PODCAST · technology

Security Stuff

Publisher-supplied feed metadata · PodParley refreshed Jun 13, 2026 · Source feed

  1. 391

    ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

    Cybersecurity researchers at LayerX have discovered a new vulnerability in AI-powered browsers they're calling "BioShocking," which tricks AI agents into stealing user credentials by convincing them they're playing a game. The researchers created a puzzle webpage that manipulated six different AI browsers—including ChatGPT Atlas, Claude Chrome, and others—into abandoning their safety guardrails by teaching them that incorrect actions were acceptable within the game's context, ultimately leading them to exfiltrate sensitive data like SSH login credentials. While OpenAI has patched the issue, other vendors either failed to fix it or didn't respond to the security report at all.

  2. 390

    Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

    Cisco has confirmed that a recently patched vulnerability in its Unified Communications Manager is now being actively exploited in the wild. The security flaw, which affects appliances with the WebDialer service enabled, could allow attackers to drop malicious files on the system and potentially gain root access through server-side request forgery attacks. Cisco is urging customers to immediately upgrade to the patched versions released in June, following reports of exploitation from security researchers.

  3. 389

    Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm

    The Trump administration has lifted restrictions on Anthropic's Claude chatbot models after a weekslong ban triggered by cybersecurity concerns. The models were blocked in mid-June after Amazon security researchers discovered a way to bypass safeguards on Claude Fable 5 that could enable exploitation of software vulnerabilities. Anthropic's most powerful model, Mythos 5, is now accessible only to government-approved U.S. organizations, while Fable 5 has returned to wider availability, following Trump's executive order establishing a framework for vetting advanced AI systems before public release.

  4. 388

    FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

    A massive credential-harvesting campaign called FortiBleed, which has targeted over 430,000 FortiGate firewalls worldwide and compromised an estimated 110 million credentials, has now been directly linked to ransomware attacks. Security researchers discovered that stolen credentials from the operation are being used to deploy INC Ransom and Lynx ransomware, with at least 12 organizations suffering encryption attacks and hundreds of endpoints locked down. An operational security mistake by the attackers revealed that the same operator manages both ransomware families, proving that this credential theft operation is actively feeding into the ransomware ecosystem.

  5. 387

    How to Conduct a Successful Audit of AI-Driven Software Development

    One in five organizations has experienced a serious security incident directly tied to AI-generated code, prompting security leaders to conduct comprehensive audits of their AI-assisted software development processes. The article outlines a framework for CISOs to assess risks by tracking who uses AI tools, evaluating developer capabilities to catch vulnerabilities, and mapping specific tools to code outputs. Key recommendations include creating risk scores for developers, establishing governance policies for approved AI tools, and implementing what's called time travel auditing to quickly isolate and fix code linked to compromised AI models.

  6. 386

    New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

    Security researchers are being targeted by a new malware campaign called ChocoPoC RAT that's distributed through fake proof-of-concept exploit repositories on GitHub. The attackers are specifically going after vulnerability researchers who regularly download and test exploit code, using these poisoned repositories to deliver remote access trojans to their systems. This social engineering tactic exploits the trust researchers place in the security community when sharing and testing new vulnerability demonstrations.

  7. 385

    FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

    Researchers have connected credential theft exploiting the FortiBleed vulnerability to active ransomware campaigns by the INC and Lynx groups. The attacks leverage stolen credentials from vulnerable Fortinet devices to gain initial access to corporate networks. Security experts are urging organizations to patch affected systems and review access logs for signs of compromise linked to these ongoing ransomware operations.

  8. 384

    AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

    Researchers have demonstrated how an AI agent can exploit a remote code execution vulnerability in Langflow to automate a complete database ransomware attack. The proof-of-concept shows AI systems can now independently chain together exploits, from initial compromise through lateral movement to data encryption, raising new concerns about AI-powered autonomous cyber attacks. This development highlights the urgent need for organizations to implement robust security measures specifically designed to defend against AI-driven threats that operate at machine speed.

  9. 383

    Identity Lifecycle Management Wasn't Built for AI Agents

    Identity lifecycle management systems were designed for human users, but the rise of AI agents is exposing critical gaps in how organizations manage digital identities. These autonomous systems operate at machine speed and scale, creating challenges that traditional identity management frameworks weren't built to handle. Organizations now face the urgent task of adapting their security infrastructure to govern AI agents that can make decisions and take actions independently, requiring new approaches to authentication, authorization, and access control.

