Security This Week: Recent Episodes

Carl Franklin

Enterprise security topics are discussed through the lens of current events, which catapult us into a discussion about hacking methods, security measures, and outcomes. Your hosts are Carl Franklin, Patrick Hynds, and Duane LaFlotte

View Details

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

View Details

OpenAI finds AI agent leaving escape notes for its future versions

View Details

OpenAI Models Autonomously Hack Hugging Face

View Details

New Windows LegacyHive zero-day gives hackers admin privileges

View Details

AI-Powered Attack Compromises AWS Cloud in 72 Hours

View Details

Trump administration lifts restrictions on Anthropic's Claude models after cybersecurity alarm

View Details

Hackers leak facial recognition records tied to millions of Madison Square Garden visitors

View Details

FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

View Details

Anthropic rolls out Claude Fable 5, but it's available for a limited time

View Details

Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

View Details

FBI warns of in-person data theft attacks from extortion gang

View Details

First public macOS kernel memory corruption exploit on Apple M5

View Details

New Linux 'Dirty Frag' zero-day gives root on all major distros

View Details

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

View Details

Anthropic investigates unauthorized Mythos access by Discord group

View Details

AI chatbots used tactical nuclear weapons in 95% of AI war games, launched strategic strikes three times!

View Details

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks

View Details

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

View Details

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

View Details

FCC bans foreign routers, putting enterprise network risk in focus

View Details

Researchers uncover iPhone spyware capable of penetrating millions of devices.

View Details

Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges

View Details

Anthropic ditches its core safety promise in the middle of an AI red line fight with the Pentagon

View Details

Exploitable Flaws Found in Cloud-Based Password Managers

View Details

iPhone Lockdown Mode is so good even the FBI can’t crack it

View Details

Hacking Moltbook: The AI Social Network Any Human Can Control

View Details

How to get Doom running on a pair of earbuds

View Details

New Study Shows GPT-5.2 Can Reliably Develop Zero-Day Exploits at Scale

View Details

New China Linked VoidLink Linux Malware Targets Major Cloud Providers

View Details

ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants

View Details

MongoDB warns admins to patch severe vulnerability immediately

View Details

PornHub extorted after hackers steal Premium member activity data

View Details

Attackers hit React defect as researchers quibble over proof

View Details

An ingenious Apple Service hoax is convincing users their account is under attack

View Details

Anthropic claims of Claude AI-automated cyberattacks met with doubt

View Details

Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

View Details

No one pays ransomware demands anymore - so attackers have a new goal. Also: Ransomware Surge in Europe: Cybercriminals Exploit GDPR Penalties, Target Key Sectors

View Details

AWS crash causes $2,000 Smart Beds to overheat and get stuck upright

View Details

Skynet-1A: Military Spacecraft Launched 56 Years Ago Has Been Moved By Persons Unknown

View Details

Carl, Duane, and Patrick recorded this week's episode in front of a live audience at CyberSecurity Intersection, a cyber conference held at Universal Studio in Orlando, FL the week of October 5.

View Details

Japan's beer giant Asahi Group cannot resume production after cyberattack

View Details

U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area

View Details

New attack on ChatGPT research agent pilfers secrets from Gmail inboxes

View Details

Hackers left empty-handed after massive NPM supply-chain attack

View Details

Salt Typhoon pwned 'nearly every American'

View Details

Someone Created the First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model

View Details

Security researcher driven by free nuggets unearths McDonald's security flaw — changing 'login' to 'register' in URL prompted site to issue plain text password for a new account

View Details

BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data

View Details

Federal court filing system hit in sweeping hack

View Details

Minnesota National Guard activated, state of emergency declared after cyberattack against St. Paul

View Details

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

View Details

Russian alcohol retailer WineLab closes stores after ransomware attack

View Details

Call of Duty: WW2 pulled from PC following reports of remote code exploit trolling players with 'Notepad pop-ups, PC shutdowns' and desktop wallpaper of a lawyer

View Details

Quantum tech is coming — and with it a risk of cyber doomsday

View Details

Russian hackers bypass Gmail MFA using stolen app passwords.

