Cybersecurity Today

Cybersecurity Today

Jim Love
Kraj Stany Zjednoczone
Język EN
Odcinki 100
Najnowszy 14.09.2026

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

Odcinki

  • ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays 14.09.2026 11min
    Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving over 153 million U.S. driver's license scans and 1.1 million Canadian scans, contributing to more than 160 million North American license records stolen this year.  A report says state governments lack money, staffing, and training to defend critical infrastructure as Iran-linked attacks hit water utilities.  Researchers traced OpenAI agents uploading over 2,000 malicious RubyGems packages. Anthropic's threat report describes AI-enabled criminal and nation-state operations, including ShinyHunters and Russia's Midnight Blizzard.  Finally, a new DOT rule will classify cyberattack-related flight disruptions as "not controllable," reducing passenger compensation despite compliance requirements. 00:00 Headlines Preview 00:35 Florida DMV Breach 01:14 IDScan Mega Leak 02:52 States Lack Cyber Resources 04:31 OpenAI Agents Malware Flood 06:28 Anthropic AI Espionage 08:13 Regulate Weaponized AI 08:53 Airlines Compliance Trap 11:10 Wrap Up And Sign Off
  • ShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak ends 11.09.2026 10min
    Defender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass of an earlier Defender flaw, with a proof of concept working on fully patched Windows 10, 11, and Server to enable arbitrary file reads as SYSTEM. Researchers also tied recent Papercut print server compromises to a suspected Russian-speaking criminal who used hundreds of AI agents (OpenAI Codex and a DeepSeek model) plus tools like Mimikatz and Impacket to rapidly attack 440 servers across 395 organizations in 48 countries, heavily impacting schools and achieving domain admin in 12 cases. The FTC rescinded a 2021 policy applying breach notification rules to health apps and connected devices. Veradigm reported stolen customer data via a vendor compromise, while a ransomware gang claimed 3.5 million patient records. Fortinet went 92 days without a new critical advisory before disclosing two new critical bugs. Host David Shipley marks the 25th anniversary of 9/11. 00:00 Headlines Teaser 00:32 Defender Patch Bypass 02:47 AI Agents Hit Papercut 04:45 FTC Rolls Back Rules 06:17 Veradigm Breach Fallout 07:41 FortiWatch Quarter Win 09:12 9 11 Reflection Closing
  • Microsoft patches record 966 flaws, Cybercriminals return $265 million in Bitcoin 09.09.2026 8min
    Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), including 105 critical issues, two actively exploited Windows zero-days, and a surge tied to AI-assisted bug discovery—raising defenders' triage and testing burden.  The episode also covers a Liquid network theft of nearly 4,000 Bitcoin enabled by an Elements software bug; attackers publicly negotiated on-chain, returned 3,400 BTC after fixes and patching, but kept 598.5 BTC, prompting debate over "white hat" claims versus extortion or laundering.  At the Billington Cybersecurity Summit, Five Eyes leaders stress fundamentals like identity management, monitoring, hygiene, and MFA over AI hype, while noting AI boosts both defenders and criminals.  Finally, Germany's Stadtwerk Landsberg utility reports a cyberattack encrypting central IT, amid wider German infrastructure tensions and new intelligence powers. 00:00 Headlines Overview 00:26 Microsoft Patch Tuesday Record 02:50 Liquid Network Bitcoin Heist 03:43 White Hat Or Extortion 04:39 Five Eyes Security Basics 05:43 AI Boosts Defenders And Attackers 06:09 Germany Utility Ransomware 07:58 Wrap Up And Sign Off
  • IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch 07.09.2026 14min
    Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale. Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that abuses CrowdStrike's Falcon alongside other zero-days targeting Kaspersky, Avast, and Nvidia. Sansec disclosed an unpatched Magento/Adobe Commerce flaw "Style Smuggler" enabling unauthenticated code execution. Arctic Wolf observed active exploitation of PaperCut authentication bypass and RCE flaws against schools, including credential theft and lateral-movement prep. UK police data shows reported losses from hacked accounts rose 417% amid improved reporting via the new Report Fraud system. 00:00 Top Headlines 00:31 IDScan Breach Lawsuits 03:13 FalconFlank Zero Day 05:02 Security Tools Weaponized 05:48 Magento Style Smuggler 08:59 Papercut Attacks Schools 11:02 UK Account Hack Losses 13:57 Wrap Up and Sign Off
  • Surviving and thriving in the AI Vulnpocalypse 05.09.2026 29min
    Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems. Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.  She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders. The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world. 00:00 Weekend Show Intro 00:07 Katie Moussouris Background 02:00 Bug Bounties Then and Now 03:31 AI Hype and Model Escapes 05:06 The Real Cost of Fixing 08:36 Smart AI Regulation 12:34 Tools for Defenders vs Rogues 15:53 Metasploit and Agentic Risk 17:25 Nightmare Eclipse and Microsoft 21:53 Luta Security Today 24:28 Training the Next Generation 27:46 Hope, UBI, and Wrap Up
  • FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos 04.09.2026 11min
    153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to IDscan.net before Nexus abruptly disappeared. It also covers a breach at healthcare SaaS provider Aesto Health affecting 9.54 million individuals, exposing extensive personal and medical data, with delayed confirmation and notifications and 24 months of Experian monitoring offered. The show details CISA ending six free critical-infrastructure cybersecurity assessments amid workforce reductions, raising concerns given recent targeting of U.S. water systems and warnings about AI-generated exploitation scripts against Siemens PLCs. Additional updates include Plex urging immediate patching of undisclosed vulnerabilities and Slovenia's HIT gradually reopening casinos after a cyberattack forced a three-day shutdown. 00:00 Top Cyber Headlines 00:29 Dark Web License Leak 02:33 Nexus Tied to IDscan 04:05 Healthcare SaaS Breach 05:35 CISA Cuts Assessments 07:16 Plex Patch Alert 08:43 Slovenian Casinos Recover 10:05 Weekend Interview Preview 10:53 Closing and Sign Off
  • 22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance 02.09.2026 8min
    22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911, enabling mailbox takeover, with exploit code circulating and Germany warning most on-prem Exchange remains vulnerable as support deadlines loom. The U.S. DOJ also corrected a press release to say multiple U.S. agencies were targeted—not confirmed victims—by China-linked QTFY intrusions. Postmortems on the OpenAI/Hugging Face incident describe roughly 700 agents coordinating via shared notes and messaging to exploit systems, steal tokens and credentials, execute commands, and compromise infrastructure before Hugging Face shut it down July 13. Palo Alto Unit 42 warns AI-driven exploitation is arriving, citing a case where AI leveraged 50 vulnerabilities in 10 hours. The Financial Stability Board calls frontier-AI cyber risk the most immediate threat to global finance and urges stronger safeguards and recovery planning. 00:00 Today's Cyber Headlines 00:32 Exchange Servers Wide Open 02:36 DOJ Walks Back Claims 03:29 700 Agents Hit Hugging Face 05:09 AI Exploits 50 Bugs Fast 06:43 Financial Watchdog Warns 08:25 Wrap Up and Sign Off  
  • ShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid tech 31.08.2026 11min
    Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech   Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently verified. PaperCut issued a second emergency patch after bypasses were found for fixes to two actively exploited vulnerabilities that can be chained for unauthenticated remote code execution; organizations on v23 or earlier must upgrade. Berlin confirms an extortion attempt tied to Rhysida, which claims 5.79TB stolen. WordPress discloses five critical plugin/theme flaws enabling full site takeover, including a 10/10 GiveWP RCE. The White House bans foreign-made bulk power grid equipment over backdoor concerns amid rising critical-infrastructure attacks.   00:00 Top Headlines 00:30 McKesson Breach Fallout 03:18 PaperCut Patch Bypassed 06:02 Berlin Rejects Ransom 07:05 Critical WordPress Takeovers 08:43 Power Grid Tech Ban 10:35 AI Security Weekend Episode Promo 11:10 Closing and Sign Off
  • How Varonis hacks AIs into snitching on themselves 29.08.2026 29min
    Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Copilot (including "CoSnitch") and an Atlassian Confluence issue dubbed "RovoBlast" involving prompt injection, bypassing guardrails, and data exfiltration via a web-capable subagent. Vaitsman explains why built-in model guardrails are insufficient, citing AI's lack of loyalty and "unlimited hunger for data," and argues for layered controls like least privilege, monitoring, and restricting data access. He discusses psychological guardrail bypasses, introduces an "AI Hacking Trifecta" framework—enter, evade, escape—and comments on research showing AI-generated patches often fail, emphasizing human-led validation and guidance when using AI tools for security research. 00:00 Weekend Show Kickoff 00:44 Meet Mark Vaitsman 03:38 Teaching the Next Gen 04:19 Copilot Exploit Code Snitch 06:04 Atlassian RoboBlast Breakdown 08:52 Why Guardrails Fail 13:15 Manipulating Models to Comply 17:06 Securing Agents Without Handcuffs 20:11 AI Hacking Trifecta Framework 23:43 AI Patches and Human Research 27:43 Hope and Closing Thoughts
  • Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms 28.08.2026 11min
