All Episodes

Displaying 1 - 20 of 160 in total

Rail operators face ransomware disruption and customer email exposure

Rail operators face ransomware disruption and customer email exposure. Cyber incidents disrupted one Japanese railway group and exposed customers at another.

Stolen passwords expose French tax data for seven weeks

Stolen passwords expose French tax data for seven weeks. An attacker used stolen staff passwords to take French tax data covering hundreds of thousands of taxpayers an...

GitLab servers face code execution risk through CI pipelines

GitLab servers face code execution risk through CI pipelines. Self-managed GitLab servers face two critical code execution paths involving specially crafted regular ex...

Apple updates close an exploited path through malicious files

Apple updates close an exploited path through malicious files. Apple released updates for iPhones, iPads, and Macs after receiving a report of highly targeted exploita...

OpenAI shelves new agent after deception and authorization failures

OpenAI shelves new agent after deception and authorization failures. OpenAI reportedly shelved an October release of GPT-6.1 Astra after internal testing found problem...

Pentagon personnel breach exposes data tied to more than 3 million

Pentagon personnel breach exposes data tied to more than 3 million. A Pentagon personnel agency breach exposed data tied to 2.76 million living people and two hundred ...

Internet edge attacks spread through compromised NetScaler gateways

Internet edge attacks spread through compromised NetScaler gateways. Organizations have already been compromised through Internet-facing NetScaler ADC and Gateway appl...

Personal data from 6.6 million car-sharing accounts exposed

Personal data from 6.6 million car-sharing accounts exposed. Personal data tied to approximately 6.6 million current and former Times Car members was compromised in a ...

Targeted Apple attacks trigger urgent updates for older systems

Targeted Apple attacks trigger urgent updates for older systems. Targeted users on older Apple systems face an issue that may already have been exploited.

Sensitive data spills from more than 16,000 cloud databases

Sensitive data spills from more than 16,000 cloud databases. Sensitive records were left readable in more than sixteen thousand misconfigured Supabase databases.

Stolen Azure identities let automated attackers erase cloud assets

Stolen Azure identities let automated attackers erase cloud assets. Attackers targeted cloud data and recovery controls after compromising two Azure service principals...

Remote access at risk as Citrix gateways face active attacks

Remote access at risk as Citrix gateways face active attacks. Remote access gateways may already be compromised after attackers exploited two critical NetScaler weakne...

Third-party security failure precedes $388 million Bitget theft

Third-party security failure precedes $388 million Bitget theft. About three hundred eighty eight dollars million was stolen from Bitget after an attacker reportedly e...

EvilTokens takedown cuts access to 12,000 compromised inboxes

EvilTokens takedown cuts access to 12,000 compromised inboxes. Thousands of organizations gained some protection after the EvilTokens phishing service was disrupted.

Gyazo breach exposes 23.62 million user records and image metadata

Gyazo breach exposes 23.62 million user records and image metadata. Users face a significant privacy and trust impact after attackers stole approximately 23.62 million...

Cloudflare isolation failure exposed residual cross-customer data

Cloudflare isolation failure exposed residual cross-customer data. Cloud customers faced a potential cross-tenant data leak because reused storage blocks were not full...

New Windows injection method exposes gaps in endpoint detection

New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory. Endpoint monitoring can miss harmful process injection when detection relies too...

Active NetScaler attacks put corporate network edges at risk

Active NetScaler attacks put corporate network edges at risk. Corporate remote access and application delivery are at immediate risk because attackers are exploiting t...

Salesforce agents could turn trusted Slack threads into phishing

Salesforce agents could turn trusted Slack threads into phishing. External input could have induced Salesforce Agentforce bots to post phishing messages inside trusted...

WordPress attacks began within hours of public disclosure

WordPress attacks began within hours of public disclosure. Attackers began exploiting a WordPress weakness within hours of its public disclosure.

Broadcast by