SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
Sécurité des ERP
Episode #551 conscacré à la sécurité des ERP Avec Wael Feguiri The post Sécurité des ERP appeared first on NoLimitSecu.
The Insider You Built with author Camille Stewart Gloster. [Special Edition]
On this special edition podcast, N2K CyberWire's Dave Bittner spoke with Camille Stewart Gloster. Camille is the author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of CAS Strategies. Dave and Camille discuss her new book and the broader questio…
Space cybersecurity starts on the ground. [T-Minus: Space-Cyber Briefing]
Though spacecraft are important, space cybersecurity extends well beyond these assets touching ground stations, mission-control assets, and other critical components. Host Maria Varmazis speaks with Milenk Starcevic, cybersecurity lead at Vision Space, and Andrzej “Andy” Olchawa, a space-focused off…
An apple a day, a phish away. [Research Saturday]
Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation…
Shut it down before they do.
Kiteworks urges customers pull the plug on vulnerable servers. CISA lays out its election security plan. Known vulnerabilities linger unpatched. Big AI labs consider a new standards body. Questions surround claims of an OpenAI Medicare hack. File notifications become a privacy leak. SectopRAT hides …
SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
No factoring necessary.
Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches critical flaws. A placeholder domain delivers ClickFix. Digital forensics executiv…
AI Will Save Us, or Not? - PSW #945
In the security news this week: Build your own router, or just buy one What to patch first But maybe don't buy D-Link AI nearly starts a war Flock cameras lose their keys The AI slowdown won't save bad security Opus at home, just slower Black Hat says fundamentals still work Hacker gadgets, and my t…
404: scam not found.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…
SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
Vibe-coded shops, and hackable Flock cameras
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong?Meanwhile, a hacker collective backed a truck into one of the license-…
Risky Business #854 -- We're Jevpilled
THE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14 On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including: Google’s Gemini finally did some crimes OpenAI admits more agents did silly things because…
SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying. The wisdom of outs…
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
LOW - Now Available
After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop running from oursel…
dumpster diving (noun) [Word Notes]
Please enjoy this encore of Word Notes. The act of searching through an organization's trash for discarded sensitive material. CyberWire Glossary link: https://thecyberwire.com/glossary/dumpster-diving Audio reference link: “Better Call Saul jimmy digs in the Sandpiper trash scene,” uploaded by …
SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory
AI hates CAPTCHAs - PSW #944
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting requi…
Scamazon prime.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…
These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agr…
Risky Business #853 -- We're all gonna die, apparently
On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including: More tech guys penned more open letters and AI will destroy us all! Another Wednesda…
News mit Clickfix, RPKI, Roboterhacks und KI-Überlistung
Endlich wieder Aufnahmetag, die Themen stapeln sich schon! Sylvester und Christopher nutzen den Warntag, um vor allerlei Sicherheitsproblemen zu warnen. Den Auftakt macht diverser Kleinkram rund um Certificate Transparency und dann geht der Blick in die Bundeshauptstadt. Wie die Ransomware-Gangster …
SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security fixes. Five months after its start, what's the status of Project Glasswing? Ant…
SEO poisoning (noun) [Word Notes]
Please enjoy this encore of Word Notes. The manipulation of search engine optimization, SEO, to promote malicious sites in search engine results. CyberWire Glossary link: https://thecyberwire.com/glossary/search-engine-optimization-poisoning Audio reference link: Brown, B.E., 2021. The Ending Of T…
De la création d’un organisme de certification
Episode #550 consacré à la création d’un organisme de certification Avec Guillaume Carat et Ronan Lucas The post De la création d’un organisme de certification appeared first on NoLimitSecu.
