Cybersecurity Today

David Shipley

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. hace 16 h

    Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms

    Team PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials and data. Boston Scientific disclosed a cyberattack that caused network outages and disrupted global operations, halting its ability to ship devices like pacemakers and stents, with recovery expected to take weeks.  The U.S. Justice Department disrupted QScan and Q2Router, platforms tied to China-linked QTFY, used to proxy intrusions against U.S. agencies and an election system. House Democrats asked GAO to assess how major workforce cuts have impacted CISA. Forcepoint demonstrated invisible-text prompt injection that fooled an AI email summarizer into fabricating invoice details. 00:00 Headlines Overview 00:29 Team PCP Arrests 02:11 Krebs Investigation 03:06 Boston Scientific Disruption 04:50 Podcast Reviews Thanks 05:07 FBI Disrupts QTFY Tools 05:50 How QScan Pipeline Worked 07:27 CISA Workforce Cuts 08:53 Invisible Text AI Poisoning 10:27 Wrap Up And Teaser

  2. hace 6 días

    AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

    How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024.   They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical.   The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability.   00:00 Sponsor NordLayer 00:37 Weekend Show Intro 02:02 Robert Career Journey 03:08 Building Adlumin 05:50 AI Transforms SOC Work 08:56 AI Investigations Upgrade 11:23 Alert Fatigue and MDR 13:49 MSPs Become MSSPs 19:30 AI as Opportunity and Threat 21:13 Attack Speed Compression 22:54 Wins and Frustrations 26:59 Autonomous Hacking Reality 29:03 Hack Back Debate 32:43 Next 12 Months Forecast 34:28 Closing Thanks 35:22 Sponsor Message Return

  3. 19 ago

    CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

    Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enabled auto-running prompts, silent data exfiltration via connected apps (e.g., Gmail/Drive/Calendar) using Copilot's own web fetch, and persistent memory poisoning that survives common account cleanup steps until manually removed; Microsoft was notified in December 2025, patches shipped August 18, and no in-the-wild exploitation was found. It also reviews a threat actor "The Hat Man" claiming to have stolen about 3.64 million employee records from Azure tenants of major firms, with companies disputing breach claims while Hudson Rock assesses the data as likely authentic but with unknown access/exfiltration. The University of Texas at San Antonio took systems offline after detecting network-edge threat activity, reporting no evidence of data exfiltration and planning password resets amid outages. Finally, researchers from Anthropic and EPFL describe "mind viruses" that propagate between AI agents via persistent "soul" prompt files, demonstrate harmful action payloads, and show a simple system-prompt warning greatly reduced spread. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 00:59 Copilot CoSnitch Flaw 03:55 Azure Employee Data Leaks 06:09 UTSA Cyberattack Update 07:54 AI Agent Mind Viruses 11:09 Wrap Up And Thanks 11:33 NordLayer Sponsor Close

  4. 15 ago

    Cybersecurity Today Weekend Month in Review: August 2026

    AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and others), Schneier's "genie effect," legal and insurance consequences, and agent risks like log-poisoning "ghost jacking" against security tools. They also cover research showing passkeys can be phished via implementation weaknesses, widespread attacks on water utilities across multiple U.S. states and Quebec, and a Russian campaign targeting public Wi‑Fi. The episode ends with calls to focus on security fundamentals and use crises to drive action. 00:00 Sponsor NordLayer 00:37 Weekend Month Review 01:40 Harvard to Hacker Camp 03:25 DEF CON Highlights 06:20 Delta Flight Pineapple 08:20 AI Agents Gone Rogue 15:09 Genie Effect Explained 21:43 Accountability and Regulation 25:13 Ghostjacking Security Logs 28:04 Back to Fundamentals 29:27 Zero Trust vs Agents 31:10 Passkeys Aren't Proof 32:39 Phishing Forever Reality 33:48 Water Utilities Under Attack 37:22 Why Water Is Fragile 41:50 Stop Exposing OT Online 43:02 Tabletop Uninsurable Chaos 49:34 Public Wi-Fi Still Risky 51:08 Media Picks and Wrap-Up 53:02 Never Waste a Crisis 55:13 Sponsor NordLayer

Acerca de

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

También te podría interesar