  10. 382

    ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

    Security researchers have discovered that the ToddyCat threat group is using malware called Umbrij that exploits OAuth authentication to access Gmail accounts through Google's API. This technique allows attackers to bypass traditional security measures by leveraging legitimate Google services, making the malicious activity harder to detect. The discovery highlights a sophisticated evolution in cyberattack methods, where threat actors are increasingly abusing trusted authentication protocols to maintain persistent access to targeted email accounts.

  11. 381

    Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

    IBM and Red Hat are committing five billion dollars and 20,000 engineers to Project Lightwell, a new service that patches open-source software vulnerabilities for enterprise customers who can't risk disrupting production systems. The move comes after Anthropic's AI-powered Mythos model discovered vulnerabilities at an unprecedented rate through Project Glasswing, finding over 1,500 bugs across hundreds of projects but with only 6 percent patched so far, as overwhelmed maintainers struggle to keep up with AI-speed discovery. IBM's service will backport fixes to specific software versions without requiring full upgrades, though the company has notably not confirmed whether its own watsonx AI platform plays any role in the initiative.

  12. 380

    Massive Password Spray Campaign Targeting Azure CLI

    Cybersecurity firm Huntress is warning about a massive password spray campaign targeting Microsoft 365 environments through the Azure CLI. Over a nine-day period in June, attackers launched more than 81 million login attempts, successfully compromising 78 user accounts across 64 organizations by exploiting a weakness in the OAuth ROPC authentication flow that can bypass multi-factor authentication if not properly configured. The attacks, which originated from infrastructure linked to a Chinese internet hosting provider, highlight the critical importance of implementing MFA policies that cover all authentication flows and cloud applications.

  13. 379

    Dawnguard Raises $6.3 Million for Security Architecture Automation Platform

    Amsterdam-based cybersecurity startup Dawnguard has raised a total of six point three million dollars in pre-seed funding and publicly launched its security architecture automation platform. The platform helps organizations design and build secure cloud systems from the ground up, generating production-ready infrastructure-as-code and continuously validating deployments to prevent security drift. The company plans to use the funding to accelerate product development, particularly in AI-driven architecture intelligence, while expanding its international presence.

  14. 378

    Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari

    Apple has released security updates addressing 37 vulnerabilities across iOS, iPadOS, macOS Tahoe, and Safari, with 26 of those flaws specifically affecting WebKit browser components. The WebKit bugs could allow malicious websites to steal data, crash Safari, corrupt memory, and access sensitive information, while interestingly, at least four of the security issues were discovered using AI tools from Anthropic and OpenAI. Although Apple says none of the vulnerabilities are currently being exploited in the wild, users are urged to update immediately since threat actors are known to quickly weaponize newly disclosed bugs in Apple products.

  15. 377

    Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

    Frontier AI is transforming vulnerability management in cybersecurity, but enterprises need to cut through vendor hype by asking tough questions about their AI capabilities. Security expert Joshua Goldfarb recommends that companies probe vendors on six key areas: which AI model providers and specific models they're actually using, the level of automation they've truly achieved, how they're providing proper context to AI systems, what measurable results they're getting, and how they're vetting findings to avoid false positives. The bottom line is that vendors should be able to back up their Frontier AI claims with concrete details and metrics, or enterprises should be skeptical of their promises.

  16. 376

    Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

    Citrix has released security updates for NetScaler ADC and NetScaler Gateway that fix six vulnerabilities, including the newly discovered HTTP/2 Bomb denial-of-service flaw. The most concerning issue is CVE-2026-8451, described as the latest in the CitrixBleed series, which could allow attackers to leak sensitive data from vulnerable appliances and potentially achieve full device compromise. Organizations with self-managed NetScaler deployments are strongly urged to apply these patches immediately, particularly those with SAML IDP configurations enabled.

  17. 375

    Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities

    Adobe has released critical security patches for ColdFusion and Campaign Classic, addressing multiple vulnerabilities with maximum severity ratings of ten out of ten. The Campaign Classic update fixes an authorization flaw that could allow arbitrary code execution, while ColdFusion patches resolve eleven security defects including issues with file uploads, input validation, and path traversal that could also lead to code execution. While Adobe says there are no known public exploits yet, the company has given these updates top priority and is urging users to apply the patches immediately.

