PodGrabber.com
PodGrabber Logo/Mascot - Blue Gorilla with Red Headphones

Cyber Security Headlines - Archive

Generated 2026-08-14 01:19:10

← Back to PodGrabber Archives

Click title to play/pause!

Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy

Podcast image

Published: 08/14/2026 01:00:00

Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy Episode Details

Akira affiliate's innovative "crash mode" attack almost worked WhatsApp rolls out scam alert feature White House looks to private sector for help against offensive hacking Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/ Huge thanks to our sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON

Podcast image

Published: 08/13/2026 01:00:00

UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON Episode Details

UK eyes AI gene-synthesis guardrails DeadLock puts ransomware on the blockchain An evil twin flies home from DEF CON Episode show notes: https://cisoseries.com/uk-tackles-ai-bioweapon-risk-deadlock-goes-on-chain-evil-twin-flies-home-from-def-con/ Huge thanks to our sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline

Podcast image

Published: 08/12/2026 01:00:00

Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline Episode Details

Water systems get a federal cyber lifeline Hackers jump into Polish power plant Cyberattacks knock local governments offline Episode show notes: https://cisoseries.com/water-systems-cyber-lifeline-hackers-polish-power-plant-local-governments-offline/ Huge thanks to our sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits

Podcast image

Published: 08/11/2026 01:00:00

Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits Episode Details

OpenAI loosens cyber limits for vetted defenders Sandworm's fake recruiters plant a poisoned VPN Royal Navy drones phone home to China Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/ Huge thanks to our sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady

Podcast image

Published: 08/10/2026 01:00:00

OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady Episode Details

OpenAI slows release of Astra model citing cyber capabilities Irregular won't say if there were more rogue incidents U.S. cyber ambassador nominee Cassady confirmed in Senate Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/ Huge thanks to our sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

Faked bug reports, Meta's rogue AI, China investigates Palo Alto

Podcast image

Published: 08/07/2026 01:00:00

Faked bug reports, Meta's rogue AI, China investigates Palo Alto Episode Details

Apple's bug bounty program overwhelmed by fake AI generated reports China launches cybersecurity review into Palo Alto Networks products Meta AI hacks external systems during cybersecurity testing Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon

Podcast image

Published: 08/06/2026 01:00:00

AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon Episode Details

AI safety tests spill onto the real internet Private Relay flaw unmasks IP addresses Weak telcos left door open for Salt Typhoon Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/ Huge thanks to our episode sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa

Podcast image

Published: 08/05/2026 01:00:00

ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa Episode Details

ChainDrop attack hits npm Pass-ta-key attacks target passkeys AI accounts for most cybercrime in Africa Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/ Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window

Podcast image

Published: 08/04/2026 01:00:00

License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window Episode Details

When license plate readers become stalking tools ExfilSquad dumps UK police contact data China-linked hackers shrink the patch window Get the show notes here: https://cisoseries.com/cybersecurity-news-license-plate-readers-as-stalking-tools-exfilsquad-dumps-uk-police-data-the-ever-shrinking-patch-window/ Huge thanks to our episode sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

UK investments agency breach, CISA water warning, Anthropic rogue threesome

Podcast image

Published: 08/03/2026 01:00:00

UK investments agency breach, CISA water warning, Anthropic rogue threesome Episode Details

UK's state investments agency suffers data breach CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks Anthropic says its AI hacked real-world companies in three incidents Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face

Podcast image

Published: 07/31/2026 13:59:00

The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video.

Analog Devices breach, Copilot AI worm, Teams ransomware vishing

Podcast image

Published: 07/31/2026 01:00:00

Analog Devices breach, Copilot AI worm, Teams ransomware vishing Episode Details

Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead to Chaos ransomware attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start

OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money

Podcast image

Published: 07/30/2026 01:00:00

OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money Episode Details

OpenAI agent's escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/ Huge thanks to our sponsor, Pindrop TIME named Pindrop one of the 10 Most Influential Software Companies of 2026. Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended. Don't wait for an incident report. Visit pindrop.com.

Leaky BMCs, Claude finds encryption flaws, Google's new names

Podcast image

Published: 07/29/2026 01:00:00

Leaky BMCs, Claude finds encryption flaws, Google's new names Episode Details

Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/ Huge thanks to our sponsor, Pindrop AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report. Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.

Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data

Podcast image

Published: 07/28/2026 01:00:00

Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data Episode Details

Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

Iran infrastructure warning, ChatGPT global outage, self-assembling malware

Podcast image

Published: 07/27/2026 01:00:00

Iran infrastructure warning, ChatGPT global outage, self-assembling malware Episode Details

U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.

