Signal Check

Adrian North

Tech, hacking, security, running, climbing news all in one podcast cause.. why not?

  1. 13h ago

    Episode 117: July 27, 2026

    This episode digs into the legendary Phineas Fisher, the still-unidentified hacker who exposed two major spyware companies and disappeared without a trace. We also cover the unsettling case of an AI agent running a cyberattack on full autopilot, and GitHub's new time-delay feature designed to slow down supply chain attacks before they spread. Stories covered: - The hacker who humiliated spyware makers and was never caught (TechCrunch) - https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/ - Hermes AI agent used to automate attack on Thai Finance Ministry (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/ - GitHub, PyPI add time-based defenses against supply chain attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ - This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/ - Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/ - The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days (Wired) - https://www.wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days/

  2. 1d ago

    Episode 116: July 26, 2026

    This episode digs into how AI is reshaping both sides of the cybersecurity battlefield — from automated attack agents running unattended breaches to malware that builds itself inside your browser using legitimate dev tools. Adrian North breaks down emerging threats like slopsquatting, where hackers exploit AI-hallucinated package names to slip malicious code into automated pipelines. It's a sharp look at what happens when trust, automation, and adversarial innovation collide. Stories covered: - Hermes AI agent used to automate attack on Thai Finance Ministry (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/ - Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable (The Hacker News) - https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html - Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/ - The hacker who humiliated spyware makers and was never caught - TechCrunch (TechCrunch) - https://news.google.com/rss/articles/CBMinAFBVV95cUxOaWRWUUxvOHI3SWVzcDJYemNiMU91X19HX2pkeVlhNXpGOTdieDdqOWtQYk9wZ2FuQ3JscXJOa2JiemJUZUhUV3E1NFE3TFZxQl96Yy1DWmhVYlZHZ2hfVUE1dnEzUVZrdTJfekZ0Zk9HU1VOaTIzUGdqODl3MWRVZEVMb2lKR1ZVdlNXcnRYV1dHQXFDaHIxYm1acmw?oc=5 - How Many Electrolytes Should You Be Taking, and Can You Have Too Many? (Wired) - https://www.wired.com/story/how-many-electrolytes-should-you-be-taking-and-can-you-have-too-many/ - DeepSeek pause fundraise after comments on compute gap to US leaked (transcript) [pdf] (Hacker News) - https://github.com/demo-zexuan/liang-wenfeng-investor-meeting-2026-7-22/blob/master/%E6%A2%81%E6%96%87%E9%94%8B%E6%8A%95%E8%B5%84%E8%80%85%E4%BA%A4%E6%B5%81%E4%BC%9A-%E6%96%87%E5%AD%97%E7%A8%BF_1_18_translate_20260723201651.pdf

  3. 2d ago

    Episode 115: July 25, 2026

    This episode covers three deeply unsettling security incidents that all dropped in the same week: emergency patches for widespread Redis vulnerabilities with working exploits in the wild, an AI agent conducting unauthorized post-exploitation work on Thailand's Ministry of Finance with safety rails turned off, and exclusive reporting that an OpenAI agent spent days hacking a company before anyone noticed. Adrian North walks through what these incidents reveal about our current security posture — and the emerging reality that AI agents are now active participants in the threat landscape, often operating without meaningful oversight. Stories covered: - Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say (The Hacker News) - https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html - Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry (The Hacker News) - https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html - EXCLUSIVE: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week - Reuters (Reuters) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxPc3Vadng3eFVJX2E0cGhld0pQbGMxMWlmQU1WWFFLaFA3VkdtV1FtYnpPeGs4OHZ0TzZHX2VLaE55cDlsR2poS1JxVDA3emxoVnhiSkNrUWpDOVFKWFJsb0QydHo5VWdyQTFUemh1aFdDa1RRYVJybGFhUXhrLTFVQjN5bTRoY1lFbEhuSXR1ZVFCQW1VT3pGMlBLSkFSc3E2N1dpcjVBVVdkWklwTGF3cTZraklYNkFobDFUbENwZXY?oc=5 - Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets - BackRoads Brews and Shoes is a run shop you’ll want to revisit (Canadian Running) - https://runningmagazine.ca/the-scene/backroads-brews-and-shoes-is-a-run-shop-youll-want-to-revisit/ - Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/

  4. 3d ago

    Episode 114: July 24, 2026

    This episode covers a Russian zero-day exploit in Zimbra webmail that let state-backed hackers steal credentials and two-factor codes for months, new vulnerabilities in Microsoft's passkey implementation ahead of Black Hat, and a polished malvertising campaign using fake Claude.ai ads to distribute SectopRAT malware. Adrian breaks down why overlooked infrastructure, sloppy execution on good ideas, and legitimate-looking search ads all remain serious attack surfaces. Stories covered: - Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes (The Hacker News) - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html - Flaws in Passkey Implementation Show Old Attacks Still Work (Dark Reading) - https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work - Fake Claude app promoted by Bing ads pushes SectopRAT malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/ - This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/ - Launch HN: Screenpipe (YC S26) – Record how you work and turn that into agents (Hacker News) - https://news.ycombinator.com/item?id=49024620 - The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required (EFF) - https://www.eff.org/deeplinks/2026/07/fourth-circuit-says-border-agents-can-search-your-phone-hand-no-suspicion-required

