Skip to content
PodcastsBusinessCybersecurity Today

Cybersecurity Today

Jim Love
Cybersecurity Today
Latest episode

462 episodes

  • Cybersecurity Today

    Wordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomed

    2026/07/20 | 13 mins.
    New Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE
    David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized despite a stripped-back public release, as Microsoft investigates and sets a Patch Tuesday record with 570 fixes including two exploited zero-days.
    Coca-Cola suspended U.S. production at its Fairlife dairy unit after a ransomware attack, with scope still being assessed and the Food and Ag ISAC warning the sector has seen about 205 attacks this year.
    Abbott faces two separate breach claims: ShinyHunters alleges vishing-led SSO compromise and massive data theft from legacy systems, while Shadowbytes claims access via LabCentral credentials, which Abbott disputes as non-sensitive.
    The episode also highlights Conti leak revelations about healthcare targeting and details a core WordPress bug chain (WP_2Shell) enabling unauthenticated RCE, now patched in 6.9.5 and 7.0.2.
    00:00 Sponsor NordLayer
    00:36 Headlines Preview
    01:05 Windows Zero Day LegacyHive
    03:35 Record Patch Tuesday
    04:22 Fairlife Ransomware Shutdown
    05:49 Abbott Dual Breach Probes
    08:09 Conti Leaks Healthcare Cruelty
    09:33 WordPress Core RCE WP 2Shell
    11:29 Wrap Up And Listener Notes
    12:06 Sponsor Message NordLayer
  • Cybersecurity Today

    AI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026

    2026/07/18 | 33 mins.
    Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks.
    In this episode of Cybersecurity Today On The Weekend, host David Shipley speaks with Lionel Liddy, Chief Information Security Officer at Menlo Security, about why today's security strategies must evolve as AI reshapes the threat landscape.
    The conversation explores how AI is speeding up vulnerability discovery, why browser security has become a critical layer of defence, the emerging risks of AI agents operating inside browsers, and why recent NIST research suggests perfect AI guardrails may be mathematically impossible. Lionel also explains why organizations should prepare for future attacks that could spread even faster than Log4j.
    In this episode:
    How AI is accelerating cyberattacks
    Why browser isolation can reduce risk
    The security challenges created by AI agents
    Prompt injection and browser extension threats
    Why AI guardrails have fundamental limits
    Lessons from Log4j and preparing for the next major exploit
    Practical advice for CISOs and security leaders
    Chapters
    00:00 Sponsor – NordLayer
    00:39 Weekend Show Intro
    01:48 Lionel Liddy Background
    04:44 What Menlo Security Does
    06:43 AI Speeds Up Exploits
    10:09 CISO Whiplash With AI
    12:01 Agents And Browser Risks
    15:59 Guardrails And NIST Proof
    19:40 Mythos Hype And New Normal
    23:19 Hazmat Suit For Servers
    27:22 Log4j Times Four Scenario
    31:44 Wrap Up And Links
    32:54 Sponsor – NordLayer Outro
    Subscribe for weekly cybersecurity news, expert interviews, and practical insights for CISOs, IT professionals, and security leaders.
  • Cybersecurity Today

    Scattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPT

    2026/07/17 | 12 mins.
    Two leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losses estimated far higher; U.S. charges against Dubar remain unproven.
    Investigators also believe Russian hackers were behind last year's crippling Jaguar Land Rover attack that halted production for months and contributed to a £1.5 billion bailout, with Microsoft and multiple agencies assisting. 
    OpenAI unveiled GPT-Red, an automated red-teaming AI for prompt injection, alongside a NIST-backed argument that finite guardrails can't be universally robust.
    The episode also covers ClickLock, a macOS stealer that kills apps until a password is entered, and Recorded Future's report on Iran-linked groups using ChatGPT for malware, phishing, and reconnaissance.
    00:00 Headlines Kickoff
    01:08 Scattered Spider Sentencing
    02:57 US Charges Loom
    03:29 Jaguar Land Rover Hack
    04:35 GPT-Red AI Red Team
    05:40 Why Guardrails Fail
    06:36 ClickLock Mac Stealer
    06:53 How ClickLock Spreads
    07:59 Defense and Cleanup Tips
    08:37 Iran Uses AI for Ops
    10:30 Wrap Up and Next Show
  • Cybersecurity Today

    ShareFile explained, healthcare in critical cyber condition and click fix tops malware charts

    2026/07/15 | 13 mins.
    ShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware. 
    David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity path traversal flaw in Storage Zone Controller 5.x/6.x with patches available (5.12.5 and 6.0.2) and no evidence of prior exploitation.
    Microsoft's analysis of a year of ShinyHunters activity compromising corporate Salesforce environments by abusing trust via OAuth (IT-support phone cons, vendor token theft such as Salesloft/Drift, and misconfigured guest access), prompting new monitoring tooling.
    A Fortified Health Security report finding healthcare fixed only 6% of identified risks in H1 2026 amid surging vulnerabilities, third-party risk, and weak identity hygiene.
    ReversingLabs and ReliaQuest research showing ClickFix social-engineering is now a leading malware delivery method; and Telstra's nationwide outage traced to an obsolete time server hit by a GPS rollover bug, disrupting Triple Zero calls and prompting Senate scrutiny.
    00:00 Sponsor NordLayer
    00:37 Headlines Overview
    01:06 ShareFile Patch Explained
    03:25 Salesforce OAuth Break Ins
    06:01 Hospitals Drowning in Risks
    08:24 ClickFix Malware Surge
    11:13 Telstra Time Server Outage
    12:32 Wrap Up and Sign Off
  • Cybersecurity Today

    ShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishing

    2026/07/13 | 10 mins.
    ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint
     
    Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected.
     
    Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17.
     
    Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender.
     
    ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint.
     
    Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data.
    00:00 NordLayer Sponsor Message
    00:37 Today's Cyber Headlines
    01:08 ShareFile Shutdown Alert
    03:39 Ransomware Double Agent Sentenced
    05:13 Odido Breach Voice Threat
    06:24 Helix Vishing SharePoint Extortion
    08:00 Assurance America License Leak
    08:57 Wrap Up and Conference Note
    09:25 NordLayer Sponsor Reminder
More Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast website

Listen to Cybersecurity Today, Bruce Whitfield’s Business Week and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Cybersecurity Today: Podcasts in Family