The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown

Podcast image

Published: 07/24/2026 15:05:00

The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates

AI agents risk, Upbound Group breach, Dolphin X Stealer

Podcast image

Published: 07/24/2026 01:00:00

AI agents risk, Upbound Group breach, Dolphin X Stealer Episode Details

AI Agents become fastest growing exposed attack surface Consumer finance company Upbound Group blames data breach for millions in losses Dolphin X Stealer uses AI profiling to prioritize targets Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp

Podcast image

Published: 07/23/2026 01:00:00

OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp Episode Details

OpenAI behind Hugging Face hack TrickBot tunnels through DNS Acrobat extension opens WhatsApp Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

Bit2Watt instability, AI models cheat, Chinese LLM ban

Podcast image

Published: 07/22/2026 01:00:00

Bit2Watt instability, AI models cheat, Chinese LLM ban Episode Details

Bit2Watt threatens power stability All AI models cheat at cyber evaluations US weighing Chinese LLM ban Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race

Podcast image

Published: 07/21/2026 01:00:00

Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race Episode Details

Hugging Face fights AI hacks with AI World Cup streamers get a red card WordPress enters a patching race Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents

Podcast image

Published: 07/20/2026 01:00:00

Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents Episode Details

Dairy company Fairlife suffers cyberattack Microsoft warns of surge in ACR Stealer attacks on customers Abbott Labs investigates two cyber incidents amid extortion claims Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

Podcast image

Published: 07/17/2026 15:12:00

The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back Episode Details

"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/ This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security

ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login

Podcast image

Published: 07/17/2026 01:00:00

ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login Episode Details

ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what

Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill

Podcast image

Published: 07/16/2026 01:00:00

Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill Episode Details

Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed

CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing

Podcast image

Published: 07/15/2026 01:00:00

CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing Episode Details

Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran "Context Bombing" flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access

Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice

Podcast image

Published: 07/14/2026 01:00:00

Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice Episode Details

Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are

Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning

Podcast image

Published: 07/13/2026 01:00:00

Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning Episode Details

Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater

The Department of Know: France gets ready for quantum, JadePuffer ransomware, UK's Cyber Shield

Podcast image

Published: 07/10/2026 15:17:00

The Department of Know: France gets ready for quantum, JadePuffer ransomware, UK's Cyber Shield Episode Details

Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a

Interpol's global fraud sweep, China's Claude Code flag, old Github account tricks

Podcast image

Published: 07/10/2026 01:00:00

Interpol's global fraud sweep, China's Claude Code flag, old Github account tricks Episode Details

Interpol's fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future

Mexico's big cyber test, Roundcube mailserver snooped on, Cash App found lax

Podcast image

Published: 07/09/2026 01:00:00

Mexico's big cyber test, Roundcube mailserver snooped on, Cash App found lax Episode Details

Mexico's first cyber test gets tested Snoops break into Roundcube mailservers Cash App owner pays up over lax security Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey

UK Cyber Shield, Japanese telco attack, China AI model limits

Podcast image

Published: 07/08/2026 01:00:00

UK Cyber Shield, Japanese telco attack, China AI model limits Episode Details

The UK's Cyber Pledge and Cyber Shield Millions exposed in Japanese telco attack China looking to curb overseas model access Get the show notes here: Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey

India tax RAT, prompt injection crypto scam, France pushes quantum-safe

Podcast image

Published: 07/07/2026 01:00:00

India tax RAT, prompt injection crypto scam, France pushes quantum-safe Episode Details

Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT Prompt injection attacks trick AI Agents into making crypto payments France to stop certifying products without quantum-safe encryption Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used

First AI ransomware, AdaptHealth suffers cyberattack, UK cyber plan delayed

Podcast image

Published: 07/06/2026 01:00:00

First AI ransomware, AdaptHealth suffers cyberattack, UK cyber plan delayed Episode Details

JadePuffer ransomware used AI agent to automate entire attack AdaptHealth suffers cyberattack UK's National Cyber Action Plan launch delayed by political leadership crisis Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like

The Department of Know: PeopleSoft exploit, Ford brings back gray beards, LLM vetting

Podcast image

Published: 07/03/2026 14:30:00

The Department of Know: PeopleSoft exploit, Ford brings back gray beards, LLM vetting Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm. Get the show notes here: https://cisoseries.com/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers

Consumer security worries, Vought supervises spy budgets, Fortibleed exposes Fortinet

Podcast image

Published: 07/03/2026 01:00:00

Consumer security worries, Vought supervises spy budgets, Fortibleed exposes Fortinet Episode Details

Card data theft remains top concern for U.S. consumers OMB chief to oversee spy agency budgets Fortibleed leads to ransomware attacks and 430,000 Fortinet firewalls exposed Get the show notes here: https://cisoseries.com/cybersecurity-news-consumer-security-worries-vought-supervises-spy-budgets-fortibleed-exposes-fortinet/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs,

Hide My Email bug shows real addresses, Fable 5 gets the greenlight, Microsoft Teams hits back on AI bots

Podcast image

Published: 07/02/2026 01:00:00

Hide My Email bug shows real addresses, Fable 5 gets the greenlight, Microsoft Teams hits back on AI bots Episode Details

Hide My Email bug shows real addresses Fable 5 gets the greenlight DHS confirms hackers breached HSIN Get the show notes here: https://cisoseries.com/cybersecurity-news-hide-my-email-shows-real-addresses-fable-5-gets-greenlight-microsoft-teams-hits-back-on-bots/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators

Bash hits AI, DHS announces ANCHOR-CI, Aikido buys Root

Podcast image

Published: 07/01/2026 01:00:00

Bash hits AI, DHS announces ANCHOR-CI, Aikido buys Root Episode Details

Bash can spell trouble GNU for AI agents DHS to unveil critical infrastructure council Aikido buys Root Get the show notes here: https://cisoseries.com/cybersecurity-news-bash-hits-ai-dhs-announces-anchor-ci-aikido-buys-root/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators

