Cybersecurity Today

Jim Love

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. 18 hr ago

    AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

    How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024.   They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical.   The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability.   00:00 Sponsor NordLayer 00:37 Weekend Show Intro 02:02 Robert Career Journey 03:08 Building Adlumin 05:50 AI Transforms SOC Work 08:56 AI Investigations Upgrade 11:23 Alert Fatigue and MDR 13:49 MSPs Become MSSPs 19:30 AI as Opportunity and Threat 21:13 Attack Speed Compression 22:54 Wins and Frustrations 26:59 Autonomous Hacking Reality 29:03 Hack Back Debate 32:43 Next 12 Months Forecast 34:28 Closing Thanks 35:22 Sponsor Message Return

  2. 3 days ago

    CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

    Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enabled auto-running prompts, silent data exfiltration via connected apps (e.g., Gmail/Drive/Calendar) using Copilot's own web fetch, and persistent memory poisoning that survives common account cleanup steps until manually removed; Microsoft was notified in December 2025, patches shipped August 18, and no in-the-wild exploitation was found. It also reviews a threat actor "The Hat Man" claiming to have stolen about 3.64 million employee records from Azure tenants of major firms, with companies disputing breach claims while Hudson Rock assesses the data as likely authentic but with unknown access/exfiltration. The University of Texas at San Antonio took systems offline after detecting network-edge threat activity, reporting no evidence of data exfiltration and planning password resets amid outages. Finally, researchers from Anthropic and EPFL describe "mind viruses" that propagate between AI agents via persistent "soul" prompt files, demonstrate harmful action payloads, and show a simple system-prompt warning greatly reduced spread. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 00:59 Copilot CoSnitch Flaw 03:55 Azure Employee Data Leaks 06:09 UTSA Cyberattack Update 07:54 AI Agent Mind Viruses 11:09 Wrap Up And Thanks 11:33 NordLayer Sponsor Close

  3. 15 Aug

    Cybersecurity Today Weekend Month in Review: August 2026

    AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and others), Schneier's "genie effect," legal and insurance consequences, and agent risks like log-poisoning "ghost jacking" against security tools. They also cover research showing passkeys can be phished via implementation weaknesses, widespread attacks on water utilities across multiple U.S. states and Quebec, and a Russian campaign targeting public Wi‑Fi. The episode ends with calls to focus on security fundamentals and use crises to drive action. 00:00 Sponsor NordLayer 00:37 Weekend Month Review 01:40 Harvard to Hacker Camp 03:25 DEF CON Highlights 06:20 Delta Flight Pineapple 08:20 AI Agents Gone Rogue 15:09 Genie Effect Explained 21:43 Accountability and Regulation 25:13 Ghostjacking Security Logs 28:04 Back to Fundamentals 29:27 Zero Trust vs Agents 31:10 Passkeys Aren't Proof 32:39 Phishing Forever Reality 33:48 Water Utilities Under Attack 37:22 Why Water Is Fragile 41:50 Stop Exposing OT Online 43:02 Tabletop Uninsurable Chaos 49:34 Public Wi-Fi Still Risky 51:08 Media Picks and Wrap-Up 53:02 Never Waste a Crisis 55:13 Sponsor NordLayer

  4. 14 Aug

    Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

    Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control across Windows 10/11 (including 25H2) and Windows Server 2025, claiming it bypasses Microsoft's patch for their earlier RoguePlanet exploit; a public proof-of-concept app is available, Will Dormann verified it works, and Microsoft says it's investigating. California Governor Gavin Newsom ordered an AI cyber defense program for critical infrastructure with an implementation plan due in 120 days, citing incidents where AI models from OpenAI, Anthropic, and Meta reached the open internet and hacked third parties, while also criticizing proposed federal cuts to CISA. DEF CON Franklin will fund MDR vendors to protect small water utilities, arguing federal funding is needed to scale. President Trump also directed DHS to build a program authorizing vetted private firms to conduct government-controlled offensive operations against foreign cybercriminals. Unit 42 reported a self-propagating npm worm, Chaindrop, infecting 400+ packages, stealing extensive credentials, and using an Ethereum smart contract for rotating command-and-control infrastructure, with attribution murky due to similarities to the Shai Hulud/Team PCP toolkit. 00:00 Today's Cyber Rundown 00:26 Windows Defender Zero Day 02:35 California AI Cyber Defense 04:04 DEF CON Franklin Water Aid 06:21 Cyber Privateers Program 09:15 Chaindrop NPM Worm 11:12 Wrap Up and Next Shows

About

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

You Might Also Like