  18. 374

    Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

    Cybersecurity researchers have identified a new threat called "phantom squatting," where attackers exploit AI-generated hallucinated domain names to launch phishing campaigns and distribute malware. When AI models like ChatGPT fabricate non-existent websites or resources in their responses, malicious actors can register these hallucinated domains and wait for unsuspecting users who trust the AI's recommendations to visit them. This emerging attack vector highlights a novel intersection between AI's tendency to generate false information and traditional cybersquatting tactics.

  19. 373

    Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

    Microsoft has announced it's accelerating its transition to post-quantum cryptography, moving up its timeline to 2029. The shift is driven by growing concerns that quantum computers could eventually break current encryption methods, prompting the tech giant to implement quantum-resistant security measures earlier than originally planned. This move signals increasing urgency across the tech industry to protect data against future quantum computing threats.

  20. 372

    2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

    A new cybersecurity assessment warns of a growing disconnect between organizational awareness of threats and actual resilience capabilities heading into 2026. The report highlights emerging challenges including AI-discovered software vulnerabilities and the need to secure autonomous AI systems, while emphasizing that understanding attacker tools and techniques remains critical to preventing breaches. Organizations are being urged to close this awareness-resilience gap through improved governance, machine-speed response capabilities, and hands-on security training.

  21. 371

    Safe Events Start With Threat Intel and Digital Security

    Major events like the FIFA World Cup and the US sesquicentennial celebration face complex security challenges that begin long before attendees arrive at venues. Threat actors start preparing months in advance by registering fake domains, collecting exposed credentials, and monitoring public schedules across social media and dark web forums, creating digital footprints that can signal physical threats. According to ZeroFox security expert Olga Polishchuk, the most effective event security strategies integrate threat intelligence and digital monitoring early in the planning process, extending protection beyond venue perimeters to hotels, transportation hubs, and other gathering points where high-profile individuals and attendees are vulnerable.

  22. 370

    Critical SimpleHelp Vulnerability Exploited for Malware Delivery

    A critical authentication bypass vulnerability in SimpleHelp remote management software, scoring a perfect 10 out of 10 on the severity scale, has been actively exploited to deliver malware onto managed systems. The flaw, which fails to verify cryptographic signatures when OpenID Connect authentication is configured, allowed attackers to deploy TaskWeaver loader and Djinn Stealer, which specifically targets developer credentials including cloud keys, SSH access, and even AI development tool credentials. The vulnerability was patched in late May, and CISA has now added it to its catalog of actively exploited vulnerabilities, giving federal agencies just three days to update their systems.

  23. 369

    Nissan Employee Data Breached in Oracle PeopleSoft Hack

    Nissan has confirmed a data breach affecting current and former employees across North and South America after hackers exploited a zero-day vulnerability in Oracle PeopleSoft software. The breach, believed to be orchestrated by the ShinyHunters extortion group, may have exposed sensitive employee data including social security numbers, banking information, and tax records. The attack was part of a wider campaign targeting over 100 organizations, with the education sector being hit particularly hard.

  24. 368

    The AI Token Costs That Can Break Cybersecurity

    As cybersecurity vendors race to embed AI into their platforms, they're shifting from predictable software licensing to volatile, consumption-based pricing that could catch security leaders off guard. The problem lies in how agentic AI works: unlike traditional machine learning, these autonomous systems can burn through millions of tokens in a single complex investigation, potentially costing an entire quarter's cybersecurity budget during a major incident. This shift is forcing security teams to make dangerous compromises, like throttling investigations mid-incident or disabling automated workflows to preserve monthly token credits, creating the same kind of blind spots that once plagued the SIEM industry.

  25. 367

    Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

    Threat actors have begun actively exploiting a critical vulnerability in Oracle E-Business Suite's Payments component that carries a severity score of 9.8 out of 10. The flaw, which Oracle patched in late May, allows unauthenticated attackers to completely take over the Payments system via HTTP, and security firm Defused detected the first exploitation attempts over the weekend through its honeypots. Organizations are strongly urged to apply Oracle's patches immediately, as the company's enterprise products have a history of being targeted in major attack campaigns, including recent breaches by ransomware groups affecting hundreds of companies.

