PLAY PODCASTS
Talkin' Bout [Infosec] News

Talkin' Bout [Infosec] News

352 episodes — Page 2 of 8

Ep 1Cyberattack Bricks Speed Cameras – 2025-08-18

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — The gif that keeps on giffing01:46 - Cyberattack Bricks Speed Cameras – BHIS - Talkin’ Bout [infosec] News 2025-08-1802:39 - Story # 1: Perplexity made a sky-high $34.5 billion bid for Google Chrome — a bold and unusual move in the midst of antitrust scrutiny07:16 - Story # 2: Exclusive: US embeds trackers in AI chip shipments to catch diversions to China, sources say10:22 - Story # 3: How we found TeaOnHer spilling users’ driver’s licenses in less than 10 minutes12:17 - Story # 4: Cisco discloses maximum-severity defect in firewall software13:56 - Story # 5: Data Dump From APT Actor Yields Clues to Attacker Capabilities19:13 - Story # 6: Russian cyberattack in the Netherlands leaves speed cameras offline indefinitely23:30 - Story # 7: HTTP/2 MadeYouReset Vulnerability Enables Massive DDoS Attacks24:51 - Story # 8: LAPD Eyes ‘GeoSpy’, an AI Tool That Can Geolocate Photos in Seconds29:05 - Story # 9: Manpower discloses data breach affecting nearly 145,000 people34:51 - Story # 10: Hacker Offers to Sell 15.8 Million Plain-Text PayPal Credentials On Dark Web Forum35:34 - Story # 11: The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived40:54 - Story # 12: New Clever Phishing Attack Uses Japanese Character “ん” to Mimic Forward Slash “/”46:28 - Story # 13: Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild48:13 - Story # 14: Plex warns users to patch security vulnerability immediately50:53 - ChickenSec: Noble Foods using soil mapping technology at organic egg farm (00:00) - PreShow Banter™ — The gif that keeps on giffing (01:46) - Cyberattack Bricks Speed Cameras – BHIS - Talkin' Bout [infosec] News 2025-08-18 (02:38) - Story # 1: Perplexity made a sky-high $34.5 billion bid for Google Chrome — a bold and unusual move in the midst of antitrust scrutiny (07:16) - Story # 2: Exclusive: US embeds trackers in AI chip shipments to catch diversions to China, sources say (10:22) - Story # 3: How we found TeaOnHer spilling users’ driver’s licenses in less than 10 minutes (12:16) - Story # 4: Cisco discloses maximum-severity defect in firewall software (13:55) - Story # 5: Data Dump From APT Actor Yields Clues to Attacker Capabilities (19:13) - Story # 6: Russian cyberattack in the Netherlands leaves speed cameras offline indefinitely (23:30) - Story # 7: HTTP/2 MadeYouReset Vulnerability Enables Massive DDoS Attacks (24:51) - Story # 8: LAPD Eyes ‘GeoSpy’, an AI Tool That Can Geolocate Photos in Seconds (29:04) - Story # 9: Manpower discloses data breach affecting nearly 145,000 people (34:50) - Story # 10: Hacker Offers to Sell 15.8 Million Plain-Text PayPal Credentials On Dark Web Forum (35:34) - Story # 11: The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived (40:53) - Story # 12: New Clever Phishing Attack Uses Japanese Character “ん” to Mimic Forward Slash “/” (46:27) - Story # 13: Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild (48:13) - Story # 14: Plex warns users to patch security vulnerability immediately (50:52) - ChickenSec: Noble Foods using soil mapping technology at organic egg farm

Aug 20, 202558 min

Ep 1DEF CON RECAP – 2025-08-11

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — Wading Through Woods06:06 - DEF CON RECAP - Talkin’ Bout [infosec] News 2025-08-1109:16 - Story # 1: It’s time to acknowledge HTTP/1.1 is insecure12:36 - Story # 2: Research reveals possible privacy gaps in Apple Intelligence’s data handling17:51 - Story # 3: Federal court filing system hit in sweeping hack21:09 - Story # 4: Cisco discloses data breach impacting Cisco.com user accounts32:17 - Story # 5: Google says its AI-based bug hunter found 20 security vulnerabilities34:20 - Story # 6: Automate security reviews with Claude Code39:01 - Story # 7: Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands44:44 - Story # 7b: OnStar assists CHP in stopping fleeing SUV with toddler inside47:12 - Story # 7c: That viral video of a ‘deactivated’ Tesla Cybertruck is a fake49:37 - Story # 8: LegalPwn Attack Tricks GenAI Tools Into Misclassifying Malware as Safe Code50:53 - Story # 9: Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools53:08 - Story # 10: A Single Poisoned Document Could Leak ‘Secret’ Data Via ChatGPT58:10 - Story # 11: Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks (00:00) - PreShow Banter™ — Wading Through Woods (06:06) - DEF CON RECAP - Talkin' Bout [infosec] News 2025-08-11 (09:15) - Story # 1: It's time to acknowledge HTTP/1.1 is insecure (12:36) - Story # 2: Research reveals possible privacy gaps in Apple Intelligence’s data handling (17:50) - Story # 3: Federal court filing system hit in sweeping hack (21:08) - Story # 4: Cisco discloses data breach impacting Cisco.com user accounts (32:16) - Story # 5: Google says its AI-based bug hunter found 20 security vulnerabilities (34:20) - Story # 6: Automate security reviews with Claude Code (39:00) - Story # 7: Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands (44:43) - Story # 7b: OnStar assists CHP in stopping fleeing SUV with toddler inside (47:11) - Story # 7c: That viral video of a ‘deactivated’ Tesla Cybertruck is a fake (49:36) - Story # 8: LegalPwn Attack Tricks GenAI Tools Into Misclassifying Malware as Safe Code (50:52) - Story # 9: Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools (53:08) - Story # 10: A Single Poisoned Document Could Leak ‘Secret’ Data Via ChatGPT (58:09) - Story # 11: Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks

Aug 14, 202559 min

Ep 1Perplexity Stealth Crawlers Evade No-Crawl Directives - 2025-08-04

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00:00 - PreShow Banter™ — Stop Asking Wade if he’s in Vegas00:02:16 - Perplexity Uses Stealth Crawlers to Evade No-Crawl Directives – 2025-08-0400:11:25 - Story # 1: Insurance won’t cover $5M in City of Hamilton claims for cyberattack, citing lack of log-in security00:18:40 - Story # 2: States Enact Safe Harbor Laws that Provide Affirmative Defenses in Data Breach Litigation00:26:45 - Story # 3: Hackers Destroy Aeroflot’s IT Infrastructure, Causing Over 42 Flight Cancellations00:34:18 - Story # 4: Attackers exploit link-wrapping services to steal Microsoft 365 logins00:40:09 - Story # 5: Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons00:42:18 - Wade’s plugin recommendation00:44:39 - Story # 6: Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives00:51:11 - Story # 7: After Backlash, ChatGPT Removes Option to Have Private Chats Indexed by Google00:55:21 - AI 202701:01:01 - What’s Ralph been up to? (00:00) - PreShow Banter™ — Stop Asking Wade if he's in Vegas (02:16) - Perplexity Uses Stealth Crawlers to Evade No-Crawl Directives – 2025-08-04 (11:25) - Story # 1: Insurance won't cover $5M in City of Hamilton claims for cyberattack, citing lack of log-in security (18:39) - Story # 2: States Enact Safe Harbor Laws that Provide Affirmative Defenses in Data Breach Litigation (26:44) - Story # 3: Hackers Destroy Aeroflot’s IT Infrastructure, Causing Over 42 Flight Cancellations (34:18) - Story # 4: Attackers exploit link-wrapping services to steal Microsoft 365 logins (40:09) - Story # 5: Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons (42:17) - Wade’s plugin recommendation (44:38) - Story # 6: Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives (51:10) - Story # 7: After Backlash, ChatGPT Removes Option to Have Private Chats Indexed by Google (55:20) - AI 2027 (01:01:00) - What’s Ralph been up to?

Aug 7, 20251h 3m

Ep 1UK Bans Ransomware Payments - 2025-07-28

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com 00:00 - PreShow Banter™ — National Chicken Wing Day04:16 - BHIS - Talkin’ Bout [infosec] News 2025-07-2805:30 - Story # 1: Bad vibes: How an AI agent coded its way to disaster08:40 - Story # 1b: Replit goes rogue, deletes entire database.15:44 - Story # 2: A major AI training data set contains millions of examples of personal data26:05 - Story # 3: Women Dating Safety App ‘Tea’ Breached, Users’ IDs Posted to 4chan33:19 - Story # 4:A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors40:28 - Story # 5: Clorox Sues IT Provider Cognizant For Simply Giving Employee Password to Hackers49:46 - Story # 6: Businesses banned from paying hackers’ ransoms to target cybercrime57:38 - SharePoint Follow Up (00:00) - PreShow Banter™ — National Chicken Wing Day (04:15) - BHIS - Talkin' Bout [infosec] News 2025-07-28 (05:29) - Story # 1: Bad vibes: How an AI agent coded its way to disaster (08:39) - Story # 1b: Replit goes rogue, deletes entire database. (15:43) - Story # 2: A major AI training data set contains millions of examples of personal data (26:04) - Story # 3: Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan (33:18) - Story # 4:A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors (40:27) - Story # 5: Clorox Sues IT Provider Cognizant For Simply Giving Employee Password to Hackers (49:46) - Story # 6: Businesses banned from paying hackers’ ransoms to target cybercrime (57:38) - SharePoint Follow Up

Aug 1, 20251h 2m

Ep 1Microsoft's OverSharePoint 0-Day Exploit – 2025-07-21

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — PaintBallers03:55 - BHIS - Talkin’ Bout [infosec] News 2025-07-2104:21 - Story # 1: Microsoft 0-day Mass Exploitation09:39 - Story # 2: Replit AI went rogue, deleted a company’s entire database, then hid it and lied about it13:15 - Story # 3: ‘All US forces must now assume their networks are compromised’ after Salt Typhoon breach18:08 - Story # 4: After FBI Warning, Alaska Airlines Grounded; Salt Typhoon Suspected20:45 - Story # 5: FBI Cybersecurity Breach Led to Murders of Informants in El Chapo Case21:54 - Story # 5b: FBI’s Report29:57 - Story # 6: Google fixes actively exploited sandbox escape zero day in Chrome31:30 - Story # 7: Exploited Wing file transfer bug risks ‘total server compromise,’ CISA warns32:33 - Story # 8: CitrixBleed 2 situation update — everybody already got owned33:01 - Story # 9: At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds46:14 - Story # 10: Amazon Ring Doorbell May 28 Mass Hacking Claim Goes Viral48:56 - jdbgmgr.exe virus hoax51:52 - Story # 11: HPE warns of hardcoded passwords in Aruba access points (00:00) - PreShow Banter™ — PaintBallers (03:55) - BHIS - Talkin' Bout [infosec] News 2025-07-21 (04:20) - Story # 1: Microsoft 0-day Mass Exploitation (09:39) - Story # 2: Replit AI went rogue, deleted a company's entire database, then hid it and lied about it (13:14) - Story # 3: ‘All US forces must now assume their networks are compromised’ after Salt Typhoon breach (18:08) - Story # 4: After FBI Warning, Alaska Airlines Grounded; Salt Typhoon Suspected (20:44) - Story # 5: FBI Cybersecurity Breach Led to Murders of Informants in El Chapo Case (21:53) - Story # 5b: FBI's Report (29:56) - Story # 6: Google fixes actively exploited sandbox escape zero day in Chrome (31:30) - Story # 7: Exploited Wing file transfer bug risks ‘total server compromise,’ CISA warns (32:32) - Story # 8: CitrixBleed 2 situation update — everybody already got owned (33:00) - Story # 9: At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds (46:14) - Story # 10: Amazon Ring Doorbell May 28 Mass Hacking Claim Goes Viral (48:55) - jdbgmgr.exe virus hoax (51:52) - Story # 11: HPE warns of hardcoded passwords in Aruba access points

Jul 23, 20251h 4m

Ep 1McDonald’s Over 64 Million Exposed Job Applicants - 2025-07-14

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com 00:00 - PreShow Banter™ — Traditional Finger00:21 - BHIS - Talkin’ Bout [infosec] News 2025-07-1401:29 - Story # 1: ‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications22:12 - Story # 2: Employee gets $920 for credentials used in $140 million bank heist33:50 - Story # 3: Microsoft laying off about 9,000 employees in latest round of cuts37:21 - Story # 5: Scammy YouTube Ads46:31 - Story # 6: New ServiceNow flaw lets attackers enumerate restricted data (00:00) - PreShow Banter™ — Traditional Finger (00:21) - BHIS - Talkin' Bout [infosec] News 2025-07-14 (01:28) - Story # 1: '123456' password exposed chats for 64 million McDonald’s job chatbot applications (22:12) - Story # 2: Employee gets $920 for credentials used in $140 million bank heist (33:50) - Story # 3: Microsoft laying off about 9,000 employees in latest round of cuts (37:20) - Story # 5: Scammy YouTube Ads (46:31) - Story # 6: New ServiceNow flaw lets attackers enumerate restricted data

Jul 16, 202555 min

Ep 1North Korean Remote Workers are at it Again! – BHIS - Talkin' Bout [infosec] News 2025-07-07