US seizes illegal World Cup domains, WhatsApp offers usernames for phone privacy, $10M reward for Russia-based cyber campaign

Podcast image

Published: 06/30/2026 01:00:00

US seizes illegal World Cup domains, WhatsApp offers usernames for phone privacy, $10M reward for Russia-based cyber campaign Episode Details

US seizes illegal World Cup domains WhatsApp offers usernames for phone number privacy $10M reward for Russia-based cyber campaign Get the show notes here: https://cisoseries.com/cybersecurity-news-us-seizes-illegal-world-cup-domains-whatsapp-offers-usernames-for-phone-privacy-10m-reward-for-cyber-campaign/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that

CISA's Cisco deadline, China's Mythos competitor, Amazon Q flaw

Podcast image

Published: 06/29/2026 01:00:00

CISA's Cisco deadline, China's Mythos competitor, Amazon Q flaw Episode Details

CISA sets urgent deadline to fix exploited Cisco flaw Chinese cybersecurity company claims it has a better-than-Mythos bug finder Amazon Q flaw enables cloud credential theft Get the show notes here: https://cisoseries.com/cybersecurity-news-cisas-cisco-deadline-chinas-mythos-competitor-amazon-q-flaw/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs,

ShinyHunters hits MSG, Cal Water confirms no damage, CISA SASE guide

Podcast image

Published: 06/26/2026 01:00:00

ShinyHunters hits MSG, Cal Water confirms no damage, CISA SASE guide Episode Details

ShinyHunters hits Madison Square Garden Cal Water finds no evidence of OT activity New CISA guide helps agencies adopt SASE for Zero Trust Get the show notes here: https://cisoseries.com/cybersecurity-news-shinyhunters-hits-msg-cal-water-confirms-no-damage-cisa-sase-guide/ Huge thanks to our episode sponsor, Guardsquare Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

Copilot AI attacks cybercrime tools, hackers exploit Cisco zero-day, China's 360 vs Mythos

Podcast image

Published: 06/25/2026 01:00:00

Copilot AI attacks cybercrime tools, hackers exploit Cisco zero-day, China's 360 vs Mythos Episode Details

Copilot AI knocks down cybercrime tools Hackers exploit Cisco zero-day China's 360 says it matches Anthropic's Mythos Get the show notes here: https://cisoseries.com/cybersecurity-news-copilot-ai-attacks-cybercrime-tools-hackers-exploit-cisco-zero-day-chinas-360-vs-mythos/ Huge thanks to our episode sponsor, Guardsquare AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

Feds seize scam infrastructure, Dragos unveils AI for OT security, Scattered Spider hackers plead guilty

Podcast image

Published: 06/24/2026 01:00:00

Feds seize scam infrastructure, Dragos unveils AI for OT security, Scattered Spider hackers plead guilty Episode Details

Feds seize alleged cyber-scam infrastructure Dragos unveils AI for OT security Scattered Spider hackers plead guilty Get the show notes here: https://cisoseries.com/cybersecurity-news-feds-seize-scam-infrastructure-dragos-unveils-ai-for-ot-security-scattered-spider-hackers-plead-guilty/ Huge thanks to our episode sponsor, Guardsquare Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

OpenAI takes on Mythos, Klue hits security shops, Five Eyes has eyes on AI

Podcast image

Published: 06/23/2026 01:00:00

OpenAI takes on Mythos, Klue hits security shops, Five Eyes has eyes on AI Episode Details

OpenAI takes on Anthropic's Mythos Klue hack hits security shops Five Eyes has eyes on AI models Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-takes-on-mythos-klue-hits-security-shops-five-eyes-has-eyes-on-ai/ Huge thanks to our episode sponsor, Guardsquare Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

Brazil phone alert hack, Prinz Eugen ransomware, Congress deepfake bill

Podcast image

Published: 06/22/2026 01:00:00

Brazil phone alert hack, Prinz Eugen ransomware, Congress deepfake bill Episode Details

Hackers suspected in Brazil cell phone alert Prinz Eugen ransomware prioritizes recent files for encryption Congress presents bill to protect people from AI-generated deepfakes Get the show notes here: https://cisoseries.com/cybersecurity-news-brazil-phone-alert-hack-prinz-eugen-ransomware-congress-deepfake-bill/ Huge thanks to our episode sponsor, Guardsquare Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection.

