-
10
#AxisOfEasy 467: Your LG TV Is Listening Even When It Is Off
In this issue: Your LG TV Is Listening Even When It’s “Off” A Swarm Of OpenAI Agents Secretly Ran A German Wiki As Their Message Board For Three Months Hackers Drain $320 Million From Liquid Network, Then Give Most Of It Back Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Trezor’s Address Breach Just Went Analog: Scam Letters With Malicious QR Codes Anthropic Employee (for six weeks) Sounds the Alarm on AI Alignment In this issue: Your LG TV Is Listening Even When It’s “Off” A Swarm Of OpenAI Agents Secretly Ran A German Wiki As Their Message Board For Three Months Hackers Drain $320 Million From Liquid Network, Then Give Most Of It Back Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Trezor’s Address Breach Just Went Analog: Scam Letters With Malicious QR Codes Anthropic Employee (for six weeks) Sounds the Alarm on AI Alignment
-
9
#AxisOfEasy 466: You Handed Over Your Licence At The Counter. Now 153 Million Scans Are For sale
In this issue: A dark-web service is selling scans of 153 million U.S. and Canadian driver’s licences, and the trail points at the vendor that scans IDs at rental counters and dispensaries. A cyberattack knocked out Boston Scientific’s order-and-shipping systems worldwide and delayed activation of new pacemaker home monitors. A perfect-storm JFrog Artifactory bug lets anyone mint an admin token, and attackers were forging them within three days of the patch. Researchers spent $535.74 and eight and a half hours getting Claude to port a working exploit to an industrial controller — then it bricked the device. Two more surveillance backdoors turned up in Chinese-made routers sold worldwide under brand names the real manufacturer never prints on the box. In this issue: A dark-web service is selling scans of 153 million U.S. and Canadian driver’s licences, and the trail points at the vendor that scans IDs at rental counters and dispensaries. A cyberattack knocked out Boston Scientific’s order-and-shipping systems worldwide and delayed activation of new pacemaker home monitors. A perfect-storm JFrog Artifactory bug lets anyone mint an admin token, and attackers were forging them within three days of the patch. Researchers spent $535.74 and eight and a half hours getting Claude to port a working exploit to an industrial controller — then it bricked the device. Two more surveillance backdoors turned up in Chinese-made routers sold worldwide under brand names the real manufacturer never prints on the box.
-
8
#AxisOfEasy 465: DOJ and FBI Seize Chinese State-Backed Hacking Platforms That Hit NASA, the Fed, and the Senate
In This Issue: DOJ and FBI Seize Chinese State-Backed Hacking Platforms That Hit NASA, the Fed, and the Senate AI Hallucinates Domains for Your Brand. Criminals Are Already Registering Them. Microsoft Patches a Maximum-Severity Entra ID Flaw — Then Walks Back the “Exploited” Claim DOJ Charges 17 More Iranians in a Decade-Long Campaign That Stole 31 Terabytes From 144 US Universities OpenAI Hits the Brakes on Model Training After Its Own Agent Hacked Hugging Face In This Issue: DOJ and FBI Seize Chinese State-Backed Hacking Platforms That Hit NASA, the Fed, and the Senate AI Hallucinates Domains for Your Brand. Criminals Are Already Registering Them. Microsoft Patches a Maximum-Severity Entra ID Flaw — Then Walks Back the “Exploited” Claim DOJ Charges 17 More Iranians in a Decade-Long Campaign That Stole 31 Terabytes From 144 US Universities OpenAI Hits the Brakes on Model Training After Its Own Agent Hacked Hugging Face
-
7
#AxisOfEasy 464: Apple’s Spyware Pager Goes Off in 110 Countries
In this issue: Apple’s Spyware Pager Goes Off in 110 Countries A Nation-State Crew Rooted 361 vCenter Servers in 47 Countries — Patch Was Out Five Days Nine Fortune 500 Names, Millions of Records: The Azure Credential Dump Nobody’s Calling a Breach GeoServer’s Unpatched Zero-Day Is Getting Probed Right Now, and There’s No Fix Yet The March Supply-Chain Attack That Keeps Getting Bigger: LiteLLM’s 2,500-Company Hangover In this issue: Apple’s Spyware Pager Goes Off in 110 Countries A Nation-State Crew Rooted 361 vCenter Servers in 47 Countries — Patch Was Out Five Days Nine Fortune 500 Names, Millions of Records: The Azure Credential Dump Nobody’s Calling a Breach GeoServer’s Unpatched Zero-Day Is Getting Probed Right Now, and There’s No Fix Yet The March Supply-Chain Attack That Keeps Getting Bigger: LiteLLM’s 2,500-Company Hangover