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — Pre Stream Appropriate03:39 - N. Korean Remote Workers are at it Again! – BHIS - Talkin’ Bout [infosec] News 2025-07-0705:41 - Story # 1: Fortune 500 Cyber Spending Pays Off: Large Enterprise Risk Falls 33% Despite Rising Threats20:01 - Story # 2: Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations25:49 - Story # 2b: Engineer caught juggling multiple startup jobs is a cautionary tale of ‘extreme’ hustle culture, experts say34:47 - Story # 3: Taking SHELLTER: a commercial evasion framework abused in- the- wild42:15 - Story # 3b: Statement Regarding Recent Misuse of Shellter Elite and Elastic Security Labs’ Handling46:58 - Story # 4: Ingram Micro outage caused by SafePay ransomware attack49:45 - Story # 5: Germany asks Google, Apple to remove DeepSeek AI from app stores53:13 - Story # 6: This Call of Duty game just hit Xbox Game Pass, but it’s infested with RCE hackers — I’d take cover and avoid playing until there’s a fix (00:00) - PreShow Banter™ — Pre Stream Appropriate (03:39) - N. Korean Remote Workers are at it Again! – BHIS - Talkin' Bout [infosec] News 2025-07-07 (05:40) - Story # 1: Fortune 500 Cyber Spending Pays Off: Large Enterprise Risk Falls 33% Despite Rising Threats (20:00) - Story # 2: Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations (25:49) - Story # 2b: Engineer caught juggling multiple startup jobs is a cautionary tale of ‘extreme’ hustle culture, experts say (34:47) - Story # 3: Taking SHELLTER: a commercial evasion framework abused in- the- wild (42:14) - Story # 3b: Statement Regarding Recent Misuse of Shellter Elite and Elastic Security Labs’ Handling (46:58) - Story # 4: Ingram Micro outage caused by SafePay ransomware attack (49:44) - Story # 5: Germany asks Google, Apple to remove DeepSeek AI from app stores (53:13) - Story # 6: This Call of Duty game just hit Xbox Game Pass, but it's infested with RCE hackers — I'd take cover and avoid playing until there's a fix

Jul 9, 202555 min

Ep 1Year of the [European Union] Linux Desktop Finally Arrives? | BHIS - Talkin' Bout [infosec] News 2025-06-30

Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comChapters:00:00 - PreShow Banter™ — Names on Cups01:39 - Year of the [European Union] Linux Desktop Finally Arrives? | BHIS - Talkin’ Bout [infosec] News 2025-06-3003:34 - Story # 1: You should probably delete any sensitive screenshots you have in your phone right now.10:55 - Story # 2: Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails14:07 - Story # 3: The year of the European Union Linux desktop may finally arrive24:46 - Story # 4: Restricted data once again leaked on War Thunder forums27:04 - Story # 5: Scale AI Leaks Meta, Google, xAI Confidential Files Through ‘Incredibly Janky’ Document Practices31:47 - Story # 6: French police reportedly arrest suspected BreachForums administrators34:22 - Story # 7: Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages39:41 - Story # 8: CitrixBleed 2: Electric Boogaloo — CVE-2025–577742:16 - Story # 9: Millions of Brother Printers Hit by Critical, Unpatchable Bug47:05 - Story # 10: Canada orders China’s Hikvision to close Canadian operations50:13 - Story # 11: US House bans WhatsApp on staff devices over security concerns53:17 - ChickenSec: Chickens are becoming 3rd most popular pet: Tractor Supply CEO56:34 - Story # 12: Norway Dam Hacked, Valve Opened But No Danger58:11 - Review your calendar invites! (00:00) - PreShow Banter™ — Names on Cups (01:38) - Year of the [European Union] Linux Desktop Finally Arrives? | BHIS - Talkin' Bout [infosec] News 2025-06-30 (03:33) - Story # 1: You should probably delete any sensitive screenshots you have in your phone right now. (10:55) - Story # 2: Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails (14:07) - Story # 3: The year of the European Union Linux desktop may finally arrive (24:45) - Story # 4: Restricted data once again leaked on War Thunder forums (27:03) - Story # 5: Scale AI Leaks Meta, Google, xAI Confidential Files Through ‘Incredibly Janky’ Document Practices (31:46) - Story # 6: French police reportedly arrest suspected BreachForums administrators (34:21) - Story # 7: Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages (39:40) - Story # 8: CitrixBleed 2: Electric Boogaloo — CVE-2025–5777 (42:16) - Story # 9: Millions of Brother Printers Hit by Critical, Unpatchable Bug (47:05) - Story # 10: Canada orders China's Hikvision to close Canadian operations (50:12) - Story # 11: US House bans WhatsApp on staff devices over security concerns (53:16) - ChickenSec: Chickens are becoming 3rd most popular pet: Tractor Supply CEO (56:33) - Story # 12: Norway Dam Hacked, Valve Opened But No Danger (58:11) - Review your calendar invites!

Jul 4, 202559 min

Ep 1Iran Shuts Down It's Own Internet - 2025-06-23

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — Explaining the Muppets03:09 - Iran Shuts Down It's Own Internet- BHIS - Talkin’ Bout [infosec] News 2025-06-2304:52 - Story # 1: Iran’s government says it shut down internet to protect against cyberattacks20:20 - Story # 2: Iranian bank linked to revolutionary guard hit by ‘cyber attack’22:11 - Story # 3: Hackers switch to targeting U.S. insurance companies23:32 - Story # 3b: Statement: Erie Insurance Information Security Incident (June 23)33:33 - Story # 4: No, the 16 billion credentials leak is not a new data breach43:23 - Story # 5: ‘Water Curse’ Targets Infosec Pros via Poisoned GitHub Repositories47:09 - Story # 6: CISA Reveals ‘Pattern’ of Ransomware Attacks Against SimpleHelp RMM48:49 - Story # 7: Report Links Los Pollos and RichAds to Malware Traffic Operations58:29 - Story # 8: Minnesota lawmaker’s alleged killer had list of data broker websites in car, FBI says (00:00) - PreShow Banter™ — Explaining the Muppets (03:08) - Iran Shuts Down It's Own Internet - BHIS - Talkin' Bout [infosec] News 2025-06-23 (04:52) - Story # 1: Iran’s government says it shut down internet to protect against cyberattacks (20:19) - Story # 2: Iranian bank linked to revolutionary guard hit by ‘cyber attack’ (22:11) - Story # 3: Hackers switch to targeting U.S. insurance companies (23:31) - Story # 3b: Statement: Erie Insurance Information Security Incident (June 23) (33:32) - Story # 4: No, the 16 billion credentials leak is not a new data breach (43:22) - Story # 5: 'Water Curse' Targets Infosec Pros via Poisoned GitHub Repositories (47:09) - Story # 6: CISA Reveals 'Pattern' of Ransomware Attacks Against SimpleHelp RMM (48:48) - Story # 7: Report Links Los Pollos and RichAds to Malware Traffic Operations (58:29) - Story # 8: Minnesota lawmaker’s alleged killer had list of data broker websites in car, FBI says

Jun 26, 20251h 5m

Ep 1Denmark is Done with Teams! - 2025-06-16

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — Government Linux04:16 - Denmark is Done with Teams! - Talkin’ Bout [infosec] News 2025-06-1605:02 - Story # 1: ‘We’re done with Teams’: German state hits uninstall on Microsoft17:34 - Story # 1b: Denmark Wants to Dump Microsoft Software for Linux, LibreOffice18:14 - Story # 2: Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot25:50 - Story # 3: Fog ransomware attacks use employee monitoring tool to break into business networks30:25 - Story # 4: Expired Discord Invites Hijacked for Stealthy Malware Attacks34:00 - Story # 5: SmartAttack uses smartwatches to steal data from air-gapped systems40:25 - Story # 6: Mirai Botnets Exploiting Wazuh Security Platform Vulnerability44:47 - Story # 7: Google Cloud and Cloudflare hit by widespread service outages48:04 - Story # 8: UNFI cyberattack shuts down network and leaves Whole Foods and others in limbo50:34 - Story # 9: New SharePoint Phishing Attacks Using Lick Deceptive Techniques51:08 - Story # 10: US-backed Israeli company’s spyware used to target European journalists, Citizen Lab finds53:32 - Story # 11: Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud (00:00) - PreShow Banter™ — Government Linux (04:15) - Denmark is Done with Teams! - Talkin' Bout [infosec] News 2025-06-16 (05:02) - Story # 1: 'We're done with Teams': German state hits uninstall on Microsoft (17:33) - Story # 1b: Denmark Wants to Dump Microsoft Software for Linux, LibreOffice (18:14) - Story # 2: Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot (25:49) - Story # 3: Fog ransomware attacks use employee monitoring tool to break into business networks (30:24) - Story # 4: Expired Discord Invites Hijacked for Stealthy Malware Attacks (33:59) - Story # 5: SmartAttack uses smartwatches to steal data from air-gapped systems (40:25) - Story # 6: Mirai Botnets Exploiting Wazuh Security Platform Vulnerability (44:47) - Story # 7: Google Cloud and Cloudflare hit by widespread service outages (48:03) - Story # 8: UNFI cyberattack shuts down network and leaves Whole Foods and others in limbo (50:33) - Story # 9: New SharePoint Phishing Attacks Using Lick Deceptive Techniques (51:08) - Story # 10: US-backed Israeli company’s spyware used to target European journalists, Citizen Lab finds (53:31) - Story # 11: Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud

Jun 18, 202556 min

Ep 1Chatbot Tells Addict to Take Drugs - 2025-06-09

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — Time to Bake05:12 - Chatbot Tells Addict to Take Drugs - Talkin’ Bout [infosec] News 2025-05-0606:08 - Story # 1: Meta and Yandex are de-anonymizing Android users’ web browsing identifiers12:55 - Story # 2: Therapy Chatbot Tells Recovering Addict to Have a Little Meth as a Treat16:11 - Story # 3: The Cost of a Call: From Voice Phishing to Data Extortion26:56 - Story # 4: Questions Swirl Around ConnectWise Flaw Used in Attacks27:40 - Story # 4b: ConnectWise email35:28 - Story # 5: Critical Cisco ISE Auth Bypass Flaw Impacts Cloud Deployments on AWS, Azure, and OCI39:27 - Story # 6: Misconfigured HMIs Expose US Water Systems to Anyone With a Browser52:20 - Story # 7: Fact Sheet: President Donald J. Trump Reprioritizes Cybersecurity Efforts to Protect America (00:00) - PreShow Banter™ — Time to Bake (05:12) - Chatbot Tells Addict to Take Drugs - Talkin' Bout [infosec] News 2025-05-06 (06:08) - Story # 1: Meta and Yandex are de-anonymizing Android users’ web browsing identifiers (12:55) - Story # 2: Therapy Chatbot Tells Recovering Addict to Have a Little Meth as a Treat (16:11) - Story # 3: The Cost of a Call: From Voice Phishing to Data Extortion (26:56) - Story # 4: Questions Swirl Around ConnectWise Flaw Used in Attacks (27:40) - Story # 4b: ConnectWise email (35:27) - Story # 5: Critical Cisco ISE Auth Bypass Flaw Impacts Cloud Deployments on AWS, Azure, and OCI (39:26) - Story # 6: Misconfigured HMIs Expose US Water Systems to Anyone With a Browser (52:19) - Story # 7: Trump cyber executive order takes aim at prior orders, secure software, identity

Jun 12, 20251h 0m

Ep 1Victoria’s Secrets are Compromised - 2025-06-02

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — natural MSG05:31 - Victoria’s Secrets are Compromised - Talkin’ Bout [infosec] News 2025-06-0206:31 - Story # 1: Authors Are Accidentally Leaving AI Prompts In their Novels08:36 - Story # 1b: This Latest AI Book Debacle Is A Disturbing Part Of A Growing Trend09:41 - Story # 2: Developer Builds Tool That Scrapes YouTube Comments, Uses AI to Predict Where Users Live10:48 - Story # 2b: AI-powered OSINT tool profiles YouTube users, raising privacy concerns15:55 - Story # 2c: Researchers Dump 2 Billion Scraped Discord Messages Online20:28 - Story # 3: Vending-Bench: A Benchmark for Long-Term Coherence of Autonomous Agents21:02 - Story # 3b: An AI Goes Insane, Emails FBI Over $2 (YouTube)26:55 - Story # 4: The UK will totally replace two-thirds of junior civil servants with AI chatbots, says the chatbot27:27 - Story # 4b: Reeves confirms 15% cut to Civil Service running costs29:29 - Story # 5: ConnectWise Breached, ScreenConnect Customers Targeted31:28 - LOLRMM - a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors.35:34 - Story # 6: New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers36:19 - Story # 7: US intelligence employee arrested for alleged double-dealing of classified info40:12 - Story # 8: Victoria’s Secret takes down website after security incident45:43 - Story # 9: Microsoft and CrowdStrike partner to link hacking group names46:59 - Story # 10: Zscaler Acquisition of Red Canary49:57 - Story # 11: Most of CISA’s senior leaders are leaving the agency51:22 - Story # 12: Telegram announces partnership with Musk’s xAI51:32 - Story # 13: Google warns of Vietnam-based hackers using bogus AI video generators to spread malware (00:00) - PreShow Banter™ — natural MSG (05:31) - BHIS - Talkin' Bout [infosec] News 2025-06-02 (06:31) - Story # 1: Authors Are Accidentally Leaving AI Prompts In their Novels (08:36) - Story # 1b: This Latest AI Book Debacle Is A Disturbing Part Of A Growing Trend (09:40) - Story # 2: Developer Builds Tool That Scrapes YouTube Comments, Uses AI to Predict Where Users Live (10:47) - Story # 2b: AI-powered OSINT tool profiles YouTube users, raising privacy concerns (15:55) - Story # 2c: Researchers Dump 2 Billion Scraped Discord Messages Online (20:28) - Story # 3: Vending-Bench: A Benchmark for Long-Term Coherence of Autonomous Agents (21:02) - Story # 3b: An AI Goes Insane, Emails FBI Over $2 (YouTube) (26:55) - Story # 4: The UK will totally replace two-thirds of junior civil servants with AI chatbots, says the chatbot (27:27) - Story # 4b: Reeves confirms 15% cut to Civil Service running costs (29:28) - Story # 5: ConnectWise Breached, ScreenConnect Customers Targeted (31:27) - LOLRMM - a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors. (35:33) - Story # 6: New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers (36:18) - Story # 7: US intelligence employee arrested for alleged double-dealing of classified info (40:12) - Story # 8: Victoria’s Secret takes down website after security incident (45:42) - Story # 9: Microsoft and CrowdStrike partner to link hacking group names (46:59) - Story # 10: Zscaler Acquisition of Red Canary (49:57) - Story # 11: Most of CISA’s senior leaders are leaving the agency (51:21) - Story # 12: Telegram announces partnership with Musk's xAI (51:32) - Story # 13: Google warns of Vietnam-based hackers using bogus AI video generators to spread malware

