Cybersecurity Today

Jim Love

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. hace 2 días

    OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

    OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

  2. 25 jul

    AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium"

    AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium" On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it intersects with cybersecurity. They discuss Anthropic's "Mythos" and "Fable," the marketing-versus-risk debate around autonomous hacking tools, and how the sheer volume of vulnerable code creates a "digitally polluted" environment. The conversation covers whether AI is a consumer product or a weapon, the implications of U.S. export controls (including restrictions affecting foreign nationals), and how model pullbacks may have shaken allies' trust in American tech. They also examine comparisons to radium and nuclear-era unknowns, the OpenAI–Hugging Face incident, the "cathedral vs. bazaar" tension of closed vs. open models, and the broader U.S.–China economic and national security struggle. 00:00 Weekend Show Kickoff 01:15 Meet Prat Dadam 01:59 Policy Whiplash in AI 02:55 Mythos Hype and Fear 06:27 Digital Pollution Problem 07:53 AI Arms Race Begins 09:18 Export Controls Shockwave 14:31 Weapon or Consumer Tech 16:57 New Radium Analogy 21:57 Economics and Trade Wars 23:49 Cathedral Versus Bazaar 25:44 Censorship and Control 27:16 Jurassic Park Chaos 30:27 Hotel California Reality 32:36 Closing Thoughts and Thanks

Calificaciones y reseñas

4.5
de 5
2 calificaciones

Acerca de

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

También te podría interesar