View Details

https://www.malwarebytes.com/blog/news/2025/06/google-bug-allowed-phone-number-of-almost-any-user-to-be-discovered

View Details

BADBOX 2.0 Android malware infects millions of consumer devices

View Details

Meta found 'covertly tracking' Android users through Instagram and Facebook

View Details

Signal says no to Windows 11’s Recall screenshots

View Details

Chinese ‘kill switches’ found hidden in US solar farms

View Details

You can now submit your claims for Apple’s $95 million Siri spying settlement

View Details

Apple 'AirBorne' flaws can lead to zero-click AirPlay RCE attacks

View Details

Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices

View Details

Funding Expires for Key Cyber Vulnerability Database

View Details

Incomplete Patch in NVIDIA Toolkit Leaves CVE-2024-0132 Open to Container Escapes

View Details

Protect Yourself from Identity Theft and Fraud

View Details

National Security Officials Were Warned in February That Signal Was Vulnerable to Attack

View Details

Millions Of RSA Keys Expose Serious Flaws That Can Be Exploited

View Details

Undocumented commands found in Bluetooth chip used by a billion devices

View Details

Malicious Chrome extensions can spoof password managers in new attack

View Details

Microsoft deploys new state of matter in its first quantum computing chip

View Details

DOGE’s .gov site lampooned as coders quickly realize it can be edited by anyone

View Details

UK orders Apple to open up users' encrypted cloud data, report says

View Details

DeepSeek exposed internal database containing chat histories and sensitive data

View Details

Millions of Accounts Vulnerable due to Google’s OAuth Flaw

View Details

Hackers have devised a simple text scam to bypass Apple’s iPhone protections

View Details

Volkswagen leak exposed location data for 800,000 electric cars

View Details

Urgent New Gmail Security Warning For Billions As Attacks Continue

View Details

The numbers are almost incomprehensible!

View Details

Gamaredon Deploys Android Spyware "BoneSpy" and "PlainGnome" in Former Soviet States

View Details

FBI Warns iPhone And Android Users—Stop Sending Texts

View Details

Fortinet VPN design flaw hides successful brute-force attacks

View Details

Ruthless sextortion scammers now threatening to show up at your house

View Details

Schneider Electric ransomware crew demands $125k paid in baguettes

View Details

Hacked U.S. robot vacuums are yelling racial slurs and chasing pets!

View Details

https://thehackernews.com/2024/10/microsoft-reveals-macos-vulnerability.html

View Details

Hacking with a BBQ Lighter: The Unlikely Method to Gain Laptop Access

View Details

Lamborghini Carjackers Lured by $243M Cyberheist

View Details

Large language models hallucinating non-existent developer packages could fuel supply chain attacks

View Details

Severe Unauthenticated RCE Flaw (CVSS 9.9) in GNU/Linux Systems Awaiting Full Disclosure

View Details

New Details of Hezbollah Exploding Pagers' Supply Chain Emerge

View Details

New PIXHELL acoustic attack leaks secrets from LCD screen noise

View Details

Researchers find SQL injection to bypass airport TSA security checks

View Details

Windows Downdate tool lets you 'unpatch' Windows systems

View Details

Major Backdoor in Millions of RFID Cards Allows Instant Cloning

View Details

Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now

View Details

Ronin Network hacked, $12 million returned by "white hat" hackers

View Details

Deleted GitHub data is forever accessible to anyone, researchers claim

View Details

We have a lot to say about last week's CrowdStrike incident

View Details

US Disrupts AI-Powered Russian Bot Farm on X

View Details

Dev rejects CVE severity, makes his GitHub repo read-only

View Details

Mitigating Skeleton Key is a new type of generative AI jailbreak technique

View Details

Microsoft Delays AI-Powered Recall Feature for Copilot+ PCs Amid Security Concerns

View Details

Microsoft Ignored Whistleblower Warnings Before SolarWinds Attack

View Details

Hacker Tool Extracts All the Data Collected by Windows’ New Recall AI

View Details

Zoom adds 'post-quantum' encryption for video nattering

View Details

Hear about what Carl learned about AI Security while at Microsoft Build in Seattle last week.

