Defensive Security Podcast Episode 357

Please consider supporting the DefSec podcast here.

Stories:

1. Ransomware Gangs Bypass the CEO, Target the 40-Something IT Manager
https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499

2. Ransomware Attacks Spike While Industry Attention Shifts to AI
https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934

3. ChainDrop supply chain compromise: Anatomy of a self-propagating worm
https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/

4. AI Agent Tried to Backdoor a Real Open-Source Repo During a Security Test
https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html

5. Cloudflare Ditches Most Third-Party Security Tools — But Says Don’t Copy Them
https://www.theregister.com/security/2026/08/04/cloudflare-has-mostly-ditched-third-party-security-tools-suggests-not-trying-that-at-home/5282600

Defensive Security Podcast Episode 356

Please consider supporting the DefSec podcast here.

Stories:

  • https://www.cybersecuritydive.com/news/anthropic-claude-ai-hacking-test/826708
  • https://thecybersecguru.com/news/openai-ai-agent-containment-escapes-hugging-face-investigation/
  • https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
  • https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks
  • https://cybersecuritynews.com/adform-advertising-platform-compromised/

Defensive Security Podcast Episode 355

https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/

Defensive Security Podcast Episode 354

Please consider supporting the DefSec podcast here.

Stories:

https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353

https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924

https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/

https://databreaches.net/2026/07/04/adapthealth-says-attackers-sweet-talked-their-way-into-cloud-systems-and-stole-patient-data

https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html

 

Defensive Security Podcast Episode 353

Please consider supporting the DefSec podcast here.

Links to stories:

https://www.securityweek.com/massive-password-spray-campaign-targeting-azure-cli/

https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html

https://www.cybersecuritydive.com/news/klue-investigating-supply-chain-attack-salesforce-integrations/823532/

https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks

https://www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk

 

Defensive Security Podcast Episode 352

Please consider supporting the DefSec podcast here.

This week’s stories:

https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/

https://www.bleepingcomputer.com/news/security/openclaw-ai-agent-found-falling-for-phishing-attacks-spills-user-data/

https://www.cybersecuritydive.com/news/cisa-vulnerability-remediation-prioritization-directive/822504/

https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/

https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4

Defensive Security Podcast Episode 351

Please consider supporting the DefSec podcast here.

Links to this week’s stories:

https://www.theregister.com/cyber-crime/2026/06/05/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks/5251891

https://thehackernews.com/2026/06/only-10-of-socs-say-theyre-getting.html?m=1

https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/

https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/

https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/

https://www.cybersecuritydive.com/news/ai-cybersecurity-hype-reality-check-gartner/821867/0:0

Defensive Security Podcast Episode 350

Please consider supporting the DefSec podcast here.

Links to this week’s stories:

  • https://www.darkreading.com/threat-intelligence/ai-assisted-exploit-development-scanner-detection
  • https://www.bleepingcomputer.com/news/security/california-ag-sues-23andme-over-2023-breach-exposing-health-data/
  • https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/
  • https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/
  • https://www.darkreading.com/application-security/megalodon-malware-infects-thousands-github-repos

Defensive Security Podcast Episode 349

Please consider supporting the DefSec podcast here.

Links to this week’s stories:

  • https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html
  • https://www.tenable.com/blog/key-findings-from-the-verizon-dbir-2026
  • https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
  • https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/
  • https://www.bleepingcomputer.com/news/security/github-links-repo-breach-to-tanstack-npm-supply-chain-attack/
  • https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html

Defensive Security Podcast Episode 348

Please consider supporting the DefSec podcast here.

Links to this week’s stories:

https://www.theregister.com/cyber-crime/2026/05/14/security-pros-doubt-canvas-attackers-really-deleted-stolen-student-data/5240799