The Department of Know: SearchLeak, Check Point zero-day, and pulling the plug on Fable

Podcast image

Published: 06/19/2026 14:00:00

The Department of Know: SearchLeak, Check Point zero-day, and pulling the plug on Fable Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over

Police clean WordPress sites, Klue OAuth breach, Warner's CISA warnings

Podcast image

Published: 06/19/2026 01:00:00

Police clean WordPress sites, Klue OAuth breach, Warner's CISA warnings Episode Details

Police clean ups SocGholish-infected sites tied to Evil Corp Klue OAuth breach linked to Icarus Salesforce data theft attacks Warner warns of CISA cuts, staffing gaps in letter to acting chief Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them

Anthropic tells G7 to cooperate, Fortinet VPN leak exposes credentials, Crypto Clipper abuses reviews

Podcast image

Published: 06/18/2026 01:00:00

Anthropic tells G7 to cooperate, Fortinet VPN leak exposes credentials, Crypto Clipper abuses reviews Episode Details

Anthropic tells G7 to cooperate Fortinet VPN leak exposes credentials Crypto Clipper abuses reviews, narrators, and comments Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-tells-g7-to-cooperate-fortinet-vpn-leak-exposes-credentials-crypto-clipper-abuses-reviews/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users

Athena coalition, Estonia's quarantine, Arch hit with malware

Podcast image

Published: 06/17/2026 01:00:00

Athena coalition, Estonia's quarantine, Arch hit with malware Episode Details

Athena coalition looks to secure open source Estonia to quarantine Russian email domains Malicious package wave hits Arch Linux Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and

Anthropic models defended, FBI shuts down massive phishing service, 1Password acquires Apono

Podcast image

Published: 06/16/2026 01:00:00

Anthropic models defended, FBI shuts down massive phishing service, 1Password acquires Apono Episode Details

Cyber leaders defend Anthropic's banned models FBI disrupts massive phishing service 1Password acquires Apono Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are

Feds ban Fable, Maine portal disabled, ShinyHunters exploits Oracle

Podcast image

Published: 06/15/2026 01:00:00

Feds ban Fable, Maine portal disabled, ShinyHunters exploits Oracle Episode Details

Feds require Anthropic to ban 'foreign national' access to Fable, Mythos Maine disables data breach notification portal after fake disclosures ShinyHunters extorts universities through exploiting an unpatched Oracle flaw Get the show notes here: Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over

The Department of Know: CISA's quick patch, Miasma attacks, judge finds AI guilty

Podcast image

Published: 06/12/2026 15:49:00

The Department of Know: CISA's quick patch, Miasma attacks, judge finds AI guilty Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our episode sponsor, Doppel Cybercriminals don't respect your security silos. They use one connected attack chain to hit your brand externally, infiltrate your

Fortinet patches FortiSandbox, GitHub disables npm scripts, Nottingham University breach

Podcast image

Published: 06/12/2026 01:00:00

Fortinet patches FortiSandbox, GitHub disables npm scripts, Nottingham University breach Episode Details

Fortinet patches a new critical FortiSandbox flaw GitHub to disable npm install scripts by default to stop supply chain attacks Nottingham University announces data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-fortinet-patches-fortisandbox-github-disables-npm-scripts-nottingham-university-breach/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing

Big Patch Tuesday, 'Nightmare Eclipse' drops Windows 0-day, Claude Fable restricted at Microsoft

Podcast image

Published: 06/11/2026 01:00:00

Big Patch Tuesday, 'Nightmare Eclipse' drops Windows 0-day, Claude Fable restricted at Microsoft Episode Details

Patch Tuesday for the books 'Nightmare Eclipse' drops Windows 0-day Claude Fable restricted at Microsoft Get the show notes here: https://cisoseries.com/cybersecurity-news-big-patch-tuesday-nightmare-eclipse-drops-windows-0-day-claude-fable-restricted-at-microsoft/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

Fable 5, Tchap hacked, CISA priorities

Podcast image

Published: 06/10/2026 01:00:00

Fable 5, Tchap hacked, CISA priorities Episode Details

Anthropic releases Claude Fable 5 French government messaging service breached CISA rethinking risk evaluations Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-fable-5-tchap-hacked-cisa-priorities/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

Claude & Gemini malware, Mythos sneaky flaws, Instagram AI abuse

Podcast image

Published: 06/09/2026 01:00:00

Claude & Gemini malware, Mythos sneaky flaws, Instagram AI abuse Episode Details

Microsoft malware hits Claude and Gemini users Mythos can exploit new flaws in hours AI tool abuse behind Instagram hacks Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-gemini-malware-mythos-sneaky-flaws-instagram-ai-abuse/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering.

CISA Palantir Director, EU tech sovereignty, SolarWinds Serv-U flaw

Podcast image

Published: 06/08/2026 01:00:00

CISA Palantir Director, EU tech sovereignty, SolarWinds Serv-U flaw Episode Details

Palantir executive considered for CISA leadership EU unveils tech sovereignty package to cut reliance on U.S., Chinese suppliers Hackers now exploit SolarWinds Serv-U flaw to crash servers Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-palantir-director-eu-tech-sovereignty-solarwinds-serv-u-flaw/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people.