View Details

New WiFi Flaw Leaves All Devices Vulnerable to ‘SSID Confusion’ Attacks

View Details

The US Government Is Asking Big Tech to Promise Better Cybersecurity

View Details

An SEC security breach filing has us wondering!

View Details

GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories

View Details

Hackers targeted LastPass employee in failed deep fake CEO call.

View Details

Microsoft employees exposed internal passwords in security lapse

View Details

Red Hat warns of backdoor in XZ tools used by most Linux distros

View Details

New Darcula phishing service targets iPhone users via iMessage

View Details

New acoustic attack determines keystrokes from typing patterns

View Details

House passes bill that would ban TikTok if its Chinese owners don't sell the popular app.

View Details

Over 100,000 Infected Repos Found on GitHub!

View Details

White House urges devs to switch to memory-safe programming languages

View Details

Air Canada must honor refund policy invented by airline’s chatbot

View Details

Canada to ban the Flipper Zero to stop surge in car thefts

View Details

At least the API was thorough!

View Details

Mother of all breaches reveals 26 billion records!

View Details

How a 27-year-old busted the myth of Bitcoin’s anonymity

View Details

Microsoft fixes critical flaws in Windows Kerberos, Hyper-V

View Details

PornHub blocks North Carolina, Montana over new age verification laws

View Details

Blockchain dev's wallet emptied in "job interview" using npm package

View Details

Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads

View Details

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

View Details

LogoFAIL exploit bypasses hardware and software security measures and is nearly impossible to detect or remove

View Details

Last week there was a scare about the NameDrop feature in iOS 17. What's the real story?

View Details

The guys check out a list of the top 200 most common passwords used all over the world.

View Details

Fraudsters make $50,000 a day by spoofing crypto researchers

View Details

OpenAI confirms DDoS attacks behind ongoing ChatGPT outages

View Details

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover

View Details

Windows Phone gets revenge on YouTube from the grave by helping users bypass its ad-blocker-blocker

View Details

'Looney Tunables' Bug Opens Millions of Linux Systems to Root Takeover

View Details

Red Cross issues rules of engagement to war-focused hacker groups, who say 'yeah, right!'

View Details

This just in: NFTs are...

View Details

AI’s Pivotal Role in Addressing APAC’s Cybersecurity Talent Shortage

View Details

The UK Is Poised to Force a Bad Law on the Internet

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Take a nod from Microsoft, whose misconfigured DNS caused Hotmail to crash.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Zoom basically admits that they can do whatever they want with your video, audio, chat, and other information.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Redmond is accused of “negligent cybersecurity practices” that enabled a successful Chinese hack of the United States government.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

It sucks to be a smart Russian right now.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

‘Millions’ of sensitive US military emails were reportedly sent to Mali due to a typo.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Carl and Duane discover that they did NOT get a notification about the two critical security patches for iOS devices released last week!

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Critical TootRoot bug lets attackers hijack Mastodon servers

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Update now! Apple fixes three actively exploited vulnerabilities

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Google Tells Employees to Stay Away from Its Own Bard Chatbot

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Carl, Patrick, and Duane welcome Jeremy Likness (Microsoft) to talk about the short list of security measures every software developer needs to know.

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

KeePass v2.54 fixes bug that leaked cleartext master password

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Amazon to pay over $30 million in FTC settlements over Ring, Alexa privacy violations

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Malware turns home routers into proxies for Chinese state-sponsored hackers. Should you be concerned?

