All Episodes

Security Stuff — 235 episodes

#
Title
1

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

2

Chipmaker Patch Tuesday: Intel and AMD Patch 70 Vulnerabilities

3

Fortinet, Ivanti Patch Critical Vulnerabilities

4

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

5

716,000 Impacted by OpenLoop Health Data Breach

6

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

7

Webinar Today: ROI for Cyber-Physical Security Programs

8

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

9

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

10

Most Remediation Programs Never Confirm the Fix Actually Worked

11

[Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It)

12

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

13

Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

14

China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm

15

LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly

16

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

17

Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?

18

Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

19

SAP Patches Critical S/4HANA, Commerce Vulnerabilities

20

Apple Patches Dozens of Vulnerabilities in macOS, iOS

21

West Pharmaceutical Services Hit by Disruptive Ransomware Attack

22

Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform

23

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware

24

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

25

Why Agentic AI Is Security's Next Blind Spot

26

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

27

Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help

28

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

29

20 Leaders Who Built the CISO Era: 2 Decades of Change

30

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested

31

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks

32

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools

33

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

34

SailPoint Discloses GitHub Repository Hack

35

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring

36

Skoda Data Breach Hits Online Shop Customers

37

Google Detects First AI-Generated Zero-Day Exploit

38

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

39

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

40

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

41

Cyber Espionage Group Targets Aviation Firms to Steal Map Data

42

Hackers Use AI for Exploit Development, Attack Automation

43

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

44

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

45

Ransomware Group Takes Credit for Trellix Hack

46

‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

47

Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom

48

AI Firm Braintrust Prompts API Key Rotation After Data Breach

49

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants

50

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

51

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk

52

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

53

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

54

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

55

Karakurt Ransomware Negotiator Sentenced to Prison

56

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server

57

Critical Remote Code Execution Vulnerability Patched in Android

58

Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft

59

Hacker Conversations: Joey Melo on Hacking AI

60

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

61

ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

62

We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

63

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

64

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

65

How the Story of a USB Penetration Test Went Viral

66

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats

67

Over 40,000 Servers Compromised in Ongoing cPanel Exploitation

68

OpenAI Rolls Out Advanced Security for ChatGPT Accounts

69

Exploitation of ‘Copy Fail’ Linux Vulnerability Begins

70

DigiCert Revokes Certificates After Support Portal Hack

71

Cybersecurity M&A Roundup: 33 Deals Announced in April 2026

72

Trellix Source Code Repository Breached

73

Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks

74

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

75

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

76

2026: The Year of AI-Assisted Attacks

77

⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

78

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

79

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

80

How Dark Reading Lifted Off the Launchpad in 2006

81

Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

82

Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability

83

US Military Reaches Deals With 7 Tech Companies to Use Their AI on Classified Systems

84

New Bluekit Phishing Kit Features AI Assistant

85

1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom

86

FBI Warns of Surge in Hacker-Enabled Cargo Theft

87

Hugging Face, ClawHub Abused for Malware Distribution

88

Cisco Releases Open Source Tool for AI Model Provenance

89

Sophisticated Deep#Door Backdoor Enables Espionage, Disruption

90

Two US Security Experts Sentenced to Prison for Helping Ransomware Gang

91

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

92

Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks

93

Top Five Sales Challenges Costing MSPs Cybersecurity Revenue

94

20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage

95

Name That Toon: Mark of (Security) Progress

96

Sandhills Medical Says Ransomware Breach Affects 170,000

97

‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover

98

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

99

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

100

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

101

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

102

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

103

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

104

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

105

Oracle Red Bull Racing Team Revs Up Automation to Boost Security

106

Chrome 147, Firefox 150 Security Updates Rolling Out

107

38 Vulnerabilities Found in OpenEMR Medical Software

108

Iranian Cyber Group Handala Targets US Troops in Bahrain

109

Checkmarx Confirms Data Stolen in Supply Chain Attack

110

Hundreds of Internet-Facing VNC Servers Expose ICS/OT

111

Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure

112

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

113

Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

114

What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)