Jun 5, 202554 min

Ep 1Blackmailing A.I. - 2025-05-27

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — I just want Jorts!05:42 - Blackmailing A.I. - Talkin’ Bout [infosec] News 2025-05-2707:01 - Story # 1: Experimental drones developed to neutralize mass shooters, disable weapons11:29 - Story # 2: How a global malware operation was taken down from a federal court in Georgia13:50 - Story # 3: Judge allows Workday AI bias lawsuit to proceed as collective action15:23 - Marker 1719:25 - Story # 4: Anthropic’s new AI model turns to blackmail when engineers try to take it offline32:19 - Story # 5: TeleMessage customers include DC Police, Andreessen Horowitz, JP Morgan, and hundreds more34:53 - Story # 6: TikTok videos now push infostealer malware in ClickFix attacks36:57 - Story # 7: Beware, Coinbase users. Crypto thieves are taking fingers now40:56 - Story # 8: Signal now blocks Microsoft Recall screenshots on Windows 1143:16 - Story # 9: Suspected InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords44:54 - Story # 10: Google Chrome’s Built-in Manager Lets Users Update Breached Passwords with One Click48:09 - Story # 11: Russian military hackers ‘Fancy Bear’ target Western aid supply chains to Ukraine, NSA report says50:13 - Story # 12: Google Gemini AI assistant coming to new cars in 2025, starting with Volvo54:17 - Story # 13: Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales56:55 - Story # 13b: [HOPE_16] International Travel Tips (00:00) - PreShow Banter™ — I just want Jorts! (05:41) - Blackmailing A.I. - Talkin' Bout [infosec] News 2025-05-27 (07:00) - Story # 1: Experimental drones developed to neutralize mass shooters, disable weapons (11:28) - Story # 2: How a global malware operation was taken down from a federal court in Georgia (13:49) - Story # 3: Judge allows Workday AI bias lawsuit to proceed as collective action (19:24) - Story # 4: Anthropic’s new AI model turns to blackmail when engineers try to take it offline (32:18) - Story # 5: TeleMessage customers include DC Police, Andreessen Horowitz, JP Morgan, and hundreds more (34:53) - Story # 6: TikTok videos now push infostealer malware in ClickFix attacks (36:57) - Story # 7: Beware, Coinbase users. Crypto thieves are taking fingers now (40:56) - Story # 8: Signal now blocks Microsoft Recall screenshots on Windows 11 (43:16) - Story # 9: Suspected InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords (44:53) - Story # 10: Google Chrome's Built-in Manager Lets Users Update Breached Passwords with One Click (48:08) - Story # 11: Russian military hackers 'Fancy Bear' target Western aid supply chains to Ukraine, NSA report says (50:13) - Story # 12: Google Gemini AI assistant coming to new cars in 2025, starting with Volvo (54:17) - Story # 13: Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales (56:54) - Story # 13b: [HOPE_16] International Travel Tips

May 30, 202558 min

Ep 1WORLDS FIRST CPU Ransomware! - 2025-05-19

Register for Free, Live webcasts & summits:https://poweredbybhis.coma00:00 - PreShow Banter™ — Twiddle Me This02:04 - WORLDS FIRST CPU Ransomware! - Talkin’ Bout [infosec] News 2025-05-1903:10 - Story # 1: Coinbase - Standing Up to Extortionists11:26 - Story # 2: World’s first CPU-level ransomware15:09 - Story # 3: New Intel CPU flaws leak sensitive data from privileged memory19:04 - Story # 4: After latest kidnap attempt, crypto types tell crime bosses: Transfers are traceable21:39 - Story # 5: Chinese ‘kill switches’ found hidden in US solar farms27:52 - Story # 6: Congress proposes 10-year ban on state AI regulations31:41 - Story # 7: Hackers Abuse Copilot AI in SharePoint to Steal Passwords and Sensitive Data36:02 - Story # 8: European Vulnerability Database Launches Amid US CVE Chaos37:32 - Story # 9: 89 million Steam accounts reportedly leaked. Change your password now.40:06 - Story # 10: Hackers Now Targeting US Retailers After UK Attacks, Google41:11 - Story # 11: How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes43:08 - Story # 11b: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage’s archive server47:12 - ChickenSec: ‘A Minecraft Movie’ Viral TikTok Trend Wreaks Havoc In Theaters51:20 - Story # 12: Education giant Pearson hit by cyberattack exposing customer data (00:00) - PreShow Banter™ — Twiddle Me This (02:03) - WORLDS FIRST CPU Ransomware! - Talkin' Bout [infosec] News 2025-05-19 (03:10) - Story # 1: Coinbase - Standing Up to Extortionists (11:25) - Story # 2: World's first CPU-level ransomware (15:09) - Story # 3: New Intel CPU flaws leak sensitive data from privileged memory (19:03) - Story # 4: After latest kidnap attempt, crypto types tell crime bosses: Transfers are traceable (21:38) - Story # 5: Chinese ‘kill switches’ found hidden in US solar farms (27:52) - Story # 6: Congress proposes 10-year ban on state AI regulations (31:41) - Story # 7: Hackers Abuse Copilot AI in SharePoint to Steal Passwords and Sensitive Data (36:01) - Story # 8: European Vulnerability Database Launches Amid US CVE Chaos (37:32) - Story # 9: 89 million Steam accounts reportedly leaked. Change your password now. (40:06) - Story # 10: Hackers Now Targeting US Retailers After UK Attacks, Google (41:10) - Story # 11: How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes (43:08) - Story # 11b: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage's archive server (47:12) - ChickenSec: ‘A Minecraft Movie’ Viral TikTok Trend Wreaks Havoc In Theaters (51:20) - Story # 12: Education giant Pearson hit by cyberattack exposing customer data

May 21, 202553 min

Ep 1Inside DragonForce 2025-05-12

Register for Free, Live webcasts & summits:https://poweredbybhis.coma00:00 - PreShow Banter™ — Crime is bad00:18 - dangerous trend of destroying Chromebooks04:33 - BHIS - Talkin’ Bout [infosec] News 2025-05-1205:40 - Story # 1: LockBit Ransomware Hacked, Insider Secrets Exposed06:36 - Story # 1b: https://ransomch.at09:31 - Story # 2: White House Proposes $500 Million Cut to CISA10:35 - Story # 2b: Update to How CISA Shares Cyber-Related Alerts and Notifications18:09 - Story # 3: Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks22:28 - Story # 4: Despite ransom payment, PowerSchool hacker now extorting individual school districts26:28 - Story # 5: Tech CEOs warn Senate: Outdated US power grid threatens AI ambitions32:20 - Story # 6: Warning — 19 Billion Compromised Passwords Have Been Published Online34:37 - Story # 7: Botnet Dismantled in International Operation, Russian and Kazakhstani Administrators Indicted36:33 - Story # 8: How a new type of AI is helping police skirt facial recognition bans48:38 - Story # 9: Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware51:33 - Story # 10: A Framework to Report AI’s Flaws53:42 - Story # 10b: MITRE ATLAS™54:49 - Simply Hot Ones Challenge | LIVE FIRE SPICE (00:00) - PreShow Banter™ — Crime is bad (00:18) - dangerous trend of destroying Chromebooks (04:32) - BHIS - Talkin' Bout [infosec] News 2025-05-12 (05:39) - Story # 1: LockBit Ransomware Hacked, Insider Secrets Exposed (06:36) - Story # 1b: https://ransomch.at (09:31) - Story # 2: White House Proposes $500 Million Cut to CISA (10:35) - Story # 2b: Update to How CISA Shares Cyber-Related Alerts and Notifications (18:08) - Story # 3: Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks (22:28) - Story # 4: Despite ransom payment, PowerSchool hacker now extorting individual school districts (26:28) - Story # 5: Tech CEOs warn Senate: Outdated US power grid threatens AI ambitions (32:20) - Story # 6: Warning — 19 Billion Compromised Passwords Have Been Published Online (34:37) - Story # 7: Botnet Dismantled in International Operation, Russian and Kazakhstani Administrators Indicted (36:33) - Story # 8: How a new type of AI is helping police skirt facial recognition bans (48:37) - Story # 9: Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware (51:32) - Story # 10: A Framework to Report AI’s Flaws (53:42) - Story # 10b: MITRE ATLAS™ (54:48) - Simply Hot Ones Challenge | LIVE FIRE SPICE 🔥 and CYBER

May 15, 202556 min

Ep 1Scatterd Spider Weaves Another Attack- 2025-05-05

Register for Free, Live webcasts & summits:https://poweredbybhis.com00:00 - PreShow Banter™ — Double Coffee05:04 - BHIS - Talkin’ Bout [infosec] News 2025-05-0506:05 - Story # 1: Largest bank in the world issues stark security warning about technology that billions use every single day11:15 - Story # 2: M&S cyber-attack linked to hacking group Scattered Spider13:47 - Story # 3: Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries20:10 - Story # 4: A North Korean agent applied for a job at a popular crypto firm: They tripped him up with a simple question about Halloween21:54 - Story # 4b: The one interview question that will protect you from North Korean fake workers23:09 - Story # 5: Santa Clarita Man Agrees to Plead Guilty to Hacking Disney Employee’s Computer, Downloading Confidential Data from Company25:33 - Story # 6: TerraStealerV2 and TerraLogger: Golden Chickens’ New Malware Families Discovered29:19 - Story # 7: Gremlin Stealer: New Stealer on Sale in Underground Forum33:17 - Story # 8: Over 290,000 citizens at risk: CloudSEK uncovers major data breach at Bangalore Water Supply and Sewerage Board34:56 - Story # 9: The Signal Clone the Trump Admin Uses Was Hacked39:58 - Story # 10: Windows RDP lets you log in using revoked passwords. Microsoft is OK with that.42:19 - Story # 11: Software dev fortifies his blog with ‘zip bombs’ — attacking bots meet their end with explosive data package43:44 - Story # 12: WhatsApp says in-app AI tools will still keep messages secret45:37 - Story # 13: House passes bill to study routers’ national security risks49:48 - Simply Hot Ones Challenge (YouTube) (00:00) - PreShow Banter™ — Double Coffee (05:03) - BHIS - Talkin' Bout [infosec] News 2025-05-05 (06:05) - Story # 1: Largest bank in the world issues stark security warning about technology that billions use every single day (11:15) - Story # 2: M&S cyber-attack linked to hacking group Scattered Spider (13:46) - Story # 3: Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries (20:10) - Story # 4: A North Korean agent applied for a job at a popular crypto firm: They tripped him up with a simple question about Halloween (21:54) - Story # 4b: The one interview question that will protect you from North Korean fake workers (23:09) - Story # 5: Santa Clarita Man Agrees to Plead Guilty to Hacking Disney Employee’s Computer, Downloading Confidential Data from Company (25:33) - Story # 6: TerraStealerV2 and TerraLogger: Golden Chickens' New Malware Families Discovered (29:19) - Story # 7: Gremlin Stealer: New Stealer on Sale in Underground Forum (33:16) - Story # 8: Over 290,000 citizens at risk: CloudSEK uncovers major data breach at Bangalore Water Supply and Sewerage Board (34:55) - Story # 9: The Signal Clone the Trump Admin Uses Was Hacked (39:57) - Story # 10: Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. (42:19) - Story # 11: Software dev fortifies his blog with 'zip bombs' — attacking bots meet their end with explosive data package (43:43) - Story # 12: WhatsApp says in-app AI tools will still keep messages secret (45:36) - Story # 13: House passes bill to study routers’ national security risks (49:47) - Simply Hot Ones Challenge (YouTube)

May 9, 202554 min

Ep 1InfoSec CEO Charged with Installing Malware! – 2025-04-28

Register for upcoming webcasts & summits - https://poweredbybhis.com00:00 - PreShow Banter™ — Talking Bout Red Green02:24 - InfoSec CEO Charged with Installing Malware! – BHIS - Talkin’ Bout [infosec] News 2025-04-2803:01 - Story # 1: CEO of cybersecurity firm charged with installing malware on hospital systems11:22 - Story # 2: 2025 Data Breach Investigations Report25:05 - Story # 3: The Age of Realtime Deepfake Fraud Is Here29:00 - Story # 4: Whistleblower: DOGE Siphoned NLRB Case Data33:09 - Story # 5: Top employee monitoring app leaks 21 million screenshots on thousands of users36:59 - Story # 6: 159 CVEs Exploited in Q1 2025 — 28.3% Within 24 Hours of Disclosure42:13 - Story # 7: SAP zero-day vulnerability under widespread active exploitation46:29 - Story # 8: FBI: US lost record $16.6 billion to cybercrime in 202447:55 - Story # 8b: FBI Report Doc53:50 - Story # 9: M- Trends 2025 Report (00:00) - PreShow Banter™ — Talking Bout Red Green (02:24) - InfoSec CEO Charged with Installing Malware! – BHIS - Talkin' Bout [infosec] News 2025-04-28 (03:01) - Story # 1: CEO of cybersecurity firm charged with installing malware on hospital systems (11:21) - Story # 2: 2025 Data Breach Investigations Report (25:04) - Story # 3: The Age of Realtime Deepfake Fraud Is Here (28:59) - Story # 4: Whistleblower: DOGE Siphoned NLRB Case Data (33:09) - Story # 5: Top employee monitoring app leaks 21 million screenshots on thousands of users (36:58) - Story # 6: 159 CVEs Exploited in Q1 2025 — 28.3% Within 24 Hours of Disclosure (42:12) - Story # 7: SAP zero-day vulnerability under widespread active exploitation (46:29) - Story # 8: FBI: US lost record $16.6 billion to cybercrime in 2024 (47:54) - Story # 8b: FBI Report Doc (53:49) - Story # 9: M- Trends 2025 Report