Snake Oilers: watchTowr, XBOW and CoreView
In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is probably a security dis…
It's More Secure When It's Disabled - PSW #943
In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debi…
Love, lies, and a fake 49er.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…
Кофе, SOC и логи №40
Специальный гость:Александр Копылов. Что-то знает про ИТ и ИБ.Начинающий престарелый инфлюенсер.Ведёт телеграм-канал «Кризис менеджера»Обсуждаемые новости:Президент Чехии предложил НАТО отключить России интернет, спутники и банки в ответ Москве.https://www.securitylab.ru/news/572973.phpМинцифры расш…
How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one …
Risky Business #852 -- Cyber Command wants to buy shells
On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including: ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits The US government plan…
SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race
OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be e…
Linux Threat Hunting - PSW #942
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs…
This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break…
Wasserzeichen, Schlüsselprüfungen und langsame Logs
Die KI-Themen lassen den Podcast ebenso wenig los, wie sie die IT- Security allgemein in Frieden lassen. Christopher und Sylvester beißen sich durch, unter anderem geht es um Wasserzeichen in KI-Texten und immer noch um frei drehende KI-Agenten. Immerhin: Mit Key-Transparency in Messengern und Certi…
Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including: Two alleged TeamPCP hackers got arrested in Australia The White House has a plan to boost security for water facilities, but we can’t see it working OpenAI keeps the ol…
SN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?
AI-generated code is flooding the industry, but researchers reveal that almost half of it contains critical vulnerabilities. This week, we unpack what happens when the race for automation outpaces security best practices. A possible means for preventing prompt injection abuse. Clear evidence of Chin…
179: The Courthouse - Revisited
In this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened in the aftermath. Sponsors This show is brought to you by Doppel. Doppel stops …
Hacking All The Devices, with AI? - Rob Allen - PSW #941
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the securit…
This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual stri…
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist
Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved–and possibly unsolvable–security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy su…
Кофе, SOC и логи №39
Специальный гость:Владимир Зайцев, заместитель технического директора компании NGENIX, который отвечает за обслуживание клиентов, техническую поддержку и сервисы управляемой безопасности.Обсуждаемые новости:«Белый интернет» для своих, VPN втридорога для всех остальных. Как Иран разделил доступ к сет…
Alarmierende Ausbrüche Agentischer Angreifer
Die KI-Agenten greifen an! Das ist zumindest auf den ersten Blick die Essenz der Berichte über LLM-basierte künstliche Sicherheitsforscher, die bei Experimenten und im Training ausbrachen, fremde Systeme knackten und anderes Schindluder trieben. Christopher und Sylvester schauen in dieser Folge gena…
Кофе, SOC и логи №38
Специальный гость:Алексей Ахмеев, глава ИБ группы компаний СВОЙ (ранее IDF Eurasia).Обсуждаемые новости:Горелкин предупредил: GitHub станет недоступен на 100% – пора переносить проекты на российские аналогиwww.securitylab.ru/news/572621.php Shai-Hulud в открытом доступе. Теперь любой желающий может …
Defensive Security Podcast Episode 357
Please consider supporting the DefSec podcast here. Stories: 1. Ransomware Gangs Bypass the CEO, Target the 40-Something IT Managerhttps://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499 2. Ransomware Attacks Spike While Ind…
Defensive Security Podcast Episode 356
Please consider supporting the DefSec podcast here. Stories: https://www.cybersecuritydive.com/news/anthropic-claude-ai-hacking-test/826708 https://thecybersecguru.com/news/openai-ai-agent-containment-escapes-hugging-face-investigation/ https://www.bleepingcomputer.com/news/security/after-the-break-…
Defensive Security Podcast Episode 355
https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.htmlhttps://thehackernews.com/2026/07/worlds-largest-ai-model-repository.htmlhttps://openai.com/index/hugging-face-model…
Digitale Embleme
Christopher weilt im wohlverdienten Urlaub, verpasst dadurch aber spannende Themen. Sylvester hat „Digitale Embleme“ entdeckt und dazu einen Gast in den Podcast eingeladen, der sich bestens damit auskennt: Felix Linker von der ETH Zürich. Er hilft unter anderem dem Roten Kreuz dabei, digitale Emblem…
178: Ubiquiti
Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing their software up to…
Эпизод №22. Корпоративный VPN
У нас в гостях команда экспертов под кодовым названием ААА. Поговорим про корпоративные VPN и не только.В гостях у нас:Алексей Данилов, руководитель продуктового направления в «ИнфоТеКС», в настоящий момент развивает в компании направление NGFW. Эксперт в сетевой безопасности с опытом 20+ лет;Андрей…
InterCERT France (Juillet 2026)
Episode #549 consacré à l’InterCERT France Avec Thibaud Binétruy The post InterCERT France (Juillet 2026) appeared first on NoLimitSecu.
