Talkin' Bout [Infosec] News

Talkin' Bout [Infosec] News

Black Hills Information Security
Maa Yhdysvallat
Kieli EN-US
Jaksot 340
Viimeisin 16.09.2026

A weekly podcast from Black Hills Information Security where the hosts and guests discuss notable information security and infosec-adjacent news stories gathered by their community news team. The show airs live on YouTube on Mondays at 4:30 PM ET.

Jaksot

  • World Leaders Reject Calls to Slow Down AI Development - 2026-09-14 16.09.2026 1t 13min
    This week, the team examines AI agents targeting RubyGems, Anthropic’s warnings about dangerous AI misuse, human review of ChatGPT conversations, predictive policing, and LG smart-TV privacy. They also cover passkey-themed phishing, ScreenConnect abuse, Microsoft Defender patch bypasses, and upcoming cybersecurity workshops, webcasts, and Wild West Hackin’ Fest training.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — A Protected Class (05:20) - World Leaders Reject Calls to Slow Down AI Development - 2026-09-14 (07:58) - OpenAI Agent Swarm Targets RubyGems (16:12) - Anthropic Warns About Claude Misuse and Calls for Slower AI Development (31:38) - OpenAI’s Project Lily and Human Review of ChatGPT Conversations (38:54) - “Minority Report” Predictive Policing Using Financial Data (42:11) - LG Smart TVs Accused of Spying on Viewers (46:49) - Passkey-Themed Phishing Campaigns (47:20) - ConnectWise Patches ScreenConnect After Worm-Like Abuse (47:47) - Microsoft Defender “Shield Break” Patch Bypassed (54:19) - News Wrap-Up and Community Discussion (01:00:04) - Kip Boyle’s Book, Fire Doesn’t Innovate (01:00:27) - “Hunting Shadow AI” Workshop — September 25 (01:01:05) - “Playbooks for Owning AI Risk” Live Training (01:03:01) - Wild West Hackin’ Fest and Karaoke (01:03:51) - Webcast: Attacking MCP and N8N Servers (01:04:10) - Webcast: Safely Using Offensive AI in Security Assessments (01:05:17) - Wild West Hackin’ Fest Satellite and SOC Classes LinksOpenAI Agent Swarm Targets RubyGemsAnthropic Warns About Claude Misuse and Calls for Slower AI DevelopmentOpenAI’s Project Lily and Human Review of ChatGPT Conversations“Minority Report” Predictive Policing Using Financial DataLG Smart TVs Accused of Spying on ViewersPasskey-Themed Phishing CampaignsConnectWise Patches ScreenConnect After Worm-Like AbuseMicrosoft Defender “Shield Break” Patch BypassedKip Boyle’s Book, Fire Doesn’t Innovate“Hunting Shadow AI” Workshop — September 25“Playbooks for Owning AI Risk” Live TrainingWild West Hackin’ Fest and KaraokeWebcast: Attacking MCP and N8N ServersWebcast: Safely Using Offensive AI in Security AssessmentsWild West Hackin’ Fest Satellite Class...and SOC ClassesCreators & Guests Kip Boyle - Guest Corey Ham - Host John Strand - Host Ralph May - Host Bronwen Aker - Host Charles "bsdbandit" - Guest Ryan Poirier - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Anthropic Warns Users of Infostealer Abuse - 2026-09-08 09.09.2026 1t 7min
    AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Internet Fall Weather (03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08 (06:59) - OpenAI Agents Exploit a German Forum for Private Communications (17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account (23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate (26:01) - CrowdStrike Releases AI Models Developed with NVIDIA (29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses (32:41) - ShinyHunters Claims a Breach of the Florida DMV (35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training (38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory (39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts (40:17) - New Plex Vulnerability Raises Home-Network Security Concerns (41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution (47:07) - Thomson Reuters Breach Disrupts State Court Systems (47:25) - CISA Cuts Six Free Cybersecurity Assessment Services (52:24) - New Research Demonstrates Ways to Compromise Passkeys (54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool (56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast (56:53) - PlexTrac’s AI-Assisted Reporting and Retesting (01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform (01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk (01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West (01:06:25) - Upcoming AI Core Skills Fundamentals Course LinksOpenAI Agents Exploit a German Forum for Private CommunicationsAnthropic Warns a User About Infostealer Abuse of Their Claude AccountOpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI DebateCrowdStrike Releases AI Models Developed with NVIDIAFBI Investigates the Sale of 103,000 Stolen Driver’s LicensesShinyHunters Claims a Breach of the Florida DMVAI Labs Amass Mac Minis and Mac Studios for Agent TrainingCritical Authentication Bypass Disclosed in JFrog ArtifactoryProxmox Vulnerability Exposes Internet-Facing HostsNew Plex Vulnerability Raises Home-Network Security ConcernsLangflow Vulnerability Enables Unauthenticated Remote Code ExecutionThomson Reuters Breach Disrupts State Court SystemsCISA Cuts Six Free Cybersecurity Assessment ServicesNew Research Demonstrates Ways to Compromise PasskeysOutflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking ToolDan DeCloss: Turning Pen Tests into Risk Intelligence Anti-CastCharles Shirer Introduces the FanMeyer Creator PlatformUpcoming AI Browser Research and Wild West Hackin’ Fest TalkHacking and Defending Satellite Infrastructure at Wild WestCreators & Guests Corey Ham - Host Bronwen Aker - Host Ralph May - Host Charles "bsdbandit" - Guest Ryan Poirier - Producer Dan DeCloss - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec....
