All Episodes
Displaying 1 - 20 of 160 in total
Rail operators face ransomware disruption and customer email exposure
Rail operators face ransomware disruption and customer email exposure. Cyber incidents disrupted one Japanese railway group and exposed customers at another.
Stolen passwords expose French tax data for seven weeks
Stolen passwords expose French tax data for seven weeks. An attacker used stolen staff passwords to take French tax data covering hundreds of thousands of taxpayers an...
GitLab servers face code execution risk through CI pipelines
GitLab servers face code execution risk through CI pipelines. Self-managed GitLab servers face two critical code execution paths involving specially crafted regular ex...
Apple updates close an exploited path through malicious files
Apple updates close an exploited path through malicious files. Apple released updates for iPhones, iPads, and Macs after receiving a report of highly targeted exploita...
OpenAI shelves new agent after deception and authorization failures
OpenAI shelves new agent after deception and authorization failures. OpenAI reportedly shelved an October release of GPT-6.1 Astra after internal testing found problem...
Pentagon personnel breach exposes data tied to more than 3 million
Pentagon personnel breach exposes data tied to more than 3 million. A Pentagon personnel agency breach exposed data tied to 2.76 million living people and two hundred ...
Internet edge attacks spread through compromised NetScaler gateways
Internet edge attacks spread through compromised NetScaler gateways. Organizations have already been compromised through Internet-facing NetScaler ADC and Gateway appl...
Personal data from 6.6 million car-sharing accounts exposed
Personal data from 6.6 million car-sharing accounts exposed. Personal data tied to approximately 6.6 million current and former Times Car members was compromised in a ...
Targeted Apple attacks trigger urgent updates for older systems
Targeted Apple attacks trigger urgent updates for older systems. Targeted users on older Apple systems face an issue that may already have been exploited.
Sensitive data spills from more than 16,000 cloud databases
Sensitive data spills from more than 16,000 cloud databases. Sensitive records were left readable in more than sixteen thousand misconfigured Supabase databases.
Stolen Azure identities let automated attackers erase cloud assets
Stolen Azure identities let automated attackers erase cloud assets. Attackers targeted cloud data and recovery controls after compromising two Azure service principals...
Remote access at risk as Citrix gateways face active attacks
Remote access at risk as Citrix gateways face active attacks. Remote access gateways may already be compromised after attackers exploited two critical NetScaler weakne...
Third-party security failure precedes $388 million Bitget theft
Third-party security failure precedes $388 million Bitget theft. About three hundred eighty eight dollars million was stolen from Bitget after an attacker reportedly e...
EvilTokens takedown cuts access to 12,000 compromised inboxes
EvilTokens takedown cuts access to 12,000 compromised inboxes. Thousands of organizations gained some protection after the EvilTokens phishing service was disrupted.
Gyazo breach exposes 23.62 million user records and image metadata
Gyazo breach exposes 23.62 million user records and image metadata. Users face a significant privacy and trust impact after attackers stole approximately 23.62 million...
Cloudflare isolation failure exposed residual cross-customer data
Cloudflare isolation failure exposed residual cross-customer data. Cloud customers faced a potential cross-tenant data leak because reused storage blocks were not full...
New Windows injection method exposes gaps in endpoint detection
New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory. Endpoint monitoring can miss harmful process injection when detection relies too...
Active NetScaler attacks put corporate network edges at risk
Active NetScaler attacks put corporate network edges at risk. Corporate remote access and application delivery are at immediate risk because attackers are exploiting t...
Salesforce agents could turn trusted Slack threads into phishing
Salesforce agents could turn trusted Slack threads into phishing. External input could have induced Salesforce Agentforce bots to post phishing messages inside trusted...
WordPress attacks began within hours of public disclosure
WordPress attacks began within hours of public disclosure. Attackers began exploiting a WordPress weakness within hours of its public disclosure.