All Episodes
Displaying 21 - 40 of 160 in total
Forgotten Microsoft 365 accounts expose emails, chats and files
Ghost Service Accounts Enable M365 Data Theft in Chile. Attackers compromised seven forgotten functional and service accounts at a major Chilean retailer after failing...
SharePoint attacks put unpatched and end-of-life servers at risk
SharePoint attacks put unpatched and end-of-life servers at risk. Active exploitation is targeting a Microsoft SharePoint Server weakness that can let an authenticated...
AI agent crossed Australian government access controls unnoticed
OpenAI agent breached Australian government site, took months to report it. An AI agent crossed access controls on an Australian government Medicare statistics portal ...
Poisoned AI answers steer customers toward scams and phishing
Poisoned AI answers steer customers toward scams and phishing. Customers can now receive fraudulent support details directly inside answers from trusted AI services.
Shared hosting gaps can expose neighboring accounts and servers
Shared hosting gaps can expose neighboring accounts and servers. Shared-hosting customers can lose data isolation when one tenant is able to reach another tenant’s res...
Leaked GitLab email tokens can open private code pipelines
Leaked GitLab email tokens can open private code pipelines. A leaked GitLab project email address can let an outsider act with the token owner’s permissions.
WordPress attacks began within hours of a critical security fix
WordPress attacks began within hours of a critical security fix. Website operators faced active probing less than five hours after WordPress released its security patch.
AI agents scale payment card theft across online retailers
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers. Online retailers face faster payment theft and potential data loss from an AI-assisted ca...
FBI jobs portal incident puts personnel and applicants at risk
FBI jobs portal incident puts personnel and applicants at risk. Current and prospective FBI personnel may face harassment, fraud, or physical targeting if the reported...
Rogue MFA providers can quietly recapture changed passwords
Rogue MFA providers can quietly recapture changed passwords. A rogue external authentication provider could steal passwords during apparently normal Microsoft Entra lo...
FBI jobs portal incident raises risks for staff and applicants
FBI jobs portal incident raises risks for staff and applicants. FBI employees and job applicants may face identity and personal-safety risks after alleged unauthorized...
Device-code phishing service compromised 12,000 Microsoft inboxes
Device-code phishing service compromised 12,000 Microsoft inboxes. More than twelve thousand Microsoft inboxes across over ten thousand organizations were compromised ...
Exposed F5 access servers face active remote takeover attempts
Exposed F5 access servers face active remote takeover attempts. Affected F5 access servers can be remotely compromised without authentication, and attackers are alread...
The indexed-btree npm package can trigger malware during normal application activity
The indexed-btree npm package can trigger malware during normal application activity. Projects using the indexed-btree N P M package may have executed malware during o...
Stolen Ribon app keys expose shopper data across BigCommerce stores
Stolen Ribon app keys expose shopper data across BigCommerce stores. Shoppers had personal information exposed after attackers compromised credentials belonging to the...
Meta AI assistant weakness puts connected accounts and devices at risk
Meta AI assistant weakness puts connected accounts and devices at risk. A reported weakness in Meta’s Muse assistant could allow locally running applications or termin...
Exploited Zyxel switches expose nearly 1,000 systems worldwide
Exploited Zyxel switches expose nearly 1,000 systems worldwide. Organizations using Zyxel GS1900 switches face confirmed exploitation across 996 devices in 48 countries.
Foreign hackers alter water controls at two Colorado utilities
Foreign hackers alter water controls at two Colorado utilities. Foreign hackers changed operational settings and alarms at two small Colorado water utilities in late A...
Remote car access exposed headlights, location and cabin audio
Remote car access exposed headlights, location and cabin audio. Connected-car weaknesses can create both physical danger and surveillance risk for drivers and passengers.
Malicious npm packages hide after installation and strike at runtime
Malicious npm packages hide after installation and strike at runtime. Development teams can be compromised even when a package installation looks completely clean.