The Department of Know: NVD audit, Meta's leaky AI, Microsoft is closer to quantum

Podcast image

Published: 06/05/2026 16:02:00

The Department of Know: NVD audit, Meta's leaky AI, Microsoft is closer to quantum Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian. Get the show notes here. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in

Chinese cybercrime group, Cisco CM flaw, CISA faces changes

Podcast image

Published: 06/05/2026 01:00:00

Chinese cybercrime group, Cisco CM flaw, CISA faces changes Episode Details

Chinese cybercrime group sets record pace Cisco warns of critical Unified CM flaw with PoC exploit code Hackers spied on a stock exchange executive's Outlook mailbox for five months Get the show notes here: https://cisoseries.com/cybersecurity-news-chinese-cybercrime-group-cisco-cm-flaw-cisa-faces-changes/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is

Illegal streamers, EU digital sovereignty, cost of a cyber force

Podcast image

Published: 06/04/2026 01:00:00

Illegal streamers, EU digital sovereignty, cost of a cyber force Episode Details

Law enforcement cracks down on illegal streamers The European Commission releases digital sovereignty plan The startup costs for US cyber force Get the show notes here: https://cisoseries.com/cybersecurity-news-illegal-streamers-eu-digital-sovereignty-cost-of-a-cyber-force/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving

Russia claims officials' surveillance, Project Glasswing expands, CISA flags two-year-old Oracle flaw

Podcast image

Published: 06/03/2026 01:00:00

Russia claims officials' surveillance, Project Glasswing expands, CISA flags two-year-old Oracle flaw Episode Details

Russia claims officials' surveillance Project Glasswing access expands CISA flags two-year-old Oracle flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are

Meta AI hands over Instagram access, Dutch police dismantle botnet, RedHat packages backdoored

Podcast image

Published: 06/02/2026 01:00:00

Meta AI hands over Instagram access, Dutch police dismantle botnet, RedHat packages backdoored Episode Details

Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and

GlobalProtect VPN exploited, ChatGPT share links exploits, Feds criticize NIST

Podcast image

Published: 06/01/2026 01:00:00

GlobalProtect VPN exploited, ChatGPT share links exploits, Feds criticize NIST Episode Details

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks ChatGPT share links used to host fake outage pages to deliver malware Federal audit reveals NIST's NVD problems Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is

The Department of Know: Google's CodeMender, CISA's big leak, Torvalds open-source warning

Podcast image

Published: 05/29/2026 15:29:00

The Department of Know: Google's CodeMender, CISA's big leak, Torvalds open-source warning Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Bruce Schneier, chief of security architecture, Inrupt, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. Huge thanks to our sponsor, Guardsquare Mobile security incidents are no longer the exception—they are the norm. Last year, seventy-two percent of companies suffered a mobile app security incident. As the primary gateway to your APIs and data, your mobile app requires more than just basic encryption; it needs a multi-layered security strategy. Protect your brand and

World Cup fraud, US military location targets, IBM and Red Hat go Project Lightwell

Podcast image

Published: 05/29/2026 01:00:00

World Cup fraud, US military location targets, IBM and Red Hat go Project Lightwell Episode Details

Fraud gang steals from World Cup fans Pentagon says US military targeted by location IBM and Red Hat commit to "Project Lightwell" Check out your show notes here: https://cisoseries.com/cybersecurity-news-world-cup-fraud-us-military-location-targets-ibm-and-red-hat-go-project-lightwell/ Huge thanks to our sponsor, Guardsquare Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

Glassworm botnet shattered, China overhauls surveillance, Charter confirms ShinyHunters breach

Podcast image

Published: 05/28/2026 01:00:00

Glassworm botnet shattered, China overhauls surveillance, Charter confirms ShinyHunters breach Episode Details

Glassworm botnet gets shattered China overhauls world's biggest surveillance network Charter confirms ShinyHunters data breach Check out your show notes here: https://cisoseries.com/cybersecurity-news-glassworm-botnet-shattered-china-overhauls-surveillance-charter-confirms-shinyhunters-breach/ Huge thanks to our sponsor, Guardsquare AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

Nimbus Manticore, real-time credential harvesting, the 12-hour patch

Podcast image

Published: 05/27/2026 04:27:00

Nimbus Manticore, real-time credential harvesting, the 12-hour patch Episode Details

Nimbus Manticore learning new tricks Phishing moves to real-time credential harvesting India wants 12-hour patches Check out your show notes here: https://cisoseries.com/cybersecurity-news-nimbus-manticore-real-time-credential-harvesting-12-hour-patches/ Huge thanks to our sponsor, Guardsquare Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

Megalodon infects GitHub repositories, Netherlands seizes 800 servers, Ghost CMS exploited for ClickFix attacks

Podcast image

Published: 05/26/2026 01:00:00

Megalodon infects GitHub repositories, Netherlands seizes 800 servers, Ghost CMS exploited for ClickFix attacks Episode Details

'Megalodon' infects GitHub repositories Netherlands seizes 800 servers over cyberattacks Ghost CMS exploited for ClickFix attacks Check out your show notes here: https://cisoseries.com/cybersecurity-news-megalodon-infects-github-netherlands-server-seize-ghost-cms-exploited-for-clickfix/ Huge thanks to our sponsor, Guardsquare Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

Drupal KEV addition, Underminr revives domain fronting, Canadian KimWolf arrest

Podcast image

Published: 05/25/2026 01:00:00

Drupal KEV addition, Underminr revives domain fronting, Canadian KimWolf arrest Episode Details

CISA adds Drupal Core flaw to KEV Underminr hides malicious connections behind trusted domains Canadian man charged with running KimWolf DDoS botnet Check out your show notes here: https://cisoseries.com/cybersecurity-news-drupal-kev-addition-underminr-revives-domain-fronting-canadian-kimwolf-arrest/ Huge thanks to our sponsor, Guardsquare Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more

The Department of Know: Google's CodeMender, CISA's big leak, Torvalds open-source warning