  26. 366

    Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History

    The Supreme Court ruled 6-3 that constitutional privacy protections extend to cellphone location data, even when users voluntarily opt into services like Google's location history. Justice Kagan wrote that people shouldn't be viewed as giving up privacy rights "just by doing the ordinary things cellphone users do." The case involved a bank robber identified through a geofence warrant that captured location data from all phones near the crime scene, with the court sending it back to lower courts to determine if that specific search violated Fourth Amendment protections against unreasonable searches.

  27. 365

    Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat

    Chris Thompson went from hacking video games as a teenager to founding IBM's first dedicated red team and leading X-Force Red, before recently launching RemoteThreat to use AI against malicious actors. His unconventional path included convincing major companies like EA to hire him at eighteen for security work, and he built his career on proving skills rather than academic credentials — a philosophy he maintains when hiring, seeking domain expertise and collaboration over college degrees. Thompson, who has ADHD, believes neurodivergence is common among elite hackers and serves as a "superpower" in the field, contributing to the deep focus and different thinking style that makes great security researchers.

  28. 364

    Aflac Japan Data Breach Impacts 4.38 Million

    Aflac Life Insurance Japan has disclosed a major data breach affecting 4.38 million customers after hackers accessed their systems between June 15th and 25th. The stolen information includes names, addresses, phone numbers, dates of birth, and insurance account details, with banking information for about 230,000 people also compromised, though credit card data remained secure. The incident has disrupted at least five company services, with no estimated timeline for restoration, and only affects Aflac's Japan operations, not its US business.

  29. 363

    Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

    Adversa AI has discovered a major vulnerability in open source AI coding agents, dubbed GuardFall, that exploits decades-old Bash shell tricks to bypass security guards and execute malicious commands. Of eleven popular agents tested, only one—Continue—was able to block all the attack techniques, which use methods like quote removal and spacing manipulation to disguise destructive commands that the AI agent then executes with the developer's full authority. This creates a significant supply chain risk, especially in CI pipelines where auto-approval modes are common, potentially allowing attackers to exfiltrate credentials or wipe development environments through poisoned files in malicious repositories.

  30. 362

    BlueHammer Vulnerability Exploited in Ransomware Attacks

    The cybersecurity agency CISA has confirmed that the BlueHammer vulnerability in Microsoft Defender is now being actively exploited in ransomware attacks. The flaw, tracked as CVE-2026-33825, was publicly disclosed by a disgruntled researcher in April before Microsoft had released patches, and was initially exploited as a zero-day for privilege escalation. While CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, the specific ransomware group using the exploit remains unknown, and the agency's update has raised questions about how useful these notifications are for security defenders.

  31. 361

    Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

    Progress Software has disclosed a critical vulnerability in its Kemp LoadMaster product that could allow attackers to execute commands with root privileges without authentication. The pre-authentication flaw represents a serious security risk, as it would give unauthorized users complete control over affected systems. Organizations using Kemp LoadMaster are urged to patch immediately to prevent potential exploitation.

  32. 360

    New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

    Researchers have discovered a new attack method called "BioShocking" that exploits vulnerabilities in AI-powered web browsers to steal user credentials. The attack takes advantage of how AI agents interact with websites, potentially tricking them into revealing sensitive login information. Security experts warn that as AI-powered browsing tools become more common, organizations need to implement new safeguards against these emerging threats that specifically target artificial intelligence systems rather than traditional software.

  33. 359

    AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

    Researchers have discovered critical vulnerabilities in Apple's AirDrop and Android's Quick Share features that allow nearby attackers to crash devices and bypass security checks. The flaws affect the file-sharing systems that millions of users rely on daily, potentially enabling malicious actors within wireless range to disrupt device functionality. Both Apple and Google will need to issue patches to address these proximity-based attack vectors.

  34. 358

    Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

    Cybercriminals are actively exploiting a vulnerability in SimpleHelp remote access software, identified as CVE-2026-48558, to deploy malicious tools including TaskWeaver and the Djinn Stealer credential-stealing malware. The attacks demonstrate how threat actors are quickly weaponizing newly discovered software vulnerabilities to gain unauthorized access to systems and steal sensitive data. Organizations using SimpleHelp are urged to patch immediately and monitor for signs of compromise.