  • South Korea Offers Free AI Services – 2026-08-31 01.09.2026 1t 12min
    This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — What is the whole point of RAM? (07:47) - South Korea Offers Free AI Services – 2026-08-31 (08:44) - South Korea Offers Free Government AI Services (18:38) - White House Targets Foreign Components in the U.S. Power Grid (24:11) - How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved (25:15) - Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests (27:44) - The Strava Heat Map and the End of Secrets (29:37) - Officer reportedly leaks location of French aircraft carrier with Strava run (30:09) - FBI Disrupts Chinese Botnets Targeting Critical Infrastructure (32:31) - ShinyHunters Claims Theft of 284 Million McKesson Records (37:23) - Alleged Team PCP Hackers Arrested in Australia (39:08) - Rumored NVIDIA Acquisition of Hugging Face (49:48) - OpenAI, Cursor, and Competition Between AI Coding Platforms (53:11) - Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More (55:51) - PaperCut warns of NG, MF flaw exploited in zero-day attacks (56:20) - Technology Companies Call for an AI Defensive Surge (57:42) - 58 arrested in international cybercrime crackdown (58:48) - How to start the AI-accelerated defense (01:02:21) - TRAINING: Fundamentals of Cybersecurity: Threats and Defenses (01:07:07) - TRAINING: Hacking and Defending Satellite Infrastructure LinksSouth Korea Offers Free Government AI ServicesWhite House Targets Foreign Components in the U.S. Power GridHow Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has EvolvedIranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data SuggestsThe Strava Heat Map and the End of SecretsOfficer reportedly leaks location of French aircraft carrier with Strava runFBI Disrupts Chinese Botnets Targeting Critical InfrastructureShinyHunters Claims Theft of 284 Million McKesson RecordsAlleged Team PCP Hackers Arrested in AustraliaRumored NVIDIA Acquisition of Hugging FaceOpenAI, Cursor, and Competition Between AI Coding PlatformsCritical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and MorePaperCut warns of NG, MF flaw exploited in zero-day attacksTechnology Companies Call for an AI Defensive Surge58 arrested in international cybercrime crackdownHow to start the AI-accelerated defenseTRAINING: Fundamentals of Cybersecurity: Threats and DefensesTRAINING: Hacking and Defending Satellite InfrastructureCreators & Guests Corey Ham - Host John Strand - Host Bronwen Aker - Host Ryan Poirier - Producer Ralph May - Host Michael "Shecky" Kavka - Guest Doc Blackburn - Guest Hayden Covington - Host Wade Wells - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.com
  • Using AI to Debug the Linux Kernel - 2026-08-24 25.08.2026 1t 4min
    This episode examines the alleged GTA 6 leak and Rockstar’s efforts to identify the leaker, a Flock Safety critic’s unconventional response to being barred from its conference, and Linus Torvalds’ use of AI to debug Linux. The discussion also covers ShinyHunters targeting ReliaQuest, “security through antiquity,” AliExpress using silent audio for browser fingerprinting, and invisible watermarks in Microsoft Paint’s AI-generated images. Additional stories include an Iran-linked cyberattack that disrupted a UK power plant, prompt injection hidden in a legal filing, and a cyberattack against an Australian chicken-processing facility.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — String Cheese and Security (04:29) - Using AI to Debug the Linux Kernel - 2026-08-24 (06:50) - Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord (12:47) - Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio (16:58) - Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel (29:40) - Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering (31:07) - Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”? (37:44) - Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting (41:30) - Story # 7: Darth Vader defends Flock cameras to San Diego City Council (42:44) - Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images (44:45) - Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant (50:04) - Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing (57:56) - Story # 11: Australian Chicken Processing Plant Taken Offline by Cyberattack LinksStory # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and DiscordStory # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless AudioStory # 3: Linus Torvalds Uses AI to Debug the Linux KernelStory # 4: ShinyHunters Targets ReliaQuest Employees with Social EngineeringStory # 5: Can Obsolete Technology Provide “Security Through Antiquity”?Story # 6: AliExpress Uses Silent Audio for Browser FingerprintingStory # 7: Darth Vader defends Flock cameras to San Diego City CouncilStory # 8: Microsoft Paint Embeds Watermarks in AI-Generated ImagesStory # 9: Iran-Linked Cyberattack Shuts Down a UK Power PlantStory # 10: Hidden AI Prompt Injection Discovered in a Legal FilingStory # 12: Australian Chicken Processing Plant Taken Offline by CyberattackFundamentals of Cybersecurity: Threats and DefensesCourse Authored by Doc Blackburn.Practical iOS Application Security TestingCourse Authored by Cameron Cartier and David Blandford.Creators & Guests Corey Ham - Host John Strand - Host Wade Wells - Host Aisling nic Lynne "siriciryel" - Guest Doc Blackburn - Guest Ralph May - Host Cameron Cartier - Guest Ryan Poirier - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • White House Announces "Digital Letters of Marque" - 2026-08-17 18.08.2026 1t 6min
