491 episodios
IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch
07/09/2026 | 14 minIdentity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale.
Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that abuses CrowdStrike's Falcon alongside other zero-days targeting Kaspersky, Avast, and Nvidia.
Sansec disclosed an unpatched Magento/Adobe Commerce flaw "Style Smuggler" enabling unauthenticated code execution.
Arctic Wolf observed active exploitation of PaperCut authentication bypass and RCE flaws against schools, including credential theft and lateral-movement prep.
UK police data shows reported losses from hacked accounts rose 417% amid improved reporting via the new Report Fraud system.
00:00 Top Headlines
00:31 IDScan Breach Lawsuits
03:13 FalconFlank Zero Day
05:02 Security Tools Weaponized
05:48 Magento Style Smuggler
08:59 Papercut Attacks Schools
11:02 UK Account Hack Losses
13:57 Wrap Up and Sign Off- Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation
In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems.
Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.
She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders.
The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world.
00:00 Weekend Show Intro
00:07 Katie Moussouris Background
02:00 Bug Bounties Then and Now
03:31 AI Hype and Model Escapes
05:06 The Real Cost of Fixing
08:36 Smart AI Regulation
12:34 Tools for Defenders vs Rogues
15:53 Metasploit and Agentic Risk
17:25 Nightmare Eclipse and Microsoft
21:53 Luta Security Today
24:28 Training the Next Generation
27:46 Hope, UBI, and Wrap Up FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos
04/09/2026 | 11 min153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments
The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to IDscan.net before Nexus abruptly disappeared.
It also covers a breach at healthcare SaaS provider Aesto Health affecting 9.54 million individuals, exposing extensive personal and medical data, with delayed confirmation and notifications and 24 months of Experian monitoring offered.
The show details CISA ending six free critical-infrastructure cybersecurity assessments amid workforce reductions, raising concerns given recent targeting of U.S. water systems and warnings about AI-generated exploitation scripts against Siemens PLCs.
Additional updates include Plex urging immediate patching of undisclosed vulnerabilities and Slovenia's HIT gradually reopening casinos after a cyberattack forced a three-day shutdown.
00:00 Top Cyber Headlines
00:29 Dark Web License Leak
02:33 Nexus Tied to IDscan
04:05 Healthcare SaaS Breach
05:35 CISA Cuts Assessments
07:16 Plex Patch Alert
08:43 Slovenian Casinos Recover
10:05 Weekend Interview Preview
10:53 Closing and Sign Off22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance
02/09/2026 | 8 min22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk
Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911, enabling mailbox takeover, with exploit code circulating and Germany warning most on-prem Exchange remains vulnerable as support deadlines loom.
The U.S. DOJ also corrected a press release to say multiple U.S. agencies were targeted—not confirmed victims—by China-linked QTFY intrusions.
Postmortems on the OpenAI/Hugging Face incident describe roughly 700 agents coordinating via shared notes and messaging to exploit systems, steal tokens and credentials, execute commands, and compromise infrastructure before Hugging Face shut it down July 13.
Palo Alto Unit 42 warns AI-driven exploitation is arriving, citing a case where AI leveraged 50 vulnerabilities in 10 hours. The Financial Stability Board calls frontier-AI cyber risk the most immediate threat to global finance and urges stronger safeguards and recovery planning.
00:00 Today's Cyber Headlines
00:32 Exchange Servers Wide Open
02:36 DOJ Walks Back Claims
03:29 700 Agents Hit Hugging Face
05:09 AI Exploits 50 Bugs Fast
06:43 Financial Watchdog Warns
08:25 Wrap Up and Sign OffShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid tech
31/08/2026 | 11 minShiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech
Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently verified. PaperCut issued a second emergency patch after bypasses were found for fixes to two actively exploited vulnerabilities that can be chained for unauthenticated remote code execution; organizations on v23 or earlier must upgrade. Berlin confirms an extortion attempt tied to Rhysida, which claims 5.79TB stolen. WordPress discloses five critical plugin/theme flaws enabling full site takeover, including a 10/10 GiveWP RCE. The White House bans foreign-made bulk power grid equipment over backdoor concerns amid rising critical-infrastructure attacks.
00:00 Top Headlines
00:30 McKesson Breach Fallout
03:18 PaperCut Patch Bypassed
06:02 Berlin Rejects Ransom
07:05 Critical WordPress Takeovers
08:43 Power Grid Tech Ban
10:35 AI Security Weekend Episode Promo
11:10 Closing and Sign Off
Más podcasts de Economía y empresa
Podcasts a la moda de Economía y empresa
Acerca de Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Sitio web del podcastEscucha Cybersecurity Today, Chisme Corporativo y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Cybersecurity Today
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.

























