Crisis Averted 07:24 Conclusion and Contact Information
Cybersecurity Today: Allegations Against Elon Musk, Microsoft Lockout Issues, Cozy Bear's New Malware, and Canada's Anti-Fraud Proposals In this episode of Cybersecurity Today, hosted by David Shipley, we examine several major cybersecurity stories. A whistleblower accuses Elon Musk's team's involvement in a significant cyber breach at the National Labor Relations Board. Administrators face challenges with Microsoft's Mace feature, causing widespread account lockouts over the Easter weekend. The Russian hacking group Cozy Bear targets European diplomats using wine-themed phishing tactics. Canadian Conservative leader Pierre Poilievre proposes stringent measures against online fraud, including hefty fines and criminal charges for companies failing to act against digital scammers. 00:00 Breaking News: Doge and the US Labor Watchdog Cyber Breach 03:30 Microsoft Security Feature Causes Weekend Chaos 06:08 Russian Hackers Target European Diplomats with Wine-Themed Phishing 07:30 Canadian Conservative Leader Proposes Anti-Fraud Measures 09:25 Conclusion and Contact Information
In this episode of Cybersecurity Today titled 'The Secret CISO,' host Jim Love, along with guests Octavia Howell, Daniel Pinsky, and John Pinard, delves into the personal and professional experiences of Chief Information Security Officers (CISOs). They share their journeys into cybersecurity, discuss the challenges and pressures of their roles, and offer insights into effective leadership and talent development. The discussion also covers the evolving nature of security threats, resource constraints, and the importance of continuous learning and strategic alignment in cybersecurity. This candid conversation aims to provide valuable perspectives for both aspiring and seasoned security professionals.
00:00 Introduction to The Secret CISO 01:11 Meet the CISOs 03:08 Career Journeys and Reflections 08:45 Challenges and Pressures of the Job 23:21 Learning and Staying Ahead 28:15 Leadership and Team Development 40:34 Advice for Aspiring CISOs 43:14 Conclusion and Audience Engagement
In this episode of Cybersecurity Today, hosted by Jim Love, the show salutes Katie Moussouris of Luta Security for her courage in speaking truth to power. The episode covers various significant news in the cybersecurity world: the explosion of identity theft in Canada’s tax system, Prodaft’s strategic purchase of hacker forum accounts for intelligence, Google’s new security feature for Android devices, Hertz's data breach due to a vendor hack, and a US attorney's allegations against a UK intelligence firm for orchestrating a hack-for-hire scheme. Additionally, the episode discusses the troubling political ramifications following President Trump’s revocation of security clearance from Chris Krebs, former CISA director, and the subsequent investigation, highlighting the importance of protecting free speech and integrity within the cybersecurity profession.
00:00 Introduction and Salute to Katie Moussoursis 00:44 Identity Theft Nightmare in Canada 03:20 Prodaft's Innovative Cybercrime Monitoring 05:22 Google's New Android Security Feature 07:08 Hertz Data Breach and Legal Implications 09:22 Controversial Hack-for-Hire Allegations 11:26 Conclusion and Final Thoughts 11:36 Speaking Truth to Power: The Case of Chris Krebs
In this episode of Cybersecurity Today, host David Shipley discusses several pressing concerns in the cybersecurity landscape. Attackers have been exploiting Fortinet VPN devices to maintain access even after patches were applied; administrators are urged to upgrade and follow recovery guidance. Microsoft has created a new INET Pub folder through its latest Windows update, advising users not to delete it due to a linked security flaw. Lastly, AI-generated code dependencies are becoming a serious supply chain risk, with attackers creating malicious packages based on AI hallucinations. Users are advised to thoroughly review AI-generated code to avoid 'slop squatting'.
00:00 Introduction and Fortinet VPN Exploits 02:46 Microsoft's INET Pub Folder Issue 04:57 AI Hallucinations and Code Dependencies 06:22 Conclusion and Contact Information
In this captivating interview, host Jim Love sits down with Licenia Rojas, Senior Vice President and Chief Architect at TD Bank. They discuss Licenia's journey in the technology sector, the importance of mentorship, and the role of continuous learning in career development. The conversation also delves into evolving topics such as cybersecurity, AI innovation, and the increasingly pivotal role of architecture in modernizing financial institutions. Whether you're early in your career or a seasoned professional, this episode offers authentic and practical advice on navigating the tech industry.
00:00 Introduction to the Interview Series 01:25 Meet Licenia Rojas: Career Journey and Early Influences 02:35 Discovering a Passion for Technology 04:43 The Importance of Continuous Learning and Mentorship 05:44 Navigating Career Transitions and Embracing New Roles 08:06 The Role of Curiosity and Asking Questions 13:24 The Value of Company Culture 15:09 Current Role and Responsibilities at TD Bank 17:08 The Evolution and Importance of Architecture in Technology 21:23 Understanding the Technology Life Cycle 22:48 Defining and Achieving Good Outcomes 24:34 Customer-Centric Innovation 26:40 Encouraging Employee Ideas and Feedback 28:34 Overcoming Cynicism in Tech Teams 31:35 Exciting Emerging Technologies 35:57 The Role of AI in Enhancing Productivity 38:50 Advice for Aspiring Technologists 41:59 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host Jim Love covers the shutdown of a spammer exploiting OpenAI's GPT model, a cybersecurity breach at the US Office of the Comptroller of the Currency, and a new malware operation called 'Operation End Game' targeting major cybercrime networks. He also discusses the emergence of a destructive RAT on GitHub that poses a significant risk to Windows systems, and a critical vulnerability in the WordPress plugin AutoKit that was exploited mere hours after its disclosure. Ensure you stay updated on these evolving threats and the necessary precautions to safeguard your systems.
00:00 Introduction and Headlines 00:25 Spammers Exploit OpenAI's GPT Model 02:14 US Bank Regulator Hacked 04:25 Operation End Game: Tackling Cybercrime 07:06 Neptune RAT: A New Threat to Windows 09:12 WordPress Plugin Vulnerability Exploited 11:25 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love covers important security updates and warnings including critical flaws in WinRAR, a patch for a high severity zero-day vulnerability in Windows CLFS, and a security vulnerability in WhatsApp's Windows desktop application. He urges users to update their software to protect against exploits. Additionally, Jim discusses Identity Management Day and the concerning findings from an OKTA survey revealing Canadians' growing worries about identity theft. He announces his plan to create a special segment on new identity solutions to address these concerns. The episode also includes a shout-out to the BSides Calgary event for information security professionals.
00:00 Introduction and Event Announcement 00:51 Critical Flaws in Compression Utility 03:33 Microsoft Patches Zero-Day Exploits 05:01 WhatsApp Security Vulnerability 06:46 Identity Management Day Insights 10:13 Conclusion and Contact Information
In this episode of Cybersecurity Today, host David Shipley covers a range of crucial issues. With tax day approaching, Microsoft reports a rise in sophisticated tax-themed phishing campaigns. The IRS has issued a warning against using its name in phishing simulations to avoid legal repercussions. Furthermore, cybersecurity journalist Brian Krebs reveals that Minnesota cybersecurity expert Mark Lanterman is under FBI investigation for potentially falsifying his credentials, impacting thousands of court cases. Lastly, several Australian superannuation funds have been targeted in a cyber scam, raising questions about the necessity of multifactor authentication for financial services. The episode emphasizes the need for stringent standards in cybersecurity expertise and shared responsibility in financial security.
00:00 Introduction and Headlines 00:24 Tax-Themed Phishing Scams on the Rise 00:36 Microsoft's Findings and IRS Warnings 01:32 Phishing Simulations and Legal Risks 02:53 Educating Employees on Phishing 03:15 Minnesota Cybersecurity Expert Under Scrutiny 04:25 Allegations and Legal Implications 05:52 Australian Retirement Funds Cyber Scam 06:16 Impact and Response to the Breach 07:07 The Need for Stronger Security Measures 08:26 Conclusion and Contact Information
In this episode of the cybersecurity month-end review, host Jim Love is joined by Daina Proctor from IBM in Ottawa, Randy Rose from The Center for Internet Security from Saratoga Springs, and David Shipley, CEO of Beauceron Security from Fredericton.
The panel discusses major cybersecurity stories from the past month, including the Oracle Cloud breach and its communication failures, the misuse of Signal by U.S. government officials, and global cybersecurity regulation efforts such as the UK's new critical infrastructure laws. They also cover notable incidents like the Kuala Lumpur International Airport ransomware attack and the NHS Scotland cyberattack, the continuous challenges of EDR bypasses, and the importance of fusing anti-fraud and cybersecurity efforts. The discussion emphasizes the need for effective communication and stringent security protocols amidst increasing cyber threats.
00:00 Introduction and Panelist Introductions 01:25 Oracle Cloud Breach: A Case Study in Incident Communication 10:13 Signal Group Chat Controversy 20:16 Leadership and Cybersecurity Legislation 23:30 Cybersecurity Certification Program Overview 24:27 Challenges in Cybersecurity Leadership 24:59 Importance of Data Centers and MSPs 26:53 UK Cybersecurity Bill and MSP Standards 28:09 Cyber Essentials and CMMC Standards 32:47 EDR Bypasses and Small Business Security 39:32 Ransomware Attacks on Critical Infrastructure 43:34 Law Enforcement and Cybercrime 47:24 Conclusion and Final Thoughts
In this episode, host Jim Love discusses a rise in unauthorized network scans targeting Juniper and Palo Alto devices, raising concerns about espionage and botnet activities. The podcast also delves into the controversial use of the Signal app by National Security Advisor Mike Waltz's team for sensitive communications, sparking debates on security and legality. Additionally, the episode highlights the potential misuse of OpenAI’s advanced image generation tool for creating fraudulent documents. Finally, it covers the mysterious disappearance of cybersecurity professor JF Wang and his wife, following an FBI and Homeland Security investigation.
00:00 Introduction and Overview 00:23 Unauthorized Scans on Network Devices 02:01 National Security Concerns with Signal App 05:21 Risks of AI-Generated Images 07:44 The Disappearance of a Cybersecurity Professor 09:57 Conclusion and Upcoming Events
In this episode of Cyber Security Today, host Jim Love covers several major cybersecurity incidents and vulnerabilities. Key stories include the compromise of Windows Defender and other Endpoint Detection and Response (EDR) systems, a data breach on X (formerly known as Twitter) exposing over 200 million user records, and a security flaw in several UK-based dating apps that led to the exposure of approximately 1.5 million private images. The discussion highlights how attackers are increasingly using legitimate software tools to bypass security measures, the implications of these breaches for users, and offers practical tips for maintaining robust cybersecurity.
00:00 Introduction to Today's Cyber Security News 00:29 Compromised Endpoint Detection and Response Systems 01:06 Bypassing Windows Defender: Methods and Implications 02:52 Ransomware Tactics and Legitimate Tool Exploits 04:20 Time Traveling Attacks and EDR Limitations 06:33 Massive Data Breach on X (Twitter) 08:30 UK Dating Apps Expose Private Images 10:47 Fraud Alerts and Scams 13:25 Conclusion and Final Thoughts
Cybersecurity Today: Hacktivism, Solar Power Vulnerabilities, and Global Phishing Challenges
In this episode of Cybersecurity Today, host David Shipley covers multiple cybersecurity stories including: a Canadian hacker charged for the 2021 Texas GOP hack, vulnerabilities in solar power gear, France's national phishing test for students, and the tragic impact of online fraud in India. Shipley delves into the implications for cybersecurity professionals and emphasizes the need to destigmatize fraud and support victims.
00:00 Introduction and Headlines 00:25 Canadian Hacker Charged for Texas GOP Hack 02:12 Vulnerabilities in Solar Power Gear 02:56 France's National Phishing Simulation for Students 04:19 Tragic Consequences of Online Fraud in India 05:16 Rising Online Fraud and Its Impact in Canada 06:15 Conclusion and Call to Action
In this episode, host Jim Love kicks off his new profile series with a deep dive into the compelling career of Dr. Priscilla Johnson, an environmental advocate at the crossroads of technology and sustainability. Dr. Johnson discusses her work in building a data center in South Africa amidst a severe drought, her tenure as Director of Water Strategy at Microsoft, and her transition into cyber intelligence. She explains how her unique background and empathetic approach have informed her career decisions and advocacy for responsible resource management. The conversation also touches on the importance of situational awareness in cybersecurity, making this episode a must-listen for anyone interested in the intersections of environmental engineering, infrastructure, and cybersecurity.
00:00 Introduction to the Series 00:29 Meet Dr. Priscilla Johnson 00:54 Challenges of Building a Data Center in Africa 01:16 Dr. Johnson's Background and Role at Microsoft 02:38 Addressing the Water Crisis in South Africa 06:34 Innovative Solutions and Collaborations 19:12 Dr. Johnson's Journey into Environmental Engineering 24:47 Discovering Texas and Dow Chemical 25:15 Environmental Impact and Agent Orange 27:00 Challenges in Environmental Management 29:00 Maternity Leave and Data Issues 34:46 Transition to Cybersecurity 37:19 Cybersecurity Threats and Preparedness 48:26 Mentorship and Career Advice 53:20 Conclusion and Final Thoughts
Exposing Security Flaws: Government Officials' Data Leaks, Defense Contractor Fines, and Cyber Crime Involvement
In this episode of Cybersecurity Today, host Jim Love highlights significant cybersecurity breaches affecting US security officials, a government defense contractor, and a Department of Government Efficiency staffer. Personal information of senior US security officials was found accessible online, raising concerns about national security. Morse Corp, a defense contractor, was fined $4.6 million for failing to meet cybersecurity requirements. Additionally, a 19-year-old tech aide from the Department of Government Efficiency was found linked to a cyber crime group, causing alarm due to his recent advisory roles with significant government agencies. The episode underscores the need for stringent cybersecurity practices and accurate compliance within government and defense circles.
00:00 Introduction and Headlines 00:24 Exposure of US Security Officials' Personal Information 02:22 US Defense Contractor's Cybersecurity Failures 04:40 19-Year-Old Linked to Cyber Crime Ring 07:05 Conclusion and Final Thoughts
Oracle Denies Cloud Hack & Top Secret Military Leaks: Cybersecurity Today
In today's episode of 'Cybersecurity Today,' host Jim Love delves into Oracle's denial of a claimed breach of its cloud systems, detailing the hacker's allegations and Oracle's firm response. Additionally, the episode explores an accidental leak of top-secret US military information to an editor at the Atlantic, revealing the astonishing lapses in secure communication. The show also covers renowned security expert Troy Hunt's phishing attack incident on his MailChimp account, highlighting vulnerabilities and lessons learned in cybersecurity. Stay tuned for comprehensive insights and expert analysis on these significant security events.
00:00 Introduction and Oracle Cloud Breach Allegations 00:52 Oracle's Response and Hacker Demands 02:07 Classified Military Details Leaked to Journalist 04:34 Troy Hunt's MailChimp Phishing Attack 06:17 Lessons Learned and Final Thoughts 07:38 Conclusion
In this episode of 'Cybersecurity Today,' host Jim Love covers several major cybersecurity events. A devastating breach at Oracle Cloud Infrastructure has exposed 6 million records affecting 140,000 businesses, linked to a threat actor known as Rose87168. The attack exploited vulnerabilities in Oracle Fusion Middleware 11G. New browser-in-the-middle attack techniques are discussed, which can steal data by bypassing multi-factor authentication. The episode also highlights a severe vulnerability in Synology's DiskStation Manager software that could allow remote attackers to take full control of affected systems. Lastly, significant budget cuts in the Cybersecurity and Infrastructure Security Agency’s (CISA) Red Team might weaken US government cyber defenses. Critical insights and mitigation strategies for these emerging threats are provided.
00:00 Massive Oracle Supply Chain Attack 03:08 Browser in the Middle Attack Explained 06:03 Synology's Major Security Flaw 08:08 US Government Red Team Disruptions 10:31 Conclusion and Final Thoughts
The Escalating Cyber Threats Against K-12 Schools: Insights and Solutions
In this episode of 'Cybersecurity Today,' host Jim Love discusses the rising trends and severe impacts of cyber attacks on K-12 schools with Randy Rose, VP of Security Operations and Intelligence at the Center for Internet Security (CIS). They scrutinize recent studies showing a surge in cyber threats targeting educational institutions, emphasizing the vulnerability of schools and the motives behind these attacks. The discussion covers how cyber criminals exploit budgetary information and schedules to maximize impact, the profound repercussions of ransomware attacks on school communities, and the critical need for better cybersecurity practices and support. Randy Rose shares insights from the 2025 CIS MS-ISAC K-12 Cybersecurity Report and offers practical advice on elevating security standards and fostering community resilience to protect sensitive school data from cyber threats.
00:00 Introduction to Cybersecurity in Schools 00:02 Iconic Hacking Movies and Real-Life Cyber Threats 00:41 The Seriousness of School Cybersecurity 01:10 Interview with Randy Rose: Introduction and CIS Overview 01:40 CIS's Role and Randy's Journey 03:27 Supporting Various Organizations 04:26 Challenges Faced by Schools and Local Governments 06:21 Cybersecurity Threats and Attack Patterns 09:11 Impact of Cyber Attacks on Schools 13:22 Detailed Findings from the CIS Report 19:16 Human Factor in Cybersecurity 19:29 Supply Chain and Data Security 27:13 The Role of AI in Cybersecurity 30:49 Ransomware and Its Devastating Effects 32:27 Recommendations for Improving School Cybersecurity 34:01 Conclusion and Final Thoughts
Cybersecurity Today: Critical IBM AIX Vulnerability and Major Browser Exploits Revealed
In this episode, host Jim Love discusses pressing cybersecurity issues, including IBM's AIX operating system scoring a perfect 10 in security vulnerability, leaving critical sectors exposed to remote attacks. The episode also covers the mishandling of sensitive data by U.S. government agencies amid rapid layoffs, the viral exposure of dangerous browser exploits by YouTuber Matt Johansson, and the removal of over 300 malicious Android apps from the Google Play Store. Key recommendations for protecting against these threats are provided.
00:00 Introduction to Cybersecurity News 00:26 IBM AIX Vulnerabilities Exposed 02:12 Government Layoffs and Security Risks 04:02 Browser Exploits and Malicious Extensions 06:39 Malicious Android Apps on Google Play 08:45 Conclusion and Upcoming Topics
Cybersecurity Today: Exploited Vulnerabilities and Innovative Threat Mitigations
In this episode of Cybersecurity Today, host Jim Love discusses several pressing cybersecurity issues including the exploitation of a server-side request forgery (SSRF) vulnerability in OpenAI's ChatGPT infrastructure (CVE-2024-27564), leading attackers to redirect users to malicious URLs. He also talks about how researchers at Tiny Hack have made breakthroughs in cracking Akira ransomware using high-powered GPUs, and Malwarebytes' warning about malware embedded in free online file converters. The episode highlights the importance of robust cybersecurity measures, innovative methods to combat ransomware, and cautious internet usage.
00:00 Introduction to Cybersecurity Threats 00:19 Exploiting ChatGPT Vulnerabilities 02:15 Cracking Akira Ransomware 05:01 Malware in Free Online Converters 07:12 Conclusion and Listener Support
Critical Cybersecurity Updates: Ransomware, VPN Breaches, and Microsoft Vulnerabilities
In this episode of 'Cybersecurity Today,' host Jim Love delves into emerging threats and vulnerabilities in the digital world. The Black Basta Ransomware Group has created a brute force tool to target VPNs and firewalls. The FBI and CISA alert users about Medusa ransomware, which has impacted over 300 organizations. A critical flaw in the popular Updraft Plus WordPress plugin is highlighted, exposing sensitive data. The FBI reports a surge in toll payment scams, and Microsoft's latest security update addresses severe vulnerabilities in Remote Desktop Services. Additionally, a breach within the Department of Government Efficiency underscores the risks of improper data handling. Stay informed about how to protect your systems and data in this comprehensive cybersecurity update.
00:00 Introduction to Cybersecurity News 00:27 Black Basta Ransomware Group's New Tool 02:18 Medusa Ransomware Advisory 03:43 WordPress Updraft Plus Vulnerability 05:12 Toll Payment Scams on the Rise 06:40 Microsoft's Critical RDS Vulnerabilities 09:35 DOGE's Treasury Data Breach 11:37 Conclusion and Contact Information
Unveiling Cyber Security Insights with David Shipley: The Truth Behind Phishing and Technology Bias
Join Jim Love and cybersecurity expert David Shipley in this insightful episode of 'Cyber Security Today.' They delve into the realities of phishing in the workplace, revealing surprising data about email filter leakage rates and the critical role of human behavior in cybersecurity. Discover the importance of balanced security training, the dangers of over-reliance on technology, and the psychological biases that can compromise your organization. Gain actionable insights and learn how to benchmark your cybersecurity efforts effectively.
00:00 Introduction to Cybersecurity Today 00:10 The Fascination with Science and Truth 00:31 Heroes and Influences 00:47 The Reality of Tech Research 01:43 Phishing Email Statistics 03:52 Technology Bias in Cybersecurity 07:30 The Importance of Security Awareness 15:02 Effective Training Strategies 20:53 Optimism Bias and Security 21:57 Exploring Popular Courses and Their Impact 23:33 Understanding Phishing Metrics: Click Rate and Report Rate 26:28 The Importance of Post-Click Report Rate 31:39 Analyzing Industry Trends in Phishing 35:00 Key Takeaways and Future Directions 39:29 Accessing the Annual Report and Final Thoughts
Cybersecurity Madness: Halting Operations, Google Gemini, and Fake Captchas
In this episode, host Jim Love delves into controversial cybersecurity decisions and the latest trends. The US government's directive to halt offensive cyber operations against Russia sparks debate about national security. Google Gemini's new personalized services interface with users' search histories, raising privacy concerns. Additionally, there's a discussion on rising fake Captcha scams designed to install malware on users' systems. Jim also shares a real-world hacking incident involving a small utility company compromised by a Chinese state-sponsored hacking group. Tune in to explore these pressing issues and more in the world of cybersecurity.
00:00 Introduction: Has the US Government Lost Its Mind? 00:44 Controversial Cybersecurity Decisions 01:12 Expert Opinions on Cybersecurity 03:02 Google Gemini: Personalized AI Assistant 04:59 Cyber Threats to Utilities 06:53 The Rise of Fake Captchas 08:57 Conclusion and Upcoming Content
Cybersecurity Today: From DDoS Attacks to Developer Sabotage
In today's episode, host Jim Love discusses several major cybersecurity incidents: the pro-Palestinian group Dark Storm's claimed DDoS attack on X Twitter and its implications; the impact of budget cuts from the Department of Government Efficiency on the US Cybersecurity and Infrastructure Security Agency; the recovery of $23 million from the Ripple wallet hack allegedly linked to the LastPass breach; New York State's lawsuit against Allstate Insurance for inadequate data security and resultant breaches compromising 200,000 individuals' data; and finally, the conviction of a developer who sabotaged his employer's systems post-termination. The episode underscores the importance of robust cybersecurity measures and responsible handling of personnel changes.
00:00 Pro-Palestinian Group Claims Credit for Twitter Outage 02:51 US Cybersecurity Agency Faces Devastating Cuts 04:23 US Authorities Recover $23 Million from Cryptocurrency Hack 06:31 New York Sues Allstate Over Data Breaches 09:12 Developer Sentenced for Malicious Code Sabotage 11:34 Support the Podcast
This episode also covers recent ransomware as a service (RaaS) trends, including the rise of SpearWing and Akira groups, advanced ransomware techniques exploiting IoT vulnerabilities, and issues with the ESP32 microcontroller's hidden commands. Additionally, Signal President Meredith Whitaker warns about privacy risks in agentic AI systems. Tune in for in-depth cybersecurity updates and more.
00:00 The Talk: Supporting Our Podcast 01:37 Cybersecurity Today: Ransomware as a Service 04:57 Akira Ransomware: Exploiting IoT Devices 06:50 ESP32 Microcontroller Vulnerabilities 08:21 AI Agents: Privacy and Security Risks 09:56 Conclusion and Contact Information
Understanding Insider Threats in Cybersecurity with Eran Barak
Join host Jim Love as he discusses the critical issue of insider threats in cybersecurity with Eran Barak, CEO of MIND, a data security firm. In this episode, they explore the various types of insider threats, from innocent mistakes to malicious actors, and how companies can effectively protect their sensitive data. Learn about data loss prevention strategies, the impact of remote work, and the role of AI in enhancing data security. Get insights on practical steps that CISOs can take to mitigate risks and safeguard their organization's crown jewels.
00:00 Introduction and Guest Welcome 00:10 Understanding Insider Threats 01:20 Types of Insider Threats 02:18 Monitoring and Preventing Data Leaks 03:37 Remote Work and Security Risks 06:03 Access Control and Permissions 08:41 Real-World Scenarios and Solutions 21:20 The Role of AI in Data Security 34:53 Final Thoughts and Conclusion
Cybersecurity Today: Rising Fraud in Canada and Major Cyber Crime Crackdowns
Welcome to another episode of Cybersecurity Today with your host, Jim Love. As fraud prevention month begins, we delve into the rising fraud rates in Canada, with new data from Equifax revealing Canadians' growing concerns about data protection, particularly among seniors and Quebec residents. We also cover the significant international law enforcement actions that dismantled the 8Base ransomware group and Garantex, a Russian cryptocurrency exchange linked to cybercriminal activities. Additionally, we discuss the emergence of a new botnet orchestrating record-breaking DDoS attacks, highlighting the persistent vulnerabilities in IoT devices. Don't miss our deeper analysis and the latest updates in cybersecurity.
00:00 Introduction to Fraud Prevention Month 00:23 Rising Fraud Concerns in Canada 02:24 Law Enforcement Actions Against Cyber Crime 04:34 Emergence of a New Botnet 06:46 Conclusion and Upcoming Shows
US Cybersecurity Confusion, Massive ISP Cyber Attack, and Talent Shortages
In this episode of 'Cybersecurity Today,' host Jim Love discusses the mounting confusion over the US cybersecurity stance on Russia, following conflicting reports about potential policy changes and operational directives. The show also covers a massive cyber attack that compromised over 4,000 ISPs, deploying malware and cryptocurrency miners. Additionally, the episode highlights the ongoing talent crisis in the cybersecurity industry, with a growing disconnect between hiring practices and industry needs. Tune in for the latest updates and in-depth analysis.