    This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender. Other topics include a post-DEF CON in-flight Wi-Fi incident, Signal’s automatic key verification, airport phone searches, and a PBS broadcaster’s loss of access to 70 years of archived television.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Making Investments (04:59) - Airport phone searches, “kill codes,” and border privacy (09:12) - White House Announces "Digital Letters of Marque" - 2026-08-17 (11:29) - Story # 1: Digital letters of marque and private-sector “hack back” (18:45) - Story # 2: New Orleans adopts AI for 911 calls (25:10) - Story # 3: LiteLLM supply-chain attack (28:32) - Story # 4: Chris Hansen banned from Roblox during a safety demonstration (32:34) - Story # 5: On-premises Microsoft SharePoint under attack (34:18) - Story # 6: AI agents escape testing sandboxes and hack real targets (42:05) - Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw (44:54) - Story # 8: Post-DEF CON Delta flight Wi-Fi incident (52:44) - Story # 9: ShieldBreak exploit abuses Microsoft Defender (56:55) - Story # 10: Signal introduces automatic key verification (58:32) - Story # 11: PBS broadcaster loses access to 70 years of archived television (01:03:02) - Upcoming webcasts and training LinksStory # 1: Digital letters of marque and private-sector “hack back”Story # 2: New Orleans adopts AI for 911 callsStory # 3: LiteLLM supply-chain attackStory # 4: Chris Hansen banned from Roblox during a safety demonstrationStory # 5: On-premises Microsoft SharePoint under attackStory # 6: AI agents escape testing sandboxes and hack real targetsStory # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flawStory # 8: Post-DEF CON Delta flight Wi-Fi incidentStory # 9: ShieldBreak exploit abuses Microsoft DefenderStory # 10: Signal introduces automatic key verificationStory # 11: PBS broadcaster loses access to 70 years of archived televisionANTICAST - Your Cheap IoT Devices Are Hiding Secrets. Let's Find ThemTraining by Jake Williams – Assessing AI Security: Model Context ProtocolCreators & Guests Alex Minster "Belouve" - Guest Wade Wells - Host Ralph May - Host Hayden Covington - Host Derek Banks - Guest Ryan Poirier - Producer Adrien Lasalle - Guest Jake Williams - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10 11.08.2026 1t 6min
    This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones, reports of AI models hacking real targets, and research into the reliability of AI-generated security patches.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Old Jerks (08:30) - OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10 (12:00) - Story # 1: OpenClaw cancels another person’s gym reservation (27:43) - Story # 2: Ransomware attacks surge 20% amid the AI distraction (39:08) - Story # 3: Backlash grows against Meta’s AI smart glasses (46:28) - Story # 4: Passkey theft and MFA-bypass research (49:19) - Story # 5: Canadian Snowflake hacker pleads guilty (51:16) - Story # 6: ZBT-Link routers found with a China-linked backdoor (53:06) - Story # 7: UK Navy drone cameras reportedly transmitted data to China (56:19) - Story # 8: Meta reports AI models hacking real targets (01:02:44) - Story # 9: AI-generated security patches succeed only about half the time LinksStory # 1: OpenClaw cancels another person’s gym reservationStory # 2: Ransomware attacks surge 20% amid the AI distractionStory # 3: Backlash grows against Meta’s AI smart glassesStory # 4: Passkey theft and MFA-bypass researchStory # 5: Canadian Snowflake hacker pleads guiltyStory # 6: ZBT-Link routers found with a China-linked backdoorStory # 7: UK Navy drone cameras reportedly transmitted data to ChinaStory # 8: Meta reports AI models hacking real targetsStory # 9: AI-generated security patches succeed only about half the timeInfosec: Age of AI SummitCreators & Guests Wade Wells - Host Ralph May - Host John Strand - Host Bronwen Aker - Host Corey Ham - Host Ryan Poirier - Producer Kip Boyle - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Iranian Cyberattacks on U.S. Water Systems - 2026-08-03 04.08.2026 1t 6min
    This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also explore Google’s Android age-verification plans, Chrome protections against hijacking extensions, Microsoft Teams impersonation attacks deploying Chaos ransomware, and Bank of America’s acquisition of MDSec. Additional topics include the GrapheneOS duress-password court case, a DEF CON prediction market, continued Kali365 phishing activity, and credential-stuffing attacks against Chick-fil-A loyalty accounts.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Zuckers (03:43) - Iranian Cyberattacks on U.S. Water Systems - 2026-08-03 (07:00) - Story # 1: Anthropic’s Claude Breaches Companies During Security Testing (11:35) - Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident (13:37) - Story # 3: ExfilSquad Claims a Microsoft Cloud Breach (19:34) - Story # 4: Iranian Cyberattacks Target U.S. Water Systems (28:27) - Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud (40:51) - Story # 6: Google Introduces Android Age Verification (43:26) - Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions (47:02) - Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware (48:38) - Story # 9: Bank of America Acquires MDSec (51:15) - Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search (55:25) - Story # 11: Pony Market Takes Bets on DEF CON and Black Hat (58:06) - Story # 12: Kali365 Phishing Platform Remains Active (01:02:26) - ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential Stuffing LinksStory # 1: Anthropic’s Claude Breaches Companies During Security TestingStory # 2: Hugging Face Publishes Technical Details of the OpenAI IncidentStory # 3: ExfilSquad Claims a Microsoft Cloud BreachStory # 4: Iranian Cyberattacks Target U.S. Water SystemsStory # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad FraudStory # 6: Google Introduces Android Age VerificationStory # 7: Chrome Targets Tab- and Homepage-Hijacking ExtensionsStory # 8: Fake Microsoft Teams Support Calls Deploy Chaos RansomwareStory # 9: Bank of America Acquires MDSecStory # 10: GrapheneOS Duress Password Wipes Phone During Border SearchStory # 11: Pony Market Takes Bets on DEF CON and Black HatStory # 12: Kali365 Phishing Platform Remains ActiveChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential StuffingInfosec: Age of AI SummitDEATHcon- November 13 - 14, 2026- Univeristy of San Diego5998 Alcala Park Way San Diego, California 92110Creators & Guests Ralph May - Host Wade Wells - Host Bronwen Aker - Host Corey Ham - Host Nick Ascoli - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • OpenAI accidentally Hacked Hugging Face - 2026-07-27 28.07.2026 1t 4min
    This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴event-live-chatChapters(00:00) - PreShow Banter™ — Sol with a Goal (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27 (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system (18:33) - Story #2 - Lapsus is shutting down (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25 (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi (55:51) - Ads and Mike at the AI Summit (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants LinksStory #1 - OpenAI says it accidentally hacked Hugging Face with a new AI systemStory #2 - Lapsus is shutting downStory #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent ForgeryAgentForger, Part 2: The Autonomous InsiderStory #4 - Beyond the Terminal: Offensive Security Evals for Embodied ReasoningStory #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-FiAds and Mike at the AI SummitStory #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular ImplantsCreators & Guests Ads Dawson - Guest Mike Takahashi - Guest Corey Ham - Host John Strand - Host Bronwen Aker - Host Hayden Covington - Host Ralph May - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Initiative Gold Eagle - 2026-07-20 21.07.2026 1t 11min