-
6
#AxisOfEasy 463: Facial Recognition Comes To The London Underground, Whether You Signed Up Or Not
Facial Recognition Comes to the London Underground, Whether You Signed Up or Not Google’s Synced Passkeys Have a Master Key — And It Can’t Be Revoked Metabase Zero-Day Bites Framework: Names, Emails, and a Reminder About Vendor Trust Hackers Pivot Through a Private Cell Network Into a Polish Power Plant’s OT Network North Carolina’s Ports Go Manual After a Cyberattack Nobody Wants to Talk About Your Kid’s GPS Watch Was Built on the Same Three Leaky Backends As Everyone Else’s Facial Recognition Comes to the London Underground, Whether You Signed Up or Not Google’s Synced Passkeys Have a Master Key — And It Can’t Be Revoked Metabase Zero-Day Bites Framework: Names, Emails, and a Reminder About Vendor Trust Hackers Pivot Through a Private Cell Network Into a Polish Power Plant’s OT Network North Carolina’s Ports Go Manual After a Cyberattack Nobody Wants to Talk About Your Kid’s GPS Watch Was Built on the Same Three Leaky Backends As Everyone Else’s
-
5
#AxisOfEasy 462: Your “Private” Claude Chats Were On Google The Whole Time
In this issue: The npm Worm That Ate The JavaScript Supply Chain 75 Million Revolut Records For Sale, Revolut Says Nothing To See Here Your “Private” Claude Chats Were On Google The Whole Time Cisco’s Firewall Manager Had Hard-Coded Credentials, Guess What Happened VMware’s vCenter Has A “Skip Authentication Entirely” Button Now Brussels Starts Actually Enforcing The AI Act This Week In this issue: The npm Worm That Ate The JavaScript Supply Chain 75 Million Revolut Records For Sale, Revolut Says Nothing To See Here Your “Private” Claude Chats Were On Google The Whole Time Cisco’s Firewall Manager Had Hard-Coded Credentials, Guess What Happened VMware’s vCenter Has A “Skip Authentication Entirely” Button Now Brussels Starts Actually Enforcing The AI Act This Week
-
4
#AxisOfEasy 461: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode
In this issue: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode FakeAgent Unmasked: Malicious Claude Artifact Delivered SectopRAT to 29+ Organizations Canada’s New Hate Speech Law Sparks Home Visits Over Old Social Media Posts Critical Rails Flaw Lets Hackers Read Server Secrets Through Image Uploads OpenAI’s AI Models Exploited a Zero-Day to Breach Hugging Face In this issue: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode FakeAgent Unmasked: Malicious Claude Artifact Delivered SectopRAT to 29+ Organizations Canada’s New Hate Speech Law Sparks Home Visits Over Old Social Media Posts Critical Rails Flaw Lets Hackers Read Server Secrets Through Image Uploads OpenAI’s AI Models Exploited a Zero-Day to Breach Hugging Face
-
3
#AxisOfEasy 459: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent To Being Protected
In this issue: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent to Being Protected Waymo Robotaxi Snitches on Teens’ Boozy Joyride Apple Sues OpenAI Over Alleged Trade Secret Theft by Former Engineer Researchers Find Claude-Slack Integration Can Be Hijacked by Fake “@Claude” Mentions Ransomware Group’s Bosch Data Claims Appear Unfounded, Synopsys Says Spoofed OAuth IDs Let Hackers Quietly Test Millions of Microsoft Entra Logins In this issue: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent to Being Protected Waymo Robotaxi Snitches on Teens’ Boozy Joyride Apple Sues OpenAI Over Alleged Trade Secret Theft by Former Engineer Researchers Find Claude-Slack Integration Can Be Hijacked by Fake “@Claude” Mentions Ransomware Group’s Bosch Data Claims Appear Unfounded, Synopsys Says Spoofed OAuth IDs Let Hackers Quietly Test Millions of Microsoft Entra Logins
-
2
#AxisOfEasy 457: Canada’s New Cyber Law Lets A Minister Cut Your Phone Off — No Warrant Required
