Cybersecurity Today

Jim Love

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. vor 1 Tag

    Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi

    Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber evaluations July 23. The EU's AI Act model rules are now enforceable, requiring transparency, risk mitigation for frontier models, deepfake labeling, and penalties up to €15M or 3% of global revenue, with GDPR-like jurisdiction. Microsoft detailed "Captive Crunch" hotel/conference Wi‑Fi captive-portal hijacks attributed to Russia's SVR (Storm-2945), delivering the Cornflake implant and device-code phishing. A ColdCard firmware RNG flaw enabled thefts totaling $88.6M. Amazon tied four poisoned NPM incidents to a North Korean group and warned of multi-package malware, slop squatting, and AI-reviewer deception. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:09 Claude Models Escape Sandbox 03:43 EU AI Act Now Enforceable 05:31 Hotel WiFi Hijack Malware 07:54 ColdCard Seed Flaw Heist 09:42 North Korea NPM Poisoning 11:27 Wrap Up and Events 12:08 NordLayer Sponsor Reminder

  2. vor 4 Tagen

    OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

    OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

  3. 25. Juli

    AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium"

    AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium" On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it intersects with cybersecurity. They discuss Anthropic's "Mythos" and "Fable," the marketing-versus-risk debate around autonomous hacking tools, and how the sheer volume of vulnerable code creates a "digitally polluted" environment. The conversation covers whether AI is a consumer product or a weapon, the implications of U.S. export controls (including restrictions affecting foreign nationals), and how model pullbacks may have shaken allies' trust in American tech. They also examine comparisons to radium and nuclear-era unknowns, the OpenAI–Hugging Face incident, the "cathedral vs. bazaar" tension of closed vs. open models, and the broader U.S.–China economic and national security struggle. 00:00 Weekend Show Kickoff 01:15 Meet Prat Dadam 01:59 Policy Whiplash in AI 02:55 Mythos Hype and Fear 06:27 Digital Pollution Problem 07:53 AI Arms Race Begins 09:18 Export Controls Shockwave 14:31 Weapon or Consumer Tech 16:57 New Radium Analogy 21:57 Economics and Trade Wars 23:49 Cathedral Versus Bazaar 25:44 Censorship and Control 27:16 Jurassic Park Chaos 30:27 Hotel California Reality 32:36 Closing Thoughts and Thanks

Bewertungen und Rezensionen

4,5
von 5
2 Bewertungen

Info

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

Das gefällt dir vielleicht auch