00:00 Introduction and Host Welcome 00:21 US Cybersecurity Stance on Russia 02:16 Massive Cyber Attack on ISPs 03:57 Cybersecurity Talent Shortage 06:15 Conclusion and Final Thoughts
Cybersecurity Insights: February Review & Current Trends
Join us in this comprehensive discussion on February's cybersecurity highlights, featuring experts Laura Payne from White Tuque and David Shipley from Beauceron Security. We delve into Canada's cybercrime progress, discuss significant global cyber incidents, and explore the ongoing challenges in cybersecurity regulation, AI integration, and digital identity. Additionally, we address the impacts of U.S. policy changes on cybersecurity standards and the vital need for effective cybersecurity education in the face of rapid technological advancements. Stay tuned for crucial insights and pragmatic advice to navigate today's cybersecurity landscape.
00:00 Introduction and Panel Welcome 01:30 Cybercrime Trends in Canada 05:59 International Cybercrime and Ransomware 08:08 Nation-State Cyber Heists 14:14 Legacy Systems and Cybersecurity Challenges 17:08 Open Banking and FinTech Security 24:35 US Federal Cybersecurity Cuts 30:57 The Reality of Cyber Threats 31:13 Cultural Perceptions of Cybersecurity 31:57 Political Will and Cybersecurity Policies 32:44 North Korean Cyber Threats 33:17 Generational Knowledge and Cybersecurity 34:20 Cryptocurrency Regulation Challenges 35:11 Digital Identity Concerns 41:00 Encryption and Privacy Debates 47:08 AI and Cybersecurity Risks 57:06 Concluding Thoughts and Future Directions
In this episode, host Jim Love covers a $1.5 billion Ethereum heist attributed to the North Korean Lazarus Group, Google's shift from SMS to QR codes for multifactor authentication, a massive botnet targeting Microsoft 365 accounts, and new phishing scams exploiting PayPal's address feature. Tune in for essential insights into the latest cybersecurity threats and measures.
00:00 Introduction and Announcements 00:18 Record-Breaking $1.5 Billion Cryptocurrency Heist 03:06 Google Enhances Security with QR Codes 04:55 Massive Botnet Targets Microsoft 365 Accounts 07:10 Scammers Exploit PayPal's New Address Feature 08:58 Cybersecurity Best Practices and Conclusion
Unveiling Cybercrime: Black Basta Leaks, VPN Attacks, RCMP Crackdown & AI Vulnerabilities
In this episode of Cybersecurity Today, Jim Love discusses the leaked chat logs of the Black Basta Ransomware Group, a colossal cyber attack targeting VPN devices with 2.8 million IP addresses, and the RCMP's successful dismantling of a major cyber fraud operation in Ontario. Additionally, researchers reveal a technique called Indiana Jones that exposes significant vulnerabilities in large language models like ChatGPT, showcasing the ease of bypassing their safety filters. Stay informed on the latest in cybersecurity.
00:00 Introduction and Headlines 00:24 Inside Black Basta Ransomware Group 03:11 Massive VPN Cyber Attack 05:30 Ontario's RCMP Cyber Fraud Bust 08:26 Indiana Jones Jailbreak Exposes AI Vulnerabilities 11:08 Conclusion and Contact Information
Unveiling the Complexities: The Dark Side of AI and Its Real-World Implications
In this episode, explore the intricate discussions surrounding AI with experts Marcel Gagné, John Pinard, and Jim Love. Dive into contemporary understandings of AI, its potential threats, and its application in both personal and professional realms. The panel discusses the 'dark side' of AI not to instill fear, but to devise strategies for managing its risks. Topics include AI misconceptions, the potential for AI to misbehave, operational security in AI implementation, and philosophical debates on AI consciousness. The episode emphasizes the importance of critical thinking, debate, and responsible use as AI technologies become increasingly integrated into society. Join the conversation and share your thoughts on AI's evolving landscape.
00:00 Introduction to Project Synapse 00:46 Exploring the Dark Side of AI 01:05 Invitation to Join the Discussion 02:01 Three Key Areas of AI Concerns 02:38 Speculative Risks and Science Fiction Scenarios 03:29 Implementing AI in Corporate Settings 04:37 AI Misbehavior and Security Concerns 07:09 Consciousness and AI 20:04 AI as Hyper-Intelligent Children 29:18 Security and Data Privacy in AI 31:36 Human Weakness in Security 31:50 Social Engineering Tactics 32:37 Security Misconceptions in Engineering 33:11 AI Data Storage and Security 34:45 AI Data Retrieval Concerns 39:05 Testing Security in Development 40:35 Regulatory Challenges with AI 43:26 Bias and Decision Making in AI 46:47 The Importance of Critical Thinking 50:09 The Role of Social Interaction in Business 54:35 AI as a Consultant 01:01:50 The Future of AI and Responsibility 01:04:24 Conclusion and Contact Information
Cyber Security Today: OpenSSH Vulnerabilities and Black Stash's Stolen Cards
In this episode, host Jim Love discusses two significant OpenSSH vulnerabilities that risk man-in-the-middle and denial-of-service attacks. The hacker group Black Stash has released 4 million stolen credit cards for free, potentially enticing further illegal activities. Palo Alto Networks' firewalls face active attacks, with multiple CVEs allowing privilege escalation and bypassing authentication. Critical updates and secure management practices are emphasized to protect systems.
00:00 Introduction and Headlines 00:21 OpenSSH Vulnerabilities Explained 02:39 BlackStash's Stolen Credit Card Dump 04:40 Palo Alto Networks Under Attack 06:21 Conclusion and Contact Information
Critical PostgreSQL Bug Exploited in Treasury Hack & New Threats Unveiled - Cybersecurity Today
In today's episode of Cybersecurity Today, hosted by Jim Love, we delve into major cybersecurity events, including a crucial PostgreSQL vulnerability exploited in the U.S. Treasury hack, Russian hackers bypassing traditional password security with device code authentication, and the discovery of the 'Final Draft' malware hijacking Microsoft Outlook drafts. Additionally, we explore the BBC's new tool to combat digital misinformation with Content Credentials. Tune in for in-depth insights and latest cybersecurity updates.
00:00 Introduction and Headlines 00:24 PostgreSQL Vulnerability and U.S. Treasury Hack 02:21 Russian Hackers Exploit Device Code Authentication 04:09 New Malware Hijacks Outlook Drafts 05:55 BBC Tests Truth Marks to Combat Fake News 07:49 Conclusion and Contact Information
Unpacking AI: Executive Insights & Essential Questions
Join us in this special edition of Hashtag Trending and Cybersecurity Today as we dive deep into AI with technology consultant Marcel Gagné and cybersecurity expert John Pinard. We discuss the necessity for executives to understand and implement AI despite limited knowledge, the need for question-based learning, and the significance of a comprehensive AI bootcamp. From real-world applications to the evolving AI landscape, this episode provides a nuanced view on leveraging AI in business while addressing the critical question of safety.
00:00 Introduction and Welcome 00:19 Meet the Panelists 00:38 AI in the Executive World 00:54 Bootcamp for Executives 01:17 Starting the Discussion 01:44 Understanding AI Challenges 03:00 The Importance of Asking Questions 07:45 Historical Context of AI 11:30 Practical Applications of AI 15:06 Generative AI and Its Impact 23:09 Future of AI Models 30:39 Introduction to Google Recorder App 31:11 AI for Meeting Transcriptions 33:18 AI in Marketing and Business Applications 34:07 The Future of AI in Business 36:03 Debating AI's Potential and Limitations 38:09 Advanced AI Models and Their Uses 40:12 AI in Consulting and Decision Making 49:47 Risk Management in AI Implementation 59:34 Final Thoughts and Wrap-Up
Cybersecurity Today: North Korean Hacks, AI Memory Breach, and School Data Comprimise
In this episode of Cybersecurity Today, host Jim Love covers a range of crucial topics in the cybersecurity landscape. North Korean hackers are using new social engineering tactics to infiltrate systems by posing as South Korean officials, while prompt injection attacks are compromising the long-term memory of Google's Gemini AI. Canada's Privacy Commissioner is investigating a significant data breach affecting students' personal information in PowerSchool, and the FBI's Operation Level Up is tackling cryptocurrency investment frauds, potentially saving victims millions. Get the latest insights and stay informed on how to protect yourself against these evolving threats.
00:00 Introduction and Headlines 00:23 North Korean Hackers' New Tactics 02:35 Prompt Injection Attacks on AI 04:37 Canada's PowerSchool Data Breach 06:38 FBI's Operation Level Up 09:20 Conclusion and Upcoming AI Show
Scammers Exploit DeepSeek Hype & Jailbreak OpenAI's O3 Mini – TechNewsDay Update
In this episode, we uncover how scammers are exploiting the recent hype around DeepSeek, a new AI model, by creating fake websites, counterfeit cryptocurrency tokens, and malware-laced downloads. We also discuss the jailbreaking of OpenAI's newly released O3 mini model, highlighting its security vulnerabilities. Additionally, a woman is sought by police for purchasing an iPhone using a stolen identity in a London Apple store. Stay tuned for important updates on cybersecurity, AI advancements, and fraud prevention.
00:00 Scammers Exploit DeepSeek Hype 01:43 DeepSeek's Security Challenges 04:10 OpenAI's O3 Mini Model Jailbreak 06:49 iPhone Fraud in London Apple Store 07:44 Conclusion and Call for Tips
In this episode of Cyber Security Today with host Jim Love, we delve into the significant 35% drop in global ransomware payments in 2024, highlighting a growing resistance to hacker demands and improved law enforcement actions. We also discuss a national security crisis sparked by Treasury's DOGE access and its broader implications for intelligence operations. Additionally, we share an eye-opening backup horror story emphasizing the critical importance of not just taking backups but ensuring they are restorable. Tune in for these updates and more in today's episode.
00:00 Ransomware Payments Drop in 2024 02:48 Treasury's DOGE Access Crisis 05:02 The Dangers of Untested Backup Systems 07:28 Conclusion and Contact Information
In this episode of Cybersecurity Today, host Jim Love dives deep into the latest advancements in AI technology with a focus on the new open-source model, DeepSeek, from China. Love discusses the significant cost differences in training and running this model compared to competitors like OpenAI and highlights DeepSeek's efficiency and ability to run on older GPUs. The conversation pivots to the cybersecurity implications of such open-source models, especially for professionals in the field. Special guest Robert Falzon, head of engineering at CheckPoint Software, joins the discussion to provide insights on how cybercriminals are leveraging AI tools and the newfound accessibility of powerful AI models. Love and Falzon also explore the current state of cybersecurity education, risk assessment, and the importance of realistic conversations about risks and safeguards in the face of these technological advancements. Tune in for an in-depth analysis of the intersection of AI and cybersecurity and what it means for professionals and companies moving forward.
00:00 Introduction to Cybersecurity Today 00:05 DeepSeek: A Game-Changer in AI 00:48 DeepSeek's Cost Efficiency and Accessibility 01:30 Open Source and Democratization of AI 02:59 Cybersecurity Concerns with AI Advancements 03:51 Interview with Robert Falzon from CheckPoint Software 04:13 AI's Impact on Everyday Life and Cybersecurity 05:17 The Knowledge Gap in AI and ML 07:50 The Risks of Data Security in AI 10:20 Cybersecurity Fundamentals and AI 10:59 The Growing Threat of AI in Cybercrime 18:29 The Need for Improved Security Measures 23:07 The Reality of AI-Driven Cyber Attacks 25:08 Advanced Malware Targeting Specific Industries 25:48 The Evolution of Phishing Attacks 27:13 AI and Home Automation Security 28:12 Banking System Vulnerabilities 29:23 Internal AI Threats and Risk Management 31:07 The Need for Updated Risk Assessments 31:43 Educating Organizations on AI and Cybersecurity 36:19 The Importance of Cyber Hygiene 45:11 Final Thoughts and Optimism for the Future
Cybersecurity Today: EDR Evasion, SSH Backdoor, WhatsApp Zero-Click Hack, and DeepSeek AI
In today's episode of Cybersecurity Today, host Jim Love discusses several pressing cybersecurity issues. The show covers Canada's Digital Governance Council's launch of a cyber ready validation program designed to help small and medium-sized businesses improve their cybersecurity. Jim then delves into a new cyber attack technique that bypasses Endpoint Detection and Response (EDR) systems, an SSH backdoor used by the Chinese cyber espionage group Evasive Panda, and a zero-click hacking technique targeting WhatsApp users. The episode concludes with insights on the Chinese open-source AI DeepSeek and the importance of nuanced discussion in security debates. Stay tuned for expert interviews on AI and cybersecurity in upcoming episodes.
00:00 Introduction to Cyber Ready Validation Program 00:52 Emerging Cyber Threats: EDR Evasion 04:42 New SSH Backdoor by Evasive Panda 06:31 WhatsApp Zero-Click Exploit 08:03 DeepSeek AI and Security Concerns 10:45 Conclusion and Call for Discussion
In this episode of Cybersecurity Today with Jim Love, explore the growing concerns surrounding DeepSeek AI's censorship and lack of guardrails, the rise of 'Shadow AI' in workplaces, and how cybercriminals exploit major cloud providers like AWS and Azure. Learn about a phishing scam targeting Microsoft single sign-on that's been undetected for six years, and get insights into the critical measures needed to safeguard against these evolving threats.
00:00 Introduction to Cybersecurity Today 00:25 DeepSeek AI: Censorship and Security Concerns 02:56 Shadow AI: The Rise of Unauthorized Generative Tools 05:05 Cloud Providers Exploited by Cybercriminals 07:31 Phishing Scams Targeting Microsoft Single Sign-On 09:03 Conclusion and Listener Engagement
Cybersecurity Threats: Fraud in Canada, DeepSeek AI Jailbreak & Toll Scams - Exclusive Interview with Ivan Novikov
In this episode of Cybersecurity Today, host Jim Love discusses the alarming $638 million lost by Canadians to fraud in 2024, with investment fraud being the most significant contributor. The episode also covers the successful jailbreak of China's DeepSeek AI model, raising major security concerns, and a new phishing scam targeting US toll road users. The episode concludes with a detailed interview with Ivan Novikov, CEO of Wallarm, discussing API security vulnerabilities and their research findings.
00:00 Introduction and Overview 00:21 Fraud in Canada: A Deep Dive 01:14 Investment and Identity Fraud Insights 01:49 Preventive Measures and Reporting 02:47 DeepSeek AI Model Jailbreak 04:38 SMS Phishing Scams Targeting US Toll Road Users 06:34 Exclusive Interview with Ivan Novikov 07:41 Wallarm's API Security Study 15:01 DeepSeek Jailbreak Techniques 25:13 Conclusion and Final Thoughts
Cybersecurity Today: DeepSeek AI Disruptions, Nvidia Breach, and TalkTalk Hack Revisited
In this weekend edition of Cybersecurity Today, our panel reviews the most significant cybersecurity stories of the past month. This episode features Laura Payne from White Tuque, David Shipley from Beauceron Security, and Dana Proctor from IBM. Key topics include the sudden emergence of DeepSeek AI, Nvidia’s vulnerabilities and their effect on stock prices, and TalkTalk’s latest data breach. Additionally, the discussion covers the soaring API security vulnerabilities reported by Wallarm and the UK’s potential legislative action on ransomware payments. Stay tuned for expert insights and analysis on these pressing issues in the world of cybersecurity.
00:00 Introduction and Panel Welcome 00:41 DeepSeek AI Disruption 02:09 Security Concerns and Reactions 04:06 NVIDIA's Vulnerabilities and AI Security 07:15 Economic and Geopolitical Implications 12:13 AI in Business and Security Practices 20:57 Open Source AI and Cybersecurity Risks 25:37 Responsibility in Data Management 26:25 AI's Unstoppable Progress 26:53 API Security Concerns 28:41 Non-Human Identities and API Challenges 30:36 The State of Cybersecurity Awareness 35:05 Legislative Hopes and Cybersecurity 37:25 TalkTalk Breach Revisited 44:10 Ransomware Legislation Proposals 45:34 Shoutout to Cyber Police 47:04 Closing Remarks and Audience Engagement
Cybersecurity Today: DeepSeek AI's Data Breach, New API Threats, & Operation Talent
In this episode of 'Cybersecurity Today,' host Jim Love delves into the recent security lapse by DeepSeek AI, highlighting the exposure of sensitive data through an open ClickHouse database. Learn about the growing threat posed by APIs as the primary attack vector in cybersecurity, with findings from Wallarm's 2025 API Threat Stat Report. Additionally, discover the impact of international law enforcement's Operation Talent on dismantling major cybercrime forums, and be informed about a new browser attack technique, 'browser sync jacking,' which poses risks to millions of users. Stay tuned for a comprehensive overview of the latest in cybersecurity.
00:00 Major Security Concerns with DeepSeek AI Databases 03:13 The Rise of API Cyber Attacks 05:23 Global Crackdown on Cybercrime Forums 07:04 New Browser Attack Technique Discovered 08:54 Conclusion and Upcoming Discussions
Navigating AI Cyber Threats and Critical Infrastructure Vulnerabilities
In this episode of Cybersecurity Today, host Jim Love discusses the recent cyber attack on AI platform DeepSeek that exploited open source vulnerabilities. He highlights significant challenges in U.S. cybersecurity oversight following disruptions in key bodies like the Cyber Safety Review Board. The episode also covers a backdoor vulnerability in Juniper routers being actively exploited, and the FBI warning about misuse of local admin accounts. Organizations are urged to bolster their defenses by reviewing admin logs and enforcing stronger access controls amidst evolving cyber threats.
00:00 Introduction to Cybersecurity Challenges 00:23 DeepSeek Cyber Attack Incident 01:10 Leadership Crisis in Cybersecurity Oversight 02:28 Juniper Router Backdoor Vulnerability 03:49 FBI Warning on Local Admin Account Exploits 04:55 Conclusion and Contact Information
Cybersecurity Recap: Major Data Breaches, Transparency Issues, and a Twist on Script Kiddies
In this episode of Cybersecurity Today, host Jim Love covers various major cybersecurity incidents and developments. Mozilla criticizes the auto industry's data privacy practices following a Volkswagen data breach affecting 800,000 electric cars. The Upper Canada School Board faces a data breach exposing sensitive information. MasterCard is scrutinized for its lack of transparency over a DNS misconfiguration. In a surprising turn, a fake malware builder hacks 18,000 script kiddies attempting cyber attacks. Tune in for detailed insights and important cybersecurity updates.
00:00 Volkswagen Data Breach Exposes 800,000 Electric Cars 02:14 Upper Canada School Board Data Breach 03:40 MasterCard's Transparency Issues 05:56 Hackers Get Hacked: Fake Malware Builder 07:33 Conclusion and Contact Information
Exploring Cyber Vulnerabilities in Civic Infrastructure with Ethical Hacker Nick Aleks
In this episode, we dive into the vulnerabilities present in our civic infrastructure with ethical hacker Nick Aleks. We discuss the risks associated with outdated and poorly secured systems that run our cities' utilities, smart buildings, and transit networks. Nick provides insights into how nation-state hackers could exploit these vulnerabilities and the serious consequences of such attacks. The video highlights the importance of collaboration, regular security updates, and the role of ethical hackers in identifying and mitigating these threats.
00:00 Introduction to Civic Infrastructure Issues 01:28 A Hacker's Perspective on City Infrastructure 03:36 Exploring Vulnerabilities in Smart Infrastructure 12:01 The Threat to Municipal Systems 19:00 Defensive Measures and Solutions 23:42 Conclusion and Final Thoughts
Cybersecurity Today: Stolen Credentials, Firewall Leaks, and Energy Sector Risks
In this episode of Cybersecurity Today, host Jim Love discusses the alarming sale of thousands of credentials from leading cybersecurity vendors on the dark web, a massive leak of FortiGate firewall configuration files impacting nearly 5,000 organizations, and a major breach at education technology provider PowerSchool exposing sensitive data for millions. The episode also examines the increasing threats facing the U.S. energy sector, urging immediate action to modernize aging infrastructure and enhance cybersecurity measures. Tune in to learn more about these critical issues and how to safeguard against them.
00:00 Introduction to Cybersecurity Threats 00:16 Dark Web Credentials for Sale 01:56 FortiGate Firewall Configuration Leak 03:16 PowerSchool Data Breach 04:33 Rising Threats in the Energy Sector 06:42 Conclusion and Final Thoughts
Critical Cybersecurity Updates: Avery Data Breach, Hamilton Ransomware Attack, and Microsoft Outlook Patch
In this episode of Cybersecurity Today, host Jim Love covers significant cybersecurity incidents and updates. Avery experiences a massive data breach affecting 61,000 customers due to a credit card skimmer. The city of Hamilton commits $52 million to rebuild its IT infrastructure following a ransomware attack. A new study unveils serious vulnerabilities in Internet tunneling protocols, potentially exposing over 4.2 million systems globally. Lastly, Microsoft issues a critical patch for an actively exploited vulnerability in Outlook, urging users to update immediately. Stay informed on these pressing cybersecurity issues!
00:00 Introduction and Headlines 00:23 Vulnerabilities in Internet Tunneling Protocols 01:49 Avery Data Breach Details 03:05 Hamilton's Ransomware Attack and Recovery Plan 04:27 Microsoft Outlook Critical Patch 05:49 Conclusion and Contact Information
Cybersecurity Today: Sneaky 2FA Phishing Attack & AI-Powered Scams
In this episode of Cybersecurity Today, host Jim Love explores the emergence of Sneaky 2FA, a new phishing-as-a-service attack that compromises two-factor authentication for Microsoft 365 users. The episode also covers a legal case where a scam led a Western Australian company to lose $190,000, underscoring the importance of robust payment verification processes. The discussion extends to AI-powered romance scams, featuring deep fake technology that has defrauded victims worldwide, highlighting the growing need for advanced fraud detection and awareness.
00:00 Introduction to Cybersecurity Threats 00:23 Sneaky 2FA: A New Phishing Threat 01:54 Legal Consequences of Email Scams 03:34 AI-Powered Romance Scams 05:34 Conclusion and Contact Information
Addressing Social Media Fraud: Insights from Netcraft's Robert Duncan
In this weekend edition of Cybersecurity Today, host Jim Love discusses the growing issue of fraud in the cybersecurity landscape. Jim interviews Robert Duncan, VP of Product Strategy at Netcraft, who sheds light on their research into fraudulent activities on social media platforms, particularly focusing on Truth Social. The conversation delves into the mechanics of conversational scams, the role of crypto in fraud, and the challenges faced by social media platforms in combating these threats. They also discuss the need for better protective measures and the varying approaches to content moderation across different jurisdictions. Tune in for an in-depth look into the pervasive issue of online fraud and the ongoing efforts to fight it.
00:00 Introduction to Cybersecurity Today 00:21 Interview with Robert Duncan from Netcraft 01:12 Understanding Social Media Scams 06:09 The Role of Crypto in Scams 14:25 Challenges and Responsibilities of Social Media Platforms 23:31 Future Research and Conclusion
Cybersecurity Today: High-Speed Go Library Exploits & Major Data Breaches
In today's episode, host Jim Love covers recent cybersecurity threats including the exploitation of a high-speed Go library to target Microsoft 365 accounts, North Korea's Lazarus Group's new tactics to lure developers with AI-enhanced job scams, and the leak of sensitive data from over 15,000 FortiGate devices by the Belson Group. Learn more about these threats and how to protect your systems.
00:00 Hackers Exploit High-Speed Go Library to Target Microsoft 365 02:07 North Korea's Lazarus Group Targets Developers with Job Scams 04:09 Belson Group Leaks Sensitive Data from FortiGate Devices 05:58 Conclusion and Contact Information
Cybersecurity Rundown: YouTube Malware, Strava Leaks, UK Ransomware Ban, AWS Exploits & Fortinet Vulnerabilities
In this episode of 'Cybersecurity Today,' host Jim Love covers critical cybersecurity topics including YouTubers targeted with malware links, fitness apps leaking military secrets, a proposed UK ransomware payment ban, a new ransomware gang exploiting AWS encryption tools, and Fortinet firewalls facing potential zero-day attacks. Key insights, expert warnings, and security recommendations are discussed to help protect users and organizations from these growing cyber threats.
00:00 Introduction to Cybersecurity News 00:23 Malware Links Targeting YouTubers 02:01 Fitness Apps Leaking Military Secrets 03:46 UK Proposes Ransomware Payment Ban 05:08 AWS Encryption Exploited by Ransomware 07:12 Fortinet Firewalls Zero-Day Attack 08:12 Conclusion and Contact Information
Massive Data Breaches, Apple Targeted, Facebook Security Flaw - Cybersecurity Today
In this episode of Cybersecurity Today, host Jim Love covers a massive breach revealing how location data is harvested through thousands of popular mobile apps on Android and iOS. Files leaked from Gravy Analytics expose critical privacy concerns with real-time bidding systems. Additionally, hackers are increasingly targeting Apple devices, including a breakthrough hack of iPhone 15's USB-C controller. The episode also discusses a critical vulnerability in Meta's Facebook ad platform, highlighting the importance of up-to-date security measures in ad tech.
00:00 Introduction to Cybersecurity Today 00:23 Massive Location Data Harvesting Exposed 02:03 Apple Devices Under Attack 04:05 Critical Vulnerability in Facebook Ad Platform 05:39 Conclusion and Contact Information
Cybersecurity 2025: Predictions, Challenges, and AI Impacts
Welcome to Cybersecurity Today with your host, Jim Love! In this special episode, our expert panel looks ahead to 2025, discussing potential cybersecurity threats and emerging themes. Featuring Laura Payne from White Tuque, Daina Proctor from IBM, and David Shipley, CEO and culture critic from Beauceron Security, the panel dives into significant topics such as the recent Power Schools data theft, the anticipated surge in SaaS provider attacks, and the evolution of AI in the workforce. They also address crucial issues in public institutions, phishing vulnerabilities, and the looming threat of quantum computing. Tune in for an engaging and thought-provoking discussion on the future of cybersecurity.
