Skip to content
PodcastsBusinessCybersecurity Today

Cybersecurity Today

David Shipley
Cybersecurity Today
Latest episode

483 episodes

  • Cybersecurity Today

    Iranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cards

    2026/08/26 | 10 mins.
    Iran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw
    Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked to Iran Nexus hackers, though damage was contained to a single small generator.
    ReliaQuest confirms ShinyHunters targeted its staff with phone-based social engineering and a fake reliaquest.claims SSO page, gaining only temporary view-only Okta dashboard access before being blocked by device trust controls, with no customer data affected. 
    LockBit claims it hacked US Bancorp, but the bank says the incident traces to a fourth-party contractor outside its environment and LockBit has provided no proof. Microsoft is rolling out a Teams policy to automatically block detected external bots from meetings.
    UMass Amherst researchers found some expired Visa cards can be "zombified" for contactless payments via a two-phone relay, depending on issuer and bank checks.
    00:00 Top Headlines
    00:26 Iran Linked Power Attack
    01:44 ShinyHunters Targets ReliaQuest
    04:16 LockBit Claims Bank Hack
    05:46 Teams Blocks External Bots
    07:42 Expired Visa Card Zombie
    09:25 Closing Notes Tribute
  • Cybersecurity Today

    Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet

    2026/08/24 | 8 mins.
    Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware
    Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen.
    Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys.
    Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun.
    00:00 Top Stories Rundown 
    00:30 Entra ID Perfect 10 Patch
    01:55 Defender Driver Weaponized
    03:31 SickKids Hit Again
    05:10 Leaked AWS Keys Still Live
    06:48 Car Head Unit Botnet
    08:25 Wrap Up And Sign Off
  • Cybersecurity Today

    AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

    2026/08/22 | 36 mins.
    How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next
     
    In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024.
     
    They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical.
     
    The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability.
     
    00:00 Sponsor NordLayer
    00:37 Weekend Show Intro
    02:02 Robert Career Journey
    03:08 Building Adlumin
    05:50 AI Transforms SOC Work
    08:56 AI Investigations Upgrade
    11:23 Alert Fatigue and MDR
    13:49 MSPs Become MSSPs
    19:30 AI as Opportunity and Threat
    21:13 Attack Speed Compression
    22:54 Wins and Frustrations
    26:59 Autonomous Hacking Reality
    29:03 Hack Back Debate
    32:43 Next 12 Months Forecast
    34:28 Closing Thanks
    35:22 Sponsor Message Return
  • Cybersecurity Today

    NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

    2026/08/21 | 14 mins.
    NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus
    In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts.
    The show also covers ThreatFabric's findings on "Manic," an Android malware active since February that steals sensitive data and can exfiltrate it offline by relaying encrypted loot via Wi‑Fi Direct or Bluetooth through nearby infected devices.
    Black Kite data shows mid-market companies (especially $10–$50M revenue) account for most ransomware incidents, with manufacturing hit hardest and many firms running known exploited vulnerabilities.
    Finally, Wired reports Meta ran ads for "Kromix," an app promoting deepfake nude images of female politicians, raising ongoing concerns about nudify ads and enforcement.
    00:00 Sponsor NordLayer
    00:37 Headlines Preview
    01:05 AI Exploits Hit PLCs
    04:06 Android Malware Manic
    06:49 Ransomware Targets Midmarket
    09:19 Meta Nudify Ads Scandal
    12:26 Wrap Up and Weekend Tease
    13:23 Sponsor Message NordLayer
  • Cybersecurity Today

    CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

    2026/08/19 | 12 mins.
    Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses"
    The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enabled auto-running prompts, silent data exfiltration via connected apps (e.g., Gmail/Drive/Calendar) using Copilot's own web fetch, and persistent memory poisoning that survives common account cleanup steps until manually removed; Microsoft was notified in December 2025, patches shipped August 18, and no in-the-wild exploitation was found.
    It also reviews a threat actor "The Hat Man" claiming to have stolen about 3.64 million employee records from Azure tenants of major firms, with companies disputing breach claims while Hudson Rock assesses the data as likely authentic but with unknown access/exfiltration. The University of Texas at San Antonio took systems offline after detecting network-edge threat activity, reporting no evidence of data exfiltration and planning password resets amid outages.
    Finally, researchers from Anthropic and EPFL describe "mind viruses" that propagate between AI agents via persistent "soul" prompt files, demonstrate harmful action payloads, and show a simple system-prompt warning greatly reduced spread.
    00:00 NordLayer Sponsor Message
    00:37 Headlines And Intro
    00:59 Copilot CoSnitch Flaw
    03:55 Azure Employee Data Leaks
    06:09 UTSA Cyberattack Update
    07:54 AI Agent Mind Viruses
    11:09 Wrap Up And Thanks
    11:33 NordLayer Sponsor Close
More Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast website

Listen to Cybersecurity Today, Bruce Whitfield’s Business Week and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features