Apr 30, 20251h 0m

Ep 1The CVE Saga - Talkin’ Bout [infosec] News 2025-04-21

Register for upcoming webcasts & summits - https://poweredbybhis.com00:00 - PreShow Banter™ — A Monocle and a Glass of Wine05:36 - The CVE Saga - Talkin’ Bout [infosec] News 2025-04-2106:43 - Story # 1: US agency extends support for cyber vulnerability database29:08 - Story # 1b: CVE Foundation32:35 - Story # 2: Former cybersecurity agency chief Chris Krebs leaves SentinelOne after Trump targets him in executive order33:57 - Story # 3: 4chan Is Down Following What Looks to Be a Major Hack Spurred By Meme War37:17 - Story # 4: TA Phone Home: EDR Evasion Testing Reveals Extortion Actor’s Toolkit44:57 - Story # 5: The Sophos Annual Threat Report: Cybercrime on Main Street 2025 (00:00) - PreShow Banter™ — A Monocle and a Glass of Wine (05:36) - The CVE Saga - Talkin' Bout [infosec] News 2025-04-21 (06:43) - Story # 1: US agency extends support for cyber vulnerability database (29:08) - Story # 1b: CVE Foundation (32:34) - Story # 2: Former cybersecurity agency chief Chris Krebs leaves SentinelOne after Trump targets him in executive order (33:57) - Story # 3: 4chan Is Down Following What Looks to Be a Major Hack Spurred By Meme War (37:16) - Story # 4: TA Phone Home: EDR Evasion Testing Reveals Extortion Actor's Toolkit (44:56) - Story # 5: The Sophos Annual Threat Report: Cybercrime on Main Street 2025

Apr 23, 202558 min

Ep 1Largest Corporate Espionage Case this Century - 2025-04-14

Register for upcoming webcasts & summits - https://poweredbybhis.com00:00 - PreShow Banter™ — Trigger Warning00:42 - Trump Vs Chris Krebs | BHIS - Talkin’ Bout [infosec] News 2025-04-1401:54 - Story # 1: Cybersecurity Community Must Not Remain Silent On Executive Order Attacking Former CISA Director17:04 - Story # 2: Cybersecurity industry falls silent as Trump turns ire on SentinelOne18:00 - Story # 3: Maryland pharmacist used keyloggers to spy on coworkers for a decade, victim alleges33:13 - Story # 4: Rippling Believe it or Not: How the Largest Corporate Espionage Case this Century Happened41:36 - Story # 5: Moroccan cybercrime group Atlas Lion hiding in plain sight during attacks on retailers52:18 - Story # 6: Pentagon to end $5.1 billion in contracts with Accenture, Deloitte, others (00:00) - PreShow Banter™ — Trigger Warning (00:41) - Trump Vs Chris Krebs | BHIS - Talkin' Bout [infosec] News 2025-04-14 (01:54) - Story # 1: Cybersecurity Community Must Not Remain Silent On Executive Order Attacking Former CISA Director (17:03) - Story # 2: Cybersecurity industry falls silent as Trump turns ire on SentinelOne (17:59) - Story # 3: Maryland pharmacist used keyloggers to spy on coworkers for a decade, victim alleges (33:12) - Story # 4: Rippling Believe it or Not: How the Largest Corporate Espionage Case this Century Happened (41:36) - Story # 5: Moroccan cybercrime group Atlas Lion hiding in plain sight during attacks on retailers (52:17) - Story # 6: Pentagon to end $5.1 billion in contracts with Accenture, Deloitte, others

Apr 16, 202559 min

Ep 1Desperate Times Makes for More Cyber Crimes -2025-04-07

Register for upcoming webcasts & summits - https://poweredbybhis.comChapters00:00 - PreShow Banter™ — A Complex Business06:40 - BHIS - Talkin’ Bout [infosec] News 2025-04-0707:34 - Story # 1: Oracle quietly admits data breach, days after lawsuit accused it of cover-up12:47 - Story # 2: Twitter (X) Hit by 2.8 Billion Profile Data Leak in Alleged Insider Job21:13 - Story # 3: Phishing platform ‘Lucid’ behind wave of iOS, Android SMS attacks28:14 - Story # 4: GitHub expands security tools after 39 million secrets leaked in 202437:28 - Story # 5: The 10 Biggest Crypto Hacks in History40:11 - Story # 6: OpenAI tests watermarking for ChatGPT-4o Image Generation model45:44 - Story # 7: National Security Agency chief fired as Trump ousts another top military officer (00:00) - PreShow Banter™ — A Complex Business (06:40) - BHIS - Talkin' Bout [infosec] News 2025-04-07 (07:34) - Story # 1: Oracle quietly admits data breach, days after lawsuit accused it of cover-up (12:46) - Story # 2: Twitter (X) Hit by 2.8 Billion Profile Data Leak in Alleged Insider Job (21:12) - Story # 3: Phishing platform 'Lucid' behind wave of iOS, Android SMS attacks (28:13) - Story # 4: GitHub expands security tools after 39 million secrets leaked in 2024 (37:28) - Story # 5: The 10 Biggest Crypto Hacks in History (40:10) - Story # 6: OpenAI tests watermarking for ChatGPT-4o Image Generation model (45:43) - Story # 7: National Security Agency chief fired as Trump ousts another top military officer

Apr 9, 202548 min

Ep 1The Oracle of Lies! – 2025-03-31

00:00 - PreShow Banter™ — The Bed Slinger08:34 - The Oracle of Lies! - BHIS - Talkin’ Bout [infosec] News 2025-03-3110:43 - Story # 1: Oracle attempt to hide serious cybersecurity incident from customers in Oracle SaaS service20:00 - Story # 2: A Sneaky Phish Just Grabbed my Mailchimp Mailing List26:17 - Story # 3: Windows 11 is closing a loophole that let you skip making a Microsoft account29:51 - Story # 4: The Trump Administration Accidentally Texted Me Its War Plans32:51 - Story # 4b: Signal is ‘absolutely not suitable’ for government use: Former NSA hacker37:42 - Story # 5: How the FBI Tracked, and Froze, Millions Sent to Criminals in Massive Caesars Casino Hack42:27 - Story # 6: Retail giant Sam’s Club investigates Clop ransomware breach claims45:07 - WEBCAST – Keeping Things Local – Making Your Own Private LLM w/ Bronwen Aker46:16 - Story # 7: New VanHelsing ransomware targets Windows, ARM, ESXi systems48:28 - Story # 8: Infostealer campaign compromises 10 npm packages, targets devs53:13 - Story # 9: Risky Biz News: EU bans anonymous crypto payments56:02 - ChickenSec: South African Poultry Company Reports $1M Loss After Cyber Intrusion (00:00) - PreShow Banter™ — The Bed Slinger (08:34) - BHIS - Talkin' Bout [infosec] News 2025-03-31 (10:43) - Story # 1: Oracle attempt to hide serious cybersecurity incident from customers in Oracle SaaS service (20:00) - Story # 2: A Sneaky Phish Just Grabbed my Mailchimp Mailing List (26:16) - Story # 3: Windows 11 is closing a loophole that let you skip making a Microsoft account (29:50) - Story # 4: The Trump Administration Accidentally Texted Me Its War Plans (32:51) - Story # 4b: Signal is 'absolutely not suitable' for government use: Former NSA hacker (37:41) - Story # 5: How the FBI Tracked, and Froze, Millions Sent to Criminals in Massive Caesars Casino Hack (42:26) - Story # 6: Retail giant Sam’s Club investigates Clop ransomware breach claims (45:07) - WEBCAST – Keeping Things Local – Making Your Own Private LLM w/ Bronwen Aker (46:15) - Story # 7: New VanHelsing ransomware targets Windows, ARM, ESXi systems (48:27) - Story # 8: Infostealer campaign compromises 10 npm packages, targets devs (53:12) - Story # 9: Risky Biz News: EU bans anonymous crypto payments (56:02) - ChickenSec: South African Poultry Company Reports $1M Loss After Cyber Intrusion

Apr 3, 20251h 2m

Ep 1Trading in Jock Straps for Jock Hacks – 2025-03-24

00:00 - PreShow Banter™ — We’re Not Ready For the Finger Thing01:40 - Trading in Jock Straps for Jock Hacks – BHIS - Talkin’ Bout [infosec] News 2025-03-2403:24 - Story # 1: GitHub Action hack likely led to another in cascading supply chain attack07:53 - Story # 2: Wiz to Join Google Cloud: Making Magic Together14:47 - Story # 3: Oracle denies breach after hacker claims theft of 6 million data records19:52 - Story # 4: Critical flaw in Next.js lets hackers bypass authorization25:47 - Story # 5: Cloudflare builds an AI to lead AI scraper bots into a horrible maze of junk content29:20 - Story # 6: Ex-Michigan QB coach Matt Weiss facing 24 federal charges in hack of thousands of student accounts35:47 - Story # 7: DNA of 15 Million People for Sale in 23andMe Bankruptcy38:40 - Story # 8: Everything you say to your Echo will be sent to Amazon starting on March 2844:03 - Story # 9: We partner with world-renowned scambusters to create our own fraud-fighting call centre52:01 - Story # 10: Sperm donation giant California Cryobank warns of a data breach54:19 - Story # 11: Microsoft: New RAT malware used for crypto theft, reconnaissance56:32 - Story # 12: TrustedSec | Trimarc Joins Forces with TrustedSec to Strengthen… (00:00) - PreShow Banter™ — We're Not Ready For the Finger Thing (01:40) - Trading in Jock Straps for Jock Hacks – BHIS - Talkin' Bout [infosec] News 2025-03-24 (03:23) - Story # 1: GitHub Action hack likely led to another in cascading supply chain attack (07:53) - Story # 2: Wiz to Join Google Cloud: Making Magic Together (14:46) - Story # 3: Oracle denies breach after hacker claims theft of 6 million data records (19:51) - Story # 4: Critical flaw in Next.js lets hackers bypass authorization (25:46) - Story # 5: Cloudflare builds an AI to lead AI scraper bots into a horrible maze of junk content (29:20) - Story # 6: Ex-Michigan QB coach Matt Weiss facing 24 federal charges in hack of thousands of student accounts (35:46) - Story # 7: DNA of 15 Million People for Sale in 23andMe Bankruptcy (38:40) - Story # 8: Everything you say to your Echo will be sent to Amazon starting on March 28 (44:02) - Story # 9: We partner with world-renowned scambusters to create our own fraud-fighting call centre (52:00) - Story # 10: Sperm donation giant California Cryobank warns of a data breach (54:19) - Story # 11: Microsoft: New RAT malware used for crypto theft, reconnaissance (56:32) - Story # 12: TrustedSec | Trimarc Joins Forces with TrustedSec to Strengthen…

Mar 26, 202558 min

Ep 1News 2025-03-17 - Malicious Browser Plugins will Destroy us ALL!!!!!

00:00 - PreShow Banter™ — Fun Jank Decks05:25 - BHIS - Talkin’ Bout [infosec] News 2025-03-17 - Malicious browser plugins will destroy us ALL!!!!!06:35 - Story # 1: Polymorphic Extensions: The Sneaky Extension That Can Impersonate Any Browser Extension14:37 - Story # 1b: Chrome Web Store is a mess31:14 - Story # 2: Lazarus Strikes npm Again with New Wave of Malicious Packages36:17 - Story # 3: China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days44:44 - Story # 4: Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data49:31 - Story # 5: Second biggest bank in US hit by major data breach stealing social security numbers and other personal info51:25 - Story # 6: Hackers Take Credit for X Cyberattack54:32 - Story # 7: Hackers Using Advanced MFA-Bypassing Techniques To Gain Access To User Account (00:00) - PreShow Banter™ — Fun Jank Decks (05:24) - BHIS - Talkin' Bout [infosec] News 2025-03-17 - Malicious Browser Plugins will Destroy us ALL!! (06:35) - Story # 1: Polymorphic Extensions: The Sneaky Extension That Can Impersonate Any Browser Extension (14:37) - Story # 1b: Chrome Web Store is a mess (31:14) - Story # 2: Lazarus Strikes npm Again with New Wave of Malicious Packages (36:17) - Story # 3: China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days (44:43) - Story # 4: Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data (49:31) - Story # 5: Second biggest bank in US hit by major data breach stealing social security numbers and other personal info (51:25) - Story # 6: Hackers Take Credit for X Cyberattack (54:32) - Story # 7: Hackers Using Advanced MFA-Bypassing Techniques To Gain Access To User Account

Mar 19, 20251h 0m

Ep 12025-03-10 — Agent A.I.