    This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development involving Flock Safety, and the latest wave of AI news. The conversation also explores evolving AI model capabilities, security guardrails, open-weight Chinese models, and how AI is changing offensive and defensive security. Along the way, the hosts examine recent vulnerability research, industry reactions, and other cybersecurity headlines from the week.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Two Jokes (01:58) - Initiative Gold Eagle - 2026-07-20 (12:24) - Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination (18:58) - Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat (21:48) - Story #3 - Now, defenders are embracing the prompt injection, too (27:45) - Story #4 - Security incident disclosure — July 2026 (33:38) - Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift (44:25) - Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy (47:24) - Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system (48:38) - Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE (51:49) - Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities (53:20) - Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC (58:10) - Paul’s Workshop (01:00:29) - Sign up for the AI Summit to see Matt’s talk (01:02:45) - Bronwen’s Workshop (01:07:10) - Wild West Hackin’ Fest (01:07:25) - DeathCon (01:09:08) - PostShow Banter - Retirement Funds LinksStory #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability CoordinationStory #2 - Microsoft Reins in RoguePlanet Zero-Day ThreatStory #3 - Now, defenders are embracing the prompt injection, tooStory #4 - [Huggingface] Security incident disclosure — July 2026Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shiftStory #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacyStory #7 - Inside Pegasus: The evolution of the world’s most notorious spyware systemStory #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS COREStory #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilitiesStory #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFCPaul’s WorkshopSign up for the AI Summit to see Matt’s talkBronwen’s WorkshopWild West Hackin’ FestDeathConCreators & Guests Corey Ham - Host Ralph May - Host John Strand - Host Paul Clark - Guest Wade Wells - Host Meagan Bentley - Producer Bronwen Aker - Host Matt Franz - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • OnlyFans Models Are Accidental Blue Team Defenders - 2026-07-13 14.07.2026 1t 7min
    This week, the team unpacks a wide range of cybersecurity news, including a fraudulent offensive security startup tied to cybercriminals, how leaked OnlyFans content is inadvertently helping defenders identify compromised government websites, and new vishing attacks targeting Microsoft Entra passkey enrollment. They also examine AI prompt injection risks in GitHub workflows, malware campaigns abusing hundreds of GitHub repositories and Go packages, Microsoft's latest identity security developments, and the growing push for online age verification through government-issued IDs and selfies.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-event-chatChapters(00:00) - PreShow Banter™ — The New Mainframes (05:24) - OnlyFans Models are Accidental Blue Team Defenders - 2026-07-13 (06:23) - Story #1 - Felons, Fraudsters Flog Offensive Cybersecurity Startup (15:37) - Story #2 - OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear (20:37) - Story #3 - Vishing actors target Entra passkey enrollment (32:44) - Story #4 - GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos (46:32) - Story #5 - Network of 200 GitHub Repositories Used for Malware Infection (48:13) - Story #6 - Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint (53:53) - Story #7 - EU Reddit Users Must Verify Age With Government ID or Selfie (59:39) - Story #8 - Risky Bulletin: All new cars to include a camera aimed at the driver's face LinksStory #1 - Felons, Fraudsters Flog Offensive Cybersecurity StartupStory #2 - OnlyFans Models Are Accidentally Making Hacked Government Websites DisappearStory #3 - Vishing actors target Entra passkey enrollmentStory #4 - GitLost: How We Tricked GitHub’s AI Agent into Leaking Private ReposStory #5 - Network of 200 GitHub Repositories Used for Malware InfectionStory #6 - Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaintStory #7 - EU Reddit Users Must Verify Age With Government ID or SelfieStory #8 - Risky Bulletin: All new cars to include a camera aimed at the driver’s faceCreators & Guests John Strand - Host Mishaal Khan - Guest Ralph May - Host Meagan Bentley - Producer Bronwen Aker - Host Wade Wells - Host Doc Blackburn - Guest Jake Hildreth - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Apple's Hide My Email ... Doesn't! – 2026-07-06 07.07.2026 1t 7min
    This episode of BHIS - Talkin' Bout [infosec] News covers the latest cybersecurity headlines, including debate over the economics of AI infrastructure, updates on the Huntress controversy, new details surrounding Scattered Spider, a critical Microsoft SharePoint vulnerability, and reports of a breach involving a DHS information-sharing network. The discussion also examines Apple's legal battles over alternative app stores, the limitations of Apple's Hide My Email feature, a Medtronic breach, firmware security, Palo Alto Networks attribution disputes, and other notable security stories that didn't make the main rundown.