This show is part of the Spreaker Prime Network, if you are interested in advertising on this podcast, contact us at https://www.spreaker.com/show/5634794/advertisement

View Details

Scientists Use GPT AI to Passively Read People's Thoughts in Breakthrough

View Details

Ariz. Mom Says Daughter's Voice Was Cloned with AI in $1 Million Kidnapping Hoax!

View Details

The FBI says you should never use the charging port at an airport!

View Details

Florida Man drops to #2 on the dope list!

View Details

Disconnect it now!!

View Details

Just when Elan Musk thought he was in control...

View Details

Hackers drain bitcoin ATMs of $1.5 million by exploiting zero-day bug.

View Details

The US wants to ban TikTok. How likely is this to happen, and what are the consequences?

View Details

Hackers might be able to crack this top password manager and steal your logins!

View Details

Carl is horrified at how hackable your smart TV actually is!

View Details

Twitter is removing an essential security feature, putting millions of accounts at risk.

View Details

Now you HAVE to listen, don't you?

View Details

So, you better pay attention to it!

View Details

Russia targets Windows domains in Ukraine, ratcheting up tensions that are spilling over into the physical war.

View Details

Learn how China may be spying on you via 'smart' devices.

View Details

More news about password managers, MSI secure boot woes, Cacti, Cisco, and the differences between Picard and Kirk.

View Details

Following up on last week's show, we look at alternatives to LastPass

View Details

Since Christmas, some new information has come out about the latest LastPass leak.

View Details

A mom got booted from the Radio City Music Hall due to facial recognition. Oh yeah, LastPass hackers actually stole keys

View Details

No joke!

View Details

Yes, it's fascinating, but it's also dangerous!

View Details

LastPass got breached. What you need to know.

View Details

US Federal Network Hacked. Doh!

View Details

Mastodon Users are Vulnerable to Password-Stealing Attacks!

View Details

Experts Find URLScan Security Scanner Inadvertently Leaks Sensitive URLs and Data! Oh No!

View Details

The Geek Squad is a great service. The brand is being exploited, and non-techy people are vulnerable!

View Details

A vulnerability was discovered in popular hacking software that exposes the hackers!

View Details

Got an old Samsung phone sitting around? You might want to listen to this.

View Details

Criminals are hiding messages in pictures and videos!

View Details

17-year-old Uber Hacker Brags Online and gets Nabbed PDQ.

View Details

Kiwi Farms has been breached; assume passwords and emails have been leaked

View Details

Uber computer systems breached by ‘teen’ in major security alert.

View Details

Former Conti ransomware members are allegedly regrouping to attack Ukraine

View Details

A hacker has been using an image taken by the James Webb Space Telescope to load malware onto Windows computers.

View Details

TikTok can monitor users’ keystrokes, and could collect passwords, and credit card info, researcher claims.

View Details

If you get a constant barrage of SMS messages asking you to confirm a login, you may have already been hacked.

View Details

New vulnerabilities are making experts wonder how many are yet to be discovered.

View Details

Microsoft did a 180 and blocked Office macros, but is it enough?

View Details

Security This Week published its first show one year ago to the day.

View Details

Microsoft rolls back the decision to block Office macros by default! WTF!

View Details

Apple announced that a new security feature known as Lockdown Mode will roll out with iOS 16, iPadOS 16, and macOS Ventura to protect high-risk individuals against targeted spyware attacks.

View Details

Users of the Strava running app can use fake routes to track other users wherever they are!

View Details

The FBI disrupted a Russian botnet after it hacked millions of devices, and that's not even the scariest story of the week!

View Details

Local high-tech crime units are tracking and seizing stolen cryptocurrency

View Details

The big story this week involves a massive zero-day vulnerability in Microsoft Office.

View Details

Duane and Patrick school Carl on what hacker hat colors mean

View Details

Chinese Space Pirates are hacking Russian aerospace firms. Film at 11.