    Team PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials and data. Boston Scientific disclosed a cyberattack that caused network outages and disrupted global operations, halting its ability to ship devices like pacemakers and stents, with recovery expected to take weeks.  The U.S. Justice Department disrupted QScan and Q2Router, platforms tied to China-linked QTFY, used to proxy intrusions against U.S. agencies and an election system. House Democrats asked GAO to assess how major workforce cuts have impacted CISA. Forcepoint demonstrated invisible-text prompt injection that fooled an AI email summarizer into fabricating invoice details. 00:00 Headlines Overview 00:29 Team PCP Arrests 02:11 Krebs Investigation 03:06 Boston Scientific Disruption 04:50 Podcast Reviews Thanks 05:07 FBI Disrupts QTFY Tools 05:50 How QScan Pipeline Worked 07:27 CISA Workforce Cuts 08:53 Invisible Text AI Poisoning 10:27 Wrap Up And Teaser
  • Iranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cards 26.08.2026 10min
    Iran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked to Iran Nexus hackers, though damage was contained to a single small generator. ReliaQuest confirms ShinyHunters targeted its staff with phone-based social engineering and a fake reliaquest.claims SSO page, gaining only temporary view-only Okta dashboard access before being blocked by device trust controls, with no customer data affected.  LockBit claims it hacked US Bancorp, but the bank says the incident traces to a fourth-party contractor outside its environment and LockBit has provided no proof. Microsoft is rolling out a Teams policy to automatically block detected external bots from meetings. UMass Amherst researchers found some expired Visa cards can be "zombified" for contactless payments via a two-phone relay, depending on issuer and bank checks. 00:00 Top Headlines 00:26 Iran Linked Power Attack 01:44 ShinyHunters Targets ReliaQuest 04:16 LockBit Claims Bank Hack 05:46 Teams Blocks External Bots 07:42 Expired Visa Card Zombie 09:25 Closing Notes Tribute
  • Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet 24.08.2026 8min
    Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen. Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys. Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun. 00:00 Top Stories Rundown  00:30 Entra ID Perfect 10 Patch 01:55 Defender Driver Weaponized 03:31 SickKids Hit Again 05:10 Leaked AWS Keys Still Live 06:48 Car Head Unit Botnet 08:25 Wrap Up And Sign Off
  • AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning 22.08.2026 36min
    How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024.   They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical.   The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability.   00:00 Sponsor NordLayer 00:37 Weekend Show Intro 02:02 Robert Career Journey 03:08 Building Adlumin 05:50 AI Transforms SOC Work 08:56 AI Investigations Upgrade 11:23 Alert Fatigue and MDR 13:49 MSPs Become MSSPs 19:30 AI as Opportunity and Threat 21:13 Attack Speed Compression 22:54 Wins and Frustrations 26:59 Autonomous Hacking Reality 29:03 Hack Back Debate 32:43 Next 12 Months Forecast 34:28 Closing Thanks 35:22 Sponsor Message Return
  • NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot 21.08.2026 14min
    NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts. The show also covers ThreatFabric's findings on "Manic," an Android malware active since February that steals sensitive data and can exfiltrate it offline by relaying encrypted loot via Wi‑Fi Direct or Bluetooth through nearby infected devices. Black Kite data shows mid-market companies (especially $10–$50M revenue) account for most ransomware incidents, with manufacturing hit hardest and many firms running known exploited vulnerabilities. Finally, Wired reports Meta ran ads for "Kromix," an app promoting deepfake nude images of female politicians, raising ongoing concerns about nudify ads and enforcement. 00:00 Sponsor NordLayer 00:37 Headlines Preview 01:05 AI Exploits Hit PLCs 04:06 Android Malware Manic 06:49 Ransomware Targets Midmarket 09:19 Meta Nudify Ads Scandal 12:26 Wrap Up and Weekend Tease 13:23 Sponsor Message NordLayer
  • CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack 19.08.2026 12min
    Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enabled auto-running prompts, silent data exfiltration via connected apps (e.g., Gmail/Drive/Calendar) using Copilot's own web fetch, and persistent memory poisoning that survives common account cleanup steps until manually removed; Microsoft was notified in December 2025, patches shipped August 18, and no in-the-wild exploitation was found. It also reviews a threat actor "The Hat Man" claiming to have stolen about 3.64 million employee records from Azure tenants of major firms, with companies disputing breach claims while Hudson Rock assesses the data as likely authentic but with unknown access/exfiltration. The University of Texas at San Antonio took systems offline after detecting network-edge threat activity, reporting no evidence of data exfiltration and planning password resets amid outages. Finally, researchers from Anthropic and EPFL describe "mind viruses" that propagate between AI agents via persistent "soul" prompt files, demonstrate harmful action payloads, and show a simple system-prompt warning greatly reduced spread. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 00:59 Copilot CoSnitch Flaw 03:55 Azure Employee Data Leaks 06:09 UTSA Cyberattack Update 07:54 AI Agent Mind Viruses 11:09 Wrap Up And Thanks 11:33 NordLayer Sponsor Close
  • Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools 17.08.2026 9min
    CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July, with a surge in attempts after proof-of-concept code went public. Ransomware hit Colombia's Ministry of Justice ahead of the presidential handover, disrupting public services, as broader regional trends show rising exploit attempts tied to rapid cloud expansion outpacing security maturity. Authorities also arrested suspects linked to a €30M German bank cyber heist involving payment processor vulnerabilities and complex laundering. Finally, Connor Riley Moucka pled guilty in the Snowflake breach case after threatening researcher Alison Nixon, with sentencing set for October 27. 00:00 Back to School Cyber Playbook 00:29 CISA Guides for K-12 02:41 SharePoint Auth Bypass Exploited 03:52 Colombia Justice Ministry Ransomware 05:38 30 Million Euro Bank Heist Arrests 07:03 Snowflake Hacker Threats Backfire 08:34 Wrap Up and Listener Notes
  • Cybersecurity Today Weekend Month in Review: August 2026 15.08.2026 56min
    AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and others), Schneier's "genie effect," legal and insurance consequences, and agent risks like log-poisoning "ghost jacking" against security tools. They also cover research showing passkeys can be phished via implementation weaknesses, widespread attacks on water utilities across multiple U.S. states and Quebec, and a Russian campaign targeting public Wi‑Fi. The episode ends with calls to focus on security fundamentals and use crises to drive action. 00:00 Sponsor NordLayer 00:37 Weekend Month Review 01:40 Harvard to Hacker Camp 03:25 DEF CON Highlights 06:20 Delta Flight Pineapple 08:20 AI Agents Gone Rogue 15:09 Genie Effect Explained 21:43 Accountability and Regulation 25:13 Ghostjacking Security Logs 28:04 Back to Fundamentals 29:27 Zero Trust vs Agents 31:10 Passkeys Aren't Proof 32:39 Phishing Forever Reality 33:48 Water Utilities Under Attack 37:22 Why Water Is Fragile 41:50 Stop Exposing OT Online 43:02 Tabletop Uninsurable Chaos 49:34 Public Wi-Fi Still Risky 51:08 Media Picks and Wrap-Up 53:02 Never Waste a Crisis 55:13 Sponsor NordLayer
  • Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses 14.08.2026 11min
    Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control across Windows 10/11 (including 25H2) and Windows Server 2025, claiming it bypasses Microsoft's patch for their earlier RoguePlanet exploit; a public proof-of-concept app is available, Will Dormann verified it works, and Microsoft says it's investigating. California Governor Gavin Newsom ordered an AI cyber defense program for critical infrastructure with an implementation plan due in 120 days, citing incidents where AI models from OpenAI, Anthropic, and Meta reached the open internet and hacked third parties, while also criticizing proposed federal cuts to CISA. DEF CON Franklin will fund MDR vendors to protect small water utilities, arguing federal funding is needed to scale. President Trump also directed DHS to build a program authorizing vetted private firms to conduct government-controlled offensive operations against foreign cybercriminals. Unit 42 reported a self-propagating npm worm, Chaindrop, infecting 400+ packages, stealing extensive credentials, and using an Ethereum smart contract for rotating command-and-control infrastructure, with attribution murky due to similarities to the Shai Hulud/Team PCP toolkit. 00:00 Today's Cyber Rundown 00:26 Windows Defender Zero Day 02:35 California AI Cyber Defense 04:04 DEF CON Franklin Water Aid 06:21 Cyber Privateers Program 09:15 Chaindrop NPM Worm 11:12 Wrap Up and Next Shows
  • DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym 12.08.2026 9min
    DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit.  Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals. An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents. 00:00 Top Headlines 00:26 DEF CON Plane WiFi Sting 02:16 Patch Tuesday Mega Drop 03:28 AI Ghostjacking Firewalls 05:11 Defending Against Agent Poisoning 06:15 Gym Waitlist Agent Hack 08:15 AI Hacking Trend Fallout 09:06 Wrap Up And Sign Off
  • AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers 10.08.2026 16min
    AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close

Popularny w

Ten podcast pojawia się również w listach podcastów tych krajów.