00:00 - PreShow Banter™ — Agent A.I.07:35 - BHIS - Talkin’ Bout [infosec] News 2025-03-1010:47 - Story # 1: 12 Chinese hackers charged with US Treasury breach — and much, much more15:25 - Story # 2: Signal President Meredith Whittaker calls out agentic AI as having ‘profound’ security and privacy issues25:33 - Story # 3: X/Twitter is down for a third time today27:33 - Story # 4: Developer sabotaged ex-employer with kill switch activated when he was let go33:37 - Story # 5: Undocumented commands found in Bluetooth chip used by a billion devices45:37 - Story # 6: Cybercrime’s Cobalt Strike Use Plummets 80% Worldwide46:19 - Story # 7: Majority of Orgs Hit by AI Cyber-Attacks as Detection Lags55:01 - Story # 8: Ransomware gang encrypted network from a webcam to bypass EDR (00:00) - PreShow Banter™— Agent A.I. (07:35) - BHIS - Talkin' Bout [infosec] News 2025-03-10 (10:47) - Story # 1: 12 Chinese hackers charged with US Treasury breach — and much, much more (15:24) - Story # 2: Signal President Meredith Whittaker calls out agentic AI as having ‘profound’ security and privacy issues (25:32) - Story # 3: X/Twitter is down for a third time today (27:33) - Story # 4: Developer sabotaged ex-employer with kill switch activated when he was let go (33:37) - Story # 5: Undocumented commands found in Bluetooth chip used by a billion devices (45:36) - Story # 6: Cybercrime's Cobalt Strike Use Plummets 80% Worldwide (46:19) - Story # 7: Majority of Orgs Hit by AI Cyber-Attacks as Detection Lags (55:00) - Story # 8: Ransomware gang encrypted network from a webcam to bypass EDR

Mar 12, 20251h 4m

Ep 12025-03-03 - Not Talking About Anything

00:00 - PreShow Banter™ — Not Talking About Anything04:29 - BHIS - Talkin’ Bout [infosec] News 2025-03-0305:42 - Story # 1: FBI Warns iPhone, Android Users—We Want ‘Lawful Access’ To All Your Encrypted Data24:28 - Story # 2: Disney engineer downloaded ‘helpful’ AI tool that ended up completely destroying his life34:28 - Story # 3: Have I Been Pwned adds 284M accounts stolen by infostealer malware43:22 - Story # 4: Dragos’s 8th Annual OT Cybersecurity Year in Review Is Now Available45:53 - Story # 5: Trump administration retreats in fight against Russian cyber threats55:19 - Story # 5b: Exclusive: US intel shows Russia and China are attempting to recruit disgruntled federal employees, sources say57:33 - Story # 6: Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’ (00:00) - PreShow Banter™ — Not Talking About Anything (04:28) - BHIS - Talkin' Bout [infosec] News 2025-03-03 (05:42) - Story # 1: FBI Warns iPhone, Android Users—We Want ‘Lawful Access’ To All Your Encrypted Data (24:27) - Story # 2: Disney engineer downloaded 'helpful' AI tool that ended up completely destroying his life (34:27) - Story # 3: Have I Been Pwned adds 284M accounts stolen by infostealer malware (43:22) - Story # 4: Dragos's 8th Annual OT Cybersecurity Year in Review Is Now Available (45:53) - Story # 5: Trump administration retreats in fight against Russian cyber threats (55:19) - Story # 5b: Exclusive: US intel shows Russia and China are attempting to recruit disgruntled federal employees, sources say (57:32) - Story # 6: Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’

Mar 5, 202558 min

Ep 12025-05-24 - Get Political (With Jake Williams)

00:00 - PreShow Banter™ — Get Political05:27 - BHIS - Talkin’ Bout [infosec] News 2025-02-2506:07 - Story # 1: Trump 2.0 Brings Cuts to Cyber, Consumer Protections37:57 - Story # 2: OpenAI Uncovers Evidence of A.I.-Powered Chinese Surveillance Tool49:48 - Story # 3: Apple pulls data protection tool after UK government security row55:00 - Story # 4: Judge dismisses Chris Hadnagy lawsuit against DEF CON (00:00) - PreShow Banter™ — Get Political (05:26) - BHIS - Talkin' Bout [infosec] News 2025-02-25 (06:07) - Story # 1: Trump 2.0 Brings Cuts to Cyber, Consumer Protections (37:56) - Story # 2: OpenAI Uncovers Evidence of A.I.-Powered Chinese Surveillance Tool (49:48) - Story # 3: Apple pulls data protection tool after UK government security row (54:59) - Story # 4: Judge dismisses Chris Hadnagy lawsuit against DEF CON

Feb 26, 20251h 2m

Ep 12025-02-17 - Prove That You're Wearing Pants

00:00 - PreShow Banter™ — Prove That You’re Wearing Pants05:50 - BHIS - Talkin’ Bout [infosec] News 2025-05-1706:46 - Story # 1: Fortinet discloses second firewall auth bypass patched in January07:12 - Story # 1b: Fortinet CEO boasts it was voted the “most trusted” cybersecurity firm. Don’t die laughing08:45 - Story # 1c: Forbes Most Trusted Companies in America 2025 List16:25 - Story # 2: SAML Bypass Authentication on GitHub Enterprise Servers to Login as Other User Account18:37 - Story # 2b: Rapid7 Flags New PostgreSQL Zero-Day Connected to BeyondTrust Exploitation20:04 - Story # 3: Putting the human back into AI is key, former NSA Director Nakasone says36:35 - Story # 4: Apple Confirms USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack37:44 - Story # 5: DOGE Exposes Once-Secret Government Networks, Making Cyber-Espionage Easier than Ever43:14 - Story # 5b: DOGE’s .gov site lampooned as coders quickly realize it can be edited by anyone46:59 - Story # 6: Man who SIM-swapped the SEC’s X account pleads guilty51:26 - Story # 7: Russia’s Sandworm caught snarfing credentials, data from American and Brit orgs53:55 - Story # 8: Nearly 10 years after Data and Goliath, Bruce Schneier says: Privacy’s still screwed (00:00) - PreShow Banter™ — Prove That You're Wearing Pants (05:49) - BHIS - Talkin' Bout [infosec] News 2025-05-17 (06:46) - Story # 1: Fortinet discloses second firewall auth bypass patched in January (07:11) - Story # 1b: Fortinet CEO boasts it was voted the “most trusted” cybersecurity firm. Don't die laughing (08:44) - Story # 1c: Forbes Most Trusted Companies in America 2025 List (16:24) - Story # 2: SAML Bypass Authentication on GitHub Enterprise Servers to Login as Other User Account (18:37) - Story # 2b: Rapid7 Flags New PostgreSQL Zero-Day Connected to BeyondTrust Exploitation (20:04) - Story # 3: Putting the human back into AI is key, former NSA Director Nakasone says (36:34) - Story # 4: Apple Confirms USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack (37:43) - Story # 5: DOGE Exposes Once-Secret Government Networks, Making Cyber-Espionage Easier than Ever (43:14) - Story # 5b: DOGE’s .gov site lampooned as coders quickly realize it can be edited by anyone (46:58) - Story # 6: Man who SIM-swapped the SEC's X account pleads guilty (51:26) - Story # 7: Russia's Sandworm caught snarfing credentials, data from American and Brit orgs (53:55) - Story # 8: Nearly 10 years after Data and Goliath, Bruce Schneier says: Privacy’s still screwed

Feb 19, 20251h 5m

Ep 12025-02-10 - Walking Through Denver

00:00 - PreShow Banter™ — Walking Through Denver02:23 - BHIS - Talkin’ Bout [infosec] News 2025-02-1004:35 - Story # 1: Ransomware payments declined in 2024 despite massive. well-known hacks05:02 - Story # 1b: 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments14:19 - Story # 2: Critical Cisco ISE bug can let attackers run commands as root16:43 - Story # 3: The Untold Story of a Crypto Crimefighter’s Descent Into Nigerian Prison24:18 - Story # 4: IoT’s botnet problem is up 500% – three things admins must do now31:49 - Story # 5: WhatsApp identifies dozens of users hacked by Paragon spyware company39:41 - Story # 6: Sri Lanka goes bananas after monkey unplugs nation43:36 - Story # 7: Microsoft Study Finds AI Makes Human Cognition “Atrophied and Unprepared”50:17 - ChickenSec Story #: 1 Here’s a Super Bowl riddle: Why are egg prices surging — but not chicken wings?52:21 - Story # 8: DOGE Staffer Previously Fired From Cybersecurity Company for Leaking Secrets58:07 - ChickenSec Story #2: Americans to Eat 1.47 Billion Chicken Wings for Super Bowl LIX (00:00) - PreShow Banter™ — Walking Through Denver (02:23) - BHIS - Talkin' Bout [infosec] News 2025-02-10 (04:34) - Story # 1: Ransomware payments declined in 2024 despite massive. well-known hacks (05:02) - Story # 1b: 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments (14:18) - Story # 2: Critical Cisco ISE bug can let attackers run commands as root (16:42) - Story # 3: The Untold Story of a Crypto Crimefighter’s Descent Into Nigerian Prison (24:17) - Story # 4: IoT’s botnet problem is up 500% – three things admins must do now (31:48) - Story # 5: WhatsApp identifies dozens of users hacked by Paragon spyware company (39:40) - Story # 6: Sri Lanka goes bananas after monkey unplugs nation (43:35) - Story # 7: Microsoft Study Finds AI Makes Human Cognition “Atrophied and Unprepared” (50:16) - ChickenSec Story #: 1 Here's a Super Bowl riddle: Why are egg prices surging — but not chicken wings? (52:21) - Story # 8: DOGE Staffer Previously Fired From Cybersecurity Company for Leaking Secrets (58:06) - ChickenSec Story #2: Americans to Eat 1.47 Billion Chicken Wings for Super Bowl LIX

Feb 13, 20251h 2m

Ep 12025-02-05 - LIVE FROM WWHF DENVER 2025

00:00 - PreShow Banter™ — Community Swear Bucket01:40 - BHIS - Talkin’ Bout [infosec] News 2025-02-0503:27 - Story # 1: DeepSeek R1 Exposed: Security Flaws in China’s AI Model11:25 - Story # 2: Backdoor found in two healthcare patient monitors, linked to IP in China15:21 - Story # 3: Facebook flags Linux topics as ‘cybersecurity threats’ — posts and users being blocked20:56 - Story # 4: Here’s how Musk’s access to Treasury system may impact Social Security, other government payments31:29 - Story # 5: Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections34:34 - Story # 6: Insurance Company Globe Life Notifying 850,000 People of Data Breach36:15 - Story # 10: DeepSeek Fails Researchers’ Safety Tests38:35 - Story # 11: Engineering giant Smiths Group discloses security breach (00:00) - PreShow Banter™ — Community Swear Bucket (01:39) - BHIS - Talkin' Bout [infosec] News 2025-02-05 (03:26) - Story # 1: DeepSeek R1 Exposed: Security Flaws in China’s AI Model (11:24) - Story # 2: Backdoor found in two healthcare patient monitors, linked to IP in China (15:20) - Story # 3: Facebook flags Linux topics as 'cybersecurity threats' — posts and users being blocked (20:55) - Story # 4: Here’s how Musk’s access to Treasury system may impact Social Security, other government payments (31:28) - Story # 5: Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections (34:34) - Story # 6: Insurance Company Globe Life Notifying 850,000 People of Data Breach (36:15) - Story # 10: DeepSeek Fails Researchers' Safety Tests (38:35) - Story # 11: Engineering giant Smiths Group discloses security breach

Feb 12, 202544 min

Ep 12025-01-27 - Fake Australian

00:00 - PreShow Banter™ — Fake Australian04:17 - BHIS - Talkin’ Bout [infosec] News 2025-01-2704:34 - Story # 1: DeepSeek sparks AI stock selloff; Nvidia posts record market-cap loss30:50 - Story # 2: Tech giants are putting $500bn into ‘Stargate’ to build up AI in US42:23 - Story # 3: DeepSeek Faces Large-scale Cyberattack, Halts New User Registrations43:34 - Story # 4: DHS cyber review board cleaned out in Trump move to eliminate ‘misuse of resources’47:38 - Story # 5: UnitedHealth estimates 190M people impacted by Change Healthcare cyberattack50:02 - Story # 5b: UnitedHealth now says 190 million impacted by 2024 data breach53:09 - Story # 6: Cloudflare Issue Can Leak Chat App Users’ Broad Location54:09 - Story # 7: Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel59:40 - Story # 8: Researchers say new attack could take down the European power grid (00:00) - PreShow Banter™ — Fake Australian (04:17) - BHIS - Talkin' Bout [infosec] News 2025-01-27 (04:34) - Story # 1: DeepSeek sparks AI stock selloff; Nvidia posts record market-cap loss (30:49) - Story # 2: Tech giants are putting $500bn into 'Stargate' to build up AI in US (42:23) - Story # 3: DeepSeek Faces Large-scale Cyberattack, Halts New User Registrations (43:33) - Story # 4: DHS cyber review board cleaned out in Trump move to eliminate ‘misuse of resources’ (47:38) - Story # 5: UnitedHealth estimates 190M people impacted by Change Healthcare cyberattack (50:01) - Story # 5b: UnitedHealth now says 190 million impacted by 2024 data breach (53:08) - Story # 6: Cloudflare Issue Can Leak Chat App Users' Broad Location (54:09) - Story # 7: Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (59:39) - Story # 8: Researchers say new attack could take down the European power grid