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Ask GPU (02:09) - Story # 0: The memory crisis heads to court as class-action lawsuit filed against Samsung, SK Hynix, and Micron (05:15) - Apple's Hide My Email ... Doesn't! – 2026-07-06 (08:38) - Story #1 - These Recent Insider Threat Allegations (12:53) - Story #2a - Alleged Scattered Spider hacker extradited to the United States (16:40) - Story #3 - US Department of Homeland Security says it is probing a cyber breach at information-sharing network (22:20) - Story #5 - Espionage Against the European Parliament (28:33) - Story #6a - Sony Is Going Disc-Free: What It Means for PS6 and Your Wallet (33:35) - Story #6b - Resetting XBOX (38:51) - Story #7 - Command & Conquer Generals: Zero Hour — macOS, iOS & iPadOS (42:47) - Story #8 - Medtronic notifies customers impacted by ShinyHunters data breach (43:56) - Story #9 - Flipper Zero firmware development continues with community help (55:18) - Story #10 - Amazon will stop accepting new customers for Mechanical Turk (59:06) - Fletus’ YouTube Channel (59:42) - Doc’s Upcoming Workshop (01:03:22) - Story #11 - Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses (01:03:56) - Story #12 - Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage LinksStory # 0: The memory crisis heads to court as class-action lawsuit filed against Samsung, SK Hynix, and MicronStory #1 - These Recent Insider Threat AllegationsStory #2a - Alleged Scattered Spider hacker extradited to the United StatesStory #3 - US Department of Homeland Security says it is probing a cyber breach at information-sharing networkStory #5 - Espionage Against the European ParliamentStory #6a - Sony Is Going Disc-Free: What It Means for PS6 and Your WalletStory #6b - Resetting XBOXStory #7 - Command & Conquer Generals: Zero Hour — macOS, iOS & iPadOSStory #8 - Medtronic notifies customers impacted by ShinyHunters data breachStory #9 - Flipper Zero firmware development continues with community helpStory #10 - Amazon will stop accepting new customers for Mechanical TurkFletus’ YouTube ChannelDoc’s Upcoming WorkshopStory #11 - Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email AddressesStory #12 - Startup sues Palo Alto Networks’ Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionageCreators & Guests Corey Ham - Host John Strand - Host Wade Wells - Host Doc Blackburn - Guest Hayden Covington - Host Ralph May - Host Fletus Poston - Guest Ryan Poirier - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29 30.06.2026 1t 6min
    This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Next Webcast Thing (00:14) - Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29 (03:56) - Story #1 - It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns (07:49) - Story #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive users (08:55) - Story #3 - heavener: This is what happens when you can't afford EDR licenses (18:50) - Story #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues (31:59) - Story #5 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. (36:14) - Story #6 - CISA Adds Four Known Exploited Vulnerabilities to Catalog (37:09) - Story #7 - Victory! 702 has Expired! (37:43) - Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of Trial (40:52) - Story #9 - Polymarket customers lose $3 million in supply-chain attack (44:56) - Story #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general says (49:31) - Story #11 - How Android Earthquake Alerts System Works (53:47) - Story #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invites (59:34) - Story #13a - The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines (59:59) - Story #13b - Order-tracking app Shop abused to push callback phishing attacks (01:04:29) - Chinese AI vs. Anthropic Mythos | BHIS [In Focus] LinksStory #1 - It’s looking like a hot, messy summer for security teams as AI finds countless previously hidden vulnsStory #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive usersStory #3 - heavener: This is what happens when you can’t afford EDR licensesStory #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensuesStory #5 - I Could’ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.Story #6 - CISA Adds Four Known Exploited Vulnerabilities to CatalogStory #7 - Victory! 702 has Expired!Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of TrialStory #9 - Polymarket customers lose $3 million in supply-chain attackStory #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general saysStory #11 - How Android Earthquake Alerts System WorksStory #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invitesStory #13a - The Trojan horse of cybercrime: Weaponizing SaaS notification pipelinesStory #13b - Order-tracking app Shop abused to push callback phishing attacksChinese AI vs. Anthropic Mythos | BHIS [In Focus]Creators & Guests John Strand - Host Bronwen Aker - Host Corey Ham - Host Meagan Bentley - Producer Wade Wells - Host Ralph May - Host Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Rickrolling the FIFA World Cup - 2026-06-22 23.06.2026 1t 6min
    This week’s episode covers a series of cybersecurity stories, including a researcher’s discovery of vulnerabilities in FIFA’s World Cup platform that could have enabled unauthorized administrative access and even the ability to alter live broadcasts. The team also discusses the risks of large-scale identity verification data exposure, supply chain attacks impacting the scientific research community, ongoing fallout from Broadcom’s VMware acquisition, and legal challenges from major organizations facing rising VMware costs. Along the way, the hosts share commentary on AI-related security concerns, access control failures, and the broader impact of vendor decisions on enterprise security.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — There's always more suppply chain (04:52) - Rickrolling the FIFA World Cup - 2026-06-22 (07:59) - Story #1 - Texas Government Data Breach Exposes 3 Million Driver’s License Records (10:56) - Story #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. (21:00) - Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure (23:58) - Story #4a - Stakeholder-Specific Vulnerability Categorization (SSVC) (25:44) - Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for Everyone (37:19) - Story #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels (43:56) - Story #6 - FBI disrupts massive AI-powered phishing service using a million URLs (46:12) - Story #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure (47:12) - Story #8 - AI models that can take down governments and business months away, rare Five Eyes statement warns (48:44) - Story #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURS (58:45) - Story #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct” LinksStory #1 - Texas Government Data Breach Exposes 3 Million Driver’s License RecordsStory #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical DisclosureStory #4a - Stakeholder-Specific Vulnerability Categorization (SSVC)Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for EveryoneStory #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI WheelsStory #6 - FBI disrupts massive AI-powered phishing service using a million URLsStory #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After DisclosureStory #8 - AI models that can take down governments and business months away, rare Five Eyes statement warnsStory #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURSStory #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”Creators & Guests Andy Pettit "Nerf" - Guest Michael "Shecky" Kavka - Guest Ryan Poirier - Producer Corey Ham - Host Ralph May - Host John Strand - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • U.S. Government Effectively Bans Fable 5 and Mythos 5 - 2026-06-15 16.06.2026 1t 7min
