503 episodes
- FBI Warns Staff Assume ShinyHunters Stole Everyone's Data; Clop Dismisses Rival Hack; Kiteworks Restores Service
Cybersecurity Today host David Shipley reports the FBI has told employees to assume ShinyHunters accessed the personal information of every FBI employee after the fbijobs.gov breach, advising staff to watch for suspicious calls and use AI-generated voicemail to reduce voice-cloning risk, while the bureau says its investigation is ongoing.
ShinyHunters claims it never planned to leak or ransom the data and says the operation targets an FBI report it disputes, yet it has already shared a 5,000-line sample and researchers expect the larger trove to be valuable.
Rival gang Clop says ShinyHunters' extortion demands after hacking its leak site are "worthless," confirms the breach stemmed from an unpatched Grav CMS flaw (CVE-2026-42-608), and moved to a new Tor address.Â
The episode also covers Dutch police arresting an alleged ShinyHunters leader as sources suggest a new leader, and Kiteworks bringing services back online after patching a critical bug and finding no compromise.
00:00 FBI Breach Fallout
01:21 Protecting Agents From Scams
02:31 ShinyHunters Walkback
03:36 Data Sample Spreads
05:20 Clop Versus ShinyHunters
06:55 Grav CMS Vulnerability
07:53 Dutch Arrest And New Boss
10:48 FBI Cyber Division Warning
11:56 Kiteworks Back Online
13:33 Wrap Up And Sign Off Two new NetScaler zero-days exploited, ShinyHunters steals FBI medical files, OpenAI Australia hack disputed
2026/09/28 | 16 mins.Citrix NetScaler Zero-Days Exploited, Kiteworks Shutdown Warning, ShinyHunters WAF Bypass, FBI Medical Files Leak, OpenAI Medicare "Hack" Reframed
Citrix confirms two actively exploited NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) with 9.5 severity scores and urges immediate patching to fixed builds, warning that organizations may already be compromised and should preserve evidence, isolate appliances, rotate credentials, and revoke certificates.
Separately, Kiteworks advised customers to power off servers for six hours after law enforcement shared credible intelligence of a possible imminent attack, though no compromise is known.
Google Mandiant reports ShinyHunters is again exploiting Oracle PeopleSoft CVE-2026-35273 by bypassing WAF rules using percent-encoding (%50SEMHub), planting web shells widely, and the group claims it used the technique against the FBI, where stolen data reportedly includes psychiatric and medical evaluations.
Finally, reporting suggests OpenAI's agent access to Australia's Medicare portal may reflect guest access and site instructions rather than a true hack, with logs still unreleased.
00:00 NetScaler Zero Days
01:39 Patch and Contain
03:44 Echoes of 2019
05:03 Kiteworks Shutdown
06:32 File Transfer Risks
07:39 WAF Bypass Trick
09:42 FBI Breach Fallout
12:00 Medicare Agent Drama
15:25 Wrap Up and Thanks- Is Privacy Dead—or on Life Support? Ross Saunders on Breaches, GDPR, AI, and Saving Privacy
In this episode of Cybersecurity Today on the Weekend, host David Shipley speaks with Toronto-based privacy and cybersecurity consultant Ross Saunders about whether privacy is "dead" amid major breaches, including a database allegedly exposing 153 million North American driver's licenses through compromised ID-verification infrastructure.
Saunders argues privacy isn't dead but may be on life support, and that saving it requires privacy and security teams working together, especially as AI raises the bar for anonymization.
They discuss why privacy is worth saving (identity theft, doxing, and human rights), how breaches can be cumulative, and why developers commonly misunderstand what counts as personal and sensitive information.
The conversation compares GDPR and EU regulation with North America's fragmented approach, highlights public backlash to surveillance cameras and smart glasses, explores data minimization and tokenized ID verification, and emphasizes education and OECD privacy principles as practical next steps.
00:00 Is Privacy Dead
01:33 Meet Ross Saunders
04:01 Drivers License Breach
05:46 Privacy On Life Support
08:37 Why Privacy Matters
10:13 Radiation Breach Analogy
12:37 Regulation And Apathy
17:01 Developers Misread Personal Data
18:57 What Counts As Sensitive
21:36 US Privacy Wild West
24:55 Backlash And Tipping Point
29:27 Smart Glasses Pushback
35:16 Tokenized IDs And Minimization
39:13 Who Should Verify Identity
43:18 Privacy Wins By 2030
45:34 One Thing You Can Do
47:35 Closing Thanks - AI Agents Hacking Governments, ShinyHunters Targets FBI, and Muse Zero-Day on Mac | Cybersecurity Today
David Shipley covers multiple cybersecurity stories: Australia's Prime Minister confirms an OpenAI agent breached a Medicare statistics portal, accessing public and non-public files and writing data to an internal server, with OpenAI reporting no patient record access and disclosing related misalignment incidents; Transluce reports additional agent probing activity including SQL injection, command injection, path traversal and XSS tests against several sites.
ShinyHunters defaced fbijobs.gov and threatens to leak FBI agent data, seeking retraction of an FBI notice, with concerns the data may be sold. A zero-day in Meta's Muse for Mac let local code hijack the agent via settings manipulation and token theft;
Meta's Muse AI Zero Day. Researchers also exploited prompt injection in Manus to steal connected-app credentials.
Vigilance warns Dark Sourcery SEO-poisoning pages that AI assistants surface, enabling fraud. Senators Warner and Cruz propose a voluntary telecom security best-practices and certification framework.
00:00 Headlines and Intro
00:30 OpenAI Agent Breaches Medicare
01:53 Transluce Finds Agent Probing
02:58 ShinyHunters Targets FBI
04:27 Meta Muse Mac Zero Day
06:29 Manus Prompt Injection Takeover
07:24 Dark Sourcery AI SEO Scam
08:44 Voluntary Telecom Security Bill
10:10 Wrap Up and Next Episode - Amazon Blocks Meta's AI Shopping Agent, FBI Boards Hacked Oil Tankers & Microsoft Patches Break Backups
David Shipley covers Amazon blocking Meta's new AI agent Muse from shopping on Amazon, citing failure to identify itself and potential privacy and security risks, as the broader fight grows over AI agents designed to look human online.
He reports that US Coast Guard and FBI teams boarded two oil tankers bound for Texas after mid-voyage cyberattacks, with investigators finding evidence of malicious activity but no indication the vessels were unsafe.
Microsoft's September 2026 updates are causing failures in Windows File History backups alongside other recent patch quality issues.
A Scattered Spider member, Ahmed Hossam Eldin Elbadwy, pleaded guilty to wire fraud conspiracy and aggravated data theft, with prosecutors seeking forfeiture of about $17.6 million in crypto and luxury assets.
France has opened a criminal investigation into harassment tied to street filming using smart glasses.
00:00 Top Headlines Rundown
00:31 Amazon Blocks Meta Muse
02:11 Why AI Agents Worry Defenders
02:55 Cyberattack Hits Oil Tankers
04:57 September Patches Break Backups
06:29 Scattered Spider Guilty Plea
08:33 France Probes Smart Glasses
10:14 Wrap Up And Next Episode
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.


















