Saltar al contenido
PodcastsEconomía y empresaCybersecurity Today

Cybersecurity Today

David Shipley
Cybersecurity Today
Último episodio

489 episodios

  • Cybersecurity Today

    FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos

    04/09/2026 | 11 min
    153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments
    The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to IDscan.net before Nexus abruptly disappeared.
    It also covers a breach at healthcare SaaS provider Aesto Health affecting 9.54 million individuals, exposing extensive personal and medical data, with delayed confirmation and notifications and 24 months of Experian monitoring offered.
    The show details CISA ending six free critical-infrastructure cybersecurity assessments amid workforce reductions, raising concerns given recent targeting of U.S. water systems and warnings about AI-generated exploitation scripts against Siemens PLCs.
    Additional updates include Plex urging immediate patching of undisclosed vulnerabilities and Slovenia's HIT gradually reopening casinos after a cyberattack forced a three-day shutdown.
    00:00 Top Cyber Headlines
    00:29 Dark Web License Leak
    02:33 Nexus Tied to IDscan
    04:05 Healthcare SaaS Breach
    05:35 CISA Cuts Assessments
    07:16 Plex Patch Alert
    08:43 Slovenian Casinos Recover
    10:05 Weekend Interview Preview
    10:53 Closing and Sign Off
  • Cybersecurity Today

    22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance

    02/09/2026 | 8 min
    22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk

    Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911, enabling mailbox takeover, with exploit code circulating and Germany warning most on-prem Exchange remains vulnerable as support deadlines loom.
    The U.S. DOJ also corrected a press release to say multiple U.S. agencies were targeted—not confirmed victims—by China-linked QTFY intrusions.
    Postmortems on the OpenAI/Hugging Face incident describe roughly 700 agents coordinating via shared notes and messaging to exploit systems, steal tokens and credentials, execute commands, and compromise infrastructure before Hugging Face shut it down July 13.
    Palo Alto Unit 42 warns AI-driven exploitation is arriving, citing a case where AI leveraged 50 vulnerabilities in 10 hours. The Financial Stability Board calls frontier-AI cyber risk the most immediate threat to global finance and urges stronger safeguards and recovery planning.

    00:00 Today's Cyber Headlines
    00:32 Exchange Servers Wide Open
    02:36 DOJ Walks Back Claims
    03:29 700 Agents Hit Hugging Face
    05:09 AI Exploits 50 Bugs Fast
    06:43 Financial Watchdog Warns
    08:25 Wrap Up and Sign Off
  • Cybersecurity Today

    ShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid tech

    31/08/2026 | 11 min
    Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech
     
    Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently verified. PaperCut issued a second emergency patch after bypasses were found for fixes to two actively exploited vulnerabilities that can be chained for unauthenticated remote code execution; organizations on v23 or earlier must upgrade. Berlin confirms an extortion attempt tied to Rhysida, which claims 5.79TB stolen. WordPress discloses five critical plugin/theme flaws enabling full site takeover, including a 10/10 GiveWP RCE. The White House bans foreign-made bulk power grid equipment over backdoor concerns amid rising critical-infrastructure attacks.
     
    00:00 Top Headlines
    00:30 McKesson Breach Fallout
    03:18 PaperCut Patch Bypassed
    06:02 Berlin Rejects Ransom
    07:05 Critical WordPress Takeovers
    08:43 Power Grid Tech Ban
    10:35 AI Security Weekend Episode Promo
    11:10 Closing and Sign Off
  • Cybersecurity Today

    How Varonis hacks AIs into snitching on themselves

    29/08/2026 | 29 min
    Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta
    The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Copilot (including "CoSnitch") and an Atlassian Confluence issue dubbed "RovoBlast" involving prompt injection, bypassing guardrails, and data exfiltration via a web-capable subagent.
    Vaitsman explains why built-in model guardrails are insufficient, citing AI's lack of loyalty and "unlimited hunger for data," and argues for layered controls like least privilege, monitoring, and restricting data access.
    He discusses psychological guardrail bypasses, introduces an "AI Hacking Trifecta" framework—enter, evade, escape—and comments on research showing AI-generated patches often fail, emphasizing human-led validation and guidance when using AI tools for security research.
    00:00 Weekend Show Kickoff
    00:44 Meet Mark Vaitsman
    03:38 Teaching the Next Gen
    04:19 Copilot Exploit Code Snitch
    06:04 Atlassian RoboBlast Breakdown
    08:52 Why Guardrails Fail
    13:15 Manipulating Models to Comply
    17:06 Securing Agents Without Handcuffs
    20:11 AI Hacking Trifecta Framework
    23:43 AI Patches and Human Research
    27:43 Hope and Closing Thoughts
  • Cybersecurity Today

    Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms

    28/08/2026 | 11 min
    Team PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned
    Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials and data.
    Boston Scientific disclosed a cyberattack that caused network outages and disrupted global operations, halting its ability to ship devices like pacemakers and stents, with recovery expected to take weeks. 
    The U.S. Justice Department disrupted QScan and Q2Router, platforms tied to China-linked QTFY, used to proxy intrusions against U.S. agencies and an election system.
    House Democrats asked GAO to assess how major workforce cuts have impacted CISA.
    Forcepoint demonstrated invisible-text prompt injection that fooled an AI email summarizer into fabricating invoice details.
    00:00 Headlines Overview
    00:29 Team PCP Arrests
    02:11 Krebs Investigation
    03:06 Boston Scientific Disruption
    04:50 Podcast Reviews Thanks
    05:07 FBI Disrupts QTFY Tools
    05:50 How QScan Pipeline Worked
    07:27 CISA Workforce Cuts
    08:53 Invisible Text AI Poisoning
    10:27 Wrap Up And Teaser
Más podcasts de Economía y empresa
Acerca de Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Sitio web del podcast

Escucha Cybersecurity Today, Maldita Pobreza y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app