Podcast image

Published: 05/22/2026 15:16:00

The Department of Know: Google's CodeMender, CISA's big leak, Torvalds open-source warning Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials

Cisco's 10.0 vulnerability, Microsoft email spammed, Chrome vulnerability surge

Podcast image

Published: 05/22/2026 01:00:00

Cisco's 10.0 vulnerability, Microsoft email spammed, Chrome vulnerability surge Episode Details

Cisco issues 10.0 Secure Workload admin flaw warning Spammers abuse internal Microsoftonline account Google's surge in Chrome vulnerability announcements Get the show notes here: https://cisoseries.com/cybersecurity-news-ciscos-10-0-vulnerability-microsoft-email-spammed-chrome-vulnerability-surge/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With

GitHub VS Code extension breach, Shai-Hulud npm package compromise, Huawei/Luxembourg telecom link

Podcast image

Published: 05/21/2026 01:00:00

GitHub VS Code extension breach, Shai-Hulud npm package compromise, Huawei/Luxembourg telecom link Episode Details

GitHub breach via VS Code extension Shai-Hulud wave compromises 600 npm packages Huawei attack behind Luxembourg telecom crash Get the show notes here: https://cisoseries.com/cybersecurity-news-github-vs-code-extension-breach-shai-hulud-npm-package-compromise-huawei-luxembourg-telecom-link/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker,

Microsoft hits Fox Tempest, robotics OS flaw, CISA admins leaks keys

Podcast image

Published: 05/20/2026 01:00:00

Microsoft hits Fox Tempest, robotics OS flaw, CISA admins leaks keys Episode Details

Microsoft disrupts malware-signing-as-a-service Critical flaw found in industrial robot OS CISA admin leaks keys Get the show notes here: https://cisoseries.com/cybersecurity-news-microsoft-hits-fox-tempest-robotics-os-flaw-cisa-admins-leaks-keys/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and

Linus Torvalds talks AI bug hunters, 7-Eleven ransom demand, MENA's new cybercrime op

Podcast image

Published: 05/19/2026 01:00:00

Linus Torvalds talks AI bug hunters, 7-Eleven ransom demand, MENA's new cybercrime op Episode Details

Linus Torvalds not into AI bug hunters 7-Eleven hit with ransom demand MENA runs new cybercrime op Get the show notes here: https://cisoseries.com/cybersecurity-news-linus-torvalds-talks-ai-bug-hunters-7-eleven-ransom-demand-menas-new-cybercrime-op/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing

Grafan GitHub extortion, Microsoft rejects Azure report, Funnel Builder flaw

Podcast image

Published: 05/18/2026 01:00:00

Grafan GitHub extortion, Microsoft rejects Azure report, Funnel Builder flaw Episode Details

Grafana GitHub token breach leads to extortion attempt Microsoft rejects Azure vulnerability report, researcher disputes decision Funnel Builder flaw actively exploited to steal payment data Get the show notes here: https://cisoseries.com/cybersecurity-news-grafan-github-extortion-microsoft-rejects-azure-report-funnel-builder-flaw/ Thanks to our episode sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can

The Department of Know: GemStuffer attack, AI SBOMs, and AI-created zero-days

Podcast image

Published: 05/15/2026 15:02:00

The Department of Know: GemStuffer attack, AI SBOMs, and AI-created zero-days Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Gary Chan, CISO, SSM Health and Peter Liebert, CISO, Salesloft. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts

G7 releases AI SBOM, DELL SupportAssist BSOD, Dirty Frag sequel

Podcast image

Published: 05/15/2026 01:00:00

G7 releases AI SBOM, DELL SupportAssist BSOD, Dirty Frag sequel Episode Details

G7 countries release AI SBOM guidance Dell confirms its SupportAssist software causes Windows BSOD crashes Dirty Frag sequel arrives as Fragnesia Get the show notes here: https://cisoseries.com/cybersecurity-news-g7-releases-ai-sbom-dell-supportassist-bsod-dirty-frag-sequel/ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in

Foxconn confirms factory attacks, BitLocker zero-day accesses protected drives, MDASH patches Windows flaws

Podcast image

Published: 05/14/2026 01:00:00

Foxconn confirms factory attacks, BitLocker zero-day accesses protected drives, MDASH patches Windows flaws Episode Details

Foxconn confirms North American factory attack BitLocker zero-day accesses protected drives MDASH patches 16 Windows flaws Get the show notes here: https://cisoseries.com/cybersecurity-news-foxconn-factory-attacks-bitlocker-zero-day-accesses-protected-drives-mdash-patches-windows-flaws/↗ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at

Instructure's agreement, Shai Hulud campaign, OpenAI's Daybreak

Podcast image

Published: 05/13/2026 01:00:00

Instructure's agreement, Shai Hulud campaign, OpenAI's Daybreak Episode Details

Instructure reaches an "agreement" with ShinyHunters Shai Hulud campaign is back OpenAI launches Daybreak Get the show notes here: https://cisoseries.com/cybersecurity-news-instructures-agreement-shai-hulud-campaign-openais-daybreak/ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

