471 episodes
- Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes
Â
This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and manipulating project files, with effects like loss of pressure, flooding, and tampered operator displays.
Â
It also covers a separate Quebec incident in Saint-Noël shared by "Z Pen Test Alliance," where attackers adjusted chlorine settings and the plant entered safe mode without contamination.
Â
The show reviews competing attributions (Cyber Avengers vs. Hondala), procurement and triage challenges for small utilities, an insurance war game simulating a mass water-sector crisis, concerns about uninsurability and act-of-war exclusions, and the DEF CON Franklin volunteer program helping rural utilities implement basics like password resets, MFA, and incident response plans.
00:00Â Sponsor NordLayer
00:37Â Deep Dive Setup
01:25Â Iran Linked Water Hacks
02:27Â Attack Mechanics Impact
03:38Â Who Did It
04:13Â Canadian Utility Breach
04:54Â BSides Lessons Learned
05:51Â Insurance War Game
07:59Â Uninsurable Risk Fixes
09:00Â DEF CON Franklin Volunteers
10:11Â Franklin Findings Challenges
11:24Â Local Sharing Next Steps
11:55Â Wrap Up Listener Notes
12:46Â Sponsor NordLayer Again Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi
2026/08/03 | 13 mins.Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw
David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber evaluations July 23.
The EU's AI Act model rules are now enforceable, requiring transparency, risk mitigation for frontier models, deepfake labeling, and penalties up to €15M or 3% of global revenue, with GDPR-like jurisdiction. Microsoft detailed "Captive Crunch" hotel/conference Wi‑Fi captive-portal hijacks attributed to Russia's SVR (Storm-2945), delivering the Cornflake implant and device-code phishing.
A ColdCard firmware RNG flaw enabled thefts totaling $88.6M. Amazon tied four poisoned NPM incidents to a North Korean group and warned of multi-package malware, slop squatting, and AI-reviewer deception.
00:00 NordLayer Sponsor Message
00:37 Today's Cyber Headlines
01:09 Claude Models Escape Sandbox
03:43 EU AI Act Now Enforceable
05:31 Hotel WiFi Hijack Malware
07:54 ColdCard Seed Flaw Heist
09:42 North Korea NPM Poisoning
11:27 Wrap Up and Events
12:08 NordLayer Sponsor ReminderHealthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident Readiness
2026/08/01 | 22 mins.On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026.
Â
Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes.
Â
He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response.
Â
The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools.
Â
00:00Â Weekend Show Intro
00:39Â Meet Matt Burke
01:23Â Concierge Care Model
02:45Â Why Healthcare Security
03:13Â Origin Story 3AM Call
05:20Â Top Threats 2026
06:29Â Defense Tools That Work
07:50Â AI Helps And Hurts
09:37Â Winning Doctor Buy In
10:57Â Castle Versus Response
13:42Â Threat Surge And Resilience
18:17Â Culture And MFA Everywhere
19:59Â Career Advice And Magic Wand
22:33Â Closing ThanksOpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange
2026/07/31 | 11 mins.OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover
Â
David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.
Â
Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.
Â
Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets.
MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.
Â
00:00Â Headlines and intro
00:29Â OpenAI rogue agent fallout
02:18Â Genie effect and benchmarks
03:29Â Minnesota water systems hit
05:02Â Iran-linked PLC warnings
06:23Â Exchange OWA mailbox backdoor
08:24Â Medical billing breach tally
09:43Â IPMI BMCs exposed online
11:00Â Wrap-up and next episodesAI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
2026/07/29 | 12 mins.Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry.
South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began.
Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps.
Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance.
Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft.
00:00 Introduction and Headlines
00:30 South Carolina Hospital Ransomware Attack
02:07 Healthcare Ransomware Crisis
03:25 IoT Botnet Uses Blockchain
05:40 Shared AI Chats Exposed
08:00 AI Agent Infiltrates Thailand Ministry
10:45 Swiss Train Maker Refuses Ransom
12:31 Closing Remarks
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, Aspire with Emma Grede and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.
Cybersecurity Today: Podcasts in Family



















