485 episodios
- Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta
The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Copilot (including "CoSnitch") and an Atlassian Confluence issue dubbed "RovoBlast" involving prompt injection, bypassing guardrails, and data exfiltration via a web-capable subagent.
Vaitsman explains why built-in model guardrails are insufficient, citing AI's lack of loyalty and "unlimited hunger for data," and argues for layered controls like least privilege, monitoring, and restricting data access.
He discusses psychological guardrail bypasses, introduces an "AI Hacking Trifecta" framework—enter, evade, escape—and comments on research showing AI-generated patches often fail, emphasizing human-led validation and guidance when using AI tools for security research.
00:00 Weekend Show Kickoff
00:44 Meet Mark Vaitsman
03:38 Teaching the Next Gen
04:19 Copilot Exploit Code Snitch
06:04 Atlassian RoboBlast Breakdown
08:52 Why Guardrails Fail
13:15 Manipulating Models to Comply
17:06 Securing Agents Without Handcuffs
20:11 AI Hacking Trifecta Framework
23:43 AI Patches and Human Research
27:43 Hope and Closing Thoughts Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms
28/08/2026 | 11 minTeam PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned
Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials and data.
Boston Scientific disclosed a cyberattack that caused network outages and disrupted global operations, halting its ability to ship devices like pacemakers and stents, with recovery expected to take weeks.
The U.S. Justice Department disrupted QScan and Q2Router, platforms tied to China-linked QTFY, used to proxy intrusions against U.S. agencies and an election system.
House Democrats asked GAO to assess how major workforce cuts have impacted CISA.
Forcepoint demonstrated invisible-text prompt injection that fooled an AI email summarizer into fabricating invoice details.
00:00 Headlines Overview
00:29 Team PCP Arrests
02:11 Krebs Investigation
03:06 Boston Scientific Disruption
04:50 Podcast Reviews Thanks
05:07 FBI Disrupts QTFY Tools
05:50 How QScan Pipeline Worked
07:27 CISA Workforce Cuts
08:53 Invisible Text AI Poisoning
10:27 Wrap Up And TeaserIranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cards
26/08/2026 | 10 minIran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw
Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked to Iran Nexus hackers, though damage was contained to a single small generator.
ReliaQuest confirms ShinyHunters targeted its staff with phone-based social engineering and a fake reliaquest.claims SSO page, gaining only temporary view-only Okta dashboard access before being blocked by device trust controls, with no customer data affected.
LockBit claims it hacked US Bancorp, but the bank says the incident traces to a fourth-party contractor outside its environment and LockBit has provided no proof. Microsoft is rolling out a Teams policy to automatically block detected external bots from meetings.
UMass Amherst researchers found some expired Visa cards can be "zombified" for contactless payments via a two-phone relay, depending on issuer and bank checks.
00:00 Top Headlines
00:26 Iran Linked Power Attack
01:44 ShinyHunters Targets ReliaQuest
04:16 LockBit Claims Bank Hack
05:46 Teams Blocks External Bots
07:42 Expired Visa Card Zombie
09:25 Closing Notes TributeMicrosoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet
24/08/2026 | 8 minEntra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware
Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen.
Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys.
Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun.
00:00 Top Stories Rundown
00:30 Entra ID Perfect 10 Patch
01:55 Defender Driver Weaponized
03:31 SickKids Hit Again
05:10 Leaked AWS Keys Still Live
06:48 Car Head Unit Botnet
08:25 Wrap Up And Sign OffAI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning
22/08/2026 | 36 minHow AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next
In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024.
They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical.
The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability.
00:00 Sponsor NordLayer
00:37 Weekend Show Intro
02:02 Robert Career Journey
03:08 Building Adlumin
05:50 AI Transforms SOC Work
08:56 AI Investigations Upgrade
11:23 Alert Fatigue and MDR
13:49 MSPs Become MSSPs
19:30 AI as Opportunity and Threat
21:13 Attack Speed Compression
22:54 Wins and Frustrations
26:59 Autonomous Hacking Reality
29:03 Hack Back Debate
32:43 Next 12 Months Forecast
34:28 Closing Thanks
35:22 Sponsor Message Return
Más podcasts de Economía y empresa
Podcasts a la moda de Economía y empresa
Acerca de Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Sitio web del podcastEscucha Cybersecurity Today, Seminario fénix - Brian Tracy y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Cybersecurity Today
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.





























