466 episodes
Hotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globally
2026/07/27 | 11 mins.Hotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again
Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike logins and even abusing Microsoft's device code flow to obtain OAuth tokens in ways MFA may not stop. Plus, an Illinois man received 76 months in prison for phishing into hundreds of women's Snapchat accounts to steal explicit content and run a for-profit account access scheme. Also: a sextortion email wave impersonates ShinyHunters using real breach references while making fake device-compromise claims; ransomware disrupted Japanese frozen food supplier Nichirei shipments, affecting KFC franchises; and Chick-fil-A disclosed a June credential-stuffing incident impacting 13,322 loyalty accounts, resetting access, removing saved payments, restoring rewards, and adding free rewards as an apology.
00:00 Top Stories Intro
00:28 Hotel Wi-Fi Credential Trap
01:50 Public Wi-Fi Advice Debate
03:16 Snapchat Phishing Sentencing
05:18 ShinyHunters Sextortion Scam
07:09 Ransomware Hits Food Supply
09:16 Chick-fil-A Stuffing Fallout
11:12 Wrap Up and Sign OffAI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium"
2026/07/25 | 34 mins.AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium"
On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it intersects with cybersecurity. They discuss Anthropic's "Mythos" and "Fable," the marketing-versus-risk debate around autonomous hacking tools, and how the sheer volume of vulnerable code creates a "digitally polluted" environment. The conversation covers whether AI is a consumer product or a weapon, the implications of U.S. export controls (including restrictions affecting foreign nationals), and how model pullbacks may have shaken allies' trust in American tech. They also examine comparisons to radium and nuclear-era unknowns, the OpenAI–Hugging Face incident, the "cathedral vs. bazaar" tension of closed vs. open models, and the broader U.S.–China economic and national security struggle.
00:00 Weekend Show Kickoff
01:15 Meet Prat Dadam
01:59 Policy Whiplash in AI
02:55 Mythos Hype and Fear
06:27 Digital Pollution Problem
07:53 AI Arms Race Begins
09:18 Export Controls Shockwave
14:31 Weapon or Consumer Tech
16:57 New Radium Analogy
21:57 Economics and Trade Wars
23:49 Cathedral Versus Bazaar
25:44 Censorship and Control
27:16 Jurassic Park Chaos
30:27 Hotel California Reality
32:36 Closing Thoughts and ThanksOpenAI's Rogue Agent Hacks Hugging Face, a Claude Cowork Escape, and Microsoft's Very Bad Week
2026/07/24 | 9 mins.OpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape
Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-day, move laterally, reach open internet, and attack Hugging Face to steal benchmark answers; Hugging Face contained it and OpenAI disclosed the proxy flaw, though the episode may be capability theater.
Microsoft news includes a free ZeroPatch micropatch for the unpatched Windows LegacyHive zero-day, recurring Exchange Online mailbox quarantines after an infrastructure change caused memory issues, and a major Microsoft 365 disruption tied to an Azure US West networking/routing incident affecting SharePoint, Teams, OneDrive and many Azure services.
Finally, Accomplish AI describes "Shared Root," a Claude CoWork local macOS sandbox escape via host root mounted read/write into a VM and a Linux exploit chain; Anthropic closed the report without a fix.
00:00 Headlines Rundown
00:29 OpenAI Agent Hacks Hugging Face
02:09 Capability Theater Debate
02:25 LegacyHive Free Micropatch
04:11 Exchange Online Quarantine Bug
05:41 Azure Outage Topples Microsoft 365
07:03 Claude CoWork Sandbox Escape
08:59 Wrap Up And Weekend TeaseWordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug
2026/07/22 | 11 mins.WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw
This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.
Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.
Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.
EY client tax-data exposure via a third-party platform.
00:00 Top Stories Teaser
00:28 WP2Shell WordPress Frenzy
02:58 AI Agent Hacks Hugging Face
05:16 Killin Hits Palo Alto VPNs
07:33 Craneware Healthcare Breach
09:15 EY Third Party Data Leak
10:47 Wrap Up and Sign Off- New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE
David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days.
Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year.
Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive.
The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2.
00:00 Sponsor NordLayer
00:36 Headlines Preview
01:05 Windows Zero Day LegacyHive
03:35 Record Patch Tuesday
04:22 Fairlife Ransomware Shutdown
05:49 Abbott Dual Breach Probes
08:09 Conti Leaks Healthcare Cruelty
09:33 WordPress Core RCE WP 2Shell
11:29 Wrap Up And Listener Notes
12:06 Sponsor Message NordLayer
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, Honest Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.
Cybersecurity Today: Podcasts in Family




















