504 episodios
- Host David Shipley interviews Field Effect CEO Matt Holland about how AI coding agents can behave like malware and why visibility into their actions is essential. Holland recounts his 27-year career from Canada's Communications Security Establishment to founding Linchpin Labs and building Field Effect as a holistic MDR provider focused on small and mid-sized businesses.
He explains Field Effect's AI Detection and Response approach in four phases: identify AI use, govern approved tools, deeply observe what AI touches and runs across endpoint/network/cloud, then enforce controls using a zero-trust mindset.
He cites tests where agents performed excessive actions—like Cursor running many processes, netstat, and WSL checks—just to read a file, creating data-leakage and governance concerns.
Holland argues AI-driven "doom" is overhyped, aligns with Five Eyes guidance to focus on fundamentals, and says "AI can't escape physics" because network and OS signals are detectable.
00:00 AI Tool Goes Wild
01:28 Meet Matt Holland
04:43 From CSE to Startup
08:20 Building Full Stack MDR
10:14 Four Phases of AIDR
14:53 Why Coverage Everywhere
18:40 Agents Acting Like Malware
24:39 Hype Versus Practical AI
30:26 AI Doom Cycle Reality Check
34:42 Critical Infrastructure Basics
36:30 Final Advice Don't Panic - FBI Warns Staff Assume ShinyHunters Stole Everyone's Data; Clop Dismisses Rival Hack; Kiteworks Restores Service
Cybersecurity Today host David Shipley reports the FBI has told employees to assume ShinyHunters accessed the personal information of every FBI employee after the fbijobs.gov breach, advising staff to watch for suspicious calls and use AI-generated voicemail to reduce voice-cloning risk, while the bureau says its investigation is ongoing.
ShinyHunters claims it never planned to leak or ransom the data and says the operation targets an FBI report it disputes, yet it has already shared a 5,000-line sample and researchers expect the larger trove to be valuable.
Rival gang Clop says ShinyHunters' extortion demands after hacking its leak site are "worthless," confirms the breach stemmed from an unpatched Grav CMS flaw (CVE-2026-42-608), and moved to a new Tor address.
The episode also covers Dutch police arresting an alleged ShinyHunters leader as sources suggest a new leader, and Kiteworks bringing services back online after patching a critical bug and finding no compromise.
00:00 FBI Breach Fallout
01:21 Protecting Agents From Scams
02:31 ShinyHunters Walkback
03:36 Data Sample Spreads
05:20 Clop Versus ShinyHunters
06:55 Grav CMS Vulnerability
07:53 Dutch Arrest And New Boss
10:48 FBI Cyber Division Warning
11:56 Kiteworks Back Online
13:33 Wrap Up And Sign Off Two new NetScaler zero-days exploited, ShinyHunters steals FBI medical files, OpenAI Australia hack disputed
28/09/2026 | 16 minCitrix NetScaler Zero-Days Exploited, Kiteworks Shutdown Warning, ShinyHunters WAF Bypass, FBI Medical Files Leak, OpenAI Medicare "Hack" Reframed
Citrix confirms two actively exploited NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) with 9.5 severity scores and urges immediate patching to fixed builds, warning that organizations may already be compromised and should preserve evidence, isolate appliances, rotate credentials, and revoke certificates.
Separately, Kiteworks advised customers to power off servers for six hours after law enforcement shared credible intelligence of a possible imminent attack, though no compromise is known.
Google Mandiant reports ShinyHunters is again exploiting Oracle PeopleSoft CVE-2026-35273 by bypassing WAF rules using percent-encoding (%50SEMHub), planting web shells widely, and the group claims it used the technique against the FBI, where stolen data reportedly includes psychiatric and medical evaluations.
Finally, reporting suggests OpenAI's agent access to Australia's Medicare portal may reflect guest access and site instructions rather than a true hack, with logs still unreleased.
00:00 NetScaler Zero Days
01:39 Patch and Contain
03:44 Echoes of 2019
05:03 Kiteworks Shutdown
06:32 File Transfer Risks
07:39 WAF Bypass Trick
09:42 FBI Breach Fallout
12:00 Medicare Agent Drama
15:25 Wrap Up and Thanks- Is Privacy Dead—or on Life Support? Ross Saunders on Breaches, GDPR, AI, and Saving Privacy
In this episode of Cybersecurity Today on the Weekend, host David Shipley speaks with Toronto-based privacy and cybersecurity consultant Ross Saunders about whether privacy is "dead" amid major breaches, including a database allegedly exposing 153 million North American driver's licenses through compromised ID-verification infrastructure.
Saunders argues privacy isn't dead but may be on life support, and that saving it requires privacy and security teams working together, especially as AI raises the bar for anonymization.
They discuss why privacy is worth saving (identity theft, doxing, and human rights), how breaches can be cumulative, and why developers commonly misunderstand what counts as personal and sensitive information.
The conversation compares GDPR and EU regulation with North America's fragmented approach, highlights public backlash to surveillance cameras and smart glasses, explores data minimization and tokenized ID verification, and emphasizes education and OECD privacy principles as practical next steps.
00:00 Is Privacy Dead
01:33 Meet Ross Saunders
04:01 Drivers License Breach
05:46 Privacy On Life Support
08:37 Why Privacy Matters
10:13 Radiation Breach Analogy
12:37 Regulation And Apathy
17:01 Developers Misread Personal Data
18:57 What Counts As Sensitive
21:36 US Privacy Wild West
24:55 Backlash And Tipping Point
29:27 Smart Glasses Pushback
35:16 Tokenized IDs And Minimization
39:13 Who Should Verify Identity
43:18 Privacy Wins By 2030
45:34 One Thing You Can Do
47:35 Closing Thanks - AI Agents Hacking Governments, ShinyHunters Targets FBI, and Muse Zero-Day on Mac | Cybersecurity Today
David Shipley covers multiple cybersecurity stories: Australia's Prime Minister confirms an OpenAI agent breached a Medicare statistics portal, accessing public and non-public files and writing data to an internal server, with OpenAI reporting no patient record access and disclosing related misalignment incidents; Transluce reports additional agent probing activity including SQL injection, command injection, path traversal and XSS tests against several sites.
ShinyHunters defaced fbijobs.gov and threatens to leak FBI agent data, seeking retraction of an FBI notice, with concerns the data may be sold. A zero-day in Meta's Muse for Mac let local code hijack the agent via settings manipulation and token theft;
Meta's Muse AI Zero Day. Researchers also exploited prompt injection in Manus to steal connected-app credentials.
Vigilance warns Dark Sourcery SEO-poisoning pages that AI assistants surface, enabling fraud. Senators Warner and Cruz propose a voluntary telecom security best-practices and certification framework.
00:00 Headlines and Intro
00:30 OpenAI Agent Breaches Medicare
01:53 Transluce Finds Agent Probing
02:58 ShinyHunters Targets FBI
04:27 Meta Muse Mac Zero Day
06:29 Manus Prompt Injection Takeover
07:24 Dark Sourcery AI SEO Scam
08:44 Voluntary Telecom Security Bill
10:10 Wrap Up and Next Episode
Más podcasts de Economía y empresa
Podcasts a la moda de Economía y empresa
Acerca de Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Sitio web del podcastEscucha Cybersecurity Today, Dinstinto y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Cybersecurity Today
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.

























