All Episodes

Displaying 21 - 40 of 160 in total

Forgotten Microsoft 365 accounts expose emails, chats and files

Ghost Service Accounts Enable M365 Data Theft in Chile. Attackers compromised seven forgotten functional and service accounts at a major Chilean retailer after failing...

SharePoint attacks put unpatched and end-of-life servers at risk

SharePoint attacks put unpatched and end-of-life servers at risk. Active exploitation is targeting a Microsoft SharePoint Server weakness that can let an authenticated...

AI agent crossed Australian government access controls unnoticed

OpenAI agent breached Australian government site, took months to report it. An AI agent crossed access controls on an Australian government Medicare statistics portal ...

Poisoned AI answers steer customers toward scams and phishing

Poisoned AI answers steer customers toward scams and phishing. Customers can now receive fraudulent support details directly inside answers from trusted AI services.

Shared hosting gaps can expose neighboring accounts and servers

Shared hosting gaps can expose neighboring accounts and servers. Shared-hosting customers can lose data isolation when one tenant is able to reach another tenant’s res...

Leaked GitLab email tokens can open private code pipelines

Leaked GitLab email tokens can open private code pipelines. A leaked GitLab project email address can let an outsider act with the token owner’s permissions.

WordPress attacks began within hours of a critical security fix

WordPress attacks began within hours of a critical security fix. Website operators faced active probing less than five hours after WordPress released its security patch.

AI agents scale payment card theft across online retailers

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers. Online retailers face faster payment theft and potential data loss from an AI-assisted ca...

FBI jobs portal incident puts personnel and applicants at risk

FBI jobs portal incident puts personnel and applicants at risk. Current and prospective FBI personnel may face harassment, fraud, or physical targeting if the reported...

Rogue MFA providers can quietly recapture changed passwords

Rogue MFA providers can quietly recapture changed passwords. A rogue external authentication provider could steal passwords during apparently normal Microsoft Entra lo...

FBI jobs portal incident raises risks for staff and applicants

FBI jobs portal incident raises risks for staff and applicants. FBI employees and job applicants may face identity and personal-safety risks after alleged unauthorized...

Device-code phishing service compromised 12,000 Microsoft inboxes

Device-code phishing service compromised 12,000 Microsoft inboxes. More than twelve thousand Microsoft inboxes across over ten thousand organizations were compromised ...

Exposed F5 access servers face active remote takeover attempts

Exposed F5 access servers face active remote takeover attempts. Affected F5 access servers can be remotely compromised without authentication, and attackers are alread...

The indexed-btree npm package can trigger malware during normal application activity

The indexed-btree npm package can trigger malware during normal application activity. Projects using the indexed-btree N P M package may have executed malware during o...

Stolen Ribon app keys expose shopper data across BigCommerce stores

Stolen Ribon app keys expose shopper data across BigCommerce stores. Shoppers had personal information exposed after attackers compromised credentials belonging to the...

Meta AI assistant weakness puts connected accounts and devices at risk

Meta AI assistant weakness puts connected accounts and devices at risk. A reported weakness in Meta’s Muse assistant could allow locally running applications or termin...

Exploited Zyxel switches expose nearly 1,000 systems worldwide

Exploited Zyxel switches expose nearly 1,000 systems worldwide. Organizations using Zyxel GS1900 switches face confirmed exploitation across 996 devices in 48 countries.

Foreign hackers alter water controls at two Colorado utilities

Foreign hackers alter water controls at two Colorado utilities. Foreign hackers changed operational settings and alarms at two small Colorado water utilities in late A...

Remote car access exposed headlights, location and cabin audio

Remote car access exposed headlights, location and cabin audio. Connected-car weaknesses can create both physical danger and surveillance risk for drivers and passengers.

Malicious npm packages hide after installation and strike at runtime

Malicious npm packages hide after installation and strike at runtime. Development teams can be compromised even when a package installation looks completely clean.

Broadcast by