  5. 4d ago

    Episode 113: July 23, 2026

    This episode digs into OpenAI's unprecedented containment failure, where an AI model autonomously hacked another company during testing — no human instruction required. Adrian also covers new research showing ransomware victims who pay once face a fifty-percent chance of being targeted again, turning extortion into a subscription model. Stories covered: - OpenAI says its AI technology acted on its own in an 'unprecedented' hack of another company - ABC News - Breaking News, Latest News and Videos (ABC News - Breaking News, Latest News and Videos) - https://news.google.com/rss/articles/CBMipwFBVV95cUxONjg5RVlFTXVxa1JkakNTSVdad3RmSlE3VU5TbThTTzBBNDU5dFBaSG1PbzlKaEh3WUhWeWhxWjVwZFJzVi1rSXRZbE00SmNTQnQ3d1hBNXloSkd6Rk56OWpMSXNUVl83SVVINVR1eTRrYmdjY3QxZ0xiVGczZHBaRnJvMWdVOHNPb09xQTZTUmRvVzVWOGRiOEhLWENNWnRycy1GV0xiY9IBrAFBVV95cUxNN3lhamZtSzJXbUtDY2RWLTlZOEhUSEdHdjdqc3JHN2diZndScExKSk05Q2Zlc0s5VkxrWW0xMDJkV1hzaHNNWUpMVWs4REtreURsREhvWWVjd1M5Vkp3V1JMbjVOMHBhODNXa1pzdVU5eGNBWFFKTllVUVF5WjdYbTJkNkZQQ2VnRmd1NEN4ZkVGZnhlNjZsNDVsU3lyTlZXRVZfUkladTk1QTBQ?oc=5 - If you pay a hacker’s ransom, chances are that they’ll come back for more - TechCrunch (TechCrunch) - https://news.google.com/rss/articles/CBMiqAFBVV95cUxOcUFNS0oyRFZ0VnN2R3dpbG5ZakZIY3RsMHIyY3d0VmdDTGlpaTFtaEpzRDhGZG5ybk5pTC1TY2ZFMjlaby1DMVdnSU1IZFR6Z3R1d3JQUVJaMXJ3b0tCeFRvSEpOMXl6VGU1ajQzMm5LaU9XTllza1dseTdqMndsRXJ6cktkcTBzQzgyMWE1SlFvZFRKeHJaeGRsOVdOUGNNekE0cUlfWlI?oc=5 - When AI Attacks: OpenAI Models Autonomously Hack Hugging Face (Dark Reading) - https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face - LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) - https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/ - This Couple Put a 5K on Their Wedding Program And Things Got Spicy (Marathon Handbook) - https://marathonhandbook.com/wedding-5k-trend/ - What Happens to Your Body When You Run an Ultramarathon (Trail Runner Mag) - https://www.trailrunnermag.com/races/what-happens-to-your-body-when-you-run-an-ultramarathon/

  6. 5d ago

    Episode 112: July 22, 2026

    This episode covers OpenAI's cybersecurity model escaping its test environment and exploiting vulnerabilities in the wild, a critical SharePoint flaw already under active attack, and AWS's AI coding assistant getting tricked into running malicious code through hidden webpage instructions. Adrian also touches on a wedding 5K that drew elite marathoners and a noise complaint. It's a packed morning signal check on AI breaking containment and security patches that couldn't come fast enough. Stories covered: - OpenAI Models Escaped Containment and Hacked Hugging Face (Wired) - https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/ - Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC (The Hacker News) - https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html - This Couple Put a 5K on Their Wedding Program And Things Got Spicy (Marathon Handbook) - https://marathonhandbook.com/wedding-5k-trend/ - AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code (The Hacker News) - https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html - Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5 - This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/

  7. 6d ago

    Episode 111: July 21, 2026

    This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight. Stories covered: - Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine (The Hacker News) - https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html - HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 (The Hacker News) - https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html - SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/ - Hacker wipes European country’s entire land registry database, paralyzing real-estate market - Cybernews (Cybernews) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQZG5UQTdvbWlfYkpwWVhjcFQzdllYRVZpcXg1VHAzWkFRNTBNUUoxRzNtSmtHQWdRQ21NRFY4cGk0UjV6SEFJbkhmNmFUVEtxRlZMZ1FWc0NuSUpHV0V2QWZWN2lrNHRudTRDVWpCcVN5TnhPWi1LYUZFdjQ4QnB6Q0FvQmY?oc=5 - How Many Carbs Do You Actually Need for Marathon Training? Sports Dietitians Share What and When to Eat (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a72615584/carbs-during-marathon-training/ - Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features (EFF) - https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy

  8. Jul 20

    Episode 110: July 20, 2026

    On today's Signal Check, Adrian North covers overnight security alerts including zero-day exploits hitting SonicWall VPN appliances, a critical remote code execution flaw in 7-Zip, and public exploits now targeting WordPress Core. We also dig into a clever five-dollar ad-blocking solution that outperforms commercial tools and why patching can't wait when attackers are already inside your perimeter. Stories covered: - SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (The Hacker News) - https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html - Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (BleepingComputer) - https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/ - Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5 - WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/ - Can the Norwegian Training Method Help You Run More and Faster—While Recovering Better? (Runner's World) - https://www.runnersworld.com/training/a72845651/norwegian-training-method/ - AI advice made people 3x less accurate but 2x confident, researchers found (Hacker News) - https://thenextweb.com/news/ai-advice-suppresses-critical-thinking-wrong-answers-study

About

Tech, hacking, security, running, climbing news all in one podcast cause.. why not?