Pular para o conteúdo
PodcastsNegóciosCybersecurity Today

Cybersecurity Today

Jim Love
Cybersecurity Today
Último episódio

472 episódios

  • Cybersecurity Today

    The Era of Cheap Bugs, Water utility attacks spread to 12 states, Coldcard wallet losses could hit 130 million

    07/08/2026 | 14min
    Passkeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw
    In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside research showing exploit success against AI agents and weaknesses across agent frameworks, plus notable hardware and supply-chain hacks.
    The show details BlackHat and Unit 42 findings that passkeys on Windows and Chrome can be phished or abused through logging, validation gaps, and malware techniques, undermining "phishing-resistant" claims.
    It also covers cyber incidents impacting water utilities across at least 12 U.S. states, with manual operations and boil-water advisories but safe drinking water, and Forescout's count of thousands of exposed Rockwell controllers.
    Finally, it updates the ColdCard seed-generation flaw with potential losses up to 2,000 BTC and reports indictments tied to a violent crypto "wrench attack."
    00:00 Sponsor NordLayer
    00:38 Headlines Passkeys Water Crypto
    01:07 Black Hat Cheap Offense
    02:43 Rogue AI Incidents
    03:18 Passkeys Phished Windows
    04:55 Chrome Synced Passkeys Flaws
    05:53 Water Utilities Under Attack
    08:20 ColdCard Wallet Losses
    09:59 Wrench Attack Crypto Robbery
    12:24 Wrap Up And Thanks
    13:05 Sponsor NordLayer Reminder
  • Cybersecurity Today

    Inside the North American Water Utility Hacking Crisis

    05/08/2026 | 13min
    Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes
     
    This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and manipulating project files, with effects like loss of pressure, flooding, and tampered operator displays.
     
    It also covers a separate Quebec incident in Saint-Noël shared by "Z Pen Test Alliance," where attackers adjusted chlorine settings and the plant entered safe mode without contamination.
     
    The show reviews competing attributions (Cyber Avengers vs. Hondala), procurement and triage challenges for small utilities, an insurance war game simulating a mass water-sector crisis, concerns about uninsurability and act-of-war exclusions, and the DEF CON Franklin volunteer program helping rural utilities implement basics like password resets, MFA, and incident response plans.


    00:00 Sponsor NordLayer
    00:37 Deep Dive Setup
    01:25 Iran Linked Water Hacks
    02:27 Attack Mechanics Impact
    03:38 Who Did It
    04:13 Canadian Utility Breach
    04:54 BSides Lessons Learned
    05:51 Insurance War Game
    07:59 Uninsurable Risk Fixes
    09:00 DEF CON Franklin Volunteers
    10:11 Franklin Findings Challenges
    11:24 Local Sharing Next Steps
    11:55 Wrap Up Listener Notes
    12:46 Sponsor NordLayer Again
  • Cybersecurity Today

    Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi

    03/08/2026 | 13min
    Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw

    David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber evaluations July 23.
    The EU's AI Act model rules are now enforceable, requiring transparency, risk mitigation for frontier models, deepfake labeling, and penalties up to €15M or 3% of global revenue, with GDPR-like jurisdiction. Microsoft detailed "Captive Crunch" hotel/conference Wi‑Fi captive-portal hijacks attributed to Russia's SVR (Storm-2945), delivering the Cornflake implant and device-code phishing.
    A ColdCard firmware RNG flaw enabled thefts totaling $88.6M. Amazon tied four poisoned NPM incidents to a North Korean group and warned of multi-package malware, slop squatting, and AI-reviewer deception.

    00:00 NordLayer Sponsor Message
    00:37 Today's Cyber Headlines
    01:09 Claude Models Escape Sandbox
    03:43 EU AI Act Now Enforceable
    05:31 Hotel WiFi Hijack Malware
    07:54 ColdCard Seed Flaw Heist
    09:42 North Korea NPM Poisoning
    11:27 Wrap Up and Events
    12:08 NordLayer Sponsor Reminder
  • Cybersecurity Today

    Healthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident Readiness

    01/08/2026 | 22min
    On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026.
     
    Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes.
     
    He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response.
     
    The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools.
     
    00:00 Weekend Show Intro
    00:39 Meet Matt Burke
    01:23 Concierge Care Model
    02:45 Why Healthcare Security
    03:13 Origin Story 3AM Call
    05:20 Top Threats 2026
    06:29 Defense Tools That Work
    07:50 AI Helps And Hurts
    09:37 Winning Doctor Buy In
    10:57 Castle Versus Response
    13:42 Threat Surge And Resilience
    18:17 Culture And MFA Everywhere
    19:59 Career Advice And Magic Wand
    22:33 Closing Thanks
  • Cybersecurity Today

    OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

    31/07/2026 | 11min
    OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover
     
    David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.
     
    Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.
     
    Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets.
    MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.
     
    00:00 Headlines and intro
    00:29 OpenAI rogue agent fallout
    02:18 Genie effect and benchmarks
    03:29 Minnesota water systems hit
    05:02 Iran-linked PLC warnings
    06:23 Exchange OWA mailbox backdoor
    08:24 Medical billing breach tally
    09:43 IPMI BMCs exposed online
    11:00 Wrap-up and next episodes
Mais podcasts de Negócios
Sobre Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Site de podcast

Ouça Cybersecurity Today, Como Você Fez Isso? e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net

  • Guardar rádios e podcasts favoritos
  • Transmissão via Wi-Fi ou Bluetooth
  • Carplay & Android Audo compatìvel
  • E ainda mais funções
Cybersecurity Today: Podcast do grupo
Aplicações
Social
v8.12.4 | © 2007-2026 radio.de GmbH
Generated: 8/7/2026 - 7:27:31 PM