  35. 357

    What the Numbers Say About FIFA 2026 Cyber Risk

    The 2026 FIFA World Cup presents significant cybersecurity challenges, with major sporting events historically attracting increased cyber threats from hackers seeking to exploit massive data flows and interconnected systems. Organizers and security teams are analyzing threat patterns from previous tournaments to prepare defenses against potential attacks on ticketing systems, broadcasting infrastructure, and financial transactions. The event's scale, spanning multiple North American cities, creates an expanded attack surface that requires coordinated international cybersecurity efforts to protect against ransomware, DDoS attacks, and data breaches.

  36. 356

    AI-Generated Workflows Are a Silent Security Disaster

    AI-generated workflows are creating a significant security problem in organizations. These automated systems function effectively but lack transparency, meaning team members can't fully understand how they work or identify potential vulnerabilities. The issue is particularly concerning because the automation operates silently in the background, making security risks harder to detect and address before they become serious breaches.

  37. 355

    OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI

    OpenAI has launched a limited preview of its GPT-5.6 model lineup, with Sol being marketed as its most advanced cybersecurity AI, specifically optimized for defensive security tasks like vulnerability identification and patch development. Following consultation with the US government, the tiered release includes Sol for high-intensity reasoning, Terra for everyday workloads at half the cost of previous models, and Luna as the fastest, most affordable option. The restricted rollout to trusted partners is temporary as OpenAI works with federal authorities to address national security concerns, though the company has pushed back against making government pre-clearance a permanent requirement, arguing it delays essential defensive tools from reaching the broader cybersecurity community.

  38. 354

    US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve

    The US government is offering up to $10 million for information on two Russian state-sponsored hacking groups that have been targeting government officials, military personnel, journalists, and political figures through sophisticated phishing campaigns on messaging apps like Signal and WhatsApp. The hackers, tracked as UNC5792 and UNC4221 and linked to Russian intelligence services, pose as app support accounts to steal verification codes and are now also requesting Backup Recovery Keys, which can grant them access to victims' accounts even after password changes. CISA and the FBI warn that compromised users must generate new recovery keys to fully secure their accounts, though hackers may have already accessed historical conversations.

  39. 353

    OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

    OpenAI and Anthropic are releasing their newest AI models to limited, Trump administration-approved customers following unprecedented government cybersecurity reviews. OpenAI's GPT-5.6 Sol will be accessible only to approved partners, while Anthropic received clearance to deploy its Mythos 5 model to select cyber defenders after earlier being blocked by export controls. The government scrutiny stems from concerns that these powerful AI models could find software vulnerabilities that hackers might exploit, though critics warn the unpredictable interventions could hamper US tech companies as they compete globally and consider going public.

  40. 352

    ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

    JFrog has released technical details and a proof of concept for DirtyClone, a high-severity Linux kernel vulnerability that allows local users to gain root privileges. The flaw, tracked as CVE-2026-43503 with a score of 8.8, is a variant of similar memory corruption bugs and affects popular distributions like Debian, Fedora, and Ubuntu that enable unprivileged user namespaces. The vulnerability poses particular risks to multi-tenant cloud environments and Kubernetes clusters, and systems require Linux kernel version v7.1-rc5 with the complete chain of fixes to be fully protected.

  41. 351

    Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack

    The National Association of Insurance Commissioners has confirmed it was hit in the recent Oracle PeopleSoft zero-day attack campaign orchestrated by the ShinyHunters cybercrime group. The breach compromised publicly available financial reporting data and technical information, though NAIC says no personal or payment information was stolen, and state insurance department systems were not affected. ShinyHunters initially claimed to have stolen over 3 terabytes of data from NAIC but later revised its claims, blaming an "AI-generated misinterpretation" for the inflated figures.

  42. 350

    Chinese Framework Powers 200,000 Scam Sites

    Cybersecurity researchers at Infoblox have discovered over 200,000 scam websites built using templates powered by Uni-App, a legitimate Chinese open-source development framework. The fraudulent sites range from fake cryptocurrency exchanges to phishing operations and so-called pig-butchering scams, including the notorious RainbowEx platform that defrauded thousands in Argentina. While the framework's maker DCloud isn't involved in the fraud, threat actors have been selling scam templates since 2022, with activity surging to 15,000 new sites monthly after the RainbowEx scandal gained media attention in late 2024.

  43. 349

    OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

    OpenAI has unveiled a preview of GPT-5.6 Sol, a new model that will feature restricted access and enhanced cybersecurity protections. The limited rollout suggests OpenAI is taking a cautious approach with this latest iteration, prioritizing security safeguards before a wider release. The announcement comes as AI companies face increasing pressure to address potential security vulnerabilities in their models.

