You've Already Been Hacked

Professor CyberRisk

A Cybersecurity Podcast for the Rest of Us In a world of evolving cyber threats, You’ve Already Been Hacked breaks down cybersecurity for everyone—from experts to everyday users. Hosted by Professor CyberRisk and Cyber Cowboy, we tackle major cyber attacks, emerging threats, and real-world security strategies. Each episode offers expert analysis, case studies, and actionable tips to help listeners stay ahead of hackers and digital risks.

  1. 2d ago

    FortiMail Zero-Day Exploited Now — 3 Branches Still Unpatched

    Hosts * Professor CyberRisk * Cyber Cowboy Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: FortiMail Zero-Day Exploited Now — 3 Branches Still Unpatched Episode Number: 364 Overview Weekly roundup of the most critical cybersecurity developments from 2026-09-27 to 2026-10-01. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Actively exploited email gateway zero-days and workarounds * Government personnel-records breaches and espionage risk * Agentic AI attacks on cloud infrastructure * Ransomware takedowns and the edge-device attack path Top Stories 1. Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (CVE-2026-104286) - https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/ Additional Cybersecurity News – Titles and URLs 2. Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data - https://arstechnica.com/security/2026/10/hacks-of-2-federal-agencies-in-a-month-have-spilled-a-bonanza-of-sensitive-data/ 3. JadePuffer agentic AI attacks target Azure, destroy cloud resources - https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/ 4. Police dismantle KillSec ransomware gang allegedly led by 16-year-old - https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  2. Sep 27

    ShinyHunters Claims a 2-Terabyte FBI Heist — Powered by a Zero-Day

    Hosts * Professor CyberRisk * Cyber Cowboy Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: ShinyHunters Claims a 2-Terabyte FBI Heist — Powered by a Zero-Day Episode Number: 363 Overview Weekly roundup of the most critical cybersecurity developments from 2026-09-20 to 2026-09-24. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * PeopleSoft zero-day and the claimed FBI breach * Worm-like Docker botnet driven by AI agents * Rogue OpenAI agent swarm and government website intrusions * macOS infostealer using iCloud calendars as C2 * $351.6M Bitget crypto exchange theft * Windows Defender zero-day that blocks AV updates Top Stories 1. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach - https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/ Additional Cybersecurity News – Titles and URLs 2. New Carbonato malware uses AI agents to hijack exposed Docker hosts - https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/ 3. Researchers link more cyberattacks to OpenAI agent swarm - https://siliconangle.com/2026/09/24/researchers-link-more-cyberattacks-to-openai-agent-swarm/ 4. MacSync malware uses public iCloud calendars to deliver new payloads - https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/ 5. Hackers steal $351.6 million in Bitget crypto exchange hack - https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/ 6. New Windows Defender zero-day blocks Microsoft antivirus updates - https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/ Resources & Links * Transluce agent-activity research: https://transluce.org/agent-activity * ThreatDown Carbonato analysis: https://www.threatdown.com/blog/carbonato/ * Kaspersky MacSync writeup: https://securelist.com/macsync-new-version/121383/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  3. Sep 20

    Why Your Phone's Accessibility Permission Is the New Infostealer Door

    Hosts * Professor CyberRisk * Cyber Cowboy Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Why Your Phone's Accessibility Permission Is the New Infostealer Door Episode Number: 362 Overview Weekly roundup of the most critical cybersecurity developments from 2026-09-13 to 2026-09-17. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * RatHat: AI-driven Android malware that serializes the accessibility tree to a commercial LLM for live device control (Zimperium zLabs, China-linked) * Brevo supply-chain attack: stolen Cloudflare API key injected ClickFix scripts into ~100,000 customer sites * GitLab CVE-2026-85706: CVSS 10.0 unauthenticated arbitrary file read, CISA KEV, actively exploited * CHOSEN BRICK: Iranian state Windows spyware targeting dissidents, activists, and journalists (NCSC + FBI joint advisory) Top Stories 1. New RatHat Android malware uses AI to automate device control - https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ Additional Cybersecurity News – Titles and URLs 2. Brevo supply-chain attack injected ClickFix scripts on customer sites - https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/ 3. GitLab CVE-2026-85706: CVSS 10.0 unauthenticated file read exploited in the wild - https://hoploninfosec.com/cve-2026-85706-gitlab-vulnerability 4. Iranian hackers use CHOSEN BRICK Windows malware to spy on targets - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/ Resources & Links * Zimperium RatHat analysis (via BleepingComputer): https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ * Brevo post-mortem: https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up * Sansec Brevo supply-chain report: http://sansec.io/research/brevo-supply-chain-attack * GitLab patch release notes (19.3.2): https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ * CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog * NCSC joint advisory (FBI) on Iranian targeting: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  4. Sep 7

    Artifactory's Backdoor: Why Patching Isn't Enough

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Artifactory's Backdoor: Why Patching Isn't Enough Episode Number: 3x61 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-30 to 2026-09-03. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Software supply-chain poisoning via forged admin tokens (CVE-2026-82329) * Mass-exposed Exchange servers and mailbox hijack (CVE-2026-62911) * GDPR enforcement: French hospital fined €500,000 after 727,000-record breach * Stealthit infostealer abusing Node.js Single Executable Applications Top Stories 1. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/ Additional Cybersecurity News – Titles and URLs 2. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks - https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 3. French hospital fined €500,000 after breach exposes data of 727,000 - https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/ 4. Stealthit infostealer gets a Node.js makeover — fake games and VPNs are the bait - https://hoploninfosec.com/stealit-malware-attacks Resources & Links * JFrog security advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories * Microsoft CVE-2026-62911 advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911 * NCSC-NL Exchange alert: https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-microsoft-exchange-server Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  5. Aug 30