Jan 29, 20251h 3m

Ep 12025-01-20 - Highest Rated Chalk

00:00 - PreShow Banter™ — Highest Rated Chalk04:14 - BHIS - Talkin’ Bout [infosec] News 2025-01-2008:53 - Story # 1: Data From 15,000 Fortinet Firewalls Leaked by Hackers14:25 - Story # 2: China’s Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says16:29 - Story # 3: TikTok reportedly plans ‘immediate’ Sunday shutdown in the US if it’s banned25:47 - Story # 4: FBI forces Chinese malware to delete itself from thousands of US computers35:06 - WWHF Denver36:03 - BSides San Diego37:23 - Security Stadium38:22 - Story # 5: Exchange 2016 and 2019 reach end-of-life status later this year42:45 - Story # 6: Snyk security researcher deploys malicious NPM packages targeting Cursor.com46:17 - Story # 7: New UEFI Secure Boot flaw exposes systems to bootkits, patch now57:34 - Story # 8: Lawsuit: Allstate used GasBuddy and other apps to quietly track driving (00:00) - PreShow Banter™ — Highest Rated Chalk (04:13) - BHIS - Talkin' Bout [infosec] News 2025-01-20 (08:53) - Story # 1: Data From 15,000 Fortinet Firewalls Leaked by Hackers (14:24) - Story # 2: China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says (16:28) - Story # 3: TikTok reportedly plans ‘immediate’ Sunday shutdown in the US if it’s banned (25:47) - Story # 4: FBI forces Chinese malware to delete itself from thousands of US computers (35:05) - WWHF Denver (36:03) - BSides San Diego (37:22) - Security Stadium (38:21) - Story # 5: Exchange 2016 and 2019 reach end-of-life status later this year (42:45) - Story # 6: Snyk security researcher deploys malicious NPM packages targeting Cursor.com (46:16) - Story # 7: New UEFI Secure Boot flaw exposes systems to bootkits, patch now (57:33) - Story # 8: Lawsuit: Allstate used GasBuddy and other apps to quietly track driving behavior

Jan 22, 20251h 4m

Ep 12025-01-13 — An RGB State of Mind

00:00:00 - PreShow Banter™ — An RGB State of Mind00:07:20 - BHIS - Talkin’ Bout [infosec] News 2025-01-1300:10:24 - Story # 1: A Day in the Life of a Prolific Voice Phishing Crew00:18:39 - Story # 2: Dental group lied through teeth about data breach, fined $350,00000:25:49 - Story # 3: Hacker claims breach of US location tracking company Gravy Analytics00:27:48 - Story # 4: License Plate Readers Are Leaking Real-Time Video Feeds and Vehicle Data00:33:19 - Story # 5: US Cyber Trust Mark launches as the Energy Star of smart home security00:43:08 - Story # 6: Hackers are exploiting a new Ivanti VPN security bug to hack into company networks00:45:09 - Story # 7: Hacker Broke into ‘Path of Exile 2’ Admin Account, Hijacked Wave of Characters00:47:36 - Story # 8: Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit00:54:47 - Story # 9: Ransomware crew abuses AWS native encryption01:00:41 - Story # 10: Cannabis company Stiiizy says hackers accessed customers’ ID documents (00:00) - PreShow Banter™ — An RGB State of Mind (07:19) - BHIS - Talkin' Bout [infosec] News 2025-01-13 (10:24) - Story # 1: A Day in the Life of a Prolific Voice Phishing Crew (18:38) - Story # 2: Dental group lied through teeth about data breach, fined $350,000 (25:48) - Story # 3: Hacker claims breach of US location tracking company Gravy Analytics (27:47) - Story # 4: License Plate Readers Are Leaking Real-Time Video Feeds and Vehicle Data (33:18) - Story # 5: US Cyber Trust Mark launches as the Energy Star of smart home security (43:08) - Story # 6: Hackers are exploiting a new Ivanti VPN security bug to hack into company networks (45:09) - Story # 7: Hacker Broke into ‘Path of Exile 2’ Admin Account, Hijacked Wave of Characters (47:35) - Story # 8: Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit (54:47) - Story # 9: Ransomware crew abuses AWS native encryption (01:00:40) - Story # 10: Cannabis company Stiiizy says hackers accessed customers’ ID documents

Jan 15, 20251h 7m

Ep 12025-01-06 - Coffee With Wade

00:00:00 - PreShow Banter™ — Coffee With Wade Wells00:05:41 - BHIS - Talkin’ Bout [infosec] News 2025-01-0600:06:45 - Story # 1: BeyondTrust says hackers breached Remote Support SaaS instances00:13:18 - Things Continued to be ignored in 202500:24:39 - Story # 2: Classified fighter jet specs leaked on War Thunder – again00:28:26 - Story # 3: New Proposed HIPAA Security Rule Changes00:34:33 - Story # 4: The Breachies 2024: The Worst, Weirdest, Most Impactful Data Breaches of the Year00:35:47 - Story # 5: AT&T and Verizon say networks secure after Salt Typhoon breach00:37:20 - Story # 6: Net Neutrality Rules Struck Down by Appeals Court00:41:56 - Story # 7: U.S. Army Soldier Arrested in AT&T, Verizon Extortions00:45:28 - Story # 8: New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy00:48:38 - Story # 9: Meta’s AI Profiles Are Indistinguishable From Terrible Spam That Took Over Facebook00:50:42 - Story # 9b: Meta deletes AI character profiles after backlash, racism accusations00:51:40 - Story # 10: Watch: Tiny robot ‘kidnaps’ 12 big Chinese bots from a Shanghai showroom, shocks world00:55:27 - Story # 11: China Arrests 4 Who Weaponized ChatGPT for Ransomware Attacks00:58:42 - Story # 12: Man Accused of SQL Injection Hacking Gets 69-Month Prison Sentence01:01:22 - Story # 13: Germany cuts hacker access to 30,000 devices infected with BadBox malware (00:00) - PreShow Banter™ — Coffee With Wade Wells (05:40) - BHIS - Talkin' Bout [infosec] News 2025-01-06 (06:44) - Story # 1: BeyondTrust says hackers breached Remote Support SaaS instances (13:17) - Things Continued to be ignored in 2025 (24:38) - Story # 2: Classified fighter jet specs leaked on War Thunder – again (28:25) - Story # 3: New Proposed HIPAA Security Rule Changes (34:32) - Story # 4: The Breachies 2024: The Worst, Weirdest, Most Impactful Data Breaches of the Year (35:46) - Story # 5: AT&T and Verizon say networks secure after Salt Typhoon breach (37:19) - Story # 6: Net Neutrality Rules Struck Down by Appeals Court (41:55) - Story # 7: U.S. Army Soldier Arrested in AT&T, Verizon Extortions (45:28) - Story # 8: New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy (48:38) - Story # 9: Meta's AI Profiles Are Indistinguishable From Terrible Spam That Took Over Facebook (50:41) - Story # 9b: Meta deletes AI character profiles after backlash, racism accusations (51:40) - Story # 10: Watch: Tiny robot ‘kidnaps’ 12 big Chinese bots from a Shanghai showroom, shocks world (55:27) - Story # 11: China Arrests 4 Who Weaponized ChatGPT for Ransomware Attacks (58:42) - Story # 12: Man Accused of SQL Injection Hacking Gets 69-Month Prison Sentence

Jan 9, 20251h 4m

Ep 12024-12-16 - ChickenSec News Part 3

00:00 - PreShow Banter™ — ChickenSec News Part 312:23 - BHIS - Talkin’ Bout [infosec] News 2024-12-1614:48 - Story # 1: $50 Million Radiant Capital Heist Blamed on North Korean Hackers20:30 - Story # 2: Trump administration wants to go on cyber offensive against China32:53 - Story # 3: Krispy Kreme cyberattack impacts online orders and operations43:02 - Story # 4: Arctic Wolf and BlackBerry Announce Acquisition Agreement for Cylance52:02 - Story # 5: Europol announces takedown of major DDoS-for-hire network56:50 - Story # 6: Data breach at Senior Dating website spills info of 765,000 users58:46 - Story # 7: US sanctions Chinese firm for hacking firewalls in ransomware attacks (00:00) - PreShow Banter™ — ChickenSec News Part 3 (12:22) - BHIS - Talkin' Bout [infosec] News 2024-12-16 (14:47) - Story # 1: $50 Million Radiant Capital Heist Blamed on North Korean Hackers (20:29) - Story # 2: Trump administration wants to go on cyber offensive against China (32:53) - Story # 3: Krispy Kreme cyberattack impacts online orders and operations (43:01) - Story # 4: Arctic Wolf and BlackBerry Announce Acquisition Agreement for Cylance (52:02) - Story # 5: Europol announces takedown of major DDoS-for-hire network (56:50) - Story # 6: Data breach at Senior Dating website spills info of 765,000 users (58:45) - Story # 7: US sanctions Chinese firm for hacking firewalls in ransomware attacks

Dec 18, 20241h 10m

Ep 12024-12-09 - A Better Mike

00:00 - PreShow Banter™ — A Better Mike04:46 - BHIS - Talkin’ Bout [infosec] News 2024-12-0905:43 - Story # 1: FBI Warns iPhone And Android Users—Stop Sending Texts23:36 - Story # 2: US agency proposes new rule blocking data brokers from selling Americans’ sensitive personal data42:55 - Story # 3: Vodka maker Stoli files for bankruptcy in US after ransomware attack46:48 - Story # 4: British hospitals hit by cyberattacks still battling to get systems back online (00:00) - PreShow Banter™ — A Better Mike (04:46) - BHIS - Talkin' Bout [infosec] News 2024-12-09 (05:43) - Story # 1: FBI Warns iPhone And Android Users—Stop Sending Texts (23:36) - Story # 2: US agency proposes new rule blocking data brokers from selling Americans’ sensitive personal data (42:55) - Story # 3: Vodka maker Stoli files for bankruptcy in US after ransomware attack (46:48) - Story # 4: British hospitals hit by cyberattacks still battling to get systems back online

Dec 11, 20241h 4m

Ep 12024-12-02 - C Squad

00:00:00 - PreShow Banter™ — C Squad00:11:03 - BHIS - Talkin’ Bout [infosec] News 2024-12-0200:15:43 - Story # 1: Gaming Engines: An Undetected Playground for Malware Loaders - Check Point Research00:30:41 - Story # 2: FTC finds that smart-device makers fail to make clear how long their products will be supported00:44:47 - Story # 3: US senators propose law to require bare minimum security standards00:46:35 - Story # 4: Starbucks baristas can’t view their schedules after ransomware attack on vendor01:04:26 - Story # 5: Volunteer DEF CON hackers dive into America’s leaky water infrastructure01:08:45 - Shameless Plugs (00:00) - PreShow Banter™ — C Squad (11:02) - BHIS - Talkin' Bout [infosec] News 2024-12-02 (15:42) - Story # 1: Gaming Engines: An Undetected Playground for Malware Loaders - Check Point Research (30:40) - Story # 2: FTC finds that smart-device makers fail to make clear how long their products will be supported (44:46) - Story # 3: US senators propose law to require bare minimum security standards (46:35) - Story # 4: Starbucks baristas can’t view their schedules after ransomware attack on vendor (01:04:26) - Story # 5: Volunteer DEF CON hackers dive into America's leaky water infrastructure (01:08:44) - Shameless Plugs - 40% off all items in the store -- cYb3rM0nD@Y40OFF This discount is good until Tuesday, Dec 2nd at 8pm ET. https://spearphish-general-store.myshopify.com/

Dec 4, 20241h 12m

Ep 12024-11-25 - Discordgate

00:00:00 - PreShow Banter™ — Discordgate00:09:24 - BHIS - Talkin’ Bout [infosec] News 2024-11-2500:10:46 - Story # 1: DOJ says Google must sell Chrome to crack open its search monopoly00:12:08 - Story # 1b: DOJ’s staggering proposal would hurt consumers and America’s global technological leadership00:19:16 - Story # 2: The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access00:24:37 - Story # 3: Palo Alto Networks tackles firewall-busting zero-days with critical patches00:25:46 - Discordgate Follow Up00:26:26 - Story # 4: Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization00:31:08 - Story # 5: Fintech giant Finastra investigates data breach after SFTP hack00:34:01 - Story # 6: CFPB Finalizes Rule on Federal Oversight of Popular Digital Payment Apps to Protect Personal Data, Reduce Fraud, and Stop Illegal “Debanking”00:38:49 - Story # 7: T-Mobile finally managed to thwart a data breach before it occured00:40:22 - Story # 8: D-Link urges users to retire VPN routers impacted by unfixed RCE flaw00:43:07 - Story # 9: US seizes PopeyeTools cybercrime marketplace, charges administrators00:46:19 - Story # 10: Razzlekhan, crypto’s most embarrassing rapper, is going to prison00:48:31 - Story # 10b: Netflix has a perfectly timed Razzlekhan doc coming out in December00:50:10 - Story # 11: Microsoft Defender Is Not Enough Anymore—This Malware Gets Around It00:55:11 - Story # 12: Microsoft president asks Trump to “push harder” against Russian hacks00:57:02 - Story # 13: Hackers Breach Andrew Tate’s Online ‘University,’ Exposing 800,000 Users01:00:36 - Story # 14: 7-Zip affected by dangerous vulnerability: users must update the app manually01:01:31 - Story # 15: Microsoft disrupts ONNX phishing-as-a-service infrastructure01:03:07 - Story # 16: US charges five linked to Scattered Spider cybercrime gang01:04:25 - Plug: Secure Code Summit 2024 (00:00) - PreShow Banter™ — Discordgate (09:23) - BHIS - Talkin' Bout [infosec] News 2024-11-25 (10:45) - Story # 1: DOJ says Google must sell Chrome to crack open its search monopoly (12:07) - Story # 1b: DOJ’s staggering proposal would hurt consumers and America’s global technological leadership (19:15) - Story # 2: The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access (24:37) - Story # 3: Palo Alto Networks tackles firewall-busting zero-days with critical patches (25:46) - Discordgate Follow Up (26:25) - Story # 4: Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization (31:07) - Story # 5: Fintech giant Finastra investigates data breach after SFTP hack (34:01) - Story # 6: CFPB Finalizes Rule on Federal Oversight of Popular Digital Payment Apps to Protect Personal Data, Reduce Fraud, and Stop Illegal “Debanking” (38:49) - Story # 7: T-Mobile finally managed to thwart a data breach before it occured (40:21) - Story # 8: D-Link urges users to retire VPN routers impacted by unfixed RCE flaw (43:06) - Story # 9: US seizes PopeyeTools cybercrime marketplace, charges administrators (46:19) - Story # 10: Razzlekhan, crypto’s most embarrassing rapper, is going to prison (48:31) - Story # 10b: Netflix has a perfectly timed Razzlekhan doc coming out in December (50:10) - Story # 11: Microsoft Defender Is Not Enough Anymore—This Malware Gets Around It (55:11) - Story # 12: Microsoft president asks Trump to “push harder” against Russian hacks (57:02) - Story # 13: Hackers Breach Andrew Tate's Online 'University,' Exposing 800,000 Users (01:00:36) - Story # 14: 7-Zip affected by dangerous vulnerability: users must update the app manually (01:01:31) - Story # 15: Microsoft disrupts ONNX phishing-as-a-service infrastructure (01:03:06) - Story # 16: US charges five linked to Scattered Spider cybercrime gang (01:04:25) - Plug: Secure Code Summit 2024