    This episode dives into the fallout from new restrictions on Anthropic’s cybersecurity-focused AI models, Mythos and Fable, and the debate over whether government pressure has effectively blocked security researchers from using advanced AI for vulnerability discovery and code analysis. The panel discusses AI “jailbreaking” claims, export-control comparisons, the impact on penetration testing and bug hunting, and how AI is accelerating vulnerability research. Other topics include responsible disclosure challenges, the growing volume of AI-assisted security findings, and what these developments mean for researchers, vendors, and the future of offensive security.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — A Banned Phrase (04:56) - U.S. Government Effectively Bans Fable 5 and Mythos 5 - 2026-06-15 (06:29) - Story #1 - Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (21:15) - Story #2 - ServiceNow discloses security incident exposing customer data (41:45) - Story #3 - Introducing Claude Corps (52:11) - Story #4 - SHINYHUNTERS HITS 100+ UNIVERSITIES WITH ORACLE ZERO-DAY (52:39) - Story #5 - Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack (59:00) - Story # - This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers Links06:30 - Story #1 - Statement on the US government directive to suspend access to Fable 5 and Mythos 521:16 - Story #2 - ServiceNow discloses security incident exposing customer data41:46 - Story #3 - Introducing Claude Corps52:12 - Story #4 - SHINYHUNTERS HITS 100+ UNIVERSITIES WITH ORACLE ZERO-DAY52:40 - Story #5 - Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack59:00 - Story # - This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate ReadersCreators & Guests Corey Ham - Host John Strand - Host Bronwen Aker - Host Wade Wells - Host Alex Minster "Belouve" - Guest Ralph May - Host Ryan Poirier - Producer Jason Haddix - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Breach Disclosure Lag is Worse Than Ever – 2026-06-08 09.06.2026 1t 9min
    This episode covers the rising costs and restrictions surrounding AI agents, including token consumption, model access policies, and the growing dependence on AI tools for security work. The hosts discuss Troy Hunt’s retrospective on Have I Been Pwned reaching its 1,000th tracked breach, examining why breach disclosures appear to be slowing and how GDPR and CCPA requirements affect notification practices. Additional topics include password and email hygiene, the value of breach-notification services, AI infrastructure and data center costs, and new research mapping AI-enabled cyber threats to the MITRE ATT&CK framework.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Token Love (05:11) - Breach Disclosure is Lag Worse Than Ever – 2026-06-08 (11:25) - Story #1 - Anthropic ‘plants’ engineers at NSA despite facing ban by Pentagon (20:59) - Story #2 - A new service branch could be joining the U.S. Armed Forces family (25:47) - Story #3 - Websites have a new way to spy on visitors: Analyzing their SSD activity (31:11) - Story #4 - The Quiet Numbers Station: Decoding Nineteen Years of GPS Cryptography (37:21) - Story #5 - 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever (43:23) - Story #6 - Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator (48:00) - Story #7 - Anthropic confidentially files IPO prospectus with SEC, prepping Wall Street for landmark AI deal (01:02:26) - Story #8 - Microsoft Wants to 'Make People Addicted' to its New AI Assistant, Internal Documents Reveal (01:03:29) - Story #9 - Amazon Shuts Down Internal AI Leaderboard After Employees Cheated (01:04:57) - ANTI-CAST : RF Attacks Every InfoSec Pro Should Know with Paul Clark (01:05:54) - Workshop: Build Your Own AI Security Agent (01:06:43) - Training: Agentic AI for Threat Hunting (01:07:16) - Training: Cyber Threat Intelligence 101 2-Day Version (01:08:58) - ANTI-CAST: Prompt Engineering 201: The Context Stack w/ Bronwen Aker LinksStory #1 - Anthropic ‘plants’ engineers at NSA despite facing ban by PentagonStory #2 - A new service branch could be joining the U.S. Armed Forces familyStory #3 - Websites have a new way to spy on visitors: Analyzing their SSD activityStory #4 - The Quiet Numbers Station: Decoding Nineteen Years of GPS CryptographyStory #5 - Russia Has Been Jamming GPS from Space Since 2019Story #6 - Mapping AI-enabled cyber threats: Insights from the LLM AT&T&CK NavigatorStory #7 - Anthropic confidentially files IPO prospectus with SEC, prepping Wall Street for landmark AI dealStory #8 - Microsoft Wants to ‘Make People Addicted’ to its New AI Assistant, Internal Documents RevealStory #9 - Amazon Shuts Down Internal AI Leaderboard After Employees CheatedANTI-CAST : RF Attacks Every InfoSec Pro Should Know with Paul ClarkWorkshop: Build Your Own AI Security AgentWorkshop: Intro to SDR Hacking: Capture, Decode, Take OverTraining: Agentic AI for Threat HuntingTraining: Cyber Threat Intelligence 101 2-Day VersionANTI-CAST: Prompt Engineering 201: The Context Stack w/ Bronwen AkerCreators & Guests John Strand - Host Ralph May - Host Corey Ham - Host Bronwen Aker - Host Faan Rossouw - Guest Ryan Poirier - Producer Paul Clark - Guest Wade Wells - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Anti-Tech Extremism - 2026-06-01 03.06.2026 1t 13min