In this issue: Canada’s New Cyber Law Lets a Minister Cut Your Phone Off — No WarrantRequired CISA Confirms Ransomware Exploitation of Unpatched Microsoft DefenderFlaw NAIC Cyberattack Exposes Insurer Credit Rating Data via OraclePeopleSoft Zero-Day Anthropic Brings Claude Fable 5 Back Online After Export ControlStandoff New “ARToken” Phishing Service Exposed as Customer of MFA-Bypassing EvilTokens Kit In this issue: Canada’s New Cyber Law Lets a Minister Cut Your Phone Off — No WarrantRequired CISA Confirms Ransomware Exploitation of Unpatched Microsoft DefenderFlaw NAIC Cyberattack Exposes Insurer Credit Rating Data via OraclePeopleSoft Zero-Day Anthropic Brings Claude Fable 5 Back Online After Export ControlStandoff New “ARToken” Phishing Service Exposed as Customer of MFA-Bypassing EvilTokens Kit
-
1
#AxisOfEasy 455: Canada’s New Bill Would Trade Online Anonymity For “Child Safety”
In this issue: Canada’s New Bill Would Trade Online Anonymity for “Child Safety” US Forces Anthropic to Pull Fable 5, Mythos 5 Over Disputed Jailbreak Claim Massive Fortinet Firewall Breach Exposes Credentials at Samsung, FedEx, Oracle, and 21,000+ Other Domains AI Sovereignty Fears Boil Over at G7 The Backdoor That Outlived the Takedown In this issue: Canada’s New Bill Would Trade Online Anonymity for “Child Safety” US Forces Anthropic to Pull Fable 5, Mythos 5 Over Disputed Jailbreak Claim Massive Fortinet Firewall Breach Exposes Credentials at Samsung, FedEx, Oracle, and 21,000+ Other Domains AI Sovereignty Fears Boil Over at G7 The Backdoor That Outlived the Takedown
-
0
#AxisOfEasy 453: Instagram’s AI Chatbot Exploited to Hijack High-Profile Accounts
In this issue: Instagram’s AI Chatbot Exploited to Hijack High-Profile Accounts Red Hat npm Channel Hijacked to Spread Credential-Stealing Worm AI-Powered Malware Lab Targets Major EDR Platforms IMA Diligence Services Data Breach Exposes 525,000+ Victims to Genesis Ransomware Group Microsoft Backs Down After Security Researcher Backlash In this issue: Instagram’s AI Chatbot Exploited to Hijack High-Profile Accounts Red Hat npm Channel Hijacked to Spread Credential-Stealing Worm AI-Powered Malware Lab Targets Major EDR Platforms IMA Diligence Services Data Breach Exposes 525,000+ Victims to Genesis Ransomware Group Microsoft Backs Down After Security Researcher Backlash
-
-1
#AxisOfEasy 452: Canada’s Bill C-22 Draws Global Tech Backlash Over Surveillance Demands
In this issue: Canada’s Bill C-22 Draws Global Tech Backlash Over Surveillance Demands Microsoft’s Email System Exploited for Months in Phishing Campaign Texas AG Sues Meta Over WhatsApp Encryption Claims — But Experts Are Skeptical AI-Generated npm Malware Targets Claude Users, Exposes Itself With Rookie Mistake 7-Eleven Data Breach Exposes 185,000 Customers’ Personal Information GPG Email Forwarding Returns, Because Plaintext Was Apparently a Bad Idea In this issue: Canada’s Bill C-22 Draws Global Tech Backlash Over Surveillance Demands Microsoft’s Email System Exploited for Months in Phishing Campaign Texas AG Sues Meta Over WhatsApp Encryption Claims — But Experts Are Skeptical AI-Generated npm Malware Targets Claude Users, Exposes Itself With Rookie Mistake 7-Eleven Data Breach Exposes 185,000 Customers’ Personal Information GPG Email Forwarding Returns, Because Plaintext Was Apparently a Bad Idea
-
-2
#AxisOfEasy 451: Ontario Police Secretly Used Israeli Spyware, Watchdog Finds
In this issue: Ontario Police Secretly Used Israeli Spyware, Watchdog Finds Microsoft Dismantles Fox Tempest, a Ransomware-Enabling Code-Signing Operation Canada Promotes VPNs While Passing a Law to Kill Them GitHub Breached: 4,000 Private Repos Stolen via Poisoned VS Code Extension CISA Contractor Exposes Federal Cloud Credentials on Public GitHub for Six Months In this issue: Ontario Police Secretly Used Israeli Spyware, Watchdog Finds Microsoft Dismantles Fox Tempest, a Ransomware-Enabling Code-Signing Operation Canada Promotes VPNs While Passing a Law to Kill Them GitHub Breached: 4,000 Private Repos Stolen via Poisoned VS Code Extension CISA Contractor Exposes Federal Cloud Credentials on Public GitHub for Six Months