Defensive Security Podcast Episode 354
Please consider supporting the DefSec podcast here. Stories: https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353 https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924 https://www.blee…
Die IETF knirscht, Cisco knirscht und die Rikscha auch
Im Podcast geht es mal wieder um einen bunten Strauß an Themen der vergangengen Wochen, angefangen mit einer sehr unangenehmen aber auch wichtige Diskussion zur zukünftigen Absicherung von TLS. Weiter geht es mit LLMs, die angeblich autonom Ransomware ausliefern, und Cisco, die keine einzelnen CVEs …
Кофе, SOC и логи №37
О чём:Обсуждение лучших новостей инфобеза за неделю с 4 по 10 мая 2026 г.Специальный гость:503 (Слив засчитан Service Unavailable)Обсуждаемые новости:MITRE выпустила ATT&CK v19, и новая версия отдельно усилила описание скрытности, отключения защиты, мобильных атак, ICS и применения ИИ.https://www.se…
177: National Public Data
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show comes from ThreatLocker…
Hors Série – Vol 501 d’Ariane 5
Episode Hors Série consacré au vol 501 d’Ariane 5 Avec Lamna The post Hors Série – Vol 501 d’Ariane 5 appeared first on NoLimitSecu.
Vulnpocalypse
Episode #548 La sécurité est-elle en passe de devenir un échec ? L’intelligence artificielle va-t-elle déclencher une « apocalypse des vulnérabilités » en submergeant les défenseurs sous un flot incontrôlable de failles 0D ? Au programme de cet épisode : Le mythe d’Anthropic & « Mythos »…
Defensive Security Podcast Episode 353
Please consider supporting the DefSec podcast here. Links to stories: https://www.securityweek.com/massive-password-spray-campaign-targeting-azure-cli/ https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html https://www.cybersecuritydive.com/news/klue-investigating-supply-chain-atta…
176: NSL
One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law. Learn more about Nicks work…
145. Experto en IA ofensiva: ¿Una IA hackeó a la NSA? ¿Qué usaban Windows XP?
Hablo de Mythos con Federico Kirschbaum, líder del Security Lab de XBOW. Separamos el hype de la realidad: qué hay de cierto en eso de que "hackeó a la NSA", por qué dice que "no es que él sea bueno, es que los sistemas son malos", y qué cambia de verdad con la IA en la ciberseguridad. Con los pies …
144. Mythos
Si has leído algún titular en las últimas semanas, te habrán dicho que la nueva IA de Anthropic, Claude Mythos, es el fin de la ciberseguridad. Que la era del 0-day ha terminado. Que viene el apocalipsis. Hoy te voy a contar por qué casi todo eso es marketing, por qué la historia real es muchísimo m…
143. Contagious interview - La tertulia
Hablamos con Jaime Blasco (@jaimeblascob) de campañas de Corea del Norte contra el resto del mundo. Jaime es el CEO y cofundador de Nudge Security, con más de 15 años de experiencia en ciberseguridad y uno de los referentes mundiales en Threat Intelligence. Anteriormente fue Chief Scientist en Alien…
RadioCSIRT English Edition – Adobe ZeroDay - CVE-2026-34621 - Ep.78
On April 9, 2026, researcher Haifei Li, founder of EXPMON – a sandbox-based exploit detection system – publicly disclosed the existence of a zero-day vulnerability in Adobe Acrobat Reader actively exploited in the wild for at least five months. Adobe was notified on April 7. The vulnerability has si…
RadioCSIRT English Edition - Update about Cyber situation on middle East - Ep. 77
In this episode: the cyber dimension of the Iran conflict – a six-week retrospective from the initial strikes of February 28 through the fragile ceasefire of April 9, 2026, covering the full evolution of Iranian and pro-Iranian cyber operations from the first hacktivist DDoS waves to confirmed explo…
