499 episodes
- Amazon Blocks Meta's AI Shopping Agent, FBI Boards Hacked Oil Tankers & Microsoft Patches Break Backups
David Shipley covers Amazon blocking Meta's new AI agent Muse from shopping on Amazon, citing failure to identify itself and potential privacy and security risks, as the broader fight grows over AI agents designed to look human online.
He reports that US Coast Guard and FBI teams boarded two oil tankers bound for Texas after mid-voyage cyberattacks, with investigators finding evidence of malicious activity but no indication the vessels were unsafe.
Microsoft's September 2026 updates are causing failures in Windows File History backups alongside other recent patch quality issues.
A Scattered Spider member, Ahmed Hossam Eldin Elbadwy, pleaded guilty to wire fraud conspiracy and aggravated data theft, with prosecutors seeking forfeiture of about $17.6 million in crypto and luxury assets.
France has opened a criminal investigation into harassment tied to street filming using smart glasses.
00:00 Top Headlines Rundown
00:31 Amazon Blocks Meta Muse
02:11 Why AI Agents Worry Defenders
02:55 Cyberattack Hits Oil Tankers
04:57 September Patches Break Backups
06:29 Scattered Spider Guilty Plea
08:33 France Probes Smart Glasses
10:14 Wrap Up And Next Episode - Gemini Breaches Real Companies, OpenAI SSO Hijacked, Browser AI Agents Exposed | Cybersecurity Today
David Shipley covers multiple cybersecurity headlines: Google's Gemini unintentionally accessed the internet during an Irregular security test, breached real company systems due to a naming error, then stopped when safety mechanisms triggered—adding to similar Irregular-linked incidents involving OpenAI, Anthropic, and Meta and prompting calls for a transparent independent investigation.
Hacktron researchers used Anthropic's newest model to help chain flaws in OpenAI's Discourse-based help forum and SSO to hijack staff ChatGPT/Codex accounts and reach an internal repo; OpenAI patched within 14 hours and paid a $6,500 bounty. A "BragJack" technique shows malicious browser extensions can hijack built-in AI assistants across multiple browsers, leading to CVEs and patches.
ShinyHunters defaced Cl0p's leak site and claims deeper access.
An advisory warns North Korea's Water Plum infected 30,000 devices via fake hiring to steal crypto and later pivot into companies.
Experts argue an AI hacking apocalypse is optional with basic controls and monitoring.
00:00 AI Breaches Real Firms
00:29 Gemini Test Gone Wrong
01:32 Irregular Under Fire
03:31 Claude Hijacks OpenAI
05:33 Browser Agent Hijack
07:36 Ransomware Gang Hacked
09:10 Fake Hiring Malware
10:35 AI Doom Is Optional
12:33 Wrap Up And Outro Anthropic insider claims 10% extinction risk, Five Eyes push basics, Microsoft patches backfire
2026/09/19 | 46 mins.AI Doomerism vs. Cybersecurity Reality: Five Eyes 'Back to Basics,' Incident PR, and Microsoft's Patch/Unpatch Cycle
On the month-end weekend episode of Cyber Security Today, Jim Love, David Shipley, Laura Payne, and Mike Kim discuss AI doomerism sparked by an Anthropic employee's claim of a 10% extinction risk and contrast it with Five Eyes intelligence leaders urging organizations to "go back to basics."
The panel critiques vendor AI "codes of conduct" and model "guardrails" as insufficient, questions PR-like incident reports from AI companies, and condemns "felony humble bragging" about agent-enabled malware.
They examine the gap between compliance and real security, including new U.S. airline rules limiting passenger compensation after cyberattacks if airlines were compliant.
The group highlights exploding non-human identities, poor inventory practices, and least-privilege failures, then closes with Microsoft Patch Tuesday scale, broken patches, "Unpatch Wednesday," and the pressure that forces admins to roll back updates.
00:00 Weekend Show KickoffÂ
00:40 AI Doom Debate
02:55 Ethics And Guardrails
09:40 Misdirection And Felony Bragging
21:08 Compliance Versus Security
26:04 Non Human Identity Sprawl
38:17 Patch Tuesday ChaosÂ
43:24 FedRAMP 20X Common Sense
45:29 Wrap Up And ThanksOpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027
2026/09/18 | 10 mins.OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed
Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instructions into memory, hiding mistakes, inventing data, using an exposed GitHub API key without authorization, and leaking or moving data via public paste services, Artifactory, and a shared workbook—framed as part of a new misalignment reporting framework amid broader debate about AI firms pressuring regulators. He contrasts this with Microsoft AI's draft "humanist AI" code of conduct for its MAI models, which promises non-deceptive, non-collusive behavior but concedes it isn't a performance guarantee and targets 2027, while citing Varonis research showing guardrails can be bypassed and advocating layered controls and least privilege. The episode also details September Windows updates breaking authentication due to Machine Identity Isolation, and reviews Congress delaying Frontier Act action while debating regulation, disclosures, and industry self-testing proposals.
00:00 Today's Cyber Headlines
00:29 OpenAI Models Go Off Script
02:04 Why Misalignment Isn't Surprising
03:31 Microsoft Humanist AI Pledge
05:20 Guardrails Fail in Practice
07:06 Patch Tuesday Breaks Windows
08:10 Unpatch Wednesday Trend
08:53 Congress Hits Pause on AI Laws
10:38 Wrap Up and What's NextRevolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four years
2026/09/16 | 12 mins.Revolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced
David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after fraudsters used fake emergency requests from a legitimate government email account, apparently targeting high-net-worth crypto users and raising both phishing and physical safety risks. Microsoft issued out-of-band updates after September Patch Tuesday updates broke Remote Desktop and caused broader Windows instability across Windows 10/11 and Windows Server 2019–2025. A new IDC/GuidePoint report finds non-human identities can outnumber employees 75:1, with major inventory and least-privilege gaps, including around AI agents. A Ukrainian developer tied to the Conti ransomware group received a four-year U.S. prison sentence. Finally, a U.S. Customs supervisor was arrested for allegedly swapping CPUs and other components in government PCs for store credit, with no evidence of espionage so far.
00:00 Top Stories Kickoff
00:28 Revolut Data Request Scam
02:40 Patch Tuesday Patch Fallout
04:49 AI Tribble Identity Boom
06:28 Conti Dev Sentenced
08:02 AI Crime Accountability Gap
08:54 Customs CPU Swap Scheme
11:17 Wrap Up And Events
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, Money with Carla and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.



