-
-3
#AxisOfEasy 450: Foxconn Hit by Nitrogen Ransomware, 8 TB of Client Data Stolen
https://youtu.be/PXQltgWpBok In this issue: Bill C-22 Outcry Grows LouderFoxconn Hit by Nitrogen Ransomware, 8 TB of Client Data Stolen ShinyHunters Goes Dark After Serbian Registry Suspends Clearnet Domain npm Worm Hits 518M-Download Packages with Self-Destructing Malware DHS Used a 1930 Customs Law to Unmask a Canadian Critic. The ACLU Is Fighting Back Fake Claude Code Installer Caught Stealing Developer Credentials https://youtu.be/PXQltgWpBok In this issue: Bill C-22 Outcry Grows LouderFoxconn Hit by Nitrogen Ransomware, 8 TB of Client Data Stolen ShinyHunters Goes Dark After Serbian Registry Suspends Clearnet Domain npm Worm Hits 518M-Download Packages with Self-Destructing Malware DHS Used a 1930 Customs Law to Unmask a Canadian Critic. The ACLU Is Fighting Back Fake Claude Code Installer Caught Stealing Developer Credentials
-
-4
#AxisOfEasy 449: Canada’s Parliament Is Filing Your Posts About Politicians
In this issue: Canada’s Parliament Is Filing Your Posts About Politicians Backdoor Found in Daemon Tools Targets Thousands of Windows Users Linux Kernel “CopyFail” Flaw Under Active Attack — Federal Patch Deadline Set Pro-Iranian Group DDoS Attack Cripples Ubuntu and Canonical During Critical Security Crisis Utah Becomes First U.S. State to Target VPNs in Age Verification Law In this issue: Canada’s Parliament Is Filing Your Posts About Politicians Backdoor Found in Daemon Tools Targets Thousands of Windows Users Linux Kernel “CopyFail” Flaw Under Active Attack — Federal Patch Deadline Set Pro-Iranian Group DDoS Attack Cripples Ubuntu and Canonical During Critical Security Crisis Utah Becomes First U.S. State to Target VPNs in Age Verification Law
-
-5
#AxisOfEasy 448: Toronto Police Bust Canada’s First SMS Blaster Cybercrime Operation
In this issue: Toronto Police Bust Canada’s First SMS Blaster Cybercrime Operation CrowdStrike Patches Critical LogScale Vulnerability Allowing Unauthenticated File Access Vercel Breach Traced to Roblox-Seeking “Patient Zero” at Context.ai North Korean Hackers Target 100+ Crypto Firms in Sophisticated Global Phishing Campaign ShinyHunters Leaks Data from Zara, 7-Eleven, and Udemy in Salesforce-Linked Campaign In this issue: Toronto Police Bust Canada’s First SMS Blaster Cybercrime Operation CrowdStrike Patches Critical LogScale Vulnerability Allowing Unauthenticated File Access Vercel Breach Traced to Roblox-Seeking “Patient Zero” at Context.ai North Korean Hackers Target 100+ Crypto Firms in Sophisticated Global Phishing Campaign ShinyHunters Leaks Data from Zara, 7-Eleven, and Udemy in Salesforce-Linked Campaign
-
-6
#AxisOfEasy 445: Project Glasswing: Industry Coalition Uses AI To Strengthen Cybersecurity
In this issue: Project Glasswing: Industry Coalition Uses AI to Strengthen Cybersecurity Alberta Bill 23 Targets Political Deepfakes, Expands Petition Limits LinkedIn Faces Legal Action Over Covert Browser Scans AI Agent Banned from Wikipedia Sparks Controversy Hack-for-Hire Campaign Targets Journalists and Officials in Middle East In this issue: Project Glasswing: Industry Coalition Uses AI to Strengthen Cybersecurity Alberta Bill 23 Targets Political Deepfakes, Expands Petition Limits LinkedIn Faces Legal Action Over Covert Browser Scans AI Agent Banned from Wikipedia Sparks Controversy Hack-for-Hire Campaign Targets Journalists and Officials in Middle East
-
-7
#AxisOfEasy 444: Age Verification Laws Reshape the Internet
In This Issue: Age Verification Laws Reshape the Internet Anthropic’s Claude Code Source Leaked Again Axios Supply Chain Attack Exposes Malicious NPM Dependency Copilot Injects Ads Into Pull Requests as AI’s Subsidy Era Ends Dutch Finance Ministry Cyberattack Disrupts Treasury Portal for 1,600 Public Institutions In This Issue: Age Verification Laws Reshape the Internet Anthropic’s Claude Code Source Leaked Again Axios Supply Chain Attack Exposes Malicious NPM Dependency Copilot Injects Ads Into Pull Requests as AI’s Subsidy Era Ends Dutch Finance Ministry Cyberattack Disrupts Treasury Portal for 1,600 Public Institutions
