475 episodes
DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym
2026/08/12 | 9 mins.DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking'
Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit.
Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals.
An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents.
00:00 Top Headlines
00:26 DEF CON Plane WiFi Sting
02:16 Patch Tuesday Mega Drop
03:28 AI Ghostjacking Firewalls
05:11 Defending Against Agent Poisoning
06:15 Gym Waitlist Agent Hack
08:15 AI Hacking Trend Fallout
09:06 Wrap Up And Sign OffAI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers
2026/08/10 | 16 mins.AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons
David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile.
A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T
he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research.
00:00 NordLayer Sponsor Message
00:37 Headlines And Intro
01:08 AI Patches Fail Often
03:19 WordPress Login XSS
05:40 Wipers Target Infrastructure
08:02 North Carolina Ports Hit
09:49 DEF CON Favorite Talks
10:15 GPS Trackers Takeover
11:28 Noreply Domain Email Leak
12:37 AI Finds HTTP Desyncs
13:47 Cliff Stoll Keynote
15:09 Wrap Up And Thanks
15:31 NordLayer Sponsor Close- Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers
This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale.
In this Weekend episode of Cybersecurity Today, host David speaks with Jeff Musson, co-founder and executive director of Coding for Veterans, and Daniel Shang, a recent graduate of the program's cybersecurity stream who is enrolling in its new generative AI course. Daniel shares his path from an electrical engineering background and Canadian Army reservist service (2016–2023) into cybersecurity, describing how the program's online, guided curriculum helped him build foundational skills like Python, Linux, and ethical hacking. Jeff explains how Coding for Veterans launched in 2019, has served over 1,000 students, expanded from software development into cybersecurity and AI, and supports learners with instructors, Slack communities, and occasional in-person bootcamps. They discuss veteran transition challenges, funding options through Veterans Affairs Canada and other sources, employer engagement, mentoring, and the program's career impact.
00:00 Sponsor NordLayer
00:39 Meet Jeff and Daniel
01:31 Daniel Military Background
02:20 Choosing Cybersecurity Path
05:06 Online Learning Experience
07:27 Finding Direction in Cyber
09:07 Jeff and Program Origins
12:08 Veteran Success Stories
19:05 Student Support System
21:47 Daniel AI Next