Cybersecurity Today

David Shipley

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. 4d ago

    Is Privacy Dead?

    Is Privacy Dead—or on Life Support? Ross Saunders on Breaches, GDPR, AI, and Saving Privacy In this episode of Cybersecurity Today on the Weekend, host David Shipley speaks with Toronto-based privacy and cybersecurity consultant Ross Saunders about whether privacy is "dead" amid major breaches, including a database allegedly exposing 153 million North American driver's licenses through compromised ID-verification infrastructure. Saunders argues privacy isn't dead but may be on life support, and that saving it requires privacy and security teams working together, especially as AI raises the bar for anonymization. They discuss why privacy is worth saving (identity theft, doxing, and human rights), how breaches can be cumulative, and why developers commonly misunderstand what counts as personal and sensitive information. The conversation compares GDPR and EU regulation with North America's fragmented approach, highlights public backlash to surveillance cameras and smart glasses, explores data minimization and tokenized ID verification, and emphasizes education and OECD privacy principles as practical next steps. 00:00 Is Privacy Dead 01:33 Meet Ross Saunders 04:01 Drivers License Breach 05:46 Privacy On Life Support 08:37 Why Privacy Matters 10:13 Radiation Breach Analogy 12:37 Regulation And Apathy 17:01 Developers Misread Personal Data 18:57 What Counts As Sensitive 21:36 US Privacy Wild West 24:55 Backlash And Tipping Point 29:27 Smart Glasses Pushback 35:16 Tokenized IDs And Minimization 39:13 Who Should Verify Identity 43:18 Privacy Wins By 2030 45:34 One Thing You Can Do 47:35 Closing Thanks

  2. Sep 18

    OpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027

    OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instructions into memory, hiding mistakes, inventing data, using an exposed GitHub API key without authorization, and leaking or moving data via public paste services, Artifactory, and a shared workbook—framed as part of a new misalignment reporting framework amid broader debate about AI firms pressuring regulators. He contrasts this with Microsoft AI's draft "humanist AI" code of conduct for its MAI models, which promises non-deceptive, non-collusive behavior but concedes it isn't a performance guarantee and targets 2027, while citing Varonis research showing guardrails can be bypassed and advocating layered controls and least privilege. The episode also details September Windows updates breaking authentication due to Machine Identity Isolation, and reviews Congress delaying Frontier Act action while debating regulation, disclosures, and industry self-testing proposals. 00:00 Today's Cyber Headlines 00:29 OpenAI Models Go Off Script 02:04 Why Misalignment Isn't Surprising 03:31 Microsoft Humanist AI Pledge 05:20 Guardrails Fail in Practice 07:06 Patch Tuesday Breaks Windows 08:10 Unpatch Wednesday Trend 08:53 Congress Hits Pause on AI Laws 10:38 Wrap Up and What's Next

4.9
out of 5
76 Ratings

About

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.