    This episode covers a Wired report on the rise of “anti-tech extremism” and growing public opposition to AI infrastructure projects, including debates over data centers, resource consumption, local communities, and government responses. The hosts also discuss AI coding assistants, model safety restrictions, and the evolving capabilities of large language models. Additional topics include Anthropic’s reported IPO plans and valuation, AI’s impact on the tech industry, and a conversation with David Bianco about AI-generated threat-hunting datasets and cybersecurity training.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Solving this thing (03:52) - Anti-Tech Extremism - 2026-06-01 (08:08) - Threat Hunter Summit | June 17th 2026 (12:11) - Story # 1: US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows (20:54) - Story # 2: Anthropic files for its IPO (23:35) - Story # 3: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data (29:41) - Story # 4: Microsoft Defender can now automatically isolate hacked endpoints (30:45) - Story # 5: Microsoft's GitHub bans security researcher who posted zero-day Windows exploits because company 'ruined their life' (36:54) - Story # 6: Cyber Force? Senator pushes to create service branch under the Army (42:10) - Story # 7: Are you ready? Anthropic preparing to release Mythos publicly (46:38) - Story # 8: Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark (49:12) - Story # 9: Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (50:43) - Story # 10: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (56:02) - Story # 11: Kali365 phishing kit bypasses MFA and steals Microsoft logins (58:02) - Story # 12: Botnet of more than 17 million devices dismantled (01:01:13) - Story # 13: United flight returns midair after Bluetooth device name reportedly sparks security scare (01:03:49) - Story # 14: Inside the Charter data breach: hackers leak 13M+ customer data (01:04:37) - Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake (01:10:04) - Threat Hunter Summit | June 17th 2026 (01:10:57) - Anti-Cast : How Hackers Attack CI/CD Pipelines w/ Phil Miller (01:11:36) - Cyber Threat Intelligence 101 2-Day Version (01:11:57) - Ralph's Practical Physical Exploitation Training & Tool Bundle Links00:00:00 - PreShow Banter™ — Solving this thing00:03:52 - Anti-Tech Extremism - 2026-06-0100:08:08 - Threat Hunter Summit | June 17th 202600:12:11 - Story # 1: US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows00:20:54 - Story # 2: Anthropic files for its IPO00:23:36 - Story # 3: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data00:29:41 - Story # 4: Microsoft Defender can now automatically isolate hacked endpoints00:30:46 - Story # 5: Microsoft’s GitHub bans security researcher who posted zero-day Windows exploits because company ‘ruined their life’00:36:54 - Story # 6: Cyber Force? Senator pushes to create service branch under the Army00:42:11 - Story # 7: Are you ready? Anthropic preparing to release Mythos publicly00:46:39 - Story # 8: Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark00:49:12 - Story # 9: Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit00:50:44 - Story # 10: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked00:56:03 - Story # 11: Kali365 phishing kit bypasses MFA and steals Microsoft logins00:58:02 - Story # 12: Botnet of more than 17 million devices dismantled01:01:13 - Story # 13: United flight returns midair after Bluetooth device name reportedly sparks security scare01:03:50 - Story # 14: Inside the Charter data breach: hackers leak 13M+ customer data01:04:38 - Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake01:10:05 - Threat Hunter Summit | June 17th 202601:10:57 - Anti-Cast : How Hackers Attack CI/CD Pipelines w/ Phil Miller01:11:37 - Cyber Threat Intelligence 101 2-Day Version01:11:58 - Ralph’s Practical Physical Exploitation Training & Tool BundleCreators & Guests Corey Ham - Host Ralph May - Host Shane Hartman - Guest Wade Wells - Host Ryan Poirier - Producer David Bianco - Guest Phil Miller - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • GitHub bans vindictive security researcher - 2026-05-26 30.05.2026 1t 2min
    This episode covers a CISA contractor’s accidental exposure of AWS GovCloud credentials and internal system details on GitHub, the FBI’s efforts to patch vulnerable routers, and a critical NGINX vulnerability with public proof-of-concept code. The team also discusses Microsoft’s handling of a disputed Azure Backup security finding, the challenges of vulnerability disclosure and CVE assignment, and GitHub’s ban of security researcher Nightmare Eclipse following the publication of unpatched Windows vulnerability research.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Getting to Chili's (05:45) - GitHub bans vindictive security researcher - 2026-05-26 (07:09) - Story # 1: CISA Admin Leaked AWS GovCloud Keys on Github (10:45) - Story # 2 - PoC Code Published for Critical NGINX Vulnerability (12:53) - Story # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude Code (16:16) - Story # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlist (22:37) - Story # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid Exploitation (25:52) - Story # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issued (28:09) - Story # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” (30:41) - Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale (32:16) - Story # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension (35:21) - Story # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilities (37:51) - Story # 11 - Pizza Hut's AI system caused 'cascading' problems and $100M in damages, franchisee alleges in new suit (43:55) - Story # 12 - Data Leak at German Hospital (45:00) - Story # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware (47:50) - Story # 14 - Chicken News (50:07) - Story # 15 - New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (51:04) - Story # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment? LinksStory # 1 - CISA Admin Leaked AWS GovCloud Keys on GithubStory # 2 - PoC Code Published for Critical NGINX VulnerabilityStory # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude CodeStory # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlistStory # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid ExploitationStory # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issuedStory # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented ScaleStory # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extensionStory # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilitiesStory # 11 - Pizza Hut’s AI system caused ‘cascading’ problems and $100M in damages, franchisee alleges in new suitStory # 12 - Data Leak at German HospitalStory # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malwareStory # 14 - Chicken NewsStory # 15 - New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC releasedStory # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment?Creators & Guests Alethe Denis - Guest Corey Ham - Host Wade Wells - Host Bronwen Aker - Host Meagan Bentley - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Mythos finds a curl vulnerability - 2026-05-18 22.05.2026 1t 6min