Nov 27, 20241h 6m

Ep 12024-11-18 - Yacht Doc

00:00 - PreShow Banter™ — Yacht Doc07:40 - BHIS - Talkin’ Bout [infosec] News 2024-11-1808:49 - Story # 1: Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit16:02 - Story # 2: CISA Director Jen Easterly to depart agency on January 2019:26 - Story # 3: Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack28:44 - Story # 4: T-Mobile hacked in massive Chinese breach of telecom networks, WSJ reports30:55 - Story # 4b: T-Mobile confirms it was hacked in recent wave of telecom breaches33:03 - Story # 5: An Interview With the Target & Home Depot Hacker40:04 - Story # 6: Hacker gets 10 years in prison for extorting US healthcare provider42:47 - Story # 7: Ransomware fiends boast they’ve stolen 1.4TB from US pharmacy network44:21 - Story # 8: A surge in Pro-Russia cyberattacks after decision to monitor North Korean Troops in Ukraine45:23 - Story # 9: 23andMe cuts 40% of its workforce and discontinues therapeutics division50:38 - Story # 10: FBI, CISA, and NSA reveal most exploited vulnerabilities of 202356:45 - CPTC - Education Through Competition (00:00) - PreShow Banter™ — Yacht Doc (07:39) - BHIS - Talkin' Bout [infosec] News 2024-11-18 (08:49) - Story # 1: Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit (16:01) - Story # 2: CISA Director Jen Easterly to depart agency on January 20 (19:26) - Story # 3: Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack (28:43) - Story # 4: T-Mobile hacked in massive Chinese breach of telecom networks, WSJ reports (30:55) - Story # 4b: T-Mobile confirms it was hacked in recent wave of telecom breaches (33:02) - Story # 5: An Interview With the Target & Home Depot Hacker (40:03) - Story # 6: Hacker gets 10 years in prison for extorting US healthcare provider (42:47) - Story # 7: Ransomware fiends boast they've stolen 1.4TB from US pharmacy network (44:20) - Story # 8: A surge in Pro-Russia cyberattacks after decision to monitor North Korean Troops in Ukraine (45:22) - Story # 9: 23andMe cuts 40% of its workforce and discontinues therapeutics division (50:37) - Story # 10: FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023 (56:44) - CPTC - Education Through Competition

Nov 21, 20241h 0m

Ep 12024-11-11 - The Old and The New

00:00 - PreShow Banter™ — The Old and The New02:27 - BHIS - Talkin’ Bout [infosec] News 2024-11-1103:44 - Story # 1: Mattel pulls thousands of ‘Wicked’ dolls off shelves after printing adult website on packaging08:03 - Story # 2: Office apps crash on Windows 11 24H2 PCs with CrowdStrike antivirus11:41 - Story # 3: Mislabeled patch sends Windows Server 2022 admins on unwanted upgrade to 202516:49 - Story # 4: Suspected Snowflake Hacker Arrested in Canada18:26 - Story # 5: Interpol Cybercrime Sweep Takes Down 22,000 IP Addresses, Arrests 4129:47 - Story # 6: Google Cloud to mandate MFA for all users in 202541:30 - Story # 7: Cisco scores a perfect CVSS 10 with critical flaw in its wireless system49:26 - Story # 8: H.I.G. Capital and Thoma Bravo to Acquire CompTIA Brand and Products59:05 - SANS Holiday Hack Challenge™ 2024 (00:00) - PreShow Banter™ — The Old and The New (02:27) - BHIS - Talkin' Bout [infosec] News 2024-11-11 (03:44) - Story # 1: Mattel pulls thousands of 'Wicked' dolls off shelves after printing adult website on packaging (08:03) - Story # 2: Office apps crash on Windows 11 24H2 PCs with CrowdStrike antivirus (11:41) - Story # 3: Mislabeled patch sends Windows Server 2022 admins on unwanted upgrade to 2025 (16:48) - Story # 4: Suspected Snowflake Hacker Arrested in Canada (18:25) - Story # 5: Interpol Cybercrime Sweep Takes Down 22,000 IP Addresses, Arrests 41 (29:47) - Story # 6: Google Cloud to mandate MFA for all users in 2025 (41:30) - Story # 7: Cisco scores a perfect CVSS 10 with critical flaw in its wireless system (49:26) - Story # 8: H.I.G. Capital and Thoma Bravo to Acquire CompTIA Brand and Products (59:04) - SANS Holiday Hack Challenge™ 2024

Nov 15, 20241h 0m

Ep 12024-11-04 - The Grey Times

00:00:00 - PreShow Banter™ — The Grey Times00:04:33 - BHIS - Talkin’ Bout [infosec] News 2024-11-0400:05:54 - Story # 1: Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files00:16:45 - Story # 2: Follow Up - 5 Things To Know On Delta’s Lawsuit Against CrowdStrike00:17:43 - Story # 2b: CrowdStrike Sues Delta: 5 Key Takeaways00:22:04 - Story # 3: Russian charged by U.S. for creating RedLine infostealer malware00:22:59 - Story # 3b: How a series of opsec failures led US authorities to the alleged developer of the Redline password-stealing malware00:28:09 - Story # 4: Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info00:30:02 - Story # 4b: ‘We strive to put humanity above all’: Disney drops arbitration demand over wrongful death lawsuit after woman died from fatal food allergy00:37:10 - Story # 5: OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative00:44:54 - Story # 6: Security researchers found a serious zero-click bug in Synology’s Photos app00:50:10 - Story # 7: Inside a Firewall Vendor’s 5-Year War With the Chinese Hackers Hijacking Its Devices00:52:21 - Story # 8: Microsoft wants $30 if you want to delay Windows 11 switch01:00:03 - Story # 9: Colorado Secretary of State posted spreadsheet with voting system passwords (00:00) - PreShow Banter™ — The Grey Times (04:33) - BHIS - Talkin' Bout [infosec] News 2024-11-04 (05:54) - Story # 1: Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files (16:46) - Story # 2: Follow Up - 5 Things To Know On Delta’s Lawsuit Against CrowdStrike (17:44) - Story # 2b: CrowdStrike Sues Delta: 5 Key Takeaways (22:05) - Story # 3: Russian charged by U.S. for creating RedLine infostealer malware (23:00) - Story # 3b: How a series of opsec failures led US authorities to the alleged developer of the Redline password-stealing malware (28:10) - Story # 4: Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info (30:04) - Story # 4b: ‘We strive to put humanity above all’: Disney drops arbitration demand over wrongful death lawsuit after woman died from fatal food allergy (37:11) - Story # 5: OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative (44:56) - Story # 6: Security researchers found a serious zero-click bug in Synology's Photos app (50:12) - Story # 7: Inside a Firewall Vendor's 5-Year War With the Chinese Hackers Hijacking Its Devices (52:23) - Story # 8: Microsoft wants $30 if you want to delay Windows 11 switch (01:00:06) - Story # 9: Colorado Secretary of State posted spreadsheet with voting system passwords

Nov 6, 20241h 6m

Ep 12024-10-28 - Sarsaparilla

00:00:00 - PreShow Banter™ — Sarsaparilla00:05:50 - BHIS - Talkin’ Bout [infosec] News 2024-10-2800:06:46 - Story # 1: AWS, Azure auth keys found in Android and iOS apps used by millions00:15:02 - Story # 2: Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs00:29:03 - Story # 3: Delta officially launches lawyers at $500M CrowdStrike problem00:40:60 - Story # 4: New Rules for US National Security Agencies Balance AI’s Promise With Need to Protect Against Risks00:46:25 - Story # 4b: CISA proposes new security requirements to protect govt, personal data00:51:03 - Story # 5: Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection00:55:35 - Story # 6: Throne’s toilet camera takes pictures of your poop01:04:57 - A Community Support Moment - https://www.crisistextline.org (00:00) - PreShow Banter™ — Sarsaparilla (05:49) - BHIS - Talkin' Bout [infosec] News 2024-10-28 (06:45) - Story # 1: AWS, Azure auth keys found in Android and iOS apps used by millions (15:02) - Story # 2: Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs (29:03) - Story # 3: Delta officially launches lawyers at $500M CrowdStrike problem (40:59) - Story # 4: New Rules for US National Security Agencies Balance AI’s Promise With Need to Protect Against Risks (46:25) - Story # 4b: CISA proposes new security requirements to protect govt, personal data (51:02) - Story # 5: Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection (55:35) - Story # 6: Throne’s toilet camera takes pictures of your poop (01:04:56) - A Community Support Moment - https://www.crisistextline.org

Oct 30, 20241h 7m

Ep 12024-10-21 - Logging Con

00:00:00 - PreShow Banter™ — Log Con00:11:41 - BHIS - Talkin’ Bout [infosec] News 2024-10-2100:12:51 - Story # 1: Internet Archive exposed again – this time through Zendesk00:14:57 - Story # 1b: Hackers steal information from 31 million Internet Archive users00:20:42 - Story # 2: Sophos buys Secureworks for $859 mln to beef up cybersecurity portfolio00:24:21 - Story # 3: USDoD hacker behind National Public Data breach arrested in Brazil00:27:12 - Story # 4: Debunking Hype: China Hasn’t Broken Military Encryption With Quantum00:32:14 - Story # 5: Microsoft said it lost weeks of security logs for its customers’ cloud products00:35:03 - Story # 6: Should We Chat, Too? FAQ00:40:05 - Story # 7: More than two dozen countries have used internet outages to sway elections00:43:50 - Story # 8: Pokemon dev Game Freak confirms breach after stolen data leaks online00:46:32 - Story # 9: Hackers made robot vacuums randomly yell racial slurs00:49:19 - Story # 9b: We hacked a robot vacuum — and could watch live through its camera00:50:19 - Story # 10: The government is getting fed up with ransomware payments fueling endless cycle of cyberattacks00:54:55 - Story # 11: Google’s Chrome Browser Starts Disabling uBlock Origin01:01:00 - WWHF Recorvery (00:00) - PreShow Banter™ — Log Con (11:41) - BHIS - Talkin' Bout [infosec] News 2024-10-21 (12:50) - Story # 1: Internet Archive exposed again – this time through Zendesk (14:56) - Story # 1b: Hackers steal information from 31 million Internet Archive users (20:42) - Story # 2: Sophos buys Secureworks for $859 mln to beef up cybersecurity portfolio (24:20) - Story # 3: USDoD hacker behind National Public Data breach arrested in Brazil (27:11) - Story # 4: Debunking Hype: China Hasn't Broken Military Encryption With Quantum (32:13) - Story # 5: Microsoft said it lost weeks of security logs for its customers’ cloud products (35:02) - Story # 6: Should We Chat, Too? FAQ (40:05) - Story # 7: More than two dozen countries have used internet outages to sway elections (43:49) - Story # 8: Pokemon dev Game Freak confirms breach after stolen data leaks online (46:32) - Story # 9: Hackers made robot vacuums randomly yell racial slurs (49:18) - Story # 9b: We hacked a robot vacuum — and could watch live through its camera (50:19) - Story # 10: The government is getting fed up with ransomware payments fueling endless cycle of cyberattacks (54:54) - Story # 11: Google's Chrome Browser Starts Disabling uBlock Origin (01:01:00) - WWHF Recorvery

Oct 25, 20241h 14m

Ep 12024-09-30 — Cast of Special Characters

00:00:00 - PreShow Banter™ — Cast of Special Characters00:06:37 - BHIS - Talkin’ Bout [infosec] News 2024-09-3000:08:06 - Story # 1: CUPS flaws enable Linux remote code execution, but there’s a catch00:23:40 - Story # 2: US Capitol Hit by Massive Dark Web Cyber Attack - Newsweek00:27:40 - Story # 2b: ‘I’m a black NAZI!’: NC GOP nominee for governor made dozens of disturbing comments on porn forum00:35:57 - Story # 3: NIST proposes barring some of the most nonsensical password rules00:47:01 - Story # 3b: Why Two-Factor Authentication Is So Important - Teen Vogue00:54:04 - Story # 4: Hacker plants false memories in ChatGPT to steal user data in perpetuity01:00:42 - Story # 5: Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug01:02:54 - Story # 6: Massive E-Learning Platform Udemy Gave Teachers a Gen AI ‘Opt-Out Window’. It’s Already Over. (00:00) - PreShow Banter™ — Cast of Special Characters (06:37) - BHIS - Talkin' Bout [infosec] News 2024-09-30 (08:06) - Story # 1: CUPS flaws enable Linux remote code execution, but there’s a catch (23:39) - Story # 2: US Capitol Hit by Massive Dark Web Cyber Attack - Newsweek (27:40) - Story # 2b: ‘I’m a black NAZI!’: NC GOP nominee for governor made dozens of disturbing comments on porn forum (35:56) - Story # 3: NIST proposes barring some of the most nonsensical password rules (47:00) - Story # 3b: Why Two-Factor Authentication Is So Important - Teen Vogue (54:03) - Story # 4: Hacker plants false memories in ChatGPT to steal user data in perpetuity (01:00:42) - Story # 5: Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug (01:02:53) - Story # 6: Massive E-Learning Platform Udemy Gave Teachers a Gen AI 'Opt-Out Window'. It's Already Over.

