493 episodes
ShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak ends
2026/09/11 | 10 mins.Defender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules
Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass of an earlier Defender flaw, with a proof of concept working on fully patched Windows 10, 11, and Server to enable arbitrary file reads as SYSTEM.
Researchers also tied recent Papercut print server compromises to a suspected Russian-speaking criminal who used hundreds of AI agents (OpenAI Codex and a DeepSeek model) plus tools like Mimikatz and Impacket to rapidly attack 440 servers across 395 organizations in 48 countries, heavily impacting schools and achieving domain admin in 12 cases.
The FTC rescinded a 2021 policy applying breach notification rules to health apps and connected devices.
Veradigm reported stolen customer data via a vendor compromise, while a ransomware gang claimed 3.5 million patient records.
Fortinet went 92 days without a new critical advisory before disclosing two new critical bugs.
Host David Shipley marks the 25th anniversary of 9/11.
00:00 Headlines Teaser
00:32 Defender Patch Bypass
02:47 AI Agents Hit Papercut
04:45 FTC Rolls Back Rules
06:17 Veradigm Breach Fallout
07:41 FortiWatch Quarter Win
09:12 9 11 Reflection ClosingMicrosoft patches record 966 flaws, Cybercriminals return $265 million in Bitcoin
2026/09/09 | 8 mins.Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning
Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), including 105 critical issues, two actively exploited Windows zero-days, and a surge tied to AI-assisted bug discovery—raising defenders' triage and testing burden.Â
The episode also covers a Liquid network theft of nearly 4,000 Bitcoin enabled by an Elements software bug; attackers publicly negotiated on-chain, returned 3,400 BTC after fixes and patching, but kept 598.5 BTC, prompting debate over "white hat" claims versus extortion or laundering.Â
At the Billington Cybersecurity Summit, Five Eyes leaders stress fundamentals like identity management, monitoring, hygiene, and MFA over AI hype, while noting AI boosts both defenders and criminals.Â
Finally, Germany's Stadtwerk Landsberg utility reports a cyberattack encrypting central IT, amid wider German infrastructure tensions and new intelligence powers.
00:00 Headlines Overview
00:26 Microsoft Patch Tuesday Record
02:50 Liquid Network Bitcoin Heist
03:43 White Hat Or Extortion
04:39 Five Eyes Security Basics
05:43 AI Boosts Defenders And Attackers
06:09 Germany Utility Ransomware
07:58 Wrap Up And Sign OffIDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch
2026/09/07 | 14 mins.Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale.
Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that abuses CrowdStrike's Falcon alongside other zero-days targeting Kaspersky, Avast, and Nvidia.
Sansec disclosed an unpatched Magento/Adobe Commerce flaw "Style Smuggler" enabling unauthenticated code execution.
Arctic Wolf observed active exploitation of PaperCut authentication bypass and RCE flaws against schools, including credential theft and lateral-movement prep.
UK police data shows reported losses from hacked accounts rose 417% amid improved reporting via the new Report Fraud system.
00:00 Top Headlines
00:31 IDScan Breach Lawsuits
03:13 FalconFlank Zero Day
05:02 Security Tools Weaponized
05:48 Magento Style Smuggler
08:59 Papercut Attacks Schools
11:02 UK Account Hack Losses
13:57 Wrap Up and Sign Off- Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation
In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems.
Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.Â
She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders.
The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world.
00:00 Weekend Show Intro
00:07 Katie Moussouris Background
02:00 Bug Bounties Then and Now
03:31 AI Hype and Model Escapes
05:06 The Real Cost of Fixing
08:36 Smart AI Regulation
12:34 Tools for Defenders vs Rogues
15:53 Metasploit and Agentic Risk
17:25 Nightmare Eclipse and Microsoft
21:53 Luta Security Today
24:28 Training the Next Generation
27:46 Hope, UBI, and Wrap Up FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos
2026/09/04 | 11 mins.153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments
The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to IDscan.net before Nexus abruptly disappeared.
It also covers a breach at healthcare SaaS provider Aesto Health affecting 9.54 million individuals, exposing extensive personal and medical data, with delayed confirmation and notifications and 24 months of Experian monitoring offered.
The show details CISA ending six free critical-infrastructure cybersecurity assessments amid workforce reductions, raising concerns given recent targeting of U.S. water systems and warnings about AI-generated exploitation scripts against Siemens PLCs.
Additional updates include Plex urging immediate patching of undisclosed vulnerabilities and Slovenia's HIT gradually reopening casinos after a cyberattack forced a three-day shutdown.
00:00 Top Cyber Headlines
00:29 Dark Web License Leak
02:33 Nexus Tied to IDscan
04:05 Healthcare SaaS Breach
05:35 CISA Cuts Assessments
07:16 Plex Patch Alert
08:43 Slovenian Casinos Recover
10:05 Weekend Interview Preview
10:53 Closing and Sign Off
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.