    This episode covers Mythos uncovering a vulnerability in cURL, a recent Google Threat Intelligence report on a zero-day exploit, and the growing impact of AI on capture-the-flag competitions and bug bounty programs. The hosts also discuss the economics of AI platforms like OpenAI, security research trends, and broader concerns around software vulnerabilities, automation, and defensive tooling.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Token CTFs (03:18) - Story # 1: Mythos finds a curl vulnerability (06:36) - Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (14:47) - Story # 3: The down fall of bug bounties (15:34) - Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ (40:52) - Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots (43:51) - Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated (49:35) - Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released (56:09) - Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform (58:07) - Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach (58:54) - Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible (01:00:29) - Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach (01:04:47) - WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks LinksStory # 1: Mythos finds a curl vulnerabilityStory # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass ExploitationStory # 3: The down fall of bug bountiesStory # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat RobotsStory # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting ObliteratedStory # 5: Windows BitLocker zero-day gives access to protected drives, PoC releasedStory # 6: Deal reached with hackers to delete data stolen from the Canvas educational platformStory # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breachStory # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsibleThreat Hunting Summit Talk: Threat Hunting in the Dark: A Practical ApproachWEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek BanksCreators & Guests John Strand - Host Corey Ham - Host Wade Wells - Host Bronwen Aker - Host Ralph May - Host Shane Hartman - Guest Meagan Bentley - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • The Canvas / Instructure Breach – 2026-05-11 11.05.2026 1t 3min
    Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatThis episode of Talking About News focuses on the reported Canvas/Instructure breach, including discussion around ShinyHunters, transparency concerns, higher education security challenges, and possible attack paths involving phishing and tenant compromise. The team also explores broader cybersecurity trends such as social engineering, ransomware pressure tactics, and the growing role of AI and platform security in modern enterprise environments.Chapters(00:00) - PreShow Banter™ — Californian Problems (02:25) - The Canvas / Instructure Breach – 2026-05-11 (10:23) - Story # 1: Canvas Breach Disrupts Schools & Colleges Nationwide (13:45) - Story # 1b: Security Incident Update & FAQs (43:14) - Story # 2: Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer (47:34) - Story # 3: Google Chrome silently installs a 4 GB AI model on your device without consent. (52:19) - Story # 4: Trellix source code breach claimed by RansomHouse hackers (58:12) - Story # 5: Rose Acre Farms Targeted in Alleged Lynx Ransomware Attack - Cybersecurity LinksStory # 1: Canvas Breach Disrupts Schools & Colleges NationwideStory # 1b: Security Incident Update & FAQsStory # 2: Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerStory # 3: Google Chrome silently installs a 4 GB AI model on your device without consent.Story # 4: Trellix source code breach claimed by RansomHouse hackersStory # 5: Rose Acre Farms Targeted in Alleged Lynx Ransomware Attack - CybersecurityWade's Workshop: Threat Actor Profiling: Know Your EnemyAlethe Denis' Webcast: How to Build a Bulletproof PretextAlethe Denis' Workshop: How to Build Pressure-Proof PretextsCreators & Guests John Strand - Host Corey Ham - Host Wade Wells - Host Ched "cheddar" Wiggins - Guest Bronwen Aker - Host Hayden Covington - Host Ryan Poirier - Producer Alethe Denis - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
  • Utah Bans VPN Age Bypass - 2026-05-04 10.05.2026 1t 10min
    Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatThis episode covers several major cybersecurity and technology news stories, including Utah’s proposed crackdown on VPNs used to bypass online age-verification systems and the privacy and enforcement concerns surrounding those laws. The hosts also discuss newly disclosed MOVEit Transfer vulnerabilities and patching guidance, software trust and code-signing weaknesses, and broader issues around internet regulation and digital identity verification. Additional discussion touches on AI, science-fiction-inspired technology concepts, relativity and time dilation, and other notable developments from the week in cybersecurity and tech news.Chapters(00:00) - PreShow Banter™ — Alien Communications 101 (03:38) - Utah Bans VPN Age Bypass - 2026-05-04 (09:13) - Story #1 - DigiCert Revokes Certificates After Support Portal Hack (15:25) - Story #2 - Progress warns of critical MOVEit Automation auth bypass flaw (16:44) - Story #3 - Critical cPanel and WHM bug exploited as a zero-day, PoC now available (23:33) - Story #4 - Copy Fail (26:17) - Story #5 - Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue (33:42) - Story #6 - Elon Musk testifies that xAI trained Grok on OpenAI models (38:51) - Story #7 - Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks (51:23) - Story #8 - Why you should refuse to let your doctor record you (56:19) - Story #9 - Technique Change Type: How the ATT&CK Object Changed LinksCreators & Guests Corey Ham - Host Wade Wells - Host Ralph May - Host Tim Medin - Guest Patrick Gorman - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.