115

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

116

Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities

117

Alleged Chinese State Hacker Extradited to US

118

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi

119

Spectrum Security Emerges From Stealth Mode With $19 Million

120

Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials

121

No Patch for New PhantomRPC Privilege Escalation Technique in Windows

122

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety

123

Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable

124

Dozens of Open VSX Extension Clones Linked to GlassWorm Malware

125

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

126

After Mythos: New Playbooks For a Zero-Window Era

127

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

128

Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About

129

Firefox Vulnerability Allows Tor User Fingerprinting

130

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

131

Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access

132

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware

133

Energy and Water Management Firm Itron Hacked

134

Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

135

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

136

Incomplete Windows Patch Opens Door to Zero-Click Attacks

137

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

138

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

139

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

140

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

141

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

142

Parsing Agentic Offensive Security's Existential Threat

143

20-Year-Old Malware Rewrites History of Cyber Sabotage

144

Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation

145

Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

146

Ransomware Hits Automotive Data Expert Autovista

147

Cisco Patches Critical Vulnerabilities in Webex, ISE

148

NIST Prioritizes NVD Enrichment for CVEs in CISA KEV, Critical Software

149

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest

150

Splunk Enterprise Update Patches Code Execution Vulnerability

151

Artemis Emerges From Stealth With $70 Million in Funding

152

Data Breach at Tennessee Hospital Affects 337,000

153

Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu

154

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

155

Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

156

[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment

157

ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories

158

Fortinet Patches Critical FortiSandbox Vulnerabilities

159

Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections

160

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks

161

Two Vulnerabilities Patched in Ivanti Neurons for ITSM

162

Mirax RAT Targeting Android Users in Europe

163

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

164

Microsoft, Salesforce Patch AI Agent Data Leak Flaws

165

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities

166

Nightclub Giant RCI Hospitality Reports Data Breach

167

Google Adds Rust DNS Parser to Pixel Phones for Better Security

168

Triad Nexus Evades Sanctions to Fuel Cybercrime

169

SAP Patches Critical ABAP Vulnerability

170

Europe’s Largest Gym Chain Says Data Breach Impacts 1 Million Members

171

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

172

Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)

173

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

174

Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users

175

Fake Claude Website Distributes PlugX RAT

176

CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads

177

International Operation Targets Multimillion-Dollar Crypto Theft Schemes

178

OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack

179

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware

180

Your MTTD Looks Great. Your Post-Alert Gap Doesn't

181

Your Next Breach Will Look Like Business as Usual

182

Hims Breach Exposes the Most Sensitive Kinds of PHI

183

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

184

Google Rolls Out Cookie Theft Protections in Chrome

185

Critical Marimo Flaw Exploited Hours After Public Disclosure

186

MITRE Releases Fight Fraud Framework

187

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

188

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

189

Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

190

Juniper Networks Patches Dozens of Junos OS Vulnerabilities

191

In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack

192

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

193

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

194

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

195

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

196

Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong Hands?

197

Industrial Controllers Still Vulnerable As Conflicts Move to Cyber

198

Orange Business Reimagines Enterprise Voice Communications With Trust and AI

199

FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats

200

300,000 People Impacted by Eurail Data Breach

201

Adobe Reader Zero-Day Exploited for Months: Researcher

202

Google Warns of New Campaign Targeting BPOs to Steal Corporate Data

203

The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security

204

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

205

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

206

Can we Trust AI? No – But Eventually We Must

207

Apple Intelligence AI Guardrails Bypassed in New Attack

208

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

209

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

210

The Hidden Security Risks of Shadow AI in Enterprises

211

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

212

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

213

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking

214

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover

215

Evasive Masjesu DDoS Botnet Targets IoT Devices

216

Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption

217

FBI: Cybercrime Losses Neared $21 Billion in 2025

218

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

219

Data Leakage Vulnerability Patched in OpenSSL

220

Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long

221

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

222

N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust

223

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

224

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

225

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

226

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

227

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

228

Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs

229

Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams

230

Niobium Introduces The Fog

231

Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus

232

Fraud Rockets Higher in Mobile-First Latin America

233

AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties

234

Threat Actors Get Crafty With Emojis to Escape Detection

235

Russia's Forest Blizzard Nabs Rafts of Logins Via SOHO Routers