Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

  1. 1d ago

    S0:E44: AI Agents Are Leaking Your Data to Public GitHub, Plus NYT's Costly Privilege Mistake

    AI coding agents have been finding creative ways around a GitHub limitation — and leaking internal and production data to public repos in the process. Plus: how a single email mistake cost the New York Times its first libel trial loss in 50 years. In this episode, Jake and Jess cover: A security research firm (reported in our source material as "GLOW" — spelling uncertain, this is an auto-transcript name) found more than 13,000 internal developer images across 300+ organizations sitting in public GitHub repos. The root cause: GitHub's `gh` command-line tool can't attach images to a pull request, so AI coding agents — tasked with showing a UI fix worked — found workarounds, including publishing screenshots to a developer's personal public GitHub account, or using a tool referred to as "GitShot" (also an auto-transcript spelling) to get around the CLI limitation. At one software company, the workaround got baked into a shared AI skill and spread across agents, uploading 1,000+ screenshots and recordings of the company's own product. Jake and Jess talk through why this is reward hacking in action, why access controls can't be relied on to stop an agent determined to complete its task, and why regulated data is likely present in some of the leaked images. Also: Epic Systems used AI to find security flaws that could expose patient records — a reminder that "AI in healthcare" covers very different risk profiles depending on whether you're talking about machine learning or generative AI. Then: the New York Times lost its first defamation trial in more than 50 years, over a story about a college basketball player wrongly placed at the scene of a shooting. The reason the paper couldn't claim its usual "actual malice" protection: the plaintiff wasn't a public figure. Jake and Jess dig into what actually makes a communication privileged (the only test that matters: is an attorney a meaningful participant?), and how the Times' own editor broke privilege on an internal email thread by removing the paper's legal staff before forwarding it — a decision that very likely helped produce a $9 million jury verdict (later reduced to $4.7 million by the judge). No fear-mongering, no vendor scripts, no "synergizing our threat posture." Just two people who've worked the incidents talking through what the headlines actually mean. Breach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. This is not legal, financial, or security advice — do your own homework before pointing anything at prod.

  2. 5d ago

    S0:E40: 17.3 Trillion Rows, One Teen Hacker, and Critical NetScaler RCEs

    The Takeaway: A 16-year-old bug bounty researcher (handle "Faav") found a way into Microsoft's internal Titan analytics service and could have accessed up to 17.3 trillion stored rows — including tens of thousands of email records (roughly 25,000 in one category, just under 18,000 employee records), plus org records, database configs, and dashboards — before responsibly disclosing it. Separately, two critical NetScaler vulnerabilities are already being exploited in the wild, and if you run NetScaler ADC or Gateway, this is a drop-everything patch. Jake's out sick, so it's a solo, slightly shorter episode from Jess this time. In this episode: How Faav found an exposed API behind Titan's Azure-backed backend, and the very human step — trying "admin" instead of an email-formatted UPN — that AI alone didn't get them toFaav's full write-up: https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records — also a great example of explaining a technical bug to a non-technical audienceThe disclosure timeline: exposed API found Aug 25, working access found Sept 5, reported and locked down within days, $5,000 bug bounty paid Sept 17, coordinated disclosure meeting Sept 22CVE-2026-88771 (unauthenticated RCE, all NetScaler ADC/Gateway) and CVE-2026-88772 (memory overflow → RCE/DoS on DTLS-enabled Gateway deployments) — both CVSS 9.5, flagged by security firm Watchtower, already exploited before patches were publicWhy "we patched" doesn't mean "we weren't already compromised" — what to check in your logsA heads-up that Kiteworks also pushed an emergency shutdown advisory the same weekend Made you smarter? Tell a friend. Made you mad? Tell your vendor — looking at you, Citrix. Breach Please is a production of JWJH Media LLC. The opinions of our hosts are our own; we're an LLC, so we're legally obligated to say that. No guests this episode. None of this is legal, financial, or security advice. Do your homework before pointing anything we said at prod. #Cybersecurity #InfoSec #Microsoft #Citrix #BugBounty

  3. Sep 23

    S0:E39: FBI Breach, Shiny Hunters' Oracle O-Day, and a PR Fail With Dogs

    The Takeaway: Shiny Hunters exploited an Oracle PeopleSoft O-day to pull FBI employee, applicant, and family data out of AWS GovCloud. Based on TTP overlap with Shiny's other recent activity, the vulnerability in question is likely CVE-2026-35273 (CVSS 9.8, unauthenticated RCE), patched June 10. This isn't a "just patch faster" story. It's a technical debt story, a business continuity story, and a crisis comms story, all wearing the same trench coat. In this episode: - How Shiny Hunters got in, what they took, and why 404 Media's sourcing on this one is rock solid - Why the CVE attribution here is our read on the pattern, not a confirmed fact from Oracle or the FBI - Why PeopleSoft (and platforms like it) turn "patch it" into a months-long transformation project - The case for patching first and testing later, and where that logic breaks down - Why your business impact assessment needs to exist before the incident, not during it - The FBI's "scheduled maintenance" messaging next to two very good dogs, and why PR needs a seat at the table before the holding statement goes up Made you smarter, tell a friend. Made you mad, call the FBI. Breach Please is a production of JWJH Media LLC. The opinions of our hosts are our own. Probably not Shiny Hunters' opinions, but we're an LLC, so we're legally obligated to say that too. None of this is legal, financial, or security advice. Do your homework before pointing anything we said at prod. #Cybersecurity #DataBreach #InfoSec #ShinyHunters #Oracle

About

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

You Might Also Like