A.I. software flaw hackers, Forza Horizon 6 leak, Linux kernel hit again

Podcast image

Published: 05/12/2026 01:00:00

A.I. software flaw hackers, Forza Horizon 6 leak, Linux kernel hit again Episode Details

A.I. hackers find software flaw Xbox leaks 'Forza Horizon 6' Linux kernel hit by 2nd flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-a-i-software-flaw-hackers-forza-horizon-6-leak-linux-kernel-hit-again/ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at

New cPanel vulnerabilities, JDownloader delivers malware, Schumer pushes DHS

Podcast image

Published: 05/11/2026 01:00:00

New cPanel vulnerabilities, JDownloader delivers malware, Schumer pushes DHS Episode Details

CPanel, WHM release fixes for three new vulnerabilities Official JDownloader site serves malware to Windows and Linux users Sen. Schumer seeks DHS plan on AI cyber coordination Get the show notes here: https://cisoseries.com/cybersecurity-news-new-cpanel-vulnerabilities-jdownloader-delivers-malware-schumer-pushes-dhs/ Huge thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and

The Department of Know: AI "transformation paradox," Copy Fail chaos, hacked lawnmowers

Podcast image

Published: 05/08/2026 14:56:00

The Department of Know: AI "transformation paradox," Copy Fail chaos, hacked lawnmowers Episode Details

Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Jonathan Waldrop, CISO, Acoustic, and Jason Elrod, CISO, MultiCare Health System. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one

PAN-OS RCE exploit , Poland water hacks, Ivanti EPMM flaw

Podcast image

Published: 05/08/2026 01:00:00

PAN-OS RCE exploit , Poland water hacks, Ivanti EPMM flaw Episode Details

PAN-OS RCE exploit under active use enabling root access and espionage Polish intelligence says hackers attacked water treatment control systems Ivanti warns of new EPMM flaw exploited in zero-day attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-pan-os-rce-exploit-poland-water-hacks-ivanti-epmm-flaw/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving.

Chrome installs AI model on devices, Daemon Tools disk app backdoored, crypto security exodus

Podcast image

Published: 05/07/2026 01:00:00

Chrome installs AI model on devices, Daemon Tools disk app backdoored, crypto security exodus Episode Details

Google Chrome installs 4GB AI model on devices Daemon Tools disk app backdoored in supply-chain attack Crypto's 'decentralised finance' sector hit by investor exodus Get the show notes here: Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Video game supply chain attack, Bleeding Llama, US gets early LLM access

Podcast image

Published: 05/06/2026 01:00:00

Video game supply chain attack, Bleeding Llama, US gets early LLM access Episode Details

Video game platform hit by supply chain attack Bleeding Llama could expose your data US gets more early LLM access Get the show notes here: https://cisoseries.com/cybersecurity-news-video-game-supply-chain-attack-bleeding-llama-us-gets-early-llm-access/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Instructure discloses breach, DigiCert revokes certificates, Silver Fox targets Indian and Russian orgs

Podcast image

Published: 05/05/2026 01:00:00

Instructure discloses breach, DigiCert revokes certificates, Silver Fox targets Indian and Russian orgs Episode Details

Instructure discloses breach amid leak threats DigiCert revokes certificates Silver Fox targets Indian and Russian orgs Get the show notes here: https://cisoseries.com/cybersecurity-news-instructure-discloses-breach-digicert-revokes-certificates-silver-fox-targets-indian-and-russian-orgs/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Telegram Mini Apps malware, cPanel is Sorry, patch wave warning

Podcast image

Published: 05/04/2026 01:00:00

Telegram Mini Apps malware, cPanel is Sorry, patch wave warning Episode Details

Telegram Mini Apps deliver Android malware CISA orders Federal agencies to patch cPanel bug by Sunday British cyber agency warns of looming 'patch wave' due to speedy AI flaw discovery Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving.

The Department of Know: GitHub drama, AI deletes production data, Claude Security Beta

Podcast image

Published: 05/01/2026 15:17:00

The Department of Know: GitHub drama, AI deletes production data, Claude Security Beta Episode Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and TC Niedzialkowski, Head of IT & Security, Opendoor. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/ Thanks to our episode sponsor, Guardsqaure Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or

Critical cPanel zero-day, Swiss Black Axe arrests, HHS data center questions

Podcast image

Published: 05/01/2026 01:00:00

Critical cPanel zero-day, Swiss Black Axe arrests, HHS data center questions Episode Details

Critical cPanel and WHM bug exploited as zero-day Swiss police arrest suspected members of Black Axe group HHS ponders government posture for protecting data centers Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/ Thanks to our episode sponsor, Guardsqaure Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

Roblox hackers arrested, Microsoft 0-day falls short, Dubai scam takedown

Podcast image

Published: 04/30/2026 01:00:00

Roblox hackers arrested, Microsoft 0-day falls short, Dubai scam takedown Episode Details

Hackers arrested for selling Roblox accounts Microsoft's patch for a 0-day falls short US & China partner on Dubai scam takedown Get the show notes here: https://cisoseries.com/cybersecurity-news-roblox-hackers-arrested-microsoft-0-day-falls-short-dubai-scam-takedown/ Thanks to our episode sponsor, Guardsqaure AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