Oct 2, 20241h 12m

Ep 12024-09-23 - Plane Talk

00:00 - PreShow Banter™ — Plane Talk05:50 - BHIS - Talkin’ Bout [infosec] News 2024-09-2306:16 - A SANS Difference Maker Award Finalist09:47 - Story # 1: Pagers attack brings to life long-feared supply chain threat24:08 - Story # 2: Recaptcha Phish - John Hammond25:49 - Story # 2b: Clever ‘GitHub Scanner’ campaign abusing repos to push malware30:05 - Story # 3: Lazarus Group Targets Developers in Fresh VMConnect Campaign35:22 - Story # 4: LinkedIn Addresses User Data Collection for AI Training37:40 - Story # 5: Disney ditching Slack after massive July data breach41:42 - Story # 6: FTC exposes massive surveillance of kids, teens by social media giants51:35 - Story # 7: Kaspersky deletes itself, installs UltraAV antivirus without warning (00:00) - PreShow Banter™ — Plane Talk (05:49) - BHIS - Talkin' Bout [infosec] News 2024-09-23 (06:15) - A SANS Difference Maker Award Finalist (09:46) - Story # 1: Pagers attack brings to life long-feared supply chain threat (24:08) - Story # 2: Recaptcha Phish - John Hammond (25:49) - Story # 2b: Clever 'GitHub Scanner' campaign abusing repos to push malware (30:05) - Story # 3: Lazarus Group Targets Developers in Fresh VMConnect Campaign (35:22) - Story # 4: LinkedIn Addresses User Data Collection for AI Training (37:39) - Story # 5: Disney ditching Slack after massive July data breach (41:42) - Story # 6: FTC exposes massive surveillance of kids, teens by social media giants (51:35) - Story # 7: Kaspersky deletes itself, installs UltraAV antivirus without warning

Sep 26, 20241h 1m

Ep 12024-09-16 - Pour Over News

00:00 - PreShow Banter™ — Pour Over News06:01 - BHIS - Talkin’ Bout [infosec] News 2024-09-1607:14 - Story # 1: Fortinet confirms data breach after hacker claims to steal 440GB of files15:37 - Story # 2: Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches21:30 - Story # 3: Omnipresent AI cameras will ensure good behavior, says Larry Ellison28:11 - Story # 4: Mastercard bolsters threat intelligence capabilities with $2.65 billion deal for Recorded Future34:27 - Story # 5: Cyber insurance set for explosive growth40:20 - Story # 6: 23andMe will pay $30 million to settle 2023 data breach lawsuit45:25 - Story # 7: Google faces EU investigation over AI data compliance50:35 - Story # 8: Rogue WHOIS server gives researcher superpowers no one should ever have (00:00) - PreShow Banter™ — Pour Over News (06:01) - BHIS - Talkin' Bout [infosec] News 2024-09-16 (07:14) - Story # 1: Fortinet confirms data breach after hacker claims to steal 440GB of files (15:36) - Story # 2: Snowflake slams 'more MFA' button again – months after Ticketmaster, Santander breaches (21:29) - Story # 3: Omnipresent AI cameras will ensure good behavior, says Larry Ellison (28:11) - Story # 4: Mastercard bolsters threat intelligence capabilities with $2.65 billion deal for Recorded Future (34:27) - Story # 5: Cyber insurance set for explosive growth (40:19) - Story # 6: 23andMe will pay $30 million to settle 2023 data breach lawsuit (45:24) - Story # 7: Google faces EU investigation over AI data compliance (50:35) - Story # 8: Rogue WHOIS server gives researcher superpowers no one should ever have

Sep 18, 20241h 0m

Ep 1SPECIAL PRESENTATION: Backdoors & Breaches Live

00:00 - Introduction01:22 - The Scenario02:50 - First Steps03:48 - Endpoint Analysis Roll04:22 - Logon Scripts Were installed05:09 - I.R. Team Introductions07:17 - Second Step10:32 - Network Threat Hunting Roll11:36 - Third Step15:12 - Anyway Here’s Firewall Roll15:43 - Fourth Step18:26 - SIEM Roll19:41 - Fifth Step20:47 - UEBA Roll21:19 - Senario Recap22:20 - Senario Plausibility?25:51 - Wrap-up Takeaways (00:00) - Introduction (01:21) - The Scenario (02:50) - First Steps (03:47) - Endpoint Analysis Roll (04:21) - Logon Scripts Were installed (05:09) - I.R. Team Introductions (07:16) - Second Step (10:32) - Network Threat Hunting Roll (11:36) - Third Step (15:12) - Anyway Here's Firewall Roll (15:42) - Fourth Step (18:26) - SIEM Roll (19:41) - Fifth Step (20:47) - UEBA Roll (21:18) - Senario Recap (22:19) - Senario Plausibility? (25:50) - Wrap-up Takeaways

Sep 16, 202431 min

Ep 12024-09-09 - More Chicken Related Crimes

00:00 - PreShow Banter™ — Revenge of the Nerds / More Chicken Related Crimes05:19 - N.Y. Official Charged With Taking Money, Travel and Poultry to Aid China09:23 - BHIS - Talkin’ Bout [infosec] News 2024-09-0909:50 - Story # 1: YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel20:35 - Story # 2: Therapy Sessions Exposed by Mental Health Care Firm’s Unsecured Database25:24 - Story # 3: California legislature passes sweeping AI safety bill38:02 - Story # 4: Brain Cipher claims attack on Olympic venue, promises 300 GB data leak41:59 - Story # 5: How Navy chiefs conspired to get themselves illegal warship Wi-Fi42:45 - Story # 5b: After seeing Wi-Fi network named “STINKY,” Navy found hidden Starlink dish on US warship49:18 - Story # 6: Researchers say a bug let them add fake pilots to rosters used for TSA checks51:32 - Story # 7: Durex India spilled customers’ private order data54:53 - Story # 8: City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack (00:00) - PreShow Banter™ — Revenge of the Nerds / More Chicken Related Crimes (05:19) - N.Y. Official Charged With Taking Money, Travel and Poultry to Aid China (09:23) - BHIS - Talkin' Bout [infosec] News 2024-09-09 (09:50) - Story # 1: YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel (20:34) - Story # 2: Therapy Sessions Exposed by Mental Health Care Firm’s Unsecured Database (25:23) - Story # 3: California legislature passes sweeping AI safety bill (38:02) - Story # 4: Brain Cipher claims attack on Olympic venue, promises 300 GB data leak (41:59) - Story # 5: How Navy chiefs conspired to get themselves illegal warship Wi-Fi (42:44) - Story # 5b: After seeing Wi-Fi network named “STINKY,” Navy found hidden Starlink dish on US warship (49:18) - Story # 6: Researchers say a bug let them add fake pilots to rosters used for TSA checks (51:32) - Story # 7: Durex India spilled customers’ private order data (54:53) - Story # 8: City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack

Sep 11, 20241h 2m

Ep 12024-08-26 - Move to Signal

00:00 - PreShow Banter™ — Move to Signal03:47 - BHIS - Talkin’ Bout [infosec] News 2024-08-2604:37 - Story # 1: Pavel Durov’s Arrest Leaves Telegram Hanging in the Balance11:03 - Story # 1b: Moxie on X.com23:17 - Story # 2: Unveiling “sedexp”: A Stealthy Linux Malware Exploiting udev Rules29:39 - Story # 3: Seattle airport ‘possible cyberattack’ snarls travel yet again32:42 - Story # 4: Iran named as source of Trump campaign phish, leaks38:53 - Story # 5: Man who hacked Hawaii state registry to forge his own death certificate sentenced to 81 months44:11 - Story # 6: Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide47:26 - Story # 7: New ‘ALBeast’ Misconfiguration Exposes Weakness in AWS Application Load Balancer48:52 - Story # 8: “We will hold them accountable”: General Motors sued for selling customer driving data to third parties (00:00) - PreShow Banter™ — Move to Signal (03:47) - BHIS - Talkin' Bout [infosec] News 2024-08-26 (04:37) - Story # 1: Pavel Durov’s Arrest Leaves Telegram Hanging in the Balance (11:03) - Story # 1b: Moxie on X.com (23:17) - Story # 2: Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules (29:39) - Story # 3: Seattle airport 'possible cyberattack' snarls travel yet again (32:42) - Story # 4: Iran named as source of Trump campaign phish, leaks (38:52) - Story # 5: Man who hacked Hawaii state registry to forge his own death certificate sentenced to 81 months (44:10) - Story # 6: Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide (47:25) - Story # 7: New 'ALBeast' Misconfiguration Exposes Weakness in AWS Application Load Balancer (48:51) - Story # 8: “We will hold them accountable”: General Motors sued for selling customer driving data to third parties

Aug 29, 202452 min

Ep 12024-08-19 Nine Years for Chicken Wings

00:00:00 - PreShow Banter™ — Nine Years for Chicken Wings00:08:19 - BHIS - Talkin’ Bout [infosec] News 2024-08-1900:09:03 - Story # 1: NationalPublicData.com Hack Exposes a Nation’s Data00:18:17 - Story # 1b: National Public Data Published Its Own Passwords00:25:01 - Story # 2: RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks00:26:52 - Story # 3: T-Mobile fined $60 million for failing to stop data breaches00:34:03 - Story # 4: Massive Cyber Attack On AWS Targets 230 Million Unique Cloud Environments00:45:43 - Story # 5: The US wants to use facial recognition to identify migrant children as they age00:54:16 - Story # 6: Six ransomware gangs behind over 50% of 2024 attacks00:59:56 - Story # 7: US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years01:01:57 - Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World’s Deadliest Crooks (00:00) - PreShow Banter™ — Nine Years for Chicken Wings (08:19) - BHIS - Talkin' Bout [infosec] News 2024-08-19 (09:02) - Story # 1: NationalPublicData.com Hack Exposes a Nation’s Data (18:17) - Story # 1b: National Public Data Published Its Own Passwords (25:01) - Story # 2: RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks (26:52) - Story # 3: T-Mobile fined $60 million for failing to stop data breaches (34:02) - Story # 4: Massive Cyber Attack On AWS Targets 230 Million Unique Cloud Environments (45:42) - Story # 5: The US wants to use facial recognition to identify migrant children as they age (54:16) - Story # 6: Six ransomware gangs behind over 50% of 2024 attacks (59:55) - Story # 7: US accuses man of being 'elite' ransomware pioneer they've hunted for years (01:01:56) - Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World's Deadliest Crooks

Aug 21, 20241h 4m

Ep 12024-08-12 — Scotty's Pizza (Not Sponsored)

00:00 - PreShow Banter™ — Scotty’s Pizza (Not Sponsored)03:38 - BHIS - Talkin’ Bout [infosec] News 2024-08-1203:59 - Hacker Summer Camp Report 202408:56 - Story # 1: ‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections14:26 - Story # 2: Black Hat USA 2024, DEF CON 32 attendees treated like children – or criminals – with invasive hotel room checks29:49 - Story # 3: DEF CON Badge Maker Pulled Off Stage Amid Claims of Non-Payment and Failed Work30:06 - New raspberry pi chip in badge33:31 - Story # 4: Exploit released for Cisco SSM bug allowing admin password changes34:12 - Story # 5: 0.0.0.0 Day: Exploiting Localhost APIs From the Browser38:02 - Story # 6: Intelligence bill would elevate ransomware to a terrorist threat44:36 - Story # 6b: Proposed bill would block large ransomware payments by financial institutions46:26 - Story # 6c: Report shows decreased ransomware payments54:26 - Story # 7: After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude55:12 - Story # 8: CrowdStrike pursuing deal to buy patch management specialist Action157:24 - Story # 9: Microsoft punches back at Delta Air Lines and its legal threats (00:00) - PreShow Banter™ — Scotty's Pizza (Not Sponsored) (03:38) - BHIS - Talkin' Bout [infosec] News 2024-08-12 (03:59) - Hacker Summer Camp Report 2024 (08:55) - Story # 1: ‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections (14:25) - Story # 2: Black Hat USA 2024, DEF CON 32 attendees treated like children – or criminals – with invasive hotel room checks (29:49) - Story # 3: DEF CON Badge Maker Pulled Off Stage Amid Claims of Non-Payment and Failed Work (30:05) - New raspberry pi chip in badge (33:31) - Story # 4: Exploit released for Cisco SSM bug allowing admin password changes (34:11) - Story # 5: 0.0.0.0 Day: Exploiting Localhost APIs From the Browser (38:02) - Story # 6: Intelligence bill would elevate ransomware to a terrorist threat (44:35) - Story # 6b: Proposed bill would block large ransomware payments by financial institutions (46:26) - Story # 6c: Report shows decreased ransomware payments (54:26) - Story # 7: After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude (55:11) - Story # 8: CrowdStrike pursuing deal to buy patch management specialist Action1 (57:24) - Story # 9: Microsoft punches back at Delta Air Lines and its legal threats

Aug 14, 20241h 2m