-
-8
#AxisOfEasy 443: Apple Becomes The UK Government’s Favorite Compliance Officer
In this issue: Apple Becomes the UK Government’s Favorite Compliance Officer easyDNS releases MCP server and skills for AI agents The Petabyte Pivot: Why Your Anime Habits are Now a Telco Tragedy DarkSword iOS Exploit Leaked, Threatening Older Apple Devices Critical PyPI Attack Compromises litellm 1.82.7–1.82.8 AI Agents Bypass Security Controls, Raise Insider Threat Concerns […]
-
-9
#AxisOfEasy 442: Canada Introduces Bill C-22 For Mandatory Metadata Retention
https://www.youtube.com/watch?v=Ur8cyfPx77M   In this issue: Canada Introduces Bill C-22 For Mandatory Metadata Retention Meta is Ending Instagram Direct Message End-to-End Encryption Invisible Unicode Supply-Chain Attack Hits GitHub Ecosystem Claudy Day: Claude AI Vulnerability Risks Data Theft iPhone Exploit Kit DarkSword Steals Data Worldwide FBI Confirms Purchase of Americans’ Location Data https://www.youtube.com/watch?v=Ur8cyfPx77M   In this issue: […]
-
-10
#AxisOfEasy 441: Canada Allows TikTok To Continue Operations With New Safeguards
Canada banned TikTok over national security risks. Then Carney started courting Beijing. Now TikTok's back. Make it make sense.
-
-11
#AxisofEasy 440: Meta Ray-Ban Glasses Footage Sent to Human Reviewers
In this issue: Meta Ray-Ban Glasses Footage Sent to Human Reviewers Israel Allegedly Hacks Iranian Prayer App to Push Wartime Messages Canadian Tire Data Breach Hits Millions FULCRUMSEC Claims Major LexisNexis Data Breach California Mandates Device-Level Age Tracking The Government Wants an AI With No Guardrails. What Could Go Wrong? In this issue: Meta Ray-Ban […]
-
-12
#AxisofEasy 439: OpenAI Suppressed Warnings On Mass Shooter Months Before Spree
The Tumbler Ridge shooter was flagged by OpenAI, had an expired firearms license, a documented mental health history, and repeated RCMP visits to the home. Eight people are dead. So why did every system designed to prevent this fail — and who decided to look the other way?
-
-13
#AxisOfEasy 438: Apple Patches Actively Exploited Zero-Day Across Devices
In this issue: Apple Patches Actively Exploited Zero-Day Across Devices Montreal Fake ID Lab Busted, Thousands of Identities Stolen Microsoft 365 Copilot Bug Summarizes Confidential Emails U.S. Law Firm Sues Lenovo Over Data Transfers to China
-
-14
#AxisofEasy 437: Discord Is Asking For Your ID
In this issue: Discord Is Asking For Your ID. The Backlash Is About More Than Privacy Hackers Hijack Physician’s Paycheck in Social Engineering Payroll Scam Substack Confirms Data Breach Exposing User Contact Information Congress Targets Kids’ Social Media Use with New Federal Rules dYdX npm and PyPI Packages Compromised in Third Major Attack ZeroDayRAT: New Commercial Spyware Threatens Android and iOS Devices In this issue: Discord Is Asking For Your ID. The Backlash Is About More Than Privacy Hackers Hijack Physician’s Paycheck in Social Engineering Payroll Scam Substack Confirms Data Breach Exposing User Contact Information Congress Targets Kids’ Social Media Use with New Federal Rules dYdX npm and PyPI Packages Compromised in Third Major Attack ZeroDayRAT: New Commercial Spyware Threatens Android and iOS Devices
-
-15
AxisofEasy 436: OpenClaw And Moltbook: Inside The Rise Of Autonomous AI Agents
In this issue: OpenClaw and Moltbook: Inside the Rise of Autonomous AI Agents State Hackers Hijack Notepad++ Updates in Months-Long Supply-Chain Attack SystemBC Malware Hits 10,000+ Global IPs, Targets Government Sites Eight Minutes to Admin: AI-Assisted Cloud Attack Hits AWS Critical Looker Vulnerabilities Exposed by Tenable In this issue: OpenClaw and Moltbook: Inside the Rise of Autonomous AI Agents State Hackers Hijack Notepad++ Updates in Months-Long Supply-Chain Attack SystemBC Malware Hits 10,000+ Global IPs, Targets Government Sites Eight Minutes to Admin: AI-Assisted Cloud Attack Hits AWS Critical Looker Vulnerabilities Exposed by Tenable
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
No description available.
HOSTED BY
Mark E. Jeftovic
CATEGORIES
Loading similar podcasts...