Agent payments, Russian phishing, LeRobot RCE flaw

Podcast image

Published: 04/29/2026 01:00:00

Agent payments, Russian phishing, LeRobot RCE flaw Episode Details

FIDO Alliance working on securing AI agent payments Germany suspects Russia in Signal phishing RCE flaw in open-source robotics platform Get the show notes here: https://cisoseries.com/cybersecurity-news-agent-payments-russian-phishing-lerobot-rce-flaw/ Thanks to our episode sponsor, Guardsqaure Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

PhantomRPC flaw, Checkmarx GitHub dark web data, PyPI package infostealer

Podcast image

Published: 04/28/2026 01:00:00

PhantomRPC flaw, Checkmarx GitHub dark web data, PyPI package infostealer Episode Details

PhantomRPC flaw enables privilege escalation Checkmarx confirms GitHub data hit dark web PyPI package hacked to push infostealer Get the show notes here: https://cisoseries.com/cybersecurity-news-phantomrpc-flaw-checkmarx-github-dark-web-data-pypi-package-infostealer/ Thanks to our episode sponsor, Guardsqaure Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

ADT data breach, Toronto SMS blasting, pre-Stuxnet malware discovery

Podcast image

Published: 04/27/2026 01:00:00

ADT data breach, Toronto SMS blasting, pre-Stuxnet malware discovery Episode Details

ADT says customer data stolen in cyberattack SMS blasting comes to Toronto Researchers find pre-Stuxnet malware targeting engineering software Get the show notes here: https://cisoseries.com/cybersecurity-news-adt-data-breach-toronto-sms-blasting-pre-stuxnet-malware-discovery/ Thanks to our episode sponsor, Guardsquare Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.

The Department of Know: Vercel breach, a "Contagious Interview," and ghost breaches

Podcast image

Published: 04/24/2026 14:26:00

The Department of Know: Vercel breach, a "Contagious Interview," and ghost breaches Episode Details

Link to episode This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Michael Bickford, former CISO, New York State Gaming Commission. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud

Rituals cosmetics breach, FBI iOS flaw fixed, Teams Helpdesk impersonation

Podcast image

Published: 04/24/2026 01:00:00

Rituals cosmetics breach, FBI iOS flaw fixed, Teams Helpdesk impersonation Episode Details

Cosmetics giant Rituals discloses data breach Apple fixes iOS flaw exploited by the FBI Microsoft Teams Helpdesk impersonation Get the show notes here: https://cisoseries.com/cybersecurity-news-rituals-cosmetics-breach-fbi-ios-flaw-fixed-teams-helpdesk-malware-impersonation/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing

New OpenAI cyber product, unauthorized Mythos access, insurers to cap LLMjacking payouts

Podcast image

Published: 04/23/2026 01:00:00

New OpenAI cyber product, unauthorized Mythos access, insurers to cap LLMjacking payouts Episode Details

OpenAI shares cyber product with government orgs Unauthorized Mythos access, Firebox bugs fixed by Mythos Insurers move to cap LLMjacking cyber payouts Get the show notes here: https://cisoseries.com/cybersecurity-news-new-openai-cyber-product-unauthorized-mythos-access-insurers-to-cap-llmjacking-payouts/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of

CISA lacks Mythos, Lovable's leak by design, YouTube's deepfake detection

Podcast image

Published: 04/22/2026 01:00:00

CISA lacks Mythos, Lovable's leak by design, YouTube's deepfake detection Episode Details

CISA lacks Mythos access Lovable denies data leak YouTube opens up deepfake detection tool Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-lacks-mythos-lovables-leak-by-design-youtubes-deepfake-detection/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access

Vercel breach, ZionSiphon targets water infrastructure, Bluesky DDoS

Podcast image

Published: 04/21/2026 01:00:00

Vercel breach, ZionSiphon targets water infrastructure, Bluesky DDoS Episode Details

Vercel confirms breach, stolen data for sale ZionSiphon targets water infrastructure Bluesky blames outage on DDoS Get the show notes here: https://cisoseries.com/cybersecurity-news-vercel-breach-zionsiphon-targets-water-infrastructure-bluesky-ddos/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed,

London hospital ransomware legacy, PowerOFF takedown, Microsoft RedSun zero-day

Podcast image

Published: 04/20/2026 01:00:00

London hospital ransomware legacy, PowerOFF takedown, Microsoft RedSun zero-day Episode Details

London hospitals continue to suffer from 2024 ransomware attack Four arrested in PowerOFF takedown Microsoft Defender "RedSun" zero-day Get the show notes here: https://cisoseries.com/cybersecurity-news-london-hospital-ransomware-legacy-poweroff-takedown-microsoft-redsun-zero-day/ Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing

The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes

Podcast image

Published: 04/17/2026 15:45:00

The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes Episode Details

Link to episode page This week's Department of Know is hosted by Rich Stroffolino, with guests Andrew Storms, security engineering, Kilo Code, and Eduardo Ortiz-Romeu, VP, global head of cybersecurity, Techtronic Industries. Missed the live show? Check it out on YouTube. Huge thanks to our sponsor, Conveyor Happy Friday. Hope there isn't a fresh security questionnaire sitting in your inbox right now. If there is, here's something worth knowing. The teams that have fully automated their customer security reviews didn't just get a better trust center. They switched to an AI