  44. 348

    New Enterprise-Ready MCP Specification Brings New Security Challenges

    The Model Context Protocol, introduced by Anthropic in 2024, is transitioning to an enterprise-ready version on July 28, 2026, giving companies a 12-month window to prepare. While the new stateless protocol eliminates some vulnerabilities like session hijacking, security firm Akamai warns it introduces new attack surfaces including workflow hijacking risks, potential data leakage through HTTP headers, and denial-of-service vectors from long-running tasks. The shift fundamentally moves security responsibilities from the protocol layer to individual developers and platform operators, requiring in-house teams to carefully implement and secure their MCP servers over the next year.

  45. 347

    First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

    Cybersecurity officials have confirmed the first-ever exploitation of PTC Windchill, a widely-used product lifecycle management platform, in real-world attacks. The vulnerability, tracked as CVE-2026-12569, allows remote attackers to execute arbitrary code without authentication, and hackers have been using it to deploy webshells for remote command execution and data exfiltration. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 28, with particular concern for industrial and manufacturing sectors including aerospace, defense, and automotive companies that rely heavily on Windchill.

  46. 346

    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

    The Russian state-sponsored hacking group Turla, linked to Russia's Federal Security Service, has been deploying a new backdoor called StockStay against Ukrainian government and military targets since 2022. The espionage tool, which masquerades as legitimate software like PDF viewers or calculators, supports extensive capabilities including file exfiltration, screen capture, and system information harvesting. Recent attacks have used phishing emails and malicious RDP configuration files, with one November campaign exploiting a WinRAR vulnerability to compromise twenty Ukraine-based targets.

  47. 345

    $3 Million Reportedly Stolen in Polymarket Hack

    Cryptocurrency-based prediction market Polymarket has promised to fully refund users after hackers stole roughly 3 million dollars through a compromised third-party vendor that injected malicious code into the platform's frontend. According to blockchain security firm PeckShield, the attackers made off with around 3 million dollars worth of pUSD, Polymarket's trading currency, from at least 11 victims through a phishing campaign before converting the stolen funds into Ethereum. Polymarket says it has contained the breach and removed the malicious dependency, though the company hasn't disclosed exactly how many users were affected or confirmed the total amount stolen.

  48. 344

    Linux Foundation Unveils New Open Source Security Project Akrites

    The Linux Foundation has launched Akrites, a new open source security initiative that establishes a shared Security Incident Response Team to coordinate vulnerability discovery, patching, and disclosure across the open source software ecosystem. Backed by major tech companies including Google, Microsoft, AWS, and OpenAI, the project aims to address a critical timing problem where AI-enabled attackers can rapidly reverse engineer vulnerabilities from public patches and exploit them before organizations can deploy fixes. Akrites will also act as a maintainer of last resort for abandoned projects, ensuring security patches can still be delivered even when original developers are no longer active.

  49. 343

    Nebulock Raises $25 Million for AI-Native Contextual Security

    Boston-based cybersecurity startup Nebulock has raised 25 million dollars in Series A funding, bringing its total funding to over 33 million dollars, with FirstMark leading the round. The company, which emerged from stealth a year ago, uses AI-powered autonomous threat hunting to track behavioral patterns across endpoints, cloud, identity, and network systems, creating what they call a "behavioral system of record" that can spot suspicious activities before they become breaches. The new funding will go toward expanding the platform's capabilities and hiring across engineering and go-to-market teams as the company aims to help security teams shift from reactive to proactive protection.

  50. 342

    Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

    Google has uncovered details about STOCKSTAY, a new backdoor being used by the Russian hacking group Turla in espionage campaigns targeting Ukraine. The malware represents an evolution in Turla's toolkit as the group continues its intelligence-gathering operations against Ukrainian entities. Google's disclosure provides security teams with fresh indicators to detect and defend against this latest threat from the well-established Russian cyber-espionage group.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

No description available.

HOSTED BY

David

CATEGORIES

Frequently Asked Questions

How many episodes does Security Stuff have?

Security Stuff currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Security Stuff about?

Security Stuff is a podcast covering topics in technology.

How often does Security Stuff release new episodes?

Security Stuff has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Security Stuff?

You can listen to Security Stuff on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Security Stuff?

Security Stuff is created and hosted by David.
URL copied to clipboard!