    Your IoT Devices Might Be a Chinese Spy's Front Door

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Your IoT Devices Might Be a Chinese Spy's Front Door Episode Number: 3x60 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-23 to 2026-08-27. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure - https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers Additional Cybersecurity News – Titles and URLs 2. Unknown PaperCut NG/MF vulnerability under active exploitation — emergency patch shipped - https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 3. Critical Gitea RCE (CVE-2026-60004, CVSS 9.8) exploited in the wild — CISA adds to KEV - https://www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/ 4. Group-IB: Iran-linked Tortoiseshell expands toolset with TWOSTROKE-like backdoor and reverse SSH tunneler - https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html 5. CISA adds actively exploited Oracle WebLogic Proxy Plug-in flaw (CVE-2026-21962, CVSS 10.0) to KEV - https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  6. Aug 23

    CareCloud's 3.75M Patient Breach Confirmed 5 Months Later

    * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: CareCloud's 3.75M Patient Breach Confirmed 5 Months Later Episode Number: 359 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-16 to 2026-08-20. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. CareCloud confirms 3.75 million patients' medical records stolen — five months after the intrusion - https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/ Additional Cybersecurity News – Titles and URLs 2. UT San Antonio hit by weekend cyberattack — classes for 42,000 students delayed five days - https://cybernews.com/news/university-of-texas-san-antonio-cyberattack-systems-offline/ 3. Fake crypto conference lures security researchers into malware via rigged Google Docs - https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/ 4. CameraSwarm — 14,530 Dahua IP cameras hijacked in a 35-day campaign with factory-reset-proof backdoors - https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/ 5. Fake "leaked GTA 6" builds flood piracy sites — every download is malware - https://www.ign.com/articles/malware-disguised-as-leaked-gta-6-copies-are-popping-up-on-piracy-sites Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  7. Aug 16

    Akira Rebooted Into Safe Mode — Then Stole the Data Anyway

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Akira Rebooted Into Safe Mode — Then Stole the Data Anyway Episode Number: 358 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-09 to 2026-08-13. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Akira ransomware EDR bypass via Safe Mode * OpenAI rogue AI agents breach Hugging Face * SharePoint CVE-2026-55040 exploited by ransomware gangs * ShieldBreak Defender patch bypass claims * MyDr Poland medical data breach - 18 million records Top Stories 1. Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt - https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/ Additional Cybersecurity News – Titles and URLs 2. The Safety Reckoning Inside OpenAI - https://www.wired.com/story/openai-safety-security-ai-agents-culture/ 3. Ransomware gangs weaponize SharePoint exploit CVE-2026-55040 - https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/ 4. ShieldBreak claims Microsoft Defender patch bypass (CVE-2026-50656) - https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html 5. Poland's MyDr breached - 18 million medical records stolen - https://cybernews.com/security/mydr-medical-data-breach-hackers-politicians/ Resources & Links * CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog * Rapid7 CVE-2026-55040 writeup: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ * Shadowserver exposed SharePoint servers: https://dashboard.shadowserver.org/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  8. Aug 9

    AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying - 2026-08-07 Episode Number: 3x57 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-02 to 2026-08-06. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from Meta's AI hacking another company during testing, to critical RCE flaws in Claude Code and Gemini CLI, to researchers silently stalking a reporter via a $30 kids' smartwatch, and a Linux kernel use-after-free with public exploit code. Guest Information None this episode Topics Covered * Meta's Muse Spark 1.1 breaches external organization during Irregular sandbox test — the third AI company to confirm this pattern * ClickFix macOS campaign evolves: Go-based infostealer with browser-fingerprinting gate and partial crypto draining * Critical RCE flaws in Claude Code, Gemini CLI, and OpenAI Codex — demonstrated on vendor repos with default configs * Tens of millions of GPS trackers (kids' watches, car devices) run on three compromised Shenzhen backend platforms * Linux bridge STP use-after-free: public PoC released, affects Docker/Kubernetes/cloud infrastructure Top Stories 1. Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test - https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/ Additional Cybersecurity News – Titles and URLs 2. ClickFix attack pushes macOS infostealer for crypto theft attacks - https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/ 3. Critical flaws in Claude Code, Gemini CLI, and OpenAI Codex enable RCE and supply chain attacks - https://cyberpress.org/critical-flaws-in-claude-code-gemini-cll-openai-codex/ 4. Hackers Stalked Me by Hijacking a Smartwatch for Kids - https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/ 5. Linux Bridge STP Use-After-Free Bug PoC Released - https://hoploninfosec.com/linux-bridge-stp-use-after-free-bug-poc Resources & Links * CISA KEV Catalog (Langflow, Tomcat, N-central): https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog * Anthropic Claude testing incident disclosure: https://hoploninfosec.com/claude-ai-testing-security-incident * Black Hat USA 2026: https://blackhat.com/us-26/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

Ratings & Reviews

5
out of 5
5 Ratings

About

A Cybersecurity Podcast for the Rest of Us In a world of evolving cyber threats, You’ve Already Been Hacked breaks down cybersecurity for everyone—from experts to everyday users. Hosted by Professor CyberRisk and Cyber Cowboy, we tackle major cyber attacks, emerging threats, and real-world security strategies. Each episode offers expert analysis, case studies, and actionable tips to help listeners stay ahead of hackers and digital risks.