View Details

Sometimes your neighbors infringe on your rights. The same thing happens in multi-tenant systems. All will be explained.

View Details

If you want to see the next generation of hackers, consider monitoring the gaming cheats industry

View Details

You can play a game that, when you play it, will help take down Russian websites.

View Details

Schrödinger's cat is dead! Or is it?

View Details

Microsoft patched 120+ Windows flaws last week!

View Details

Last week, Google sent a security patch to 3.2 billion users of Chrome

View Details

A new vulnerability in the Spring framework, a tool for programmers, may become the new Log4J

View Details

Is a longer password with numbers, lower and uppercase letters, and symbols harder to hack?

View Details

Facebook blocked Russia right after Russia blocked Facebook

View Details

As the kinetic war (and cyberwar) between Ukraine and Russia marches on, a new Linux exploit wreaks havoc on all Linux (and therefore Android) systems. Patch it!

View Details

As Russia wages war on Ukraine, we see stories emerging of hacking groups on both sides joining the cyberwar.

View Details

Russia, Ukraine, Ransomware, and you.

View Details

Many scammers can be foiled by asking a simple question.

View Details

This week, Microsoft got around to disabling Internet macros in Office apps by default. Brilliant!

View Details

Why North Korea's Internet was wearing the hacker's pajamas we'll never know!

View Details

Prepare for the prospect that someday your phone may be lost or stolen.

View Details

Looks like Russia is hacking Ukraine. Who knew?

View Details

Last week cyberspies infected themselves with their own malware

View Details

You will be a breach victim sooner or later. If you don't take measures to mitigate risk, and you get breached, you could be sued.

View Details

Enable 2 Factor Authentication on your LastPass account!

View Details

More Log4j developments, more career advice for criminals, and more reasons to not click on email links.

View Details

We think we'll be talking about Log4j for a long time.

View Details

No, really. You NEED to listen to this episode before you do anything else.

View Details

Disturbing statistics show the US lost billions to cybercrime in 2021

View Details

The Dirty Dangers of DNS!

View Details

What happens when the digital world collides with the physical world?

View Details

Nation-states are ramping up the cyberwar

View Details

The three amigos can't seem to stop going on tangents when discussing ransomware and other hacks.

View Details

Nefarious individuals can steal your credit card right underneath your nose!

View Details

This week there have been some tricks, but you'll get a treat at the end!

View Details

Ransomware is the overwhelming theme for this show. As for the sharp edges, you'll have to listen to get that reference.

View Details

One good thing about last week's Facebook outage is that our kids now know what DNS is.

View Details

If you have an Android phone and get apps from the Google Play store, you might have been robbed.

View Details

Sometimes well-meaning companies implement a technical solution to a problem to be helpful, and it doesn't go well.

View Details

Microsoft and Apple go on a Patch Rampage!

View Details

Several attacks against Microsoft properties this week. They can't catch a break!

View Details

A US government mandate requires authentication systems to start adopting zero-trust policies. Are you ready?

View Details

Disgruntled employee participates in a ransomware attack against their own company! Also, what's a public/private key pair?

View Details

Patrick talks about the Pyramid of Threats, a mental model to categorize threats according to their popularity (biggest at the base). The higher you go up the pyramid, the harder it is to defend yourself against the threats.

View Details

Carl and Patrick (no Duane this week) talk about the Colonial Pipeline ransomware hack, and Pat's thoughts on how to shut down ransomware.

View Details

Phishing is when a bad actor sends you an email that looks like it came from Microsoft, Amazon, Google, or some other legit company that you probably use. They give you a link to click on for some reason, and with a single click, your entire hard drive is encrypted and your computer can't be used until you pay a ransom. This week we talk about how to spot phishing emails and how big companies are getting involved to fight ransomware. Don't miss it!

View Details

Our pilot episode, in which we lay the groundwork for what to expect from this podcast. 

View Details

Our pilot episode, in which we lay the groundwork for what to expect from this podcast.