RadioCSIRT English Edition –Patch Tuesday April 2026 Preview - Episode 76
On April 14, 2026, Microsoft releases its monthly security update cycle. This Patch Tuesday warrants direct attention from every patch management team and every operations team running Windows infrastructure. The maximum severity is critical. The primary impact is remote code execution. The affected…
RadioCSIRT English Edition – a new ransomware group operating under the name Payload -Ep.74
On April 7, 2026, Gen Threat Labs, the research arm of Gen Digital, published a detailed technical analysis of Remus, a new 64-bit infostealer attributed to the Lumma Stealer family. Active campaigns involving Remus have been observed since February 2026 – directly following a doxxing campaign betwe…
RadioCSIRT English Edition – A new ransomware group operating under the name Payload - Ep.74
Since February 2026, a new ransomware group operating under the name Payload has been conducting active double extortion campaigns against organizations across multiple sectors and geographies. In less than two months of observed activity, the group has claimed twenty-six victims across seven countr…
142. Contagious Interview
El próximo ataque a tu empresa puede empezar con una entrevista de trabajo y acabar con acceso total a tus sistemas. ⭐️ SPONSORS ⭐️ ️♂️ Flare Flare es una plataforma de inteligencia de amenazas y monitoreo de la Dark Web que te ayuda a estar un paso por delante de los ciber-delincuentes. Puedes sol…
141. Predicciones 2026
Con el comienzo del nuevo año es importante repasar lo aprendido en 2025 para adelantarnos a las amenazas que se nos vienen en 2026 y justo eso es lo que vamos a hacer en este nuevo episodio de Tierra de Hackers, ⭐️ SPONSORS ⭐️ ️♂️ Flare Flare es una plataforma de inteligencia de amenazas y monitor…
Weev, Part 2
The Electronic Frontier Foundation, long time critics of the Computer Fraud and Abuse Act, followed Weev's trial - but did not get involved. For the appeal, however, the organization decided to step it. But althought the EFF had some strong points against the CFAA - the justices, appearntly, had som…
Weev, Part 1
Much like Aaron Swartz did, Andrew "weev" Auernheimer fought against the Computer Fraud and Abuse Act, a law both men belived to be dangerous and unjust. But unlike Swartz, the internet's own boy, weev is an unapologetic troll who spread bile and chaos wherever he goes, a man who seemed to t…
Cuckoo Spear [B-Side]
APT-10 is a Chinese nation-state threat actor that in recent years has been targeting Japanese IT & Instrastructure organizations using a sophisticated backdoor malware known as LODEINFO. Recently, Jin Ito & Loic Castel, researchers from Cybereason's IR Team, uncovered a new tool used by the group: …
The Man Who Went To War With Anonymous - And Lost
Aaron Barr was en-signals intelligence officer specializing in analytics. As part of HBGary Federal, he came up with a plan to unmask the key leaders of Anonymous, the infamous hacker collective. People who worked with Aaron warned him that his data was sub-par, but the determined vet claimed he had…
What Can Organizations Learn from "Grim Beeper"? [B-Side]
On 17 and 18 of September 2024, thousands of pagers and hand held radio devices used by Hezbollah, exploded simultaneously across Lebanon and Syria, killing at least 42 terrorists and wounding more than 3,000. Devon Ackerman, Cybereason’s Global Head of Digital Forensic and Incident response and a f…
Keeping Kyiv Online: Two Years of Wartime Cybersecurity – Pavlo Chernikov
Practical lessons from running Kyiv's municipal cybersecurity through the first two years of the full-scale war. Stories over theory – every story with a takeaway.