00:00 Introduction and Panelist Introduction 00:35 Major Cybersecurity Incidents of 2024 03:40 The Impact of SaaS Provider Breaches 06:59 Challenges in Cybersecurity Culture and Practices 18:39 Global Cybersecurity Threats and Geopolitical Implications 24:04 The Pitfalls of Regulation Implementation 25:02 The Checklist Mentality in Security 26:36 The Role of AI in Modern Workplaces 27:54 The Dangers of Blind Faith in Technology 30:33 The Rise of AI Employees 40:37 Quantum Computing and AI: The Future 45:14 Resolutions and Reflections for the New Year
Cybersecurity Alert: Free VPN Risks, Packers' Data Breach, and SonicWall Vulnerability
In this episode, host Jim Love delves into critical cybersecurity issues including the hidden dangers of free VPNs, a payment skimmer attack on the Green Bay Packers’ online pro shop, and a severe vulnerability in SonicWall’s SonicOS firmware. Learn why 90% of free VPNs can compromise your security, the impact of the Packers' data breach affecting 8,500 fans, and the urgent need to update SonicWall devices to prevent potential exploitation. Stay informed to protect your privacy and data!
00:00 The Hidden Dangers of Free VPNs 02:30 The Green Bay Packers Payment Skimmer Attack 04:35 SonicWall's Critical Vulnerability Alert 06:29 Show Wrap-Up and Weekend Preview
Cybersecurity Updates: New US Cyber Trust Mark & Rising Threats
In this episode of Cyber Security Today, host Jim Love discusses the launch of the US Cyber Trust Mark, a new cybersecurity safety label for smart devices. The episode also covers increasing Mac OS attacks by North Korean hackers, including the discovery of the Spectral Blur backdoor, and US Treasury sanctions against Integrity Technology Group for supporting Chinese state-sponsored hacking. Tune in for critical insights on these pressing cybersecurity issues.
00:00 Cyber Security Safety Labels for Smart Devices 02:27 North Korean Hackers Targeting Mac OS 04:03 U.S. Sanctions Chinese Cybersecurity Firm 06:24 Conclusion and Contact Information
In this episode, we delve into the latest cybersecurity threats and developments. We cover a new double click exploit that bypasses browser protections and a massive compromise affecting millions of Chrome users through infected extensions. Additionally, we discuss the U.S. Treasury hack linked to Chinese state-sponsored hackers and how CrowdStrike rebounded from the largest IT outage in history. Join host Jim Love to explore these critical issues and understand the implications for both users and organizations.
00:00 Introduction and Headlines 00:25 Browser Exploits: Double Click and Extensions 03:24 U.S. Treasury Breach Linked to Chinese Hackers 06:03 CrowdStrike's Comeback After Major IT Outage 09:43 Conclusion and Final Thoughts
Cybersecurity Year in Review: Future Challenges and Industry Insights
Join host Jim Love and a panel of cybersecurity experts—Terry Cutler from Cyology Labs, David Shipley from Beauceron Security, and Laura Payne of White Tuque—as they review the key cybersecurity events of the past year. Topics discussed include the increasing cyber threats to universities, healthcare systems, and critical infrastructure; the importance of proper cybersecurity measures and employee training; the complexities of adopting quantum-safe encryption protocols; and the impact of AI and shadow IT on cybersecurity. The panel concludes with actionable advice for improving organizational cybersecurity posture in the coming year.
00:00 🎄 The 12 Days of Cyber Christmas 🎄 00:29 🔍 Year in Review: Cybersecurity Highlights 00:40 👥 Meet the Expert Panel 01:19 🏫 University Cyber Attacks: A Growing Concern 02:25 🔒 Penetration Testing vs. Vulnerability Scanning 03:09 🛡️ Persistent Threats and Active Directory Issues 06:28 💡 Strategies for Cybersecurity in Universities 07:34 💰 Funding and Legislation for Cybersecurity 13:52 🛠️ Practical Steps for Cybersecurity on a Budget 18:36 🔐 Quantum Readiness and Future Challenges 25:11 Quantum Computing: The Reality and Risks 25:53 Human Ingenuity and Risk Management 26:29 The Future of Cybersecurity: Q Day and Certificate Rotations 28:02 Major Cybersecurity Incidents of the Year 29:41 The Rise of Ransomware and Supply Chain Attacks 35:35 AI in Cybersecurity: Opportunities and Challenges 38:49 Critical Infrastructure Vulnerabilities 47:09 Year-End Reflections and Looking Forward
Cybersecurity Today: LastPass Hack Fallout, TP-Link Router Ban, and Microsoft's Passwordless Future
In our final daily news show of the season, host Jim Love covers key cybersecurity stories, including millions stolen from crypto wallets linked to the 2022 LastPass breach, potential US ban on TP-Link routers over national security concerns, and Microsoft's push for a passwordless future with passkeys. Don't miss our weekend wrap-up with the cybersecurity panel and special holiday content. Stay tuned for new episodes starting January 6th. Happy holidays!
00:00 Season Finale Announcement 00:29 Crypto Wallets Hacked: Fallout from LastPass Breach 02:38 TP Link Routers Under Scrutiny 04:38 Microsoft's Push for a Passwordless Future 06:38 Holiday Wishes and Future Plans
BlackBerry's Cylance Sale, Major AWS Breach, Klopp Ransomware Strikes Again, and Russian Cyber Attacks
In this episode of Cybersecurity Today, host Jim Love discusses BlackBerry's sale of Cylance to Arctic Wolf for significantly less than its purchase price, the massive AWS breach linked to the Shiny Hunters, Klopp ransomware attacks on Cleo's platforms, and the escalation of Russian cyber attacks on Western critical infrastructure. Tune in to get the details on these major cybersecurity developments and their implications.
00:00 Introduction and Sponsor Message 00:32 BlackBerry's Cylance Sale: A Strategic Move? 02:36 AWS Data Breach: Shiny Hunters Strike Again 04:54 Cleo Data Theft: Klopp Ransomware's Latest Exploit 06:39 Russian Cyber Attacks on Critical Infrastructure 08:32 Conclusion and Contact Information
PumaKit Linux Rootkit, Windows Defender Flaw, and Android Malware Outbreak!
In today's episode of Cybersecurity Today, host Jim Love delves into the discovery of the advanced Linux rootkit PumaKit, critical vulnerabilities in Microsoft's Windows Defender, a new multi-platform malware campaign downgrading browser security, and Germany's recent outbreak of pre-installed malware on 30,000 Android devices. We discuss the implications of these cybersecurity threats and the measures being taken to mitigate them. Stay informed and vigilant with our detailed analysis of these emerging cyber risks.
00:00 Introduction to Cybersecurity News 00:27 Advanced Linux Rootkit: PumaKit 01:59 Critical Windows Defender Vulnerability 03:42 Malware Downgrades Browser Security 05:08 Pre-installed Malware on Android Devices in Germany 07:02 Conclusion and Final Thoughts
AI and Quantum Computing: Waves of Innovation and Cybersecurity Concerns
In this episode of Cyber Security Today, host Jim Love delves into the latest in AI advancements, discussing their impact on cybersecurity with guests Marcel Gagné and John Pinard. The conversation covers a wide range of topics, including Google's recent quantum computing announcement, OpenAI's impressive features rollout, and practical applications for businesses. The team also discusses the security implications of these technological advancements and the importance of proactive cybersecurity measures. Tune in for an in-depth exploration of the evolving landscape of AI, quantum computing, and their intersection with cybersecurity.
00:00 Introduction to AI and Cybersecurity 00:29 Project Synapse AI in Action 02:05 Google's Quantum Computing Breakthrough 04:01 Quantum Computing: Hype vs Reality 14:42 AI and Deception: A New Report 32:39 Exploring Sora and Canvas 33:26 Canvas: Collaborative AI Tool 34:50 AI in Corporate Settings 35:53 Apple and OpenAI Integration 37:25 Advanced Voice and Vision Capabilities 41:59 Google Gemini and Real-Time Interaction 47:03 AI and Cybersecurity Concerns 52:27 The Future of AI and Privacy 57:55 Competitive AI Landscape 01:01:06 Concluding Thoughts and Future Discussions
Top 5 Phishing Exploits of 2024: Abnormal Security Report and More | Cybersecurity Today
In this episode of Cybersecurity Today, host Jim Love delves into Abnormal Security's end-of-year report outlining the top five phishing exploits of 2024 and their predictions for 2025. The episode covers cryptocurrency fraud, weaponized file sharing services, multi-channel phishing, business email compromise, and email account takeovers. Additionally, it highlights the alarming rise of text-based job scams, the takedown of a major vishing ring in Spain and Peru, and a $5 million U.S. reward to disrupt North Korean IT schemes. Stay informed on the latest cybersecurity threats and protections.
00:00 Introduction to Cybersecurity Today 00:27 Top Phishing Exploits of 2024 00:37 Cryptocurrency Fraud and File Sharing Scams 01:54 Multi-Channel Phishing and Business Email Compromise 03:10 Email Account Takeover and Future Predictions 04:39 Rise of Task Scams 06:53 Massive Vishing Operation Busted 08:42 North Korean IT Worker Fraud 11:15 Conclusion and Final Thoughts
SEC Cyber Disclosure Rules, Deloitte Hack Denial, and Critical Microsoft & SAP Patches | Cybersecurity Today
In this episode of Cybersecurity Today, host Jim Love delves into the ongoing confusion and compliance struggles faced by companies one year after the SEC's cyber disclosure rules were introduced. We analyze a BreachRx report revealing that less than 17% of public companies provide specific details in their cyber incident filings. Deloitte's recent denial of a data theft claim by the BrainCypher ransomware group is also discussed, along with the firm's history of cybersecurity challenges. Additionally, Microsoft and SAP have rolled out critical patches addressing severe vulnerabilities, emphasizing the urgency for users and organizations to apply these updates. Stay informed on these pressing cybersecurity issues.
00:00 Introduction and Headlines 00:20 SEC Cyber Disclosure Rules: One Year Later 02:30 Deloitte Denies BrainCypher Ransomware Allegations 04:23 Microsoft and SAP Issue Critical Patches 07:19 Conclusion and Show Notes
Cybersecurity Today: Email Frauds, Google Warnings, and U.S. Telecom Hacks
In this episode of Cybersecurity Today, host Jim Love discusses a personal encounter with email fraud attempts, including invoice scams and fake payroll changes. Google issues a stark warning to Gmail users about session cookie thefts leading to email takeovers. Additionally, the U.S. telecom industry grapples with the fallout from a major breach by Chinese hackers exploiting legacy systems. Love shares insights on improving email security and safeguarding against such sophisticated cyber threats. Tune in to learn more about the latest cyber challenges and solutions.
00:00 Introduction and Personal Encounter with Email Fraud 03:20 Google's Warning on Email Takeovers 05:12 Session Cookie Theft: A Rising Threat 06:48 U.S. Telecom Industry Infiltration by Chinese Hackers 08:44 Conclusion and Final Thoughts
Cyber Security Today: Navigating Novel Phishing Campaigns and Ransomware Tactics
Join host Jim Love and the Cyber Security Today panel featuring Terry Cutler of Cyology Labs, David Shipley of Beauceron Security, and cybersecurity executive John Pinard. In this episode, they delve into pressing cybersecurity challenges such as novel phishing tactics using corrupted Word documents, the importance of robust offboarding processes in light of breaches at major companies like Disney, and the ramifications of a major ransomware attack on the City of Hamilton. Topics also include the recurring issue of session cookie theft, the implications of third-party cybersecurity risk as seen in the Blue Yonder ransomware attack impacting Starbucks, and the rise of hacktivism. Tune in for valuable insights and discussions aimed at improving cybersecurity measures in an ever-evolving threat landscape.
00:00 Introduction and Panelist Introductions 00:40 David Shipley's Cyber Risk Talk 02:39 Novel Phishing Campaign Discussion 06:08 Fileless Malware and Human Error 10:44 Offboarding and Internal Audits 19:48 Vendor Responsibility and Ransomware 27:06 City of Hamilton Cyber Attack 28:19 Keynote Talks and Cybersecurity Challenges 29:30 The Reality of Cyber Attacks 29:46 Ransomware and Business Email Compromise 31:21 Cyber Insurance and Its Pitfalls 32:44 Andrew Tate Hack and Hacktivism 36:04 Chinese State-Sponsored Hacks 41:26 Canadian Cybersecurity Issues 44:53 Session Cookies and Two-Factor Authentication 49:45 AI in Software Development 56:42 Concluding Thoughts and Final Remarks
Massive Telecom Hack and the Future of Cybersecurity
In this episode of Cybersecurity Today, host Jim Love covers a series of crucial topics including a major cyber attack by Chinese hackers on U.S. telecom networks labeled as the biggest in history, the challenges tied to hardware upgrades for enhanced security, and the U.S. Department of Defense's efforts to combat deepfakes. The discussion underscores the importance of encryption, highlights moves by Microsoft and Google for hardware security, and explores the implications of AI-generated deepfakes for national security.
00:00 Introduction and Book Promotion 00:30 Major Cyber Attack on U.S. Telecom Networks 02:31 Encryption and Security Measures 03:59 Hardware Upgrades for Enhanced Security 06:19 Combating Deep Fakes 08:39 Conclusion and Upcoming Panel Discussion
Cybersecurity Today: From Data Theft to Total Destruction
In today's episode, we cover the latest shifts in cybercrime as hackers move from data theft to complete system destruction, impacting businesses on a massive scale. We discuss Palo Alto Networks' insights on these damaging attacks, Veeam's critical vulnerability patches, and a major breach affecting thousands in Saskatchewan. Additionally, we report on Russia's life sentence for a notorious cyber criminal leader and a significant European takedown of a cybercrime network. Stay informed with the latest in cybersecurity and learn about the steps being taken to counter these escalating threats.
00:00 Introduction: Cybersecurity Headlines 00:26 Evolving Cyber Threats: From Ransomware to Destruction 02:42 Veeam's Critical Vulnerability Patch 04:17 Saskatchewan Data Breach and Privacy Concerns 05:14 Massive Data Breach at SL Data Services 06:29 Russia's Crackdown on Cybercrime 08:21 Operation Passionflower: Dismantling Matrix 10:11 Conclusion and Show Notes
Cybersecurity Incidents in Healthcare and AI Exposures
In this episode, host Jim Love discusses recent cybersecurity incidents, including a major cyber attack on Wirral University Teaching Hospital in the UK, exposing healthcare vulnerabilities. An AI chatbot startup, WotNot, exposed 300,000 sensitive records online due to misconfigured storage. A novel phishing attack using corrupted Microsoft Word documents is also examined. The episode concludes with the takedown of the world's largest piracy network in Operation Takendown, underlining the international effort against cybercrime. Stay updated on the latest in cybersecurity and tech trends.
00:00 Introduction and Book Promotion 00:30 UK Hospital Cybersecurity Incident 03:11 AI Chatbot Data Exposure 05:05 Phishing Attack with Corrupted Word Documents 06:38 Operation Takendown: Largest Piracy Network Dismantled 08:39 Conclusion and Show Notes
AI and Cybersecurity: Addressing AI Myths and Strategies | Project Synapse Episode 3
Join Jim Love, host of Cyber Security Today, alongside Marcel Gagné and John Pinard in this weekend edition from our sister podcast, Hashtag Trending. This episode, part of the Project Synapse series, dives into a discussion on AI, focusing on security, strategic implementation, and addressing common myths. They explore the gap between AI strategies and their deployment, the relationship between strategy and action, and practical approaches to protect your data while utilizing AI. The conversation also touches on critical thinking and the need for proper training to make effective use of AI technology.
00:00 Introduction and Thanksgiving Break 00:31 Welcome to Hashtag Trending 00:48 Introducing Marcel Gagné and John Pinard 01:42 AI Strategy and Implementation 02:53 AI Myths and Misconceptions 06:17 AI Vulnerabilities and Security 07:27 The Role of Headlines in AI Perception 11:56 Guardrails and AI Control 16:19 Data Security and AI Models 25:07 Running Small Models on Private Networks 26:35 Leveraging Existing Tools for Cost Efficiency 28:07 Critical Thinking and AI Validation 30:53 Common Mistakes and AI Limitations 37:38 AI in Medical Diagnostics 43:04 Balancing AI Use and Human Oversight 46:37 Concluding Thoughts and Future Directions
A quick not to say that in our tradition of observing Holidays in both the US and Canada, we'll be taking the weekend off. We'll be back on Monday morning, bright and early with the Cyber Security News,
Retailers Face AI Bot Attacks, Avast Exploit, and Starbucks Ransomware Challenges
In this episode of 'Cybersecurity Today,' host Jim Love covers the latest cyber threats impacting retailers, including AI-powered bot attacks and ransomware incidents. Discover how hackers are exploiting an old Avast driver to deploy advanced Windows malware and how Starbucks is managing employee payments manually following a ransomware attack on its scheduling software provider, Blue Yonder. The episode highlights the increasing cyber risks retailers face during the holiday season and the importance of robust cybersecurity measures.
00:00 Introduction and Headlines 00:22 AI-Powered Bot Attacks on Retailers 02:51 Windows Malware Exploiting Avast Driver 04:09 Starbucks Ransomware Attack and Manual Pay 05:18 Ransomware Trends and Impacts 06:01 Conclusion and Show Notes
Cybersecurity Today: Palo Alto Firewalls Breached, APT28's Wi-Fi Hack, Meta Fights Scams
In today's episode, over 2,000 Palo Alto firewalls were hacked via patched zero-day vulnerabilities; a Russian group, APT28, exploited Wi-Fi networks in a novel 'Nearest Neighbor Attack' to breach a U.S. firm; Meta removed more than 2 million accounts linked to pig butchering scams; and Google launched a free cybersecurity certificate on Coursera to prepare students for entry-level jobs in six months. Host Jim Love provides in-depth analysis and the latest updates in the world of cybersecurity.
00:00 Introduction and Headlines 00:29 Palo Alto Firewalls Hacked 02:43 Nearest Neighbor Wi-Fi Attack 05:09 Meta's Crackdown on Pig Butchering Scams 07:10 Google's Free Cybersecurity Certificate 08:52 Conclusion and Resources
Phishmas Alert: Tackling Holiday Season Cyber Threats
In this episode of Cybersecurity Today, the weekend show, the host is joined by guest David Shipley to discuss the rise in phishing activities during the holiday season, humorously dubbed 'Phishmas.' They delve into the psychology behind phishing, the impact of seasonal stress on individuals, and the tactics cybercriminals use to exploit these conditions. The episode also highlights recent research on phishing trends, the broader scope of consumer fraud, and the challenges faced by law enforcement in combating these crimes. Practical advice for individuals and organizations to protect themselves is also provided, along with a call to action for greater governmental response and individual vigilance.
00:00 Introduction to Phishmas 00:41 The Importance of Good Research 01:01 Understanding Data vs. Facts 02:02 Phishing During the Holiday Season 03:13 The Mechanics of Phishing Scams 04:51 The Role of Typo-Squatting in Phishing 06:13 The Evolution of Phishing Techniques 09:16 The Human Factor in Phishing 13:10 The Impact of AI on Phishing 18:19 Psychological Tactics in Phishing 21:08 Retailer Perspective on Cyber Threats 22:21 Rise of Fraud in North America 22:57 Impact of Fraud on Individuals 24:01 Challenges in Combating Fraud 27:59 Strategies to Protect Yourself 32:25 Role of Retailers and Banks 35:45 Political and Legislative Actions 38:47 Final Thoughts and Call to Action
Cybersecurity Today: Zero Day Flaws, FinTech Breach, Phishing Scams & More
In today's episode, host Jim Love discusses critical updates in the cybersecurity world. Discover the latest zero day vulnerabilities patched by Apple, a significant data breach at Fintech giant Finastra, emerging phishing attack tactics using Microsoft Visio files and SVG attachments, and the launch of a new privacy-focused telecom service, CAPE. Additionally, learn about Google's AI-powered OSS Fuzz tool, which uncovered a critical flaw in the OpenSSL library. Stay informed to protect yourself and your organization from sophisticated cyber threats.
00:00 Introduction and Sponsor Message 00:59 Emerging Phishing Attack Strategies 03:12 Finastra Data Breach Investigation 04:49 Launch of CAPE: A Privacy-Focused Telecom Service 06:19 Apple's Emergency Updates for Zero-Day Vulnerabilities 07:29 Google's OSS Fuzz Uncovers Critical Vulnerabilities 09:07 Conclusion and Podcast Information
Cybersecurity Today: Microsoft Updates, Gen AI Risks, and Liminal Panda Threat
In this episode of Cybersecurity Today, host Jim Love discusses major cybersecurity updates from Microsoft's Ignite conference, including enhancements to Windows security and device recovery. A survey by LegitSecurity highlights the security risks associated with generative AI in software development. CrowdStrike reveals Liminal Panda, a Chinese cyber threat to telecoms. Additionally, a report from the EPA's Office of Inspector General exposes significant cybersecurity vulnerabilities in U.S. drinking water systems. This episode is brought to you by CDW Canada Tech Talks.
00:00 Introduction and Sponsor Message 00:42 Microsoft's New Cybersecurity Features 02:10 Generative AI and Software Development Risks 04:30 Liminal Panda: A New Cyber Threat 06:24 Cybersecurity Vulnerabilities in US Water Systems 08:35 Conclusion and Sponsor Acknowledgment
Cybersecurity Today: GitHub Attacks & Microsoft's November Patch Tuesday Updates
In this episode of Cybersecurity Today, host Jim Love highlights critical cybersecurity updates. The episode covers malicious attacks on GitHub projects, including an orchestrated attempt to frame Texas-based security researcher Mike Bell, and the associated impact on open-source repositories. Additionally, Microsoft's November Patch Tuesday is discussed in detail, with over 90 security issues disclosed, including four critical zero-day vulnerabilities. The episode also addresses a new ransomware strain exploiting vulnerabilities in Veeam backup software, and the disruptions caused by Microsoft's flawed Exchange Server security update. Stay informed on the latest cybersecurity trends and threats.
00:00 Introduction and Sponsor Message 00:29 Cybersecurity Headlines 00:46 GitHub Malicious Code Attack 03:24 Microsoft November Patch Tuesday 05:17 Veeam Backup Software Vulnerability 07:02 Microsoft Exchange Server Update Issues 08:47 Conclusion and Sign-Off
Cybersecurity Today - Weekend Edition: Project Synapse, AI in Action (Episode 2)
In this episode of Cybersecurity Today with host Jim Love, we dive into the intersection of Artificial Intelligence (AI) and cybersecurity, continuing our exploration in the series Project Synapse. Joined by Linux and open-source expert Marcel Gagné and cybersecurity professional John Pinard, we discuss practical applications of AI in business, strategies to implement AI securely, and the rapid technological advancements that pose challenges for companies. Tune in to learn how experimentation with AI can innovate business processes while figuring out what tools and strategies can add real value to your operations. This episode emphasizes the importance of maintaining security and developing a solid business strategy in the evolving landscape of artificial intelligence.
00:00 Introduction to Cybersecurity Today 01:14 Meet the Hosts and Guests 02:08 Project Synapse: AI in Action 02:20 Current State of AI and Security Concerns 04:20 Challenges and Opportunities in AI Adoption 06:36 Business Strategies in the Age of AI 11:35 The Importance of Experimentation and Play 20:26 Innovative Uses of AI in Everyday Life 23:53 Cultural Shift in Business 24:27 Rise of AI Agents 25:13 Challenges with AI Models 25:45 Specialized AI Agents 28:17 AI in Accounting and Business 32:12 AI in Customer Service 33:40 Workshops and Practical AI Applications 48:17 Security Concerns with AI 49:40 Conclusion and Future Plans
Holiday Cyber Threats, Secret Service Surveillance & AI Safety with DOE
In today's episode of Cybersecurity Today, host Jim Love covers essential cybersecurity topics heating up this holiday season. A new report from B4AI unveils sophisticated scams targeting online shoppers, including brand spoofing, fake apps, and fraudulent sites designed to steal credentials. Jim also delves into the U.S. Secret Service’s controversial use of location data without warrants, exploring the debate over privacy and government surveillance. Lastly, the episode highlights Anthropics Claude AI’s collaboration with the Department of Energy to ensure AI models cannot be misused for developing nuclear weapons, setting a precedent for future AI safety measures in government. Tune in for these stories and more on Cybersecurity Today.
00:00 Cybersecurity Threats Targeting Holiday Shoppers 04:00 Secret Service's Controversial Use of Location Data 06:07 Anthropic's AI Collaboration for Nuclear Safety 08:26 Conclusion and Additional Resources
In this episode, we discuss urgent cybersecurity concerns: Cisco's critical vulnerability affecting industrial wireless systems with a CVSS 10 rating, D-Link's refusal to patch severe flaws in over 60,000 outdated NAS devices, and Amazon's data breach tied to the MoveIT vulnerability. We'll also cover the importance of strong off-boarding processes, drawing lessons from a Disney insider threat incident involving a former employee. Join us as we dive deep into the latest security alerts and best practices to safeguard your systems and data.
00:00 Critical Flaw in Cisco's Industrial Wireless Systems 02:07 D-Link's Unpatched Vulnerabilities in NAS Devices 03:22 Amazon Employee Data Exposed in MoveIT Breach 04:41 Lessons from Disney's Insider Threat Incident 06:37 Conclusion and Final Thoughts
CyberSecurity Today: Zip File Attacks, iPhone Reboots, and LLM Vulnerabilities
In today's episode, host Jim Love discusses hackers leveraging zip file concatenation to evade detection, mysterious iPhone reboots hindering police investigations, and Mozilla's Odin's in-depth analysis of security issues in a large language model. Discover how cybercriminals hide Trojans in zip files, how the iOS 18 feature Before First Unlock (BFU) could be affecting forensic examinations, and explore the intricacies of prompt injections and security implications in ChatGPT. Plus, tune in for an exclusive interview with Marco Figueroa from Mozilla's Odin Bug Bounty project to delve deeper into these findings.
00:00 Introduction and Headlines 00:21 Hackers Exploit Zip File Concatenation 01:48 Phishing Campaign with Remcos RAT 03:12 Mysterious iPhone Reboots 04:18 Mozilla's Odin Project and LLM Security 06:40 Conclusion and Afterwords
Jailbreaking AI: Behind the Guardrails with Mozilla's Marco Figueroa
In this episode of 'Cyber Security Today,' host Jim Love talks with Marco Figueroa, the Gen AI Bug Bounty Program Manager for Mozilla's ODIN project. They explore the challenges and methods of bypassing guardrails in large language models like ChatGPT. Discussion points include jailbreaking, hexadecimal encoding, and the use of techniques like Deceptive Delight. Marco shares insights from his career, including his experiences at DEF CON, the NSA, McAfee, Intel, and Sentinel One. The conversation dives into Mozilla's efforts to build a secure AI landscape through the ODIN bug bounty program and the future implications of AI vulnerabilities.
00:00 Introduction and Guest Introduction 00:22 Understanding Large Language Models and Jailbreaking 01:53 Recent Jailbreaking Techniques and Examples 04:42 Interview with Marco Figueroa: Career Journey 10:12 Marco's Work at Mozilla and the ODIN Project 16:50 Exploring Prompt Injection and Hacking 23:21 Future of AI Security and Final Thoughts
FBI Warnings, TikTok's Canadian Shutdown, Major Data Breach Arrests & More | Cybersecurity Today
In this episode of Cybersecurity Today, host Jim Love highlights the FBI's warning about growing phishing attacks exploiting government email credentials, leading to potential data theft and ransomware attacks. The Canadian government orders TikTok to shut down its domestic operations over national security fears, while the app plans to fight the decision. Authorities arrest Alexander Connor Moucka in conjunction with massive data breaches at companies like Ticketmaster and AT&T. Additionally, a Brampton landlord becomes a victim of an e-transfer scam, emphasizing the importance of securing email accounts. Stay informed with the latest cybersecurity news and recommendations.
00:00 Introduction and Headlines 00:22 FBI Warning on Phishing Attacks 01:53 International Law Enforcement Actions 02:26 Canada Orders TikTok Shutdown 03:45 Major Data Breach Arrests 04:22 Brampton Landlord E-Transfer Scam 05:16 Securing Personal Transfers 06:02 Conclusion and Show Notes
AI Finds Zero Day Vulnerability, MFA Mandatory on Google Cloud, French Energy Firm Hacked
In today's episode of Cyber Security Today, host Jim Love discusses Google's AI-driven system Big Sleep discovering the first ever AI-identified zero day vulnerability in the SQLite database engine. He also covers Google's new requirement for Google Cloud users to implement multi-factor authentication (MFA) starting January, and a recent cyber-attack on French firm Schneider Electric, where hackers demanded a ransom in baguettes. Learn about these critical updates and their implications for the future of cybersecurity.
00:00 Introduction to Cyber Security Today 00:21 AI Discovers Zero Day Vulnerability 03:06 Google Cloud Enforces Multi-Factor Authentication 05:55 Hackers Demand Ransom in Baguettes 07:42 Conclusion and Show Notes
Chinese Cybersecurity Threats: Espionage in Silicon Valley, Canadian Government Infiltration, and Persistent Botnets
In this special edition of Cyber Security Today, host Jim Love discusses three alarming stories illustrating the increasing cybersecurity threats posed by China. The episode details China's espionage activities in Silicon Valley, including a Google employee caught stealing AI trade secrets, the infiltration of Canadian government systems by Chinese state-sponsored hackers, and a persistent botnet using compromised TP-Link routers to target Microsoft Azure accounts. The stories highlight the urgent need for enhanced cybersecurity measures to counter these sophisticated threats.
00:00 Introduction: Rising Cybersecurity Threats from China 00:33 Silicon Valley Under Siege: Espionage in the Tech Hub 03:56 Canadian Government Infiltration: A Deep Dive 05:47 Persistent Botnet Threat: Covert Network 1658 07:31 Conclusion and Final Thoughts
Welcome to the weekend edition of Cybersecurity Today! Join host Jim Love as he delves into the top cybersecurity stories of the month with industry experts David Shipley of Beauceron Security, Terry Cutler of Cyology Labs, and special guest Kim Schreader from TELUS. This episode covers a range of vital topics, including AI's impact on cybersecurity, the alarming rise in API vulnerabilities, and a shocking report on the Canadian Revenue Agency's fraud losses. The panel also discusses cybersecurity awareness, the overlooked importance of protecting our libraries, and innovative ways to educate the next generation on cybersecurity. Don't miss their insights, expert opinions, and the debut of the cyber stinky award!
00:00 Introduction and Panelist Welcome 00:39 Kim Schreader's Background and Cybersecurity Insights 01:44 Cybersecurity Awareness Month Highlights 02:11 Phishing Milestones and Challenges 03:34 Home Cybersecurity and Public Engagement 04:59 SecTor Event and Cyber Insurance Study 06:10 Sextortion Emails and Ransomware Threats 07:30 Revenue Canada Fraud Scandal 14:31 Legacy Systems and Cybersecurity Accountability 17:55 AI in Cybersecurity: Threats and Opportunities 26:43 Medical Imaging Vulnerabilities 27:35 IoT Device Security Concerns 29:25 API Vulnerabilities and Exploits 31:45 Importance of Pen Testing 39:41 AI and Prompt Injection Risks 46:58 Education and Cybersecurity Awareness 52:23 Library Cyber Attacks and Conclusion
Cyber Security Today: Deceptive Delight Jailbreak, API Vulnerabilities Surge, Hex Attack on GPT-4
In this episode of Cyber Security Today, host Jim Love discusses the new jailbreak technique 'Deceptive Delight' that highlights vulnerabilities in large language models, the 21% increase in API vulnerabilities reported by Wallarm, and the hex-encoded attack on OpenAI's GPT-4. Learn about the significant rise in API security threats, including misconfigurations and cloud-native software vulnerabilities, and how cybercriminals are exploiting them. Discover how researchers are bypassing AI safety mechanisms and what this means for the future of AI security. Stay safe and informed about the latest cybersecurity trends and risks.
00:00 Introduction to Cyber Security Today 00:20 Deceptive Delight: A New Jailbreak Technique 02:22 Surge in API Vulnerabilities 04:16 Hexadecimal Exploits in AI Models 06:01 Smishing Attacks and Personal Anecdotes 06:56 Conclusion and Upcoming Shows
Massive CRA Breach Exposed & Cyber Challenges in Healthcare and Retail
In this episode of Cyber Security Today, host Jim Love delves into the significant cyber security incidents impacting Canada, healthcare, and retail sectors. A report from CBC and Radio Canada reveals that the Canada Revenue Agency (CRA) has been compromised multiple times, leading to tens of thousands of hacked tax accounts and millions in fraudulent refunds. The episode also highlights a new report from Forescout Technologies that identifies critical vulnerabilities in connected medical devices, posing serious risks to patient safety and data security. Additionally, the 2024 Trustwave Retail Risk Radar Report outlines the evolving cyber threats facing retailers during the e-commerce boom, including phishing, credential stuffing, and ransomware attacks. Links to the detailed reports are provided in the show notes. Tune in for an in-depth discussion on these pressing cyber security challenges.
00:00 Introduction and Headlines 00:27 Canada Revenue Agency Hacked: Millions in Bogus Refunds 03:33 Medical Devices at Risk: Forescout's Alarming Report 06:42 Retail Cybersecurity Challenges: TrustWave's Insights 09:21 Conclusion and Show Notes
In today's episode of Cybersecurity Today, host Jim Love covers stories including, Cisco releases an emergency patch for a vulnerability exploited in brute force attacks, Delta Airlines sues CrowdStrike over a problematic software update leading to flight disruptions, UnitedHealth confirms the massive data breach at Change Healthcare affecting 100 million people, and Apple announces a $1 million bug bounty for hacking Apple Intelligence servers. Stay informed on these pivotal issues impacting the tech and cybersecurity landscape.
00:00 Emergency Patch for Cisco Vulnerability 02:02 Delta Sues CrowdStrike Over Flight Disruptions 03:48 Apple's $1 Million Bug Bounty Program 05:14 UnitedHealth Data Breach Impact 07:17 Show Wrap-Up and Contact Information
Mastering Cybersecurity: From AI Threats to Quantum Encryption - Insights with CDW
Join host Jim Love in a riveting discussion with Ivo Wiens, Field CTO for CDW Canada, as they review CDW's cyber security research and discussions with CISO's about the state of cyber security in Canada.
Delve into the sophistication of cyber attacks driven by organized crime and nation-states, and learn about the importance of cyber security frameworks like zero trust and NIST standards. The conversation also explores the role of AI in both enhancing phishing attacks and defending against cyber threats, as well as the challenges and strategies in implementing AI security within organizations.
Gain insights on vendor management complexities, platformization, quantum cryptography, and the future of cyber encryption. Listen to practical advice on navigating business risks, enhancing user experiences, and adopting zero trust models in today's digital landscape.
00:00 Introduction to Cybersecurity Today 00:26 Understanding CDW and Its Role 01:08 CDW's Approach to Cybersecurity 04:16 Research and Insights from CDW 05:40 The Growing Sophistication of Cyber Attacks 08:24 Adopting Cybersecurity Frameworks 12:12 The Importance of Tabletop Exercises 17:01 Human Vulnerabilities and AI in Cybersecurity 18:12 The Sophistication of Phishing Attacks 19:03 Emotional Manipulation in Cyber Attacks 21:09 AI in Cybersecurity: Opportunities and Risks 22:30 Implementing AI in Business Operations 25:08 Balancing AI and Privacy Concerns 34:09 The Future of Cybersecurity: Quantum Computing 36:53 Final Thoughts and Advice for Organizations
SEC Fines, WordPress Hacks, & Okta's New Security Standards | Cybersecurity Today
Join host Jim Love in this episode of Cybersecurity Today, sponsored by CDW Canada Tech Talks. We delve into the SEC's $7 million fine on four companies for misleading cybersecurity disclosures, the hacking of over 6,000 WordPress sites by malicious plugins, and Okta's introduction of a new identity security standard in response to rising SaaS breaches. Get detailed insights on these key topics and more. Tune in to stay updated on the most pressing cybersecurity issues!
00:00 Introduction to Cybersecurity Today 00:28 SEC Fines for Misleading Cybersecurity Disclosures 02:39 Massive WordPress Site Hacks 04:58 Okta's New Security Standards 07:49 Conclusion and Sponsor Message
In today's episode of Cyber Security Today, sponsored by CDW Canada Tech Talks, host Jim Love dives into the latest tech news and cybersecurity updates. Key stories include the FBI arrest of Eric Council Jr. for hacking the SEC's social media, the release of VulnHuntr, an AI tool designed to detect zero-day vulnerabilities in Python, and the arrest of two Sudanese brothers running a cybercrime business. Additional updates cover a security flaw in the WordPress Jetpack plugin, ongoing attacks on the Internet Archive, and the Golden Chickens spear-phishing campaign targeting HR personnel. Tune in for these stories and more.
00:00 Introduction to Cyber Security Today 00:27 FBI Arrests in SEC Social Media Hacks 02:49 Open Source Tools for Python Vulnerabilities 05:20 Cyber Crime Arrests and Scams 07:25 Golden Chickens Spear Phishing Campaign 09:15 Show Wrap-Up and Announcements
Phishing and Cybersecurity: Evolution, Tactics, and Human Factors
In this deep dive into the world of cybersecurity, join experts Jim Love and David Shipley as they unravel the ever-evolving landscape of phishing attacks and modern cyber threats. Through discussing the history and sophisticated evolution of phishing, including innovative methods like quishing, vishing, and smishing, this episode reveals the severe impacts on businesses and individuals. Discover how cybercriminals use psychological manipulation, including principles from Robert Cialdini's influence framework, to dupe unsuspecting victims. Uncover real-world examples, such as the dangers posed by AI-driven datasets, and the critical importance of Multi-Factor Authentication (MFA) in enhancing account security. The episode also delves into the human elements of cybersecurity, emphasizing the role of workplace culture, emotional intelligence Training, and assertiveness in creating a resilient defense against social engineering attacks. Join us for practical tips and insights to bolster your cybersecurity posture.
00:00 Introduction to Cybersecurity Today 00:31 Emerging Phishing Threats 01:36 Deep Dive into Phishing 03:22 History of Phishing 05:55 Types of Phishing Attacks 19:16 Social Engineering and Phishing 20:06 Research Hypothesis on Phishing 25:55 Phishing Tactics: Free Gift Card Scams 26:24 The Power of Scarcity in Phishing 28:18 Authority Figures and Phishing 29:02 Consistency: Small Requests to Big Scams 30:06 Liking and Social Proof in Phishing 32:19 The Evolution of Phishing Techniques 35:15 Fighting Back: Technical Solutions 42:57 Emotional Intelligence and Workplace Culture 46:58 Conclusion and Final Thoughts
In this episode, host Jim Love delves into sophisticated phishing attacks, cybersecurity initiatives, and significant changes in data security protocols. Listeners will learn about a national survey revealing that 53% of Canadians would switch banks after a data breach and hear insights on Apple's proposal to shorten SSL/TLS certificate lifespans. The episode also covers 23andMe's data breach and settlement, and introduces the FIDO Alliance's new protocol designed to enhance passkey portability across platforms. Emphasizing the importance of robust cybersecurity measures and user education, the discussion highlights advancements in passwordless authentication, as demonstrated by major implementations from companies like Amazon. This episode offers an in-depth look at current cybersecurity challenges and forward-thinking solutions in the realm of user authentication.
00:00 Introduction and Show Format Update 00:48 Canadian Banking Cybersecurity Concerns 01:14 Survey Insights and Financial Sector Responses 03:25 Customer Concerns and Communication Gaps 04:17 Financial Impact of Data Breaches 05:13 Apple's SSL/TLS Certificate Lifespan Proposal 06:20 Google's Push for Shorter Certificate Lifespans 07:24 23andMe Data Breach Settlement 09:55 FIDO Alliance and Passwordless Authentication 12:38 Conclusion and Show Notes
Cybersecurity Today: Wayback Machine Read-Only, AI-Driven Phishing, and Quantum Computing Breakthroughs
In this episode of Cybersecurity Today, host Jim Love discusses the recent cyber incident with the Internet Archive's Wayback Machine, which is now back online in read-only mode. He outlines sophisticated AI-driven Gmail phishing schemes that are fooling even tech experts and reports on Chinese researchers' breakthrough using a Canadian quantum computer to potentially crack military-grade encryption. Jim also shares practical advice on staying vigilant against such cyber threats.
00:00 Introduction and Schedule Update 00:22 Cybersecurity News Highlights 00:44 Internet Archive's Wayback Machine Breach 02:06 Sophisticated AI-Driven Gmail Phishing Scams 05:45 Quantum Computing Breakthrough in Encryption 07:10 Conclusion and Sign-Off
Exploring IT Trends and AI Opportunities with Brian Jackson
In this crossover episode of Hashtag Trending, host Jim Love interviews Brian Jackson, Principal Research Director at InfoTech Research Group, to discuss emerging IT trends and their intersection with cybersecurity. The conversation covers AI advancements, quantum computing, and digital humans, focusing on how to leverage technology for business opportunities while mitigating associated risks. Brian also emphasizes the importance of AI specialization and sovereignty, and the necessity for organizations to adapt encryption in preparation for quantum computing breakthroughs. Tune in for insights on current technology trends and strategies to harness emerging tools effectively.
00:00 Introduction and Overview 00:42 Meet Brian Jackson 01:51 Brian's Role at InfoTech 02:47 Tech Trends 2025 04:07 AI Opportunities and Risks 05:41 Quantum Computing and Cryptography 06:29 Digital Humans and Deepfakes 09:22 AI in Business Applications 22:32 AI Sovereignty and Cost Management 33:48 Quantum Computing in Practice 38:30 Conclusion and Final Thoughts
Cybersecurity Today: Data Breaches and Malware Threats
In this episode of Cybersecurity Today, host Jim Love discusses the hacking incidents involving the Internet Archive and Fidelity, exposing millions of users' data. Highlights include the Internet Archive breach attributed to the Black Meta Hacktivist group, affecting 31 million users, and Fidelity's data breach impacting 77,000 customers. Additionally, the bankruptcy of National Public Data after a massive leak and North Korean cyberattacks on tech job seekers are detailed. These incidents emphasize the importance of robust cybersecurity measures and industry regulations.
00:00 Major Data Breaches: Internet Archive and Fidelity 00:26 Internet Archive Breach: Details and Impact 01:49 Fidelity Data Breach: What Happened? 03:17 National Public Data Files for Bankruptcy 05:23 North Korean Hackers Target Tech Job Seekers 07:38 Conclusion and Resources
Cybersecurity Alert: White House Urges Insurance Reform & Major Hacks Revealed
In this episode of Cybersecurity Today, host Jim Love covers significant developments in cybersecurity policy and breaches. The White House, represented by U.S. Deputy National Security Advisor Ann Neuberger, calls for an end to insurance policies that incentivize ransomware payments. The episode also discusses a major ransomware attack affecting Comcast and highlights a significant breach by China-backed hackers targeting U.S. telecom providers. Additionally, American Water faces a security breach impacting its customer systems. The episode emphasizes the growing threats and debates around cybersecurity practices.
00:00 Introduction and Headlines 00:41 White House Calls to End Ransomware Payments 02:11 Comcast Data Breach Exposes 230,000 Customers 03:57 Chinese Hackers Compromise U.S. Telecom Systems 06:24 American Water Cybersecurity Incident 08:02 Conclusion and Show Notes
Cybersecurity Today: Cloudflare's DDoS Victory, Russian Hacker Arrests, and Truth Social Scams
In this episode of Cybersecurity Today, host Jim Love discusses Cloudflare's successful mitigation of the largest recorded DDoS attack, showcasing the company's advanced defense capabilities. The episode also covers the arrest of nearly 100 individuals in Russia linked to illegal cryptocurrency transactions and ransomware laundering through the Crypteks crypto exchange. Additionally, it highlights Truth Social's vulnerability to pig butchering scams, where users face significant financial losses. These stories reflect ongoing cybersecurity challenges and responses from different stakeholders.
00:00 Introduction and Headlines 00:28 Cloudflare's DDoS Defense Triumph 02:57 Russia's Crackdown on Cryptex Crypto Exchange 04:57 Truth Social's Pig Butchering Scams 07:02 Conclusion and Show Notes
Unveiling the Truth: Insights into Cyber Security Awareness and Phishing
In a special crossover episode of Cyber Security Today and Hashtag Trending, host Jim Love discusses the biases and challenges in technology marketing research with guest David Shipley, head of Beauceron Security. The conversation examines the significance of security awareness, focusing on phishing simulations. Shipley shares insights from his research, emphasizing the optimal frequency of monthly phishing tests and the importance of reporting rates. The episode also covers the psychological aspects of cyber security, sustainability of gamification in training, and highlights the need for balancing training demands to avoid negative impacts of overtraining. Listeners are encouraged to reflect on the insights shared and respond with their thoughts on the program's format.
00:00 Introduction and Overview 00:15 The Problem with Technology Marketing Research 00:46 Bias in Research and Media 01:33 Importance of Objective Research 02:24 Introducing David Shipley and His Research 03:08 Understanding Human Behavior in Cybersecurity 05:38 Phishing Research and Findings 07:19 Effective Phishing Simulations 15:02 Insights from Phishing Data 22:14 The Importance of Reporting and Feedback 22:32 Multi-Channel Communication Strategies 23:53 Gamification and Personal Cyber Risk Scores 25:16 Behavioral Economics in Cybersecurity 27:07 The Impact of Intrinsic Motivation 29:22 The Role of Psychology in Cybersecurity 30:15 The Framing Effect and Security Perception 32:19 Optimism Bias and Security Awareness 35:00 The Dunning-Kruger Effect in Training 37:29 Anchoring Bias and Phishing Indicators 39:03 Key Takeaways and Final Thoughts
Cybersecurity Today: NVD Backlogs & Emerging Threats
Host Jim Love discusses the backlog in the National Vulnerability Database and its implications for cybersecurity, highlighting two new Linux vulnerabilities. The episode also covers a sophisticated malware, Perfctl, attacking Linux servers, vulnerabilities in CUPS, and security risks of Meta's smart glasses. Additionally, insights are provided from a CIRA study on ransomware payment trends and the challenges posed by AI in cybersecurity. The podcast ends with announcements for new vulnerability threats and a preview of upcoming research with co-host David Shipley.
00:00 Introduction and Podcast Promotion 00:45 National Vulnerability Database Backlog 02:54 Linux Vulnerabilities: Perfctl Malware 04:42 CUPS Vulnerability Alert 05:56 Privacy Concerns with Meta's Smart Glasses 07:23 Critical Vulnerabilities in Zimbra and Ivanti 08:55 CIRA's Ransomware Study Insights 12:12 AI in Cybersecurity: Survey Findings 14:02 Conclusion and Upcoming Features
Cybersecurity News: Microsoft Patch Issues, Chrome Vulnerabilities, and T-Mobile Settlement
In this episode of Cybersecurity Today, Jim Love discusses several pressing issues in the tech world. Early feedback on Microsoft's Windows 11 October Patch Tuesday update reveals significant stability issues. Google Chrome receives a second major security update in ten days due to four new high severity vulnerabilities. The Canadian Internet Registration Authority (CIRA) publishes its annual cybersecurity study highlighting the costs and damages from cyberattacks on Canadian businesses. A coalition of major security agencies releases a report on detecting and mitigating Active Directory compromises. Lastly, T-Mobile agrees to a $31.5 million settlement with the FCC over multiple data breaches affecting millions of U.S. customers. Stay tuned for more insights and updates!
00:00 Introduction and Podcast Promotion 00:38 Microsoft's October Patch Tuesday Issues 02:29 Urgent Chrome Security Update 03:27 CIRA's Annual Cybersecurity Study 05:18 Active Directory Compromise Report 06:57 T-Mobile's FCC Settlement 08:38 Conclusion and Sponsor Message
New NIST Password Guidelines, Octo2 Trojan & ChatGPT Vulnerabilities | Cybersecurity Today
Join Jim Love in today's episode of Cybersecurity Today as he discusses the latest password security guidelines from NIST focusing on length and usability, the emergence of the Octo2 Trojan targeting bank accounts on Android by posing as VPN and Chrome apps, and a significant vulnerability in ChatGPT allowing attackers to plant false memories. Additionally, learn about Google's new password rules for Gmail access and the recent glitch causing ChatGPT to initiate conversations on its own. Don't miss this insightful episode to stay updated on the latest cybersecurity trends and measures.
00:00 Introduction and Podcast Promotion 00:50 NIST's New Password Guidelines 02:26 Octo2 Trojan: New Android Threat 03:27 ChatGPT Vulnerability: False Memories 04:40 Google's New Password Rules for Gmail 05:35 ChatGPT's Unprompted Messaging Bug 06:54 Conclusion and Sponsor Message
Cyber Security Week in Review: Data Breaches, MFA Bypassing, and Surveillance Insights
Join host Jim Love along with an expert panel featuring Terry Cutler, David Shipley, and Laura Payne to discuss this week in cybersecurity. Topics include the latest methods of bypassing MFA, data breaches and how to deal with compromised information, the implications of the FTC's report on tech company data collection, new findings on fraud affecting small businesses, and an intriguing German police technique to unmask TOR users. The episode also introduces the 'Stinkies' award for unnecessary fearmongering by cybersecurity vendors. Don't miss this in-depth analysis and practical advice for staying secure in an increasingly digital world.
00:00 Introduction and Panelist Introductions 02:55 Jessica's Question on Data Breaches 09:18 Small Business Fraud and Cybersecurity 17:44 Evilginx and MFA Vulnerabilities 22:44 MFA Security: Myths and Realities 25:26 The FTC's Staggering Surveillance Report 28:44 Surveillance Capitalism and Marketing Tactics 28:54 Tim Hortons' Data Collection Scandal 37:00 The German Police and TOR Anonymity 42:49 The Inaugural Stinky Awards 44:58 Final Thoughts and Farewell
Canadian SMBs Face Rising Fraud Threats & New AI-Powered Gmail Security
In this episode of Cyber Security Today, host Jim Love discusses the increasing fraud threats faced by Canadian small and medium-sized businesses, revealing that half have experienced attempted or successful fraud in the past year. The transportation sector is hit hardest, with 61% reporting fraud attempts. Google’s new Gemini AI technology offers enhanced security for Gmail, notably for smaller businesses. InfoStealer malware developments are circumventing Google Chrome’s app-bound encryption, posing significant threats. Additionally, severe vulnerabilities have been uncovered in fuel storage tank monitoring systems, emphasizing the urgency for robust security measures in critical infrastructure.
00:00 Introduction and Overview 00:25 Fraud Threats Facing Canadian SMBs 02:15 Google's AI-Powered Security Enhancements 03:54 InfoStealer Malware Targeting Google Chrome 06:11 Critical Vulnerabilities in Fuel Storage Technology 08:28 Conclusion and Final Thoughts
Evilginx: MFA Bypass Tool, Kaspersky's Exit & FTC's Data Surveillance Report - Cyber Security Today
In this episode of Cyber Security Today, host Jim Love discusses a new cyber security tool called Evilginx that bypasses multi factor authentication (MFA), Kaspersky's unexpected software replacement for North American users, ESET's patches for critical vulnerabilities, and a scathing FTC report on data collection by major tech companies. Learn about the latest cyber security threats and updates to stay informed and protected.
00:00 Introduction to Today's Cyber Security News 00:26 Evilginx: The New Threat to Multi-Factor Authentication 02:45 Kaspersky's Controversial Exit from the U.S. Market 04:36 ESET Patches Critical Vulnerabilities 06:33 FTC's Scathing Report on Big Tech's Data Practices 08:11 Conclusion and Show Notes
Security Risks with Apple's OS Update, Disney Ditches Slack, and GitHub Hack Alert
In this episode of Cyber Security Today, host Jim Love discusses pressing issues in the cybersecurity landscape: Apple's latest macOS update, Sequoia version 15, causing compatibility issues with major security tools; Disney's move to scrap Slack after a significant data breach; a sophisticated GitHub phishing attack leveraging GitHub's notification system; and German police's breakthrough in unmasking anonymous Tor users. Key takeaways include advice for IT professionals on managing OS updates, the implications of corporate messaging app breaches, precautions for GitHub users, and recommendations for maintaining anonymity on the Tor network.
00:00 Introduction and Headlines 00:21 Apple's Mac OS Sequoia Update Issues 02:00 Disney Dumps Slack After Data Breach 03:13 GitHub Phishing Campaign Exploits Developers 04:44 German Police Unmask Tor Users 07:19 Conclusion and Show Notes
A Hacker's Perspective on Vulnerable Civic Infrastructure
In this episode, host Jim Love explores the vulnerabilities of civic infrastructure with cybersecurity expert Nick Aleks. They discuss how hackers view and exploit city systems, the dangers of default passwords and outdated firmware, and the risks associated with smart buildings and operational technology. Nick provides insights on how bad actors can leverage these weaknesses for massive attacks and offers recommendations for improving security through collaboration, proactive measures, and the incorporation of AI technologies. This enlightening discussion highlights the urgent need for better security practices in our increasingly connected urban environments.
00:00 Introduction and Context 00:18 Meet the Expert: Nick Aleks 00:51 A Hacker's Perspective on City Infrastructure 03:20 Penetration Testing and Vulnerabilities 04:26 Targeting Civic Infrastructure 20:30 Smart Buildings and IoT Security 25:12 Defensive Strategies and Collaboration 32:29 The Role of AI in Security 35:06 Conclusion and Final Thoughts
Cybersecurity Today: Supply Chain Attacks, Data Breaches, and Botnet Threat Disruptions
In this episode of 'Cybersecurity Today,' host Jim Love covers pressing issues in the cybersecurity world, including a supply chain attack in Lebanon, a major data breach at AT&T resulting in a $13 million fine, and the disruption of the Chinese botnet known as Raptor Train. The AT&T breach underscores the risks of weak vendor data protection, while the weaponization of communication devices in Lebanon signals new threats in cyber-physical warfare. The episode also highlights the resilience of the Raptor Train botnet, attributed to the Chinese state-sponsored group Flax Typhoon, and the steps taken by the FBI to mitigate this threat. Listeners are advised to enhance their cybersecurity practices to protect against these multifaceted attacks.
00:00 Introduction to Cybersecurity Today 00:23 AT&T's $13 Million Fine for Data Breach 02:03 Weaponized Communication Devices in Lebanon 03:50 Disruption of the Chinese Botnet Raptor Train 05:28 Conclusion and Sign-Off
Emerging Cyber Threats: Repellent Scorpius, TfL Cyber Attack, and Online Safety for Children
In this episode, we discuss the emergence of the new ransomware group Repellent Scorpius and their use of the Ciccada 3301 ransomware. We cover the London Transport Authority's (TfL) in-person password resets following a significant cyber attack, and examine the case of Chinese national Song Wu's multi-year spear-phishing campaign. Additionally, we delve into the C community's proposal for a safe C extension to enhance memory safety and address vulnerabilities. Finally, we highlight the urgent online dangers targeting children and teens, and the measures required to combat these threats.
00:00 Emergence of Repellent Scorpius Ransomware Group 01:53 TfL's Response to Cyber Attack 02:53 Chinese National Charged in Spear Phishing Campaign 04:13 C Community's Safe C Extension Proposal 05:33 Online Dangers Targeting Children and Teens 07:19 Conclusion and Final Thoughts
Cyber Security Today: Fortinet Data Breach, Seattle Ransomware Attack, and Lazarus Targeting Developers
In this episode of Cyber Security Today, host Jim Love covers Fortinet's confirmation of a data breach after a hacker claims to have stolen 440GB of data. The episode also discusses the cyber attack on Seattle Tacoma International Airport by the Rysida ransomware group and the port's refusal to pay the ransom. Additionally, North Korean hacker group Lazarus is targeting Python developers via malicious coding tests as part of the VM connect campaign. Stay tuned to learn more about these pressing cybersecurity issues.
00:00 Introduction to Cyber Security Today 00:27 Fortinet Data Breach Details 02:15 Seattle Tacoma Airport Ransomware Attack 03:41 Lazarus Group Targets Python Developers 05:30 Conclusion and Final Thoughts
Cybersecurity Insights: Vulnerabilities, Insider Threats, and the Future of Online Safety
In this weekend edition of Cybersecurity Today, host Jim Love is joined by regulars Terry Cutler of Cyology Labs and David Shipley of Beauceron Security, alongside special guest Laura Payne from White Tuque. They discuss significant cybersecurity news including the new additions to CISA's known exploited vulnerabilities catalog, a hilarious yet eye-opening domain purchase incident, and the ongoing issue of insider threats. The panel also dives into the complexities surrounding recent breaches like the one at Avis and the broader implications of data vulnerabilities. Stay tuned for the latest insights and expert opinions on what's happening in the cybersecurity world.
00:00 Introduction and Panelist Introductions 01:31 Format Overview and First Cybersecurity Story 01:47 Discussion on CISA's Vulnerability Catalog 02:51 Challenges in Patch Management 06:45 Microsoft's Patch Tuesday Controversy 10:49 The $20 Domain Vulnerability 15:42 Insider Threats and Real-World Incidents 18:11 Handling Disgruntled Employees 18:51 Insider Threats: Real-Life Examples 19:41 Preventing Insider Threats 21:30 Password Management and Security 22:53 Case Study: Sales Employee Walks Out with Client List 23:42 Jurassic Park and Risk Management 24:32 Avis Data Breach: What Happened? 25:51 The Importance of Identity Theft Protection 29:44 Challenges in Cybersecurity Awareness 34:27 Microsoft's New Security Measures 35:07 Conclusion and Farewell
Cyber Security Today: TfL Data Breach, Critical Vulnerabilities, and Insider Threats
Join host Jim Love in 'Cyber Security Today' as we delve into the latest cyber security incidents and updates. Learn about Transport for London's data breach affecting thousands of customers, critical vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog, and the recent Microsoft Patch Tuesday addressing over 70 security flaws. We also discuss significant breaches at Avis, shocking domain purchase by a researcher highlighting internet trust issues, and insider threats exemplified by Daniel Rhyne's rogue actions against an industrial company. Stay informed with expert insights and essential recommendations!
00:00 Introduction and Breaking News 00:05 Transport for London Cyber Attack 01:04 New Vulnerabilities Added to CISA's KEV Catalog 02:38 Microsoft and Other Major Tech Companies Release Patches 04:02 Avis Data Breach 05:15 Security Researcher Buys Critical Domain 07:58 Insider Threat: The Daniel Rhyne Case 09:53 Conclusion and Final Thoughts
Cybersecurity Today: Microsoft Office 2024, Data Breach, CrowdStrike Fallout, & Ford's Privacy Concerns
In this episode of Cybersecurity Today with your host Jim Love, we discuss Microsoft's decision to disable ActiveX controls by default in Office 2024 to enhance security, the data breach at SlimCD affecting 1.7 million credit card owners, CrowdStrike's ongoing response to the July IT disruption, and privacy concerns over Ford's new patent application for in-car conversation monitoring. Learn about the implications and what these developments mean for IT professionals and end-users.
00:00 Introduction and Headlines 00:24 Microsoft Office 2024 Security Changes 01:50 Major Data Breach at SlimCD 03:51 CrowdStrike's Crisis Management 05:35 Ford's Controversial Patent Application 06:54 Conclusion and Show Notes
Massive Healthcare Data Breach, Google's Move to Rust, and New Sextortion Scams - Cybersecurity Today
In this episode of Cybersecurity Today, hosted by Jim Love, we discuss a major healthcare data breach at Confident Health where 5.3 terabytes of sensitive mental health data were exposed due to a misconfigured server. Google advocates for replacing legacy C and C++ code with Rust for better security and productivity. We also explore the disturbing new trend in sextortion scams that now include photos of victims' homes to enhance threats, and the importance of addressing such scams in corporate security programs.
00:00 Introduction and Headlines 00:18 Major Data Breach at Confident Health 02:08 Google's Move to Rust for Enhanced Security 03:59 The Rising Threat of Sextortion Scams 05:50 Conclusion and Resources
Toronto School Board Hack & Cybersecurity Best Practices: Expert Panel Discussion
Welcome to the weekend edition of Cybersecurity Today, hosted by Jim Love! Join our expert panel featuring Terry Cutler from Cyology Labs, David Shipley of Beauceron Security, and special guest Daina Proctor from IBM Security Services Canada. This episode dives into recent cybersecurity stories including a major data breach at the Toronto District School Board and continued fallout from the MoveIT software hack. Our experts discuss the importance of robust security measures, the cultural shift needed in organizations to handle cyber threats, and the increasing role of cybersecurity insurance. We’ll also explore fascinating stories like active listening on Android phones and Disney's legal backtrack. Don't miss out on this insightful and engaging conversation!
00:00 Introduction and Panelist Welcome 01:26 Toronto School Board Cyber Attack 02:16 Challenges in School Cybersecurity 10:52 MoveIT Hack and Its Implications 15:43 Insurance and Cybersecurity 25:19 City of Columbus Data Breach 26:21 Spotting the Problem: Data Overload 26:31 Columbus Breach: Encryption and Legal Battles 27:25 The Streisand Effect and Legal Protections 28:20 Personal Story: Public Information and Security 29:19 Human Element in Cyber Attacks 34:20 Incident Response Planning and Simulations 39:13 Proactive Cybersecurity Measures 46:40 Consumer Data Privacy Concerns 54:01 Conclusion and Final Thoughts
Terry referred to CyologyLab.com/start for the video and the free tools.
AI Summer Recap: OpenAI's GPT 5, GPT Next, and Beyond
Join host Jim Love as he navigates through the major AI and cybersecurity stories that dominated summer 2023. From CrowdStrike's impact on Windows security to OpenAI's tantalizing announcements of GPT 4.0 Omni and the anticipated GPT Next, this episode reflects on the giant strides in AI technology. Understand the strategic buzz created by OpenAI, the unrecognized achievements by Google, and the intricate gossip surrounding futuristic AI models like QSTAR and Strawberry. This comprehensive recap highlights why the advancements in AI could significantly shape business processes and technological systems in the near future. Don't miss the rerun of the highly informative Practical AI episode featuring industry experts, plus a hint at what's to come in tech news.
00:00 Introduction and Host Welcome 00:37 Summer's Blockbuster Stories: AI and Cybersecurity 01:06 OpenAI's Strategy and GPT 4.0 Omni 03:11 The Mystery of Sora and Other Rumors 04:53 Google's AI Achievements and OpenAI's Mastery 07:27 The GPT Next Announcement 10:27 Conclusion and Future AI Developments 11:57 Practical AI Episode Rerun and Closing Remarks
Is Your Phone Spying on You? D Link Vulnerabilities & Government Data Requests
In this episode of Cyber Security Today, host Jim Love discusses critical remote code execution vulnerabilities in D Link routers, impacting their discontinued DIR 846 series. These flaws, including CVE 2024 44341 and CVE 2024 44342, pose significant risks, prompting D Link to recommend users replace outdated devices. The episode also examines the considerable amount of data governments gather from big tech companies, with a study by Surfshark highlighting the increasing user data requests. Lastly, Jim covers a report from 404 Media that reveals Facebook's partner, Cox Media Group, using smartphone microphones for targeted ads, raising severe privacy concerns. Stay informed about the latest in cybersecurity by tuning in!
00:00 Introduction: Is Your Smartphone Listening? 00:15 D-Link Router Vulnerabilities Exposed 02:24 Government Data Requests from Big Tech 04:15 Tech Companies' Compliance with Data Requests 05:38 Facebook's Active Listening Scandal 08:20 Conclusion and Show Notes
In this episode of Cyber Security Today, host Jim Love delves into recent data breaches affecting the Toronto District School Board, Texas Dow Employees Credit Union, and the city of Columbus. Discover details on the ransomware attacks, the compromised data, and the implications for the victims involved. Additionally, explore critical questions raised about cybersecurity practices and the handling of whistleblowers. Tune in for an in-depth analysis of these significant cybersecurity incidents.
00:00 Introduction and Headlines 00:22 Toronto District School Board Data Breach 01:32 MoveIT Breach: A Continuing Saga 03:19 City of Columbus Ransomware Attack 05:04 Whistleblower Controversy in Columbus 05:42 Host's Editorial and Personal Experience 07:39 Conclusion and Contact Information
Welcome to a special weekend edition of Cyber Security Today! In this long weekend episode, we delve into the world of artificial intelligence (AI) and its impact on various sectors, particularly as organizations ramp up their plans for the upcoming year. Join our host Jim Love and a distinguished panel of experts: Evgeny Koloda, Marcel Gagne, John Pinard, and Nicole Bendrich, as they explore the current state of AI, its promises, practical implementations, and the cybersecurity challenges associated with it. Discover valuable takeaways on developing an effective AI strategy and understanding the multi-modal advancements poised to revolutionize industries.
00:00 Introduction to the Special Weekend Edition 00:45 Meet the Expert Panel 02:25 The Promise and Challenges of AI 03:31 The Evolution of AI in Various Industries 06:41 Generative AI and Its Impact 07:53 AI in Cybersecurity 19:00 Human vs. AI: Decision Making and Errors 23:50 The Future of AI and Human Interaction 33:04 Expanding Human Capabilities with AI 35:04 Choosing the Right AI Model 40:09 Navigating AI in Regulated Industries 46:23 The Rise of Deepfakes and Cybersecurity Concerns 59:35 Building an Effective AI Strategy 01:04:15 Conclusion and Final Thoughts
Resources:
https://www.aivia.ai/ - EMR with AI capabilities eCW (eClinicalWorks)
https://www.eclinicalworks.com/ - Digital Video Twin platform - HeyGen
https://www.heygen.com/ - Canadian Digital Twin creation platform - Synthesia
https://www.synthesia.io/ - Voice Cloning platform - Eleven Labs
https://elevenlabs.io/ - Automation with AI -
https://www.make.com Open Router https://openrouter.ai Jan.ai https://jan.ai/
In this episode of Cybersecurity Today, host Jim Love dives into the alarming rise of deepfake scams, highlighting how threat actors are using AI-generated videos to lure victims into fraudulent schemes. A notable campaign involves deepfake videos of Elon Musk promoting 'Quantum AI.' Additionally, the episode covers a sophisticated cyber attack where fake Palo Alto's Global Protect VPN is used to deploy malware. Lastly, it discusses Russia's potential threats against undersea communication cables and GPS systems, emphasizing the growing vulnerabilities in global infrastructure. Stay informed and secure with this essential update.
00:00 Introduction and Headlines 00:23 Deepfake Scams: The New Frontier 01:26 Quantum AI Scam Breakdown 02:47 Fake Palo Alto VPN: A Sophisticated Cyber Attack 04:21 Russia's Threat to Global Communications 06:35 Conclusion and Upcoming Show
Critical Cyber Security Alerts: Major Vulnerabilities and Exploits Unveiled
In today's episode of Cyber Security Today, host Jim Love discusses a series of alarming cyber security incidents. Topics include a sophisticated attack exploiting a zero-day vulnerability in a popular network management platform, critical patches from SonicWall and Google addressing severe vulnerabilities, and an update on the National Public Data hack revealing deeper security issues. Learn about the latest threats and essential security measures you need to take now.
00:00 Introduction and Headlines 00:22 Sophisticated Cyber Attack on ISPs 02:43 SonicWall Firewall Vulnerability 04:29 Google Chrome Zero-Day Exploit 06:23 National Public Data Breach Update 07:58 Conclusion and Additional Resources
Cybersecurity Failures: Lawsuits, Outages, and International Threats
In this episode of Cybersecurity Today, host Jim Love covers a range of critical cybersecurity issues. The U.S. sues Georgia Tech for not meeting cybersecurity standards as a Pentagon contractor. A potential cyber attack disrupts operations at Seattle’s port and airport. Microsoft plans a security summit following a major global IT outage caused by CrowdStrike. The effectiveness of publicly naming and shaming countries sponsoring cyberattacks is questioned. Join us as we delve into these pressing topics and their implications for cybersecurity policy and infrastructure resilience.
00:00 Cybersecurity Headlines: U.S. Sues Georgia Tech and Seattle Port Outage 00:24 Seattle Port and SeaTac Airport Cyber Attack Details 01:56 U.S. Government Sues Georgia Tech Over Cybersecurity Failures 03:27 Microsoft Security Summit and CrowdStrike Outage 04:11 Debate Over Microsoft's Proposed Security Changes 05:13 Effectiveness of Naming and Shaming in Cybersecurity 06:41 Challenges in Combating State-Sponsored Cyber Attacks 07:05 Conclusion and Show Notes
Join host Jim Love in this weekend edition of Cyber Security Today, featuring a distinguished panel including Terry Cutler (Cyology Labs), David Shipley (Beauceron Security), and special guest Tara Gold (Cado Security).
The episode delves into key cybersecurity topics including the value of IT certifications, the rising trend in ransomware payouts, and the novel attack vectors targeting macOS systems. The show also explores the impact of poisoned search terms and the rising threats to small and medium-sized businesses. Don't miss this engaging and insightful discussion on the latest cybersecurity trends and best practices.
00:00 Welcome to Cyber Security Today 00:05 Meet the Panel and Special Guest 02:31 Introduction to Key Stories 03:04 Debate on IT Certifications 12:07 Ransomware Trends and Insights 18:46 Search Terms as Attack Vectors 23:26 Mac OS Vulnerabilities and Malware 30:17 Conclusion and Farewell
In this episode, host Jim Love delves into significant cybersecurity news, including a rise in FakeBat malware infections from malvertising campaigns, car companies selling driver data to brokers without consent, and McAfee's new deepfake detection tool. Highlights include the sophisticated methods of the FakeBat campaign, privacy concerns from automakers' data practices, and McAfee's innovative on-device solution for detecting AI-generated content.
00:00 Introduction to Cybersecurity Today 00:24 Malvertising Campaigns and FakeBat Malware 02:21 Automakers Selling Driver Data 04:22 McAfee's Deepfake Detection Tool 06:14 Show Wrap-Up and Additional Insights
Ransomware Record Highs, North Korean Exploits, Toyota Data Breach, and Mac Security Flaws - Aug 21, 2024
In this episode of Cybersecurity Today, host Jim Love discusses the latest cybersecurity threats and incidents making headlines. Topics include record-high ransomware payments in 2024, a sophisticated malware exploit by North Korean hackers, a significant data breach at Toyota, and newly uncovered vulnerabilities in Microsoft's Office Suite for Mac users. Stay informed on these critical issues and more.
00:00 Record-Breaking Ransomware Payments in 2024 02:38 North Korea's Advanced Malware Exploits Windows Zero Day 04:53 Toyota's Massive Data Breach Exposed 06:37 Mac Users Beware: Vulnerabilities in Microsoft Office Suite 09:03 Show Wrap-Up and Listener Appreciation
Cybersecurity Today: OpenAI's Action Against Iranian Disinformation & Chrome's New Privacy Features
In this episode of Cybersecurity Today, host Jim Love discusses OpenAI's recent identification and neutralization of chat GPT accounts linked to Iranian disinformation campaigns, Google's upcoming privacy enhancements in Chrome for Android, and the cybersecurity concerns raised by U.S. lawmakers over Chinese-made TP Link routers. The episode also highlights a new study revealing the cybersecurity risks posed by employees using work laptops for personal activities. Tune in to stay informed about the latest developments in cybersecurity.
00:00 Introduction and Headlines 00:22 OpenAI's Battle Against Iranian Disinformation 02:05 Google Chrome's New Privacy Features 03:29 Domain Hijacking Risks Highlighted 05:14 Concerns Over Chinese-Made Routers 07:25 Risks of Using Work Laptops for Personal Use 09:29 Conclusion
In this special edition of Cybersecurity Today, your deepfake host Jim Love dives into the world of cybersecurity with new guests Marcel Gagné, an open-source guru, and Andréanne Bergeron, the director of research at GoSecure. The panel, including regular David Shipley, discusses the increasing threat of deepfakes in corporate and political spheres, the resilience required to combat modern cyber threats, and the necessity of critical thinking and education to navigate the ever-evolving landscape. From CrowdStrike's humble admission of a major security lapse to the growing concerns around AI-driven attacks, this episode offers insights and practical advice for both IT professionals and the general public. Don't miss out on this engaging discussion on how to stay ahead of cybersecurity challenges!
00:00 Introduction to Cybersecurity Today 00:22 Meet the Panel: Experts in Cybersecurity 02:08 CrowdStrike's Humility at DEF CON 03:54 Elon Musk and Infrastructure Failures 12:05 The Debate on Digital Identification 21:02 Deep Fakes: The New Frontier 23:59 The Rise of Digital Avatars 24:28 Open Source and Security Concerns 24:55 Commercial Availability and Control Issues 26:08 Media and Public Perception 26:56 Deepfakes in Politics and Business 27:29 Ease of Creating Deepfakes 27:57 Real-Time Deepfake Threats 29:12 Organizational Resilience and Culture 29:59 Human Psychology and Cybercrime 33:19 The Future of AI and Human Intelligence 35:23 Critical Thinking and Education 37:19 Balancing Technology and Human Factors 39:33 Final Thoughts and Recommendations 50:14 Closing Remarks and Acknowledgements
Cybersecurity Insights: Paris Olympics and Deepfake Technologies
In this episode, host Jim Love discusses proactive cybersecurity measures taken during the Paris 2024 Olympics to combat threats such as domain abuse, counterfeit shops, unauthorized live streaming, cryptocurrency scams, and betting fraud. He highlights a report from before AI on pre-Olympic threats and emphasizes the importance of relying on official sources. Additionally, Love covers advancements in deepfake technologies, including new offerings like Hey Gen, Elon Musk's GROK, and the open-source Deep Live Cam, which raise significant concerns about digital impersonation and fraud. Simple verification strategies, like safe words, are suggested as countermeasures as these technologies become more accessible. Tune in for a Week in Review panel on these topics.
00:00 Introduction and Overview 00:23 Cybersecurity Measures for the Paris Olympics 00:53 Key Findings from the Before AI Report 01:55 Proactive Measures and Advice for Viewers 02:48 Deep Fake Technology Demonstrations at DEF CON 03:54 Concerns Over Deep Live Cam and Digital Security 05:32 Ethical Implications and Future Considerations 05:40 Conclusion and Week in Review Preview
In this episode of Cybersecurity Today, host Jim Love delves into Elon Musk's claim that a DDoS attack delayed his live interview with Donald Trump, the revelation of a massive data breach compromising most U.S. social security numbers, and CrowdStrike's president accepting the 'Most Epic Fail' award at DEF CON. The episode covers the skepticism around Musk's DDoS claim, details on the National Public Data hack, and CrowdStrike's approach to owning up to its global IT outage. Tune in for the latest updates in cybersecurity!
00:00 Introduction and Headlines 00:21 Elon Musk's DDoS Claim and Technical Issues 02:06 Trump Campaign Hacked 03:00 National Public Data Breach 05:16 CrowdStrike's Epic Fail at DEF CON 06:34 Conclusion and Show Notes
Exposing Hidden Secrets: DEF CON Revelations, Ransomware Surge & GPS Spoofing Woes
Join host Jim Love in this insightful episode of Cybersecurity Today. Discover the shocking revelation of over 15,000 hard-coded secrets uncovered at DEF CON by researcher Bill Dermacapi, and learn about a new ransomware attack targeting home users. We also delve into a startling rise in GPS spoofing attacks on commercial airlines that are causing chaos in-flight. Stay informed with our latest updates and expert advice to keep you and your data secure.
00:00 Introduction and Headlines 00:22 North Korean Hackers Arrested 01:12 DEFCON Security Conference Highlights 04:05 Magniber Ransomware Attacks 05:52 GPS Spoofing Threats to Airlines 07:15 Conclusion and Listener Feedback
Cybersecurity Insights: Malvertising, Phishing Trends, and North Korean Hackers
In this weekend edition of 'Cybersecurity Today,' host Jim Love brings together experts Terry Cutler from Cyology Labs, David Shipley from Beauceron Security, and Greg Monson from Trustwave.
The panel explores the latest trends in cybersecurity, including a deep dive into a report on 'Malvertising,' the use of social media advertising to distribute malware.
They also discuss a significant rise in phishing attempts and the challenges of detecting them, revealing a worrying leakage rate of up to 50%.
The panel delves into a fascinating and concerning trend: North Korean hackers being hired as remote workers to infiltrate companies.
Finally, they analyze the recent Delta lawsuit against CrowdStrike and Microsoft's involvement in the case.
Tune in for expert insights, practical advice, and the latest updates in the ever-evolving field of cybersecurity.
00:00 Introduction and Panelist Introductions 01:27 Malvertising: A New Cyber Threat 04:13 The Rise of Alternative Communication Channels 07:39 Corporate Dangers of Facebook Account Takeovers 12:04 North Korean Hackers in Remote Work 20:11 Navigating Reference Checks and Hiring Challenges 20:27 The Intricacies of the Prisoner Swap 21:49 CrowdStrike's Legal Battle with Delta 24:24 The IT Professional's Dilemma 30:25 Phishing Email Statistics and Security Measures 35:59 Concluding Thoughts and Future Topics
Massive Data Breach, Outlook's Phishing Risk, and Windows Downgrade Attack Vulnerabilities
In this episode of Cybersecurity Today, host Jim Love delves into one of the largest data breaches in history involving 2.9 billion records leaked without user consent by National Public Data. He also covers the backlash against Microsoft Outlook's email interface, which has inadvertently facilitated phishing attacks, and discusses a Black Hat presentation revealing vulnerabilities that allow attackers to unpatch fully updated Windows systems. Join us for insights and the latest updates in the world of cybersecurity.
00:00 Introduction and Major Data Breach Overview 00:31 Details of the National Public Data Breach 01:07 Implications and Legal Actions 02:42 Microsoft Outlook Phishing Vulnerability 04:08 Windows Security Vulnerability Exposed at Black Hat 05:57 Conclusion and Upcoming Content
Cyber Security Pros: Awareness vs. Action & The CrowdStrike Controversy Explained
Join host Jim Love in this episode of 'Cyber Security Today' as he delves into a recent survey revealing a disconnect between awareness and action among global security professionals regarding unauthorized software use. Learn about the risks of shadow IT and AI applications, and the startling admittance of security pros themselves using unapproved SaaS. Additionally, explore the two latest stories from the CrowdStrike disaster, including the fallout between CrowdStrike and Delta Airlines, and the surprising involvement of Microsoft. Finally, hear about the importance of having a solid resiliency and recovery plan amidst these challenges. Tune in for these insights and more.
00:00 Introduction and Survey Findings 00:45 Shadow IT Risks and AI Concerns 02:17 CrowdStrike Controversy: Delta Airlines Incident 04:36 Microsoft's Response to Delta's Criticism 05:43 Lessons for IT Leaders 06:23 Show Conclusion and Host Announcement
In this episode of 'Cybersecurity Today: The Week in Review,' host Jim Love discusses critical cybersecurity incidents with guests Terry Cutler, CEO of Cyology Labs, and David Shipley from Beauceron Security. The panel delves into the devastating effects of a ransomware attack on the blood donation nonprofit OneBlood, emphasizing the broader implications for healthcare and emergency services. They also address the Canadian investigation into Ticketmaster's security practices and Microsoft's recent global outage, highlighting the significant challenges and necessary responses in safeguarding IT infrastructure. The discussion underscores the urgency of improving cybersecurity measures, particularly in healthcare, and the complexities of implementing effective regulations.
00:00 Introduction and Panel Introduction 00:19 Ransomware Attack on OneBlood 01:46 Healthcare System Vulnerabilities 04:05 Challenges in Cybersecurity for Healthcare 13:03 Ticketmaster Investigation and Government Inaction 20:03 Delta Airlines Lawsuit and Insurance Implications 28:38 Microsoft Global Service Interruption 35:12 Conclusion and Final Thoughts
In this episode of Cybersecurity Today, host Jim Love explores the aftermath of Microsoft's 10-hour global outage due to a DDoS attack, the Canadian Privacy Commissioner's investigation into Ticketmaster, the severe impact of a ransomware attack on U.S. blood bank OneBlood, and the cascading legal ramifications CrowdStrike faces after a disastrous software update. The episode delves into the broader implications of these cyber incidents and stresses the urgent need for robust cybersecurity measures.
00:00 Introduction and Major Headlines 00:29 Microsoft's 10-Hour Outage: Causes and Consequences 02:39 Ticketmaster Under Investigation: Privacy Concerns 03:45 OneBlood Ransomware Attack: Impact on Blood Supply 05:13 CrowdStrike Legal Battles: Fallout from Software Update 07:21 Conclusion and Upcoming Shows
Microsoft Cloud Outage, WhatsApp Vulnerability, and AI-Powered Screen Reading
In today's episode of Cyber Security Today, host Jim Love covers a significant global outage affecting Microsoft's cloud services, a vulnerability in WhatsApp that allows malicious scripts to run without warning, and a new AI-powered method that can read your screen by intercepting HDMI signals. Stay informed about these pressing cybersecurity issues and learn how to protect yourself.
00:00 Microsoft Service Takes a Nosedive 00:16 Global Impact and Response 02:12 WhatsApp Vulnerability Warning 04:02 AI Decoding Screens from Afar 05:12 Show Wrap-Up and Future Episodes
Google's Password Bug Hits Millions & French Police Battle Malware - Cybersecurity Today
In this episode of Cybersecurity Today, Jim Love covers Google's recent apology after a bug caused the passwords of 15 million Chrome users to vanish. The episode also dives into the French authorities' unique approach to combating the PlugX malware by deploying a disinfection solution. Lastly, it sheds light on the ongoing struggles with patch management in many organizations, particularly following the CrowdStrike disruption. Tune in for these stories and more, along with the challenges and solutions in today's cybersecurity landscape.
00:00 Google Apologizes for Password Vanishing Bug 01:55 French Authorities Combat PlugX Malware 03:44 The Unsexy Challenge of Patch Management 05:41 Conclusion and Show Notes
Cybersecurity Weekly Review: CrowdStrike, Malware, and Major IT Outages
Join Jim Love and a panel of experts as they delve into the top cybersecurity stories of the week. This episode covers the major CrowdStrike incident, AT&T's February outage affecting millions of calls, a new strain of malware in Ukraine targeting industrial control systems, and much more. Listen in as experts Terry Cutler, David Shipley, and Mike Walters discuss the implications, lessons learned, and future strategies needed to tackle these cybersecurity challenges.
00:00 Introduction and Overview 00:18 CrowdStrike Dominates the Headlines 00:27 AT&T's Major Outage 01:14 New Malware in Ukraine 01:51 Whiz Startup's Bold Move 02:33 Panel Discussion Begins 02:55 Introduction of Mike Walters 03:31 Whiz's Market Valuation Debate 06:59 Modbus Protocol Vulnerabilities 07:35 Penetration Testing Insights 12:50 CrowdStrike Incident Analysis 22:24 Media Focus on Airport Chaos 22:36 The Real Impact on Patient Care 23:53 Who Pays for the Outage? 25:40 CrowdStrike's Quick Response 26:27 Future Prevention Strategies 28:27 Challenges in Cybersecurity Updates 38:14 Lessons Learned and Moving Forward 42:17 Conclusion and Acknowledgements
North Korean State Actor Infiltrates US Security Firm | Cybersecurity Today
In this episode of Cybersecurity Today, host Jim Love covers two major incidents. The first is an American firm, KnowBe4, inadvertently hiring a North Korean state actor posing as a software engineer, leading to an attempted malware installation. He discusses the techniques used by the threat actor and the broader implications for cybersecurity. The second story involves CrowdStrike's post-incident review of a system crash, detailing the causes, the company's response, and criticisms of their crisis communication strategy. Tune in to learn about these pressing cybersecurity challenges and how companies are handling them.
00:00 A Shocking Cybersecurity Incident 00:20 North Korean State Actor Infiltration 01:59 CrowdStrike's Post Incident Review 05:07 CrowdStrike's Crisis Communication Failure 06:31 Conclusion and Upcoming Shows
In this episode of Cybersecurity Today, guest host Jim Love covers major events impacting the cybersecurity world, including CrowdStrike CEO George Kurtz's summons to testify before a U.S. House Committee on Homeland Security following a massive IT outage and a new malware strain, Frosty Goop, attacking critical infrastructure in Ukraine. The episode also discusses cybersecurity firm Wiz's surprising decision to decline a $23 billion acquisition offer from Google's parent company, Alphabet, opting instead to aim for an IPO. Stay informed about the latest in cybersecurity, and what these developments mean for the industry.
00:00 Introduction and Headlines 00:24 CrowdStrike CEO Summoned by U.S. House Committee 00:38 Impact and Response to the IT Outage 01:41 Frosty Goop: New Malware Threat 03:09 Wiz Rejects Alphabet's Acquisition Offer 04:45 Conclusion and Show Notes
Join Jim Love on a special edition of Cybersecurity Today and Hashtag Trending as he delves into the recent CrowdStrike incident that led to a global IT meltdown. With over 8.5 million Windows devices affected by a faulty CrowdStrike Falcon update, this event is being compared to Y2K and WannaCry. Discover the widespread impacts across key industries, the technical details behind the kernel-crashing error, and the fallout for companies and IT professionals. Learn why this disaster has created such frustration and anger in the cybersecurity community and what steps are being taken to recover. Tune in to understand the broader economic and societal implications of what is being called the 'worst cyber event in history.'
00:00 Introduction and Host Introduction 00:19 CrowdStrike Incident Overview 00:46 Community Reactions and Frustrations 02:29 Understanding CrowdStrike's Role 04:49 Technical Breakdown of the Issue 07:59 Impact and Consequences 09:04 Response and Fixes 12:33 Lessons and Future Precautions 13:20 Final Thoughts and Warnings 13:58 Conclusion
Dodging the Biggest Supply Chain Attack Ever: An Insight with JFrog's Security Research Team
In this weekend edition of Cyber Security Today, host Jim Love discusses with Brian Moussalli, the Security Research Team Lead at JFrog, how potentially the biggest supply chain attack was averted. They delve into the intricacies of supply chain attacks, the risks associated with leaked tokens, and the importance of checking binary files for vulnerabilities. The conversation also touches on securing open source software and the role of JFrog in making the cyber world safer. Tune in to learn critical lessons on cybersecurity from this insightful interview.
00:00 Introduction and Host Update 00:32 Understanding Supply Chain Attacks 02:47 Interview with Brian Moussalli, the Security Research Team Lead at JFrog 06:15 The Python Token Leak Incident 17:01 Lessons Learned and Future Outlook 23:06 Conclusion and Sign-Off
With Howard away and today's episode of Hashtag Trending being all about security stories, I took the liberty of doing a cross posting. Hope we'll have Howard back next week.
In today's episode of Hashtag Trending, host Jim Love covers significant cybersecurity news. Microsoft faces criticism for mishandling a reported MSHTML browser engine vulnerability, and Disney investigates a hack by 'Null Bulge,' a group accusing the company of unethical AI use. Additionally, Kaspersky Labs announces its exit from the U.S. market due to government sanctions. The episode also discusses the FBI's swift unlocking of a shooter's phone, indicating advanced law enforcement capabilities. Tune in for these updates and more.
00:00 Introduction and Overview 00:43 Microsoft's Vulnerability Disclosure Controversy 02:28 Disney Hacked: Internal Messages Leaked 03:42 Kaspersky Exits the U.S. Market 04:59 FBI Cracks Encrypted Phones 06:54 Conclusion and Upcoming Shows
This episode features an interview with a cybersecurity and privacy lawyer about responding to cyber attacks
Navigating Ransomware Response: Insights from Cybersecurity Expert Imran Ahmad
In this episode features an interview between Howard Solomon and Imran Ahmad, a partner at Norton Rose Fulbright, discussing effective strategies for managing ransomware attacks. Ahmad, with his extensive background in cybersecurity law, shares practical advice on incident response, the importance of having a structured plan, and the dynamic nature of cyber threats. He elucidates the common pitfalls companies face, the role of communication, and the legal nuances of dealing with cyber incidents. Ahmad also touches on the increasing sophistication of attackers, including the use of AI, and the balance organizations must strike between cybersecurity investments and other business priorities.
00:00 Introduction and Host Welcome 00:26 Meet Imran Ahmad: Cybersecurity Expert 01:37 The Reality of Ransomware Attacks 04:05 Elements of a Good Ransomware Response Plan 07:07 Inside the Incident Response Room 11:49 Legal and Communication Challenges 20:11 Government Policies and Ransomware Payments 22:29 Why Organizations Struggle with Cyber Preparedness 24:02 Conclusion and Farewell
This episode reports on some of the new ways threat actors are bypassing phishing defences
This episode reports on new reports on vulnerabilities and software supply chain security
This episode features a discussion on the latest MOVEit vulnerability, a report on recruiting cybersecurity pros and how an API coding error is being blamed for a large cyber breach in Australia
This episode reports on an updated explanation of the hack of Los Angeles County's health department, an API coding error that led to a huge data breach in Australia, and more
This episode reports on a warning to patch Serv-U applications, the workings of the Rafel trojan, and more
This episode features a discussion on an undiscovered three-year hack, the cause of Snowflake attacks and allegations of how an Australian health insurer was compromised
Join Howard Solomon and David Shipley in the weekend review edition of Cybersecurity Today for insights into major cybersecurity incidents. Topics include a three-year undetected hack by the Velvet Ant gang, major breaches involving personal data theft, the Medibank hack, misuse of Snowflake passwords, and the recent CDK Global cyberattack affecting car dealerships. Learn about the latest developments and cybersecurity lessons from these significant events. 00:00 Introduction and Overview 00:40 Weekly Headlines Recap 04:15 In-Depth Analysis: Three-Year Undetected Hack 14:27 Medibank Data Breach Investigation 25:18 Snowflake Data Breaches Update 30:04 CDK Global Cyber Attack 33:47 Conclusion and Final Thoughts
This episode reports on how gullible employees are falling for a scam and cutting and pasting malware into their organization's IT systems, and more
This episode reports on how outdated software played a role in a lengthy hack, the latest VMware security update, and more
This episode reports on complaints about the proposed UN cybercrime treaty, servers used by Islamic State terrorists shut, and more
This episode includes a discussion on Microsoft and Google's offer to help U.S. rural hospitals tighten their cybersecurity, a report on top network vulnerabilities found by penetration testers and the latest news on hacks of Snowflake customers.
This episode reports on the latest ransomware news, another North Korean threat actor putting malicious packages on the NPM registry, vulnerabilities in some open source AI apps, and more
This episode reports on the latest patches from Microsoft, Nvidia, JetBrains and ARM, as well as action by the Privacy Commissioner of Canada
This episode features a discussion of data thefts from Snowflake data stores, more on the controversy over Microsoft Recall and the Auditor-General's report on Canada's cyber fighting agencies
This episode reports on Snowflake users' credentials for sale, how Docker containers are being exploited, and more
This episode reports on vulnerabilities in unpatched versions of Progress Software's Telerik Report Server, the spread of the Remcos remote access trojan, and more
This episode reports on confirmation of cyber attacks on Ticketmaster, Santander bank, a Canadian broadcaster, and more
This week guest Terry Cutler of Cyology Labs and I discuss the controversy around Microsoft's new Recall feature, lessons learned from the MITRE hack, and more
This episode reports on ransomware news, US sanctions against Chinese citizens for running a botnet, and more
This episode features an interview with Treasury Board President Anita Anand, who announced the first cyber security strategy for the Canadian government's IT departments and agencies
This episode reports on a cyber warning to American drinking water utilities from a regulator, a ransomware attack on a prescription drug distributor and more
This episode reports on fake WinSCP file transfer and PuTTY telnet utilities, malware that steals bank login credentials, and more
This episode features a discussion on the FBI takedown of the BreachForums criminal marketplace, and more
This episode reports on the break up of a North Korean scheme tricking American firms into hiring who they thought were Americans app developers to work remotely, and more
This episode reports on the Phorpiex botnet spreading LockBit ransomware, the sentencing of a man behind the Tornado Cash cryptocurrency mixer for money laundering, and more
This episode reports on a warning from security researchers about a VPN vulnerability, a suspected Russian threat actor using generative AI tools to plagiarize or modify legitimate news stories from mainstream media to pump pro-Russian themes, and more
Join us for an interview with Francois Guay, founder of the Canadian Cyber Security Network and a new study of Canadian municipalities and how they rate in terms of attracting and retaining cybersecurity professionals.
This episode reports on Anit-Ransomware Day , big tech companies vowing to make their products and services Secure By Design, and more
This episode reports on the RSA Conference, a Canadian ruling on whether solicitor-client privilege applies when a privacy regulator demands documents after a data breach, and more
This episode reports on vulnerable routers, an attack on a Canadian digital library service and more
If you've ever been frustrated by how poorly you think politicians are dealing with the issues that face us in Cyber Security, maybe you've thought we should have more cyber security professionals in government.
Madison Horn, cyber security professional feels the same way. So she's running for the a seat in the House of Representatives.
This is my interview with Madison, originally published on Hashtag Trending, the Weekend Edition. I hope you enjoy it.
This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure, and more
This episode reports on a vulnerability in the R programming language, fines against large American wireless carriers, and more
This episode reports on a job scam aimed at app developers, the latest data breach notifications and more
This episode features a discussion on the latest in the Change Healthcare ransomware attack, a vulnerability in an abandoned Apache open-source project, the next step in Canada's proposed critical infrastructure cybersecurity law and the future of TikTok
This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and password advice
This episode reports on a new campaign to steal credentials from LastPass users, a warning to admits of Ivanti Avalanche mobile device management software, and more
On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT departments
This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international, and more
This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoom meetings
This episode features a discussion on Microsoft's cybersecurity troubles, worries about open source, a warning about abusing IT help desks to launch attacks and more
This episode reports on a new way threat actors are planting malware on GitHub, why you should watch for the running of unexpected automated scripts on your network, and more
This episode reports on a warning to application developers using the Rust language, the need to unplug end of life D-Link NAS devices, and more
This episode features a discussion on a highly critical report on the hacking of Microsoft Exchange Online email accounts, a case study of a ransomware attack and the discovery of a years-long infiltration of an open source group to insert a backdoor into Linux
This episode reports on vulnerabilities in HTTP/2, RDP weaknesses a major cause of successful cyber attacks, and more
This episode reports on a data breach at OWASP, Google to delete data it collected in Incognito Mode, and more
This episode reports on a way threat actors can get around cloud-based email filtering systems, the latest information on an AT&T data theft, and more
This episode features a discussion on World Backup Day, a security awareness report and more
This episode reports on a US$10 million reward for a ransomware gang, a new Linux version of a backdoor, and more
This episode reports on a new network of 40,000 infected small and home office routers and other devices that are part of a criminal botnet, and more
This episode reports on a new campaign stealing email passwords, the latest data breaches, and more
This episode features discussion on lessons learned from the ransomware attack on the British Library, advice for managing expectations of IT/security teams, why firms are leaving Google Firebase unprotected and more
This episode reports on the discovery of a side-channel vulnerability in Apple M-series chips and more
This episode reports on new backdoors, a new paper giving advice to OT network operators and more
This episode reports on bugs, holes, data breaches, a coming cybersecurity trust mark for US wireless consumer products and more
Here's our week in review stories that David and guest host Jim Love will discuss:
Cyber Pros flock to cybercrime side hustles. I covered this earlier this week. This story came out of the UK and a report that an ex-cop went undercover on the dark web and discovered that there were a lot of cybersecurity professionals who were moonlighting or offering their services the Dark Web.
A second municipality fell victim to a ransomware attack. First it was the city of Hamilton just outside of Toronto, a relatively large municipality – about 600,000 people hit by Ransomware on Feb 25th.
Microsoft had to admit that those Russian state hackers were still doing damage.
For those who don’t remember the story, Microsoft had a very severe breach where email accounts of senior company executives were hacked in November. The cause of the breach, if I remember it right, was a “non-production” instance that was left without two factor authentication and allowed hackers to breach that system and get into a lot more including the executive emails.
Ransomware talent moves to Akira after Lockbit’s “demise”
Lockbit, a big player in ransomware got taken down very publicly by an international law enforcement group. They took Lockbit’s servers and even publicly tried humiliate the group, taking the counter that the group used to terrorize it’s victims. It had a countdown clock that showed the time left to pay the ransom or they’d release the company’s information on the dark web. The agencies that brought them down and took over their site put up their own countdown – only this was the time it would take them to nail the leader of Lockbit referred to as LockBitSupp.
Google adds real time phishing protection to Chrome. A security bug is found in Kubernetes that allows attackers to remotely execute code on Windows nodes. The French government suffers an enormous cyber-attack and vulnerabilities in ChatGPT plug-ins.
Welcome to Cybersecurity Today for Friday March 15th, 2024. I’m your host Jim Love, filling in for Howard Solomon.
A new phishing scam uses car insurance savings as to lure its victims, a report by Sophos shows that small businesses are being targeted by cybercriminals at an increasing rate. Okta says that data claiming to be from hacking them is not their customer data. These stories and more…
Welcome to Cybersecurity Today for Wednesday March 13th, 2024. I’m your host Jim Love, filling in for Howard Solomon.
Breaking Bad in cybersecurity - UK companies are warned that cybersecurity employees may moonlight on the dark web. Microsoft reveals that Russians hackers’ attack is still ongoing. A system used by US government states and agencies has a critical flaw and a new attack vector using fonts has been detected by marketing software Canva.
Welcome to Cybersecurity Today for Monday March 11th, 2024. I’m your host Jim Love, filling in for Howard Solomon.
JIm Love, host of the daily news podcast Hashtag Trending fills in for Howard this Saturday with a replay of a show that Jim did which featured Adam Evans, CISO at RBC. It's a little different but we hope you enjoy it.
This episode reports on a survey of IT pros on insider attacks, US sanctions on a group that markets commercial spyware, and more
This episode features a discussion on how hard it is to kill a ransomware gang, Canada's proposed new online harms bill, why organizations still allow staff to use vulnerable software, and more
This episode reports on a recommendation that enterprises drop Ivanti Pulse Secure and Connect Secure devices because threat actors can get around mitigations for recent vulnerabilities
This episode reports on a threat actor taking advantage of abandoned subdomains once used by big brands, ransomwmare attacks and more
This episode reports on hackers using an open source tool aimed at helping network administrators, the latest data breaches in the U.S., and Australia, and more
This episode features a discussion on the takedown of the LockBit ransomware gang, and more
This episode reports on advice for protecting water utilities from cyber attacks, Avast agrees to a settlement with FTC on allegations it wrongly sold consumer data, and more
This episode reports on a patch for a critical vulnerability in a help desk application, threat actors using the Greatness phishing-as-a-service kit and more
This episode reports a recent fake data breach report and two real ones, a man pleads guilty to being involved in malware distribution, and more
This episode features a discussion on new cyber incident and data breach reporting obligations for American telecom companies, the progress of Canada's proposed cybersecurity law, and more
This episode reports on mulit-million dollar rewards for information on the AlphV ransomware gang, a decryptor is available for the Rhysida ransomware strain, and more
This episode reports on huge data breaches in France and the US, , a new Mac backdoor and more
This episode features discussion on a deepfake video conference call that tricked an employee into wiring US$25 million to crooks, why the U.S. Federal Trade Commission called the cybersecurity of a company "shoddy," and more
This episode reports on ransomware payments, a US$10 million bounty on a ransomware gang, and more
This episode reports on a US regulator hammering Blackbaud for a data breach, a former CIA application developer jailed for 40 years and more
This episode features discussion on hacks at 23andMe, Microsoft, the Canadian government, and on the FBI's warning on the cyber threat from China
This episode reports on ransomware news, a survey of infosec pros in the financial sector and more
This episode reports on the need for every organization to have contact information on security issues, and more
This episode features a discussion on a hack at Microsoft, the recommendations of the Network Resilience Coalition, a report on AI and cyber threats and more
This episode reports on an investigation into why US federal IT staff pushed for the purchase of forbidden video cameras, record data breach numbers last year in the US, and more
This episode reports on ransomware attacks on a North American firm that manages water utilities ,and more
This episode reports on ransomware attacks, an undetected attack on a VMware hole and more
This episode features a discussion on cryptocurrency scammers hacking X accounts, the arrest of a Ukrainian man for using hacked cloud accounts to create 1 million virtual servers for mining cryptocurrency and how an accounting firm employee fell for a phishing email pretending to be from the CEO led to a data breach
This episode reports on firmware updates from hardware manufacturers that IT admins should be watching for, a phishing warning to Middle Eastern expets and more
This episode covers reports with warnings to application developers from Recorded Future and Gitlab; how an accounting company was victimized by a phishing message, and more
This episode reports on scams aimed at employees, a report on the Medusa ransomware group, the latest on the number of data breach victims and more
This episode reports on a hole found in Bosch industrial torque wrenches, attacks on Microsoft SQL servers, and more
This episode reports on basic cybersecurity oversights that led to the hacking of a teclo, the increased number of victims of a US law firm hack, a data breach at a Canadian provider of midwives and more
Russian hackers were inside the biggest Ukrainian telecom provider for at least seven months before knocking it offline last month. This and other news are in the podcast
This episode reports on Canadian and American privacy bills before legislatures, ransomware news and more
This episode features a discussion about the biggest cybersecurity stories of 2023, and predictions for 2024
This episode reports on a warning of a vulnerability in the SSH protocol, the latest multi-million person data breaches and more
This episode reports on the new SEC cyber attack rules that come into effect today, guidance from the NSA on creating a software bill of rights, and more
This epsiode features discussion on how much responsibility governments should shoulder to fight ransomware, why North Korea's Lazarus group is still exploiting the two-year old Log4j vulnerability and the latest on insider attacks
This episode reports on the growth of the KV-botnet, the discovery of another unprotected database on the internet, and more
This episode reports on a US hospital chain notifying 2.5 million patients and employees about data stolen in a ransomware attack, and more
This episode features discussion on cyber attacks against OT networks, the discovery of exposed servers with medical images and why outdated Microsoft Exchange servers are still alive
This episode reports on how hackers break into AWS cloud instances, fake anti-Ukraine online ads using photos of celebrities, and more
This episode reports on abuse of Go language repositories, unpatched Outlook servers targeted by Russian group, and more
This episode reports on a campaign against critical infrastructure using PLCs, a vulnerability in PCs, and more
This episode features a discussion on ransomware, the latest explanation from Okta of a support hack and a survey of infosec pros whose firms were hacked
This episode reports on how a hotel allowed its reservation system to be abused by a crook, US hits at a cyrptocurrency mixer used by North Korea, and more
This episode reports on a company hit twice by a ransomware gang, the arrest in Ukraine of the alleged head of a ransomware gang, and more
This episode reports on the latest ransomware attacks, and details of how a gang that scams people selling used products online works
This episode features discussion on Australia's decision to not make ransomware payments illegal, huge hacks of third-party service suppliers in Canada and the U.S. and whether email and smartphone service providers are doing enough to protect customers
This episode reports on the increasing number of vulnerable Kubernetes containers online, the latest acknowledged data breaches, a browser scam aimed at Macs, and more
This episode reports on unpatched holes that are being exploited by threat actors, and more
This episode reports on ransomware attacks and 1.6 million more victims of MOVEit hacks
This episode features a discussion on lessons learned from a huge cyber attack in Denmark, and more
This episode reports on claims by a threat actor that they used a former employee's still active credentials for a data theft, and more
This episode reports on the latest ransomware news, why a sophisticated attack on Denmark's critical infrastructure providers was so effective, and more
This episode reports on a cyber attack on the operator of ports in Australia, the hack of a reporter's Experian account, the latest data breaches, and more
This episode features discussion on Okta explanation of a hack, Cloudflare's explanation of a power outage and more
This episode reports on a sophisticated OT and IT attack on Ukraine by Russia's Sandworm gang, how failing to patch a firewall fast led to a regulatory fine and more
This episode reports on a university investigation into data brokers, new malware and how hackers could have gotten into medical software
This episode reports on the cause of a recent hack at Okta, personal data stolen from the emaill of employees at a fast food chain, a proxy botnet found and more
This episode features a discussion on changes laid by the SEC against SolarWinds, the latest meeting of the International Counter Ransomware Initiative, cyber attacks on libraries and the departure of CEO John Chen from BlackBerry.
This episode reports on threat actors going after holes in Apache ActiveMQ and Airflow, as well as Citrix NetScaler Gateway appliances
This episode reports on a huge haul of US government workers email addresses stolen in a MOVEit hack, malware in the NuGet open source code respository and more
This episode reports on the results of the latest Toronto edition of Pwn2Own contest, hacks at a US hospital, an e-commerce processor and more MOVEit victims
This episode features a discussion on the recent Okta hack, an attack on a Canadian shared services provider to five Canadian hospitals, the SecTOR conference and more.
This episode reports on a data-stealing gang that's added ransomware to its arsenal, a new UK law forcing social media platforms to police harmful content and more
This episode reports on the latest security updates, a scam aimed at IT service desk staff of American organizations that use access management solutions from Okta, and more
This episode reports on vulnerabilities that have to be dealt with in Cisco applications, the sentencing of a Russian businessman in the US to nine years in prison for his role in a nearly US$100 million stock market cheating scheme, and more
This episode features a discussion between IT World Canada CIO Jim Love and Adam Evans, chief information and security officer of Royal Bank of Canada
This episode reports on what your organization might need to get and keep cyber insurance -- or whether you should self-insure by setting up a rigorous cybersecurity program
This episode offers cybersecurity and privacy advice and links to websites for parents about to send their kids back to school
This episode features discussion on International Women in Cybersecurity Day, a Canadian cybercrime report, the takedown of the Quakbot bot and the attacks on Barracuda Networks' ESG email gateways
This episode reports on more bad packages in open-source repositories, and why you shouldn't play the date game
This episode reports on QR codes being used by threat actors, statistics on ransomware and MOVEit hacks, and more
This episode reports on several newly revealed hacks, including the theft of the names and ranks of 47,000 London police and staff stolen after a hacker got into the IT systems of a firm that prints police warrant cards and staff passes
This episode features a discussion about zero trust and the cyber attack on Tesla by former employees
This episode reports on a persistent attacker, security updates for Ivanti Sentry and more
This episode includes reports on how much Dallas paid for a ransomware incident response, data released by the Black Basta ransomware gang after an attack on a U.S. housing authority and more
This episode features a discussion on a report into the successes of the Lapsus$ extortion gang, a ransomware attack against a Canadian non-profit, a vulnerability in the WiFi module of the infotainment system of some Ford vehicles and whether governments should mandate minimum cybersecurity standards for internet-connected devices
This episode reports on a hole in the naming policies of modules developers can put in Microsoft's PowerShell Gallery, lessons from a honeypot test and more
This episode reports on the most recent data breaches and an extortion campaign against LinkedIn users who lose access to their accounts
This episode reports on the hack of Hub International, advantages of honeypots, artificial intelligence and more
This episode features discussion on preventing ransomware in schools, a UK report on ransomware and insurance, the MOVEit hacks and sports teams and venues as cyber targets
This episode reports on the latest phishing attacks, attacks on unsupported and unpatched Zyxel routers and more
This episode reports on the latest trends in ransomware attacks, and security updates from Microsoft, SAP and PaperCut
This episode reports on the latest victims of MOVEit hacks, data thefts at Colorado's Department of Higher Education, and more
This repeat episode is a conversation with Aaron McIntosh, co-author of the Ransomware Task Forces' Blueprint for Ransomware Defence.
This episode reports on lessons from an analysis by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on 121 assessments it did on security incidents last year
This episode reports on two alerts to admins with Linux in their environments and a caution for web site and web application developers
This episode features a discussion on the latest news in artificial intelligence, women in cybersecurity and data breach reporting
This podcast reports on the need to patch MikroTik routers and Ivanti's Endpoint Manager Mobile and more
This episode reports on the slow adoption of DMARC protection, infected packages in open source repositories and more
This episode reports on a patch for Adobe OpenMeetings, a lack of patching of Zyxel devices, allegations that Microsoft's security breach may be worse than thought, and more
This episode features a discussion on an attacker forging a Microsoft authentication key for cloud access, developers including private keys in Docker containers, the continuing increase in ransomware attacks and more
This episode reports on the latest news in the MOVEIt hack, spyware, attribution in the JumpCloud hack and more
This episode reports on the jailing of an IT security analyst who tried leverage a cyber attack to extort money from the U.K. company he worked for, an AI chatbot for crooks, and more
This episode reports on attacks on AWS, Azure and Google Cloud environments, Russia's attempt to disconnect from the global internet and more
This episode features discussion on insider threats, the pace of cybersecurity spending by the private sector, how hackers are creating voice fakes and the responsibilities of CEOs during a cyber attack
This episode reports on ransomware statistics, the release of the source code for the BlackLotus bootkit and the release of the implementation plan for the U.S. National Cybersecurity Strategy
This episode reports on the cyber trial of a British teen, NATO cyber strategy, how a CEO should respond to a cyber attack and more
This episode reports on the discovery of another unprotected database of personal information, an analysis of new ransomware variants and more
This episode features a discussion with Aaron McIntosh, co-author of the Ransomware Task Force's Blueprint for Ransomware Defense
A look back at Canadian privacy commissioners' report into problems with the Tim Hortons mobile app
This episode reports on the availability of a decryptor for Akira ransomware, a $70 million ransomware demand and more
This episode features a discussion on the Suncor cyber attack, the costs of the Indigo ransomware attack and the value of SIEMs
This episode reports on a new information-stealing malware, crooks cloning voices for virtual kidnapping and more
This episode reports on the latest victim of the MOVEit vulnerability, the impact of Europol's dismantling of an encrypted communications service used by crooks and more
This episode reports on a US insurance firm and a state employees' pension fund caught in the MOVEit hack of a supplier, pilots of two airlines caught in the hack of one of their partners, an infected USB key that led to a hospital being hacked, and more
This episode features a discussion on calls by several civil rights groups for the Canadian government to tighten up its proposed cybersecurity law, the proper way companies should notify victims of a data breach, why cybercrooks like using the Telegram Messaging service and more
This episode reports on the increasing number of ransomware attacks, an email scam that tricks firms into switching payment bank accounts of employees and more
This episode reports on patches for Asus routers, a new Russian email server attack on Ukraine, a ransomware gang takes credit for an attack on Reddit and more
This episode reports on the latest news on MOVEit hacks, a DDoS site taken down by police in Poland and more
This episode features a discussion on paying ransomware demands, a crimeware gang whose targets include small and medium businesses and why some developers are less than careful with their API keys.
This episode reports on GitHub being abused by a threat actor, surveys of infosec pros and more
This episode reports on crime and punishment, civil fines for Microsoft and Spotify and more
This episode reports on the latest news in the MOVEit compromise saga, a successful attack on a SharePoint online customer, recent data breaches and more
This episode features a discussion on the Nova Scotia health data breach, the compromise of the MOVEit file transfer application and more
This episode looks at some of the numbers gathered from 16,000 cybersecurity incidents in the annual Verizon report
This episode looks at the traits a firm should consider if appointing a CISO to the board of directors
This episode reports on the BlackSuit ransomware strain, an expected EU privacy fine against Microsoft, a warning about an attack on web sites and more
This episode features a discussion on a report into the ransomware attack on Newfoundland's IT healthcare system, a penalty paid by a US medical billing supplier over a data breach, an Australian company's estimate of the costs of a ransomware attack and the sentencing in the U.S. of two Nigerian cyber crooks.
This episode reports on ransomware attacks, a proposed US$25 million fine against Amazon and more
This episode reports on CAPTCHA evasion, more exploits added to the Murai botnet and more
This episode reports on a new ransomware gang, new industrial control malware and advice for infosec leaders from a CISO whose firm suffered a ransomware attack
This episode features a discussion on employees who contributed to a company hack by sharing a password to an email account the spread of a fake image posted on Twitter of an explosion supposedly near the Pentagon and more
This episode reports on data breach notifications, an updated hacking tool, surveys of infosec pros and more
This episode reports on an IT security analyst convicted of trying to extort his own company, cybersecurity problems with government agencies in Utah and more
This episode reports on more financial penalties for a US firm's data breach, the PyPI registry can't keep up with added malware, Dole pays $US10.5 million to repair computers after ransomware attack and more
This episode features discussion about this week's U.S. Senate hearing on regulating artificial intelligence, the release of school schematics by a ransomware gang, a cybersecurity company fooled by a fake onboarded employee and the latest use of facial recognition software
This episode reports on how crooks are leveraging Dropbox and the new .,zip domain, offers tips for vacation travelers and more
This episode reports on a new DDoS attack tactic, a U.S. pharmaceuticals company reports a data breach of 5.8 million people, attacks on TP-Link routers and more
This episode reports on man-in-the-middle attacks, a new GitHub security tool, a warning about possibly fake MSI firmware updates and more
This week's review features a discussion between Jim Love and David Shipley on the progress in the fight against ransomware
This episode reports on lessons learned in a breach of security controls, a data breach at SchoolDude, a ransomware warning to admins with VMware hypervisors and more
This episode reports on a new ransomware gang, an update on a ransomware attack on an American private university and more
This episode features a discussion on the latest news about ChatGPT, data thefts of from test and decommissioned servers and whether the FBI needs more money to fight cybercrime
This episode reports on ransomware, a data theft at Yellow Pages Canada, ra[od Apple patches and more
This episode reports on increasingly good fake checkout pages being used on compromised e-commerce sites, malware hiding in supposedly free versions of utilities and games and more
This episode includes a discussion on the merits of the supervised super-penetration tests major Canadian banks and insurance companies will have to undergo
This episode reports on the need to update applications from Veeam, Apache, VMware, and more
This episode reports on common factors in successful ransomware attacks, new tools used by threat actors and a call to update PaperCut servers
This episode reports on infected versions of popular business apps circulating on the internet, attackers are getting into Kubernetes access control and the impact of the X_Trader supply chain attack
This episode features a discussion on the supply chain attack that led to the 3CX supply chain attack, how organizations using Fortra's vulnerable GoAnywhere MFT platform might have stopped ransomware attacks, sensitive data found on used routers and more
This podcast looks at slips by the LockBit ransomware gang, and how one attack was helped by poor cyber hygiene
This episode reports on a new collaboration to create new malware, the latest email campaign using the QBot malware and more
This episode reports on new macOS ransomware, a warning to accounting and tax preparation firms on a scam, and more
This episode features a discussion on the alleged cyber attack against a Canadian gas pipeline, identity management, Windows patches and a new piece of commercial spyware
This episode reports on the latest data breaches, an attack on internet-connected irrigation systems in Israel and more
This episode reports on details of a commercial spyware company, an issue in Microsoft's Azure storage accounts, how crooks try to bypass Google's Play store with malicious apps and more
This episode reports on data breaches, a Ukrainian utility compromised after an employee downloads pirated Microsoft Office, alleged dodgy activity by Tesla and Samsung employees and more
This episode features a discussion on the 3CX supply chain hack, new ransomware, the takedown of the criminal Genesis marketplace and more.
This episode reports on an attempt to take down the IT infrastructure behind stolen versions of the Cobalt Strike tool, the emerging Styx criminal marketplace and more
This episode of the podcast reports on ransomware, a compromised US income tax web site, the exploit of a backup program and more
This episode reports on millions of Americans who took out loans being notified of a data breach, a criminal group trying to defraud companies hit by ransomware by bluffing and more
This episode features a discussion on the call for a temporary halt in developing AI applications, the future of TikTok, World Backup Day and more
This episode reports on how crooks take over Instagram accounts, a WiFI problem in Linux-based devices like access points and smartphones more
This episode reports on a warning to Okta administrators, a data breach at an Australian financial corporation grows and more
This episode reports on crooks using business email compromise tactics to steal products, the latest phishing email scam and more
This episode features a discussion on penetration testing, the cybersecurity maturing rankings of companies, rotating infosec jobs across government departments and the number of people on boards with cybersecurity experience
This episode reports on code in an online payment gateway modified to skim credit cards, a security problem with Windows' Snipping tool and more
This episode reports on a review of the latest version of ChatGPT, poor passwords are compromising Linux SSH servers and more
This episode reports on the latest news on TikTok, ransomware and a hack at an NBA provider
This episode features a discussion on a Canadian parliamentary committee report on cybersecurity, the Newfoundland healthcare system ransomware attack and the cyber implications of the Silicon Valley Bank failure
This episode reports on a huge data breach, information on the Trigona ransomware and more
This episode reports on the latest FBI cybercrime statistics, Silicon Valley Bank phishing scams and more
This episode reports on a company fined for an inaccurate ransomware report, the seizure of the NetWire remote access trojan infrastructure and more
This episode includes a discussion on a damaging Windows bootkit, law firms under attack, cybersecurity help for Canadian non-profits and the hack of a LassPass developer's home computer
This episode reports on a how a recent business email compromise unfolded in just over two hours
This episode reports on a plea by Canada's privacy commissioner to get rid of fax machines, a Russian gang's video call scam and more
This episode reports on an Oauth misconfiguration at Booking.com, data breaches at US universities, security updates for Cisco IP phones and more
This episode features a discussion about artificial intelligence and ChatGPT with a University of Calgary cybersecurity expert
This episode reports on the BlackLotus bootkit, a new backdoor found, a hack of a container and more
Breaches of security controls should be blamed on unsafe applications, not attackers, says the head of the U.S. Cybersecurity and Infrastructure Security Agency. Read why
This podcast reports on a data breach at News Corp., a report on the privacy descriptions of apps in the Google Play store, and more
This episode features a discussion on employees falling for SMS text scams, Twitter's move to make users pay for SMS 2FA and burnt-out CISOs
This episode reports on vulnerabilities in Apple devices plugged, a Russian citizen extradited to the U.S. for computer fraud and more
Hackers selling data centre logins for some of the world's largest companies, phone number recycling leads to accidental account hijacking and a ransomware gang that claims that it’s really your cyber insurance firm that blocks you from getting your data back. Spoiler alert. They lie.
This episode reports on ransomware, a coming SolarWinds Platform update, a warning from VMware of a conflict with a WinServer update and more
This edition features a discussion on who's to blame for cybersecurity problems in Canadian hospitals, and why management and infosec pros aren't communicating better
This episode reports on an attempt to fool Emsisoft protection, the continued spread of the ESXiArg ransomware and more
This episode reports on 1 million patients victimized in GoAnywhere MFT hack, phony packages found in PyPI and NPM registries, WordPress website compromises and more
This episode reports on the apparent return of the Clop extortion gang, ransomware attacks against hospital groups and the city of Oakland, Calif.,, and more
This episode features discussion on ransomware attacks on VMware servers, holes found in Toyota's supplier portal and more
This episode reports on doxing and swatting against execs, screenshots being used in attacks and more
This episode reports on third-party cybersecurity risks, a warning to managed Chromebook admins, hacks at two U.S. background checking services and more
This episode features a discussion about a ransomware attack on a US school board, new data-wiping malware, a controversy the over KeePass password manager and the take-down of the Hive ransomware gang's IT infrastructure
This episode outlines news of four recent ransomware attacks, the release by Cisco Systems of security fixes for industrial products and the guilty plea of a man who tried to extort the software company he worked for
This episode reports on the latest DocuSign scam, YouTube channels hacked for cryptocoin fraud, another warning to open source code repositories and more
This episode reports on the need to protect Active Directory, a patching strategy for ICS devices, a warning to VMware admins and more
This episode features a discussion on Data Privacy Week, hacks involving GoTo and Zendesk and a report that some IT departments aren't even aware of certain vulnerabilities and patches
This episode reports on DDoS attacks in Germany, 61,000 open source Python projects patched on GitHub, Porsche problem with NFTs, facial recognition being allegedly used against lawyers and more
This episode reports on the aftermath for GoTo customers after a supply chain cyberattack, vulnerabilities in Samsung's Galaxy App Store, problems with password managers and more
This episode reports on hackers using Microsoft OneNote in phishing attacks, the number of at-risk and unsupported Cisco routers and more
This episode features a discussion on the Mailchimp hack, the theft of a customer database from a Nissan software developer, the compromise at CircleCI and whether firms have to tolerate buggy applications
This episode reports on ransomware payments, another privacy fine for a Meta company and attackers disrupting a virtual Le Mans race
This episode reports on customer test data stolen from Nissan software developer, warnings to GitHub and GitLab users and holes found in GE's historian server
This episode reports on hackers trying to exploit unpatched versions of Control Web Panel, indicators of compromise for a ManageEngine bug, FortiOS VPNs being targeted and more
This episode features a discussion on fake ChatGPT apps, whether successful ransomware attacks are decreasing, vulnerabilities found in the apps created by major car manufacturers and how fast firms should notify customers about data breaches
This episode reports on the latest efforts of a pro-Russian hacktivist group, unpatched Exchange servers being leveraged by ransomware groups and more
This episode reports on a new ransomware survey, a warning on old backdoors, DDoS attacks with ransoms going up and more
This episode reports on new thinking about the speed of reporting data breaches to victims, the end of support for Windows 8.1, and more
This episode reports on the debate in quantum computing circles, a free decryptor for firms hit by the MegaCortex ransomware strain and why cloud services platforms have to tighten their security
This episode reports on new privacy laws in California and Virginia, breach notifications sent to employees of Wabtec, security updates from Synology and more
I begin the New Year with a podcast aimed at IT and security pros in small and medium businesses on how to start a cybersecurity plan
This episode features a feisty discussion on the important cybersecurity events of 2022, and predictions for 2023
This episode reports on ransomware number for November and trouble in open-source repositories
This episode features a discussion on the US seizure of 48 DDoS-for-hire sites, security patches for Samaba, Ukrainians fooled by free Windows 10 and more
This episode reports on protecting Exchange Servers and Exchange Online, a report on the FIN7 ransomware gang and more bad Android apps
This episode reports on malware hidden in the PyPI registry for open-source projects, a huge privacy violation penalty for Epic Games and more
This episode reports on improved privacy for Gmail, a new business email scams, security updates for Samba and more
This episode features a discussion on the hack of an FBi contact database, session cookies, cyber war and how to punish government employees who don't patch applications
This episode reports on the closing of 48 DDoS for hire sites, data breaches at Social Blade and an Australian email provider, and a new Facebook scam
This episode reports on patches for Windows, a suppler hack stings Uber, malware in the PyPI registry and more
This episode reports on the results from the Toronto Pwn2Own contest, a possible way to hack air-gapped computers, a report on improving the software security supply chain and more
This episode features a discussion on the ransomware attack on Rackspace, the hack of Amnesty International Canada and a report on how threat actors are trying to get around multifactor authentication
This episode reports on another vulnerability found in Internet Explorer, a hack gets past Microsoft 365 and a vulnerability in web application firewalls
This episode reports on ransomware, the need for continued security awareness training for employees and the high cost of low software quality
This episode features a discussion on ethical hacking, fines for privacy offences and more
This episode reports on the Cuba and LockBit ransomware, a fortunate error by Akamai and advice for safer online gaming from Canada's privacy commissioner
This episode reports on an inflation benefits scam aimed at Canadians, 13 vulnerabilities found in a Lanner baseboard management controller, a con aimed at TikTok users and more
This episode reports on the latest Twitter breach numbers, a US college victimized by ransomware, survey numbers from Dell and OpenText, and more
In this episode Terry Cutler and I discuss the theft of funds from subscribers to the DraftKings betting site, ransomware and tips for safe holiday online shopping
This episode reports on vulnerabilities still not sent to some Android smartphones, a targeted scam distributing corrupted VPNs, malware may be hiding in Docker Hub images and more
This episode reports on why Telegram may not be the text service for you, the latest version of a phone scam, a warning about a the abandoned Boa web server and more
This episode reports on four new ransomware strains, how researchers have been quietly helping victims of the Zeppelin ransomware, and patches issued for Atlassian applications
This episode features a discussion on what Sobeys' parent company should be saying about a cyber incident, the reaction to ransomware in Australia and Ontario's recent report on helping the broader public sector from cyber attacks
This episode reports on the risks of misconfigured, a warning on the Log4Shell vulnerability, ransomware reports and more
This episode reports on vulnerabilities found in applications, password variations hackers have figured out, advice for suspected deepfake audio messages, and more
This episode reports on mistakes that led to hacks in Ukraine, a wave of threatening emails, work-from-home websites shut and more
This episode features a discussion about the arrest of a ransomware suspect in Canada, a settlement in a cyber insurance case and whether scanning the internet for vulnerable devices by a government agency is a good idea
This episode reports on email attacks, ransomware, and a vulnerability in Windows credential roaming capability
This episode reports on dangerous malware, crooks imprisoned in the US, and warnings about malicious USB keys and insider thefts
Get an email from the boss asking you to buy gift cards for all the employees? It may be a scam
This episode reports on infosec leaders considering leaving their jobs, hacked company access being sold and a warning about clicking on search engine ads
This episode reports on hackers taking advantage of badly configured Windows servers, IIS logs and a VMware security update
This episode reports on threats to Docker and Kubernetes containers, abuse by cryptominers of GitHub, and questions about the security awareness of employees
This episode reports on a new ransomware data exfiltration, a Microsoft Azure vulnerability, a start by Google to bring order to software bills of material efforts and more
This episode features a discussion on a common mistake in using email, the risks of using real customer data when testing applications and the latest cyber incident statistics for Canada
This episode reports on an arrest in Brazil allegedly related to the Lapsus$ gang. two convictions in the US for SIM card swapping and more
This episode reports on presentations at a Mandiant conference, data breaches in Australia and more
This episode reports on the end-of-life support for two versions of ESXi hypervisors, an encryption issue with Office 365 email, a new threat to NPM libraries and more
This episode includes a discussion on Ontario legislation mandating employers to notify staff of how they are being electronically monitored, and more
This episode reports on Emotet, new phishing scams and a heat scanner that researchers say can deduce your passwords from a keyboard
This episode reports on a data breach at Toyota, DDoS attacks on US airports, surveys by Kaspersky and Cisco Systems, and more
This episode reports on vulnerabilities in Zimbra and Fortinet products, a huge theft of cryptocurrency tokens at an exchange and more
This episode features David Shipley of Beauceron Security questioned on the value of Cyber Security Awareness Month
This episode reports on updating cyber emergency response plans, a teen accused of taking advantage of stolen data in Australia and a large US hospital chain hit by an IT security incident
This episode reports on an American imprisoned for laundering money, TD Bank alerts customers in the U.S. of a data theft by an employee, and an upcoming IT World Canada MapleSec conference
This episode reports on fixes for Exchange Server, the Comm100 support chat application, a survey of Canadian post-secondary students' attitudes towards cybersecurity and more
In this episode Terry Cutler of Cyology Labs discusses the meaning of Cybersecurity Awareness Month
This episode reports on the Royal ransomware gang, attacks on VMware virtual servers and social engineering attacks that are tricking employees
This episode reports on the Royal ransomware gang, attacks on VMware virtual servers and social engineering attacks that are tricking employees
PowerPoint delivers malware, the overwhelming majority of people fear that they personally will be victims of cyber attacks and some great visual tools to understand the impact of ransomware.
PowerPoint delivers malware, the overwhelming majority of people fear that they personally will be victims of cyber attacks and some great visual tools to understand the impact of ransomware.
This episode reports on the arrest of a teen in the UK may be tied to Uber and Rockstart Games hacks, security updates to watch for and controversial proposed US open-source legislation
This episode reports on the arrest of a teen in the UK may be tied to Uber and Rockstart Games hacks, security updates to watch for and controversial proposed US open-source legislation
This episode includes a discussion on insider threat awareness month, the latest Uber hack and the $35 million fine to Morgan Stanley's investment division
This episode includes a discussion on insider threat awareness month, the latest Uber hack and the $35 million fine to Morgan Stanley's investment division
This episode reports the value of multifactor authentication, news about new security patches for Red Hat Linux and Windows, an update on the BlackCat ransomware gang and more
This episode reports the value of multifactor authentication, news about new security patches for Red Hat Linux and Windows, an update on the BlackCat ransomware gang and more
This episode reports on browser malware, a data breach at American Airlines and ransomware
This episode reports on browser malware, a data breach at American Airlines and ransomware
This episode reports on a ransomware attack at a Bell Canada unit, why users should avoid a browser spell check utility and more
This episode reports on a ransomware attack at a Bell Canada unit, why users should avoid a browser spell check utility and more
This episode features a discussion on ransomware, how IT security leaders can deal with having to cut costs and why a UK bank told mobile customers not to install iOS 16 on their Apple devices
This episode features a discussion on ransomware, how IT security leaders can deal with having to cut costs and why a UK bank told mobile customers not to install iOS 16 on their Apple devices
This episode reports on one way crooks are taking advantage of the Queen's death to steal credentials, how Los Angeles' school board is responding to a ransomware attack, and more
This episode reports on one way crooks are taking advantage of the Queen's death to steal credentials, how Los Angeles' school board is responding to a ransomware attack, and more
This episode reports on CISOs cutting back on the number of security vendors they buy from, unsecured medical devices, Windows updates and more
This episode reports on CISOs cutting back on the number of security vendors they buy from, unsecured medical devices, Windows updates and more
This episode reports on another WordPress plugin bug, a new Linux malware discovered, US sanctions against Iran's intelligence ministry for cyber attacks and more
This episode reports on another WordPress plugin bug, a new Linux malware discovered, US sanctions against Iran's intelligence ministry for cyber attacks and more
This episode features a discussion about implementing a zero trust network architecture with Adobe's director of enterprise security
This episode features a discussion about implementing a zero trust network architecture with Adobe's director of enterprise security
Does Facebook even know what data it has about you? Or where it is stored? Cyberwar breaking out from the Russia Ukraine conflict hits many Ukraine supporters - most recently a full assault on Japan's e-government. All this and more on the back to school edition of CyberSecurity Today.
Does Facebook even know what data it has about you? Or where it is stored? Cyberwar breaking out from the Russia Ukraine conflict hits many Ukraine supporters - most recently a full assault on Japan's e-government. All this and more on the back to school edition of CyberSecurity Today.
TikTok has reportedly been breached exposing over 2 billion records. Samsung suffered a hit exposing consumer data in the US. Kaspersky report points out that vulnerabilities in public facing applications are now the leading "first step" in cyber attacks.
TikTok has reportedly been breached exposing over 2 billion records. Samsung suffered a hit exposing consumer data in the US. Kaspersky report points out that vulnerabilities in public facing applications are now the leading "first step" in cyber attacks.
This episode reports on cyber attacks on energy companies, ransomware attacks up on Linux systems, multi-million settlements in class action lawsuits and an update on PYPI attacks
This episode reports on cyber attacks on energy companies, ransomware attacks up on Linux systems, multi-million settlements in class action lawsuits and an update on PYPI attacks
This episode features a discussion about increasing the number of women in cybersecurity, how a university student fell for an email job offer scam and more
This episode reports on an Instagram scam, poorly-created mobile apps and a new way U.S. police are tracking people with the help of apps you download
This episode reports on an Instagram scam, poorly-created mobile apps and a new way U.S. police are tracking people with the help of apps you download
This episode reports on how a victim fell for an IT job scam, the Canadian government is being sued for negligence in a revenue department hack, watch for fake web sites and more
This episode reports on a Door Dash hack, a tentative deal from the Cambridge Analytica scandal, California penalizes a cosmetics retailer and more
This episode features a discussion on the latest trends in cyber insurance and on how much freedom regulated industries should have in creating cybersecurity programs
This episode reports on the latest attack on Active Directory servers, a huge text-based phishing scam and another email-based scam for stealing credentials
This episode reports on the latest attack on Active Directory servers, a huge text-based phishing scam and another email-based scam for stealing credentials
This episode reports on developments in cyber insurance, how threat actors abuse SaaS platforms, a new attack on Gmail and other mail platforms and the dangers of in-app browsers
This episode reports on a survey of CISOs, LockBit ransomware gang data leak site is offline and crooks take advantage of poorly-secured WordPress sites
This episode features a discussion about bugs in software patches that are supposed to fix bugs, fake online job offers and the dangers of collecting to much customer data
This episode reports on a record denial of service attack, the number of ransomware variants discovered this year is up and a warning about vulnerable PLCs
Reports the possible abuse of data collection by medical companies, a U.S. regulator looking at mass data collection by companies and a caution to organizations using using ultra-wideband real-time locating wireless systems
The theme of this week's discussion is why employees do risky things like click on malicious links that defeat multifactor authentication
This episode reports on the workings of the Zeppelin ransomware, a new strain of malware targeting a power distributor in Ukraine, and more
This episode reports on malware in the PyPI repository, six backdoors are used in a gang's cyber attacks, how to discover a deepfake video and more
This episode reports on vulnerabilities in routers and industrial gateways, a Twitter vulnerability that could have exposed anonymous users, a Slack password reset and more
Three formerly popular means of infiltrating and attacking have been reimagined in ways that is bringing them back in new and even more dangerous forms.
This episode reports on the release of the State of Ransomware by Blackfog, a ransomware gang attacks an energy supplier in central Europe and more
This episode reports on a proposed class action against Meta, a cyber attack on a marketing provider used by US healthcare providers and more
This episode features discussion about the continuing increase in cyber attacks, the major ways attackers compromise firms and the cybersecurity talent shortage
This episode reports on hackers dropping macros for RAR, LNK files, Robin Banks service offered for hackers, and warnings on malicious proxyware and browser extensions
This episode reports on hackers dropping macros for RAR, LNK files, Robin Banks service offered for hackers, and warnings on malicious proxyware and browser extensions
This episode reports on studies showing cyber attacks and the cost of data breaches are increasing, a threat actor hunting using Facebook Business to steal corporate data and more
This episode reports on studies showing cyber attacks and the cost of data breaches are increasing, a threat actor hunting using Facebook Business to steal corporate data and more
This episode background's today public hearing on the Rogers outage, reports on a data breach at Entrust and more
This episode reports on companies that allow short passwords, PayPal being used by scammers and a new version of the Qakbot malware is out
This episode reports on the abuse of residential IP proxy services, the discovery of data skimmers on online restaurant platforms, a new Mac backdoor discovered and more
This episode reports on a ransomware group targeting small businesses, vulnerability warnings for Digium Elastix and Netwrix Auditor administrators, advice for GitHub users and more
Cyber crooks use the KISS method - Keep it Simple . . . Quickbooks, credit cards and your supposedly anonymized data - things we think we know and trust create scams that evade technical detection and are so simple in their concept that almost anyone could be fooled
A New Zealand firm releases a free decryptor tool to fight ransomware, you are not as safe buying an app in the Apple store as you might think, and an online payment fraud will exceed 343 billion dollars next year.
This episode reports on mandatory two-factor authentication coming for critical projects in the PyPI registry, fake Google software updates spreading and another hack blamed on the use of 'password' as a password
This episode features a discussion on what qualifications people might need to start a career in cybersecurity
This episode reports on a cyber attack on SHI International, the return of the Karahurt theft and extortion group, new Linux malware and important Apache and OpenSSl updates
This episode reports on phishing tests, a ransomware developer moves on, what you shouldn't do when stuck at an airport, a warning about app toll scams and more
This episode reports on cyber insurance rate trends, a penalty for the Wegmans grocery chain, cyber attacks on a provider of services to US governments and why an insider was fired at HackerOne
This episode features a discussion on a regulator's order to Canadian telecom providers to block botnets, the CISA's recommendation to companies using Microsoft Exchange Online to move to better authentication and more
This episode reports on why Carnival Cruise Line was fined over cyber inadequacies, an FBI warning to HR departments over deepfake video job applications, and more
This episode reports on the updating of two important vulnerabilities list, a warning to Kubernetes administrators, a U.S. regulator punishes the current and former owners of a website for a data breach and SOHO routers being targeted
This episode reports on how a vulnerability in a VoIP system, nearly led to a ransomware attack, why files in open source registries should be handled with care, and a hacker is selling access to compromised Atlassian Confluence servers
This episode features a discussion on Cloudflare's service outage, a U.S. bank's discovery of a second cyber attack and more
This episode reports on successful attacks exploiting the Log4Shell hold in two unpatched VMware applications, and more
This episode reports on recent data breaches at a Michigan bank, the most popular data stolen by ransomware gangs, online fraud numbers in Canada and more
This episode reports on the need to get rid of Cisco Small Business RV routers, QNAP NAS devices under attack again, a Russian-based botnet dismantled and more
This episode features a discussion about the latest proposed Canadian cybersecurity and privacy laws
This episode reports on a way ransomware could hit Microsoft 365 files in SharePoint and OneDrive, and a warning to web developers using the Telerik UI platform
This episode reports on the latest attacks using the BlackCat /AlphV ransomware strain, a huge DDoS attack and security updates issued from Microsoft and others
This episode reports on vulnerabilities in a web-connected physical security system, new Linux ransomware and wireless security advice
This episode features a discussion on the LockBit gang's claim it has stolen data for sale from Mandiant, Mandiant's denial, ransomware and more
This episode reports on the continued rise of the Emotet botnet, more malware going after vulnerabilities in Confluence and a Facebook scam
Today's episode reports on two data breaches, a warning about a serious unpatched Windows flaw and more
Today's episode reports on critical security updates issued by Atlassian and GitHub, a ransomware attack on Foxconn and the takedown of the FluBot Android malware
This week’s guest host, Jim Love, talks to David Shipley about the US government’s statement that it is okay to conduct cyber attacks in response to the invasion of Ukraine, Tim Horton’s brush with Canadian privacy laws, and whether there is a problem with retaining “Zombie” data
An alarming increase in cyber vulnerabilities for small and medium sized businesses, the US government condones cyber attacks at Russia, and Tim Hortons admonished for breach of Canadian privacy laws
This episode reports on a study from Kaspersky that shows some new mobile device threats, how at least one government may have to rethink the security aspects of digital ID and a breach which affects the privacy of hotel customers around the world
This episode reports on vulnerabilities found in pre-installed Android utilities in phones from some Canadian and U.S. wireless carriers, Clop ransomware increases, and a warning to higher-ed institutions
This episode features a discussion about the latest move by the Conti ransomware gang and more
This episode reports on more compromised open-source packages found, and the arrest of an alleged leader of a business email compromise gang
This episode reports on the spread of a Linux trojan, malware targeting at security researchers, phishing attacks on Russian government entities, GM rewards program hacked and more
This episode reports on being prepared for working from hone, hacking contents winners, a Chicago ransomware attack on a third-party data provider amd more
This episode features a discussion a report on security problems IT needs to address, an international survey of CISOs and the EU coming closer to beefing up security standards
This episode reports on the operations of one of the biggest ransomware gangs, security updates for VMware products, a warning about Kubernetes APIs and more
This episode reports on credit card web scraping with PHP, Conti ransomware gang threatens overthrow of Costa Rica, a warning to users of Bluetooth Low Energy smart locks patches from Nvidia
This episode reports on a new version of the Sysrv botnet, a phishing campaign to spread fileless malware amd more
This episode features a discussion on ransomware, a proposed fine for Colonial Pipeline and insider threats
This episode reports on the latest addition to the Budapest Convention on fighting cybercrime, how some websites secretly capture personal data, prison time for a hacker and more
Today's podcast reports on the need to patch F5 BIG-IP devices, a proposed settlement on a Clearview AI lawsuit would limit some sales of its facial recognition software and Colonial Pipeline may be fined for its response after ransomware attack
This episode reports on data breaches, a new trick by a hacker and GitHub's determination to get developers to use two-factor authentication
This episode features a discussion on wiperware, cyber incident reporting obligations, security control over SaaS applications and World Password Day
This episode reports on the use of removable storage devices to infect companies, a three-year-old campaign to steal intellectual property, another database left open on the internet and patches from Cisco and F5 Networks
Today's episode looks at World Password Day, a new threat group after corporate information and warnings not to take short-cuts on email security
This episode reports on ransomware, wiperware, the latest attacks by APT29 and a warning to NAS users
This episode features discussion on ransomware, the Lapsus$ extortion gang, third party cyber attacks and the top 15 vulnerabilities used by hackers
This episode reports on a misconfigured Amazon data bucket, a warning on an old Microsoft Explorer bug being exploited and Facebook's privacy controls questioned
This episode reports on Log4Shell vulnerabilities, the speedy work of hackers, a website that catalogs one hacker's efforts to compromise the NPM library and a risky wireless brake light solution
This episode reports on the workings of the Lapsus$ extortion gang and the latest vulnerabilities that need patching
This episode features a discussion on ransomware, a record number of zero-day vulnerabilities and the creation of a criminal service for companies to buy stolen information from competitors
This episode reports on an FBI backgrounder on the BlackCat ransomware gang, movement from REvil, millions stolen from another DeFi system, and a Facebook scam
This episode reports on zero-day bugs, testing data recovery procedures, the world's biggest penetration test returns and vulnerabilities found in Lenovo laptops
This episode reports on alleged ties between the Conti ransomware and Karakurt extortion gangs, a warning to app developers from GitHub and a new website where companies can buy data stolen from competitors
This episode features a discussion on identity management, the FBI use of a court order to shut a botnet and why hackers were able to roam around a US government agency's IT network
This episode reports on the finding of a new botnet, low MFA adoption in US critical infrastructure sector a Struts bug finally patched and a fix issued for hospital robot carts
This episode reports on the Sandworm group's latest attack on a Ukraine power company, the closing of the RaidForums darkweb marketplace, a new Hafnium attack uses Windows Scheduler to launch attacks and more patches issued
This episode reports on the Mirai botnet abusing the unpatched Spring Java framework, a data breach at toolmaker Snap-on, action against threat actors by Microsoft and Meta and more
This episode features discussion on the Spring4Shell vulnerability, Supply Chain Integrity Month and an explosive North American electricity sector tabletop exercise
This episode reports on a survey of application developers, a phony voicemail scam and more
Today's episode reports on vulnerabilities in Linux and Totolink routers, the discovery of the Borat trojan and more on the Russia-Ukraine cyberwar
Today's podcast reports on U.K. teens charged with cyber offences, how MFA can be over-ridden and security updates to be installed
This episode features discussion on World Backup Day, the threat of cyber attacks by nation-state threat groups and how crooks fool internet providers to get personal information of users
This podcast reports on vulnerabilities in the Spring Java framework, nation-state attackers making Ukraine-themed spear-phishing attacks and how crooks send job scams to university students
This episode offers data backup advice for firms and families, the discovery of a wider malware distribution scheme in the NPM library and a new distribution method for the IceID trojan
This episode reports on putting of Kaspersky on US national security threat list, malware found in NPM open-source library and security updates for Sophos, Chrome and Western Digital products
This edition features a discussion on a ransomware survey of Canadian organizations, a US warning about Russia's cyber intents, the blowback from the Okta hack and more.
This episode reports on ransomware statistics from Palo Alto Networks and the FBI, infected Excel files spreading a trojan, a Chrome bug exploited and more
Today's podcast reports on the disruption of European service of the Viasat satellite provider, patches needed to be installed for HP and Dell devices and more
Today's episode reports on the cause of a huge hack a TransUnion South Africa, the abuse by a developer of an open source library to attack Russia, and two updates that need to be installed
This episode features a discussion on wiperware, mandatory reporting of cyber breaches to government a consumer privacy survey and mobile device threats
This episode reports on hackers exploiting misconfigured MFA, Asus routers targeted by a botnet, a tool for detecting infected MikroTik routers and more
This episode reports on the increase in mobile attacks, QNAP NAS devices at risk, fraud prevention advice, updates needed for OpenSSL projects and more
Today's episode reports on an alleged Ukraine theft of intellectual property from Russia, the discovery of vulnerable software package managers, another Spectre bug, more data breaches and an improved bad Android app
This episode features a discussion about vulnerabilities found last year in the WordPress ecosystem, a vulnerability found in unpatched collaboration systems made by Mitel and a call for companies to publicly commit to cybersecurity best practices
This episode reports on threats from internet-connected APC power supplies, a warning to ServiceNow administrators, fake Ukraine support websites and hijacked message threads
Today's episode reports on security updates need for LinuxOS and HP devices, Samsung confirms data theft, Microsoft fixes an Azure vulnerability and more
This episode reports on attackers using stolen Nvidia code certificates, a company admits real customer data was exposed, the unexplained closing of a criminal forum and a warning to Linux administrators
This episode features a discussion about Russia, Ukraine and cyberwar, as well as a look into the double cyber attack on a Canadian healthcare provider
This podcast reports on medical infusion pumps found with security vulnerabilities, help for Ukrainian organizations hit by ransomware, a warning for GitLab users and more poor passwords
Today's podcast reports on Toyota and global insurance broker Aon dealing with cyber attacks, updates on attacks on Axis and Nvidia attacks, and more
Today's episode reports on improving cyber defences, attacks on Nvidea and Axis Communications, TrickBot finally goes down and a warning to Instagram users
This episode features a discussion about ransomware trends with Brett Callow, Canadian-based threat analyst at Emsisoft
A new ransomware strain found, watch for double backdoors, a new sextortion tactic and an alert to Samsung Galaxy smartphone owners
This episode reports on a threat to SQL Server, a US logistics company hit by cyber attack, a report on smartphone attacks and more
Today's episode reports on data on Internet Society members not protected, an alert to Linux administrators, how Microsoft Teams users get tricked and more
This episode features a discussion on how fast hackers spread their attacks, companies letting former employees still access computers and more
This episode reports on crooks using virtual meetings to trick employees, security updates from Intel and Cisco Systems and a new botnet targets Windows devices
Today's episode looks at the applications with the most vulnerabilities, security updates for VMware, Chrome, and another record year of ransomware payments
This episode reports on critical vulnerabilities in Adobe Commerce and Magento, Microsoft ups Windows security and bugs found in Moxa MXview
This episode reports on another database found open on Amazon S3, why former employees can be a security risk, Apple security updates and more
This episode features commentary on ransomware, VBA macros and more from guest David Shipley of Beauceron Security
Today's podcast reports on data stolen from Puma, a QuickBooks scam to watch out for, an API warning to developers and more
Today's podcast reports on the background of the ALPHV ransomware gang, email used in cyberattacks on Ukraine, what may have been behind the theft of cryptocurrency at the Wormhole platform and more
This episode features discussion about the closing of a Canadian dark web criminal marketplace, a Windows vulnerability and attacks on QNAP network-attached storage devices
This episode reports on vulnerabilities in applications from ESET and Sealevel Systems, an apparent huge theft of cryptocurrency and more
This episode reports on critical firmware bugs found in products from major IT manufacturers, another WordPress plugin vulnerability found, and this is Identity Theft Awareness Week
Today's episode report urges the latest Windows Updates to be installed, a warning to data centre admins and a digital loan platform hacked
This Data Privacy Day episode features a discussion with world-famous privacy by design expert Ann Cavoukian
This episode reports on how multifactor authentication can blunt a phishing scam, a Zoom phishing con discovered and more
Today's episode offers advice for Data Privacy Week, reports on takeovers of corporate Instagram accounts, and another QR code scam warning
This episode reports on compromised plugins from AccessPress, the curious departure of Twitter CISO, one school district's soaring cyber insurance premium and more on MFA
This episode features a discussion with former U.S. cyber diplomat Christopher Painter on Ukraine, nation-state cyberattacks and the impending start of negotiations for an international cybercrime treaty
This episode reports on a data theft from the International Red Cross, a US Labor Department scam and the discovery of a new firmware bootkit
This episode reports on MFA bugs in cloud file sharing service, police action to close a VPN service used by crooks and the latest ransomware news
This episode reports on the discovery of a new backdoor, attacks continue against QNAP devices and a scam on a digital city
This episode includes a discussion about open source software, multifactor authentication, infected USB keys and fake QR codes
This podcast reports on alleged cybercrooks arrested in Ukraine, a warning law and accounting firms are being targeted by a threat group, and a new phone scam
Today's episode reports on updates needed for a number of routers, as well as some SonicWall devices
This episode reports on a warning about receiving infected USB keys, Salesforce makes MFA mandatory, and insider data theft and more
This episode features a discussion on SMBs being hit by threat actors, and how to fight credential stuffing attacks
This episode reports on a ransomware attack, a data theft, the alleged theft of pre-publication manuscripts and why Norton 360 includes and optional cryptomining app
Today's episode reports on data breaches at a Florida hospital system, Montreal's tourism agency, the DatPiff music site, and on a phony Telegram app
This edition offers resolutions individuals and IT leaders should make to improve their cybersecurity for the coming year
This episode outlines a privacy commissioner's investigation of a data breach at the Bank of Montreal
This extra-long podcast features a discussion with Dinah Davis, Terry Cutler and I on the significant events this year, including #ransomware attacks, supply chain attacks, and predictions for 2022
This episode reports on two alerts for Windows administrators, why a ManageEngine update has to be installed fast, and more
Today's podcast reports on the latest log4j update issued, a U.S. commission's IT network allegedly compromised, the theft of 1.8 million payment card numbers and a warning to Western Digital MyCloud users
This episode features a discussion about the Log4J vulnerability and lessons learned from the #ransomware attack on Ireland's healthcare system
This edition reports on latest trends in ransomware, and a new attack on Bluetooth systems
Today's podcast offers advice for defending against Log4Shell attacks and how a ransomware attack on hospitals in Ireland started
Today's podcast reports on the scramble to plug the Log4Shell bug, new threat and ransomware groups discovered and a warning to WordPress admins about plugins
This episode features a discussion on the release of a Ransomware Playbook for IT managers by the Canadian Centre for Cyber Security, and buying tips for internet-connected devices for kids
Today's podcast reports on e-commerce websites being infected through Google Tag Manager, poor OAuth implementations leading to hacks, and security updates for Sonicwall SMA 100-series devices
Today's episode reports on the disruption of two botnets, more activity by Nobelium and Emotet seen deploying Cobalt Strike directly
Today's episode reports on an email scam tricking verified Twitter users, a ransomware warning from the FBI, and Apple warns nine US State Department officials their devices have been hacked
This episode features a discussion about early lessons learned from cyberattacks at Ikea, Planned Parenthood Los Angeles and a medical lab
This morning's podcast reports on an uptick in ransomware during the holidays, enterprise applications that need patching and more
Today's episode reports on the seizure of an alleged ransomware gang member's funds, a cloud computing security report from Google and more malware found in the Android store
Today's episode reports on an email attack at Ikea, an evasive JavaScript loader discovered and malware found hiding in a calendar's impossible date
This episode features a discussion on the GoDaddy hack, a test of how fast hackers can find misconfigured servers on the internet and advice for safe holiday online shopping
This episode reports on what e-tailers should be doing to make their sites safer, recent legal successes against cybercrooks and an Android update to watch for
Today's episode reports on the discovery of new Windows zero-day bug, new cybersecurity resources for Canadian teachers and a holiday warning from the FBI
Today's episode reports on someone clumsily leaving a database of users of a sex video site open, free incident and vulnerability response advice for IT defenders and a report gives detailed look into the Conti ransomware gang
This episode features a discussion about the FBI hack, vulnerable DRAM and ransomware gangs increasingly bidding on zero-day vulnerabilities
This episode reports on vulnerabilities found in FatPipe appliances, and the BIOS of some Intel processors, a proposed data breach settlement in a Canadian class-action lawsuit the discovery of new malware hitting e-commerce sites
Today's episode reports on ransomware gangs being rich enough to buy zero-day vulnerabilities, a warning about vulnerable memory chips and the apparent return of Emotet
This episode reports on an attack on a Canadian health clinic, FBI email weakness exploited, a record DDoS attack and how fonts can be dangerous
This episode features a discussion on Newfoundland's admission that years of patient and employee of data was stolen in a cyberattack, what the Robinhood trading platform says about employee training and more.
This episode reports on ransomware training from a Canadian university for IT and business leaders, the hack of the Aruba Central service, the discovery of a new botnet and security updates released
Today's podcast reports on a data theft at the Robinhood trading platform, and cyber attacks on unpatched instances of software from ManageEngine and SolarWinds
Today's podcast reports on a ransomware attack delivered in 15 minutes, more information on creating an incident response plan why you need to get rid of old Windows
This episode looks at the cyberattack on Newfoundland's healthcare system, the apparent disappearance of the BlackMatter ransomware gang and how to fight password sparying
This episode reports on an increase in the number of distributed denial of service attacks, recent phone scams and a look nine years into the possible future of cybercrime
Today's podcast reports on how a phony ransomware gang fooled experts, an FBI ransomware warning and GitLab users urged to install an update
Today's podcast reports on ransomware arrests, an early Black Friday warning and trouble with a European COVID vaccination verification app
This episode features a discussion about the Nobelium supply chain attacks, facial recognition applications, cybersecurity jobs and cybersecurity awareness training
This episode reports on researchers finding an unsecured database with medical records on the internet and a flawed vaccination confirmation app
Today's podcast looks at an unexpected tactic from a ransomware gang, a hacking gang's job scam, why phone numbers are bad WiFi passwords, and more
Today's podcast reports on a problem with an NPM JavaScript library, rants from ransomware groups and an SQL vulnerability exploited in a billing suite
This episode features a discussion on how small businesses can improve their cybersecurity maturity
This episode reports on the discovery of Evil Corp.'s new ransomware strain, a scam that hijacks YouTube accounts and why developers have to scan open-source code libraries
Today's podcast reports on the need to update PowerShell, reports on the BlackMatter and BlackByte ransomware strains and a detailed analysis of the Trickbot trojan
Today's podcast reports on the value of ransomware payments in the US, a warning to cybersecurity researchers and the discovery of a phony ad blocker
This episode features a discussion about Australia's proposed tough laws to fight ransomware
This episode reports on seven Windows bugs that date back years, how one letter in a URL can fool victims and more
Today's episode reports on new ransomware attacks, a Verizon logo scam, security updates available and more
Today's episode reports on charges in a U.S. business email scam, French police arrest COVID hacker, Microsoft addresses Excel macro problem and an app developer's security mistake
This episode features a discussion on cyber security awareness training, the Facebook outage and romance scams
This episode reports on the discoveries of new Linux malware and a new hacking group, details on the FIN12 #ransomware gang and describes a thick advisory report from Microsoft
Today's podcast reports on new misconfiguration problems, hackers abusing LinkedIn link shortening, ransomware operators arrested and more
Today's podcast reports on an upcoming meeting of nations to go after cybercrooks, a warning on wrongly using multifactor authentication, another ransomware victim and more
This episode features a discussion about Cyber Security Awareness Month and what IT departments can do to improve their cybersecurity maturity
This episode reports on a flaw in Microsoft's Azure Active Directory, free advice on configuring VPNs, an Eduroam WiFi issue, a fake Amnesty International anti-virus tool and more
Today's episode reports on a new ransomware gang, another open database found, a report on poor cloud software application coding, a new threat to Active Directory and more
This episode reports on the discovery of the Vice Society #ransomware gang, the return of the AlphaBay criminal marketplace and updates from Chrome and Apple that need to be installed
This episode includes a discussion about DDoS attacks, the FBI reportedly withholding an REvil #ransowmware decryptor and users misconfiguring EventBuilder
This episode reports on the discovery of the FamousSparrow threat group, another COVID text scam hitting Canadian and American Android devices, and ransomware advice
Today's podcast reports on the theft of data from US web hosting provider Epik, misconfigurations by users of the EventBuilder tool and the discovery of a phishing campaign against the aviation sector
Today's episode reports on hackers looking to exploit the OMIGOD vulnerability, a list of ransomware exploits being used by attackers and AT&T scammer sent to prison
This edition features discussion about why brute force and vulnerability exploits are still being successfully used by threat actors, how many employees see cyber security as a hindrance and the return of Revil.
This episode reports on Microsoft extending passwordless access for home users, a report on open source code vulnerabilities and how a company was hit by a years-long attack
Today's podcast reports on the discovery of an unprotected database of fitness app information, an attack at Olympus and important security patches released
Today's podcast reports on the return of the REvil ransomware gang, the discovery of a new botnet launching huge DDoS attacks, the an increase in Formbook malware
This episode features a discussion on the latest rasomware-related events, including advice on how to better reduce the odds of being successfully attacked
This episode reports on two warnings to Windows administrators, malware and why CISOs should tighten cloud security
Today's podcast reports on the kind of companies ransomware gangs are targeting, another reminder to patch Confluence servers and patches available for Netgear hardware and NPM software
The FBI warns it received more complaints about sex-related blackmail in the first six months of this year than it did in the same period in 2020. We have advice for avoiding being a victim
This episode features a discussion about the risks of relying on one-backup source strategy and on insider threats
This episode reports on Accenture's continued denial that a recent cyber attack relates to incidents at customers, a list of the latest U.S. healthcare institutions hacked and vulnerabilities found in Bluetooth stack
Today's podcast reports on Women in Cyber Day, a weekend cyber attack warning, a list of the worst IT practices and why you should beware of proxyware
Today's podcast reports on how a new ransomware strain tries to evade detection, a ransomware gang closes, a warning for Azure Cosmos administrators and more
This episode features a discussion on configuration issues with Microsoft Power Apps, the latest business email compromise and possible ways to stop ransomware
This morning's podcast looks at the latest COVID-19 phishing scam and a report on the importance of patching SSL VPNs
This podcast reports on 38 million records with personal information left exposed by misconfigured Microsoft Power Apps, vulnerabilities found in a medical pump, and a warning on device installation apps
This episode reports on Exchange Servers under attack, ransomware-fighting advice and vulnerabilities in industrial control systems continue to climb
This episode features a discussion about vulnerabilities found on BlackBerry's QNX platform and in software development kits, as well as observations about T-Mobile's most recent hack
This episode reveals how a crook is trying to lure employees to plant ransomware on their organization's IT systems, a warning from Cisco Systems for some products and details how a U.S. government department was hacked
Today's podcast reports on the discovery of an unprotected U.S. terrorist watchlist, a hack at T-Mobile, troublesome software development kits and more
Today's episode covers the Windows Server PrintNightmare bugs, the apparent return of the AlphaBay criminal marketplace, a DDoS threat to network inspection devices and why you should check your home router
This episode looks at vulnerabilities in the Microsoft core architecture and how they are being exploited.
Crooks are still taking over computers, servers and smartphones for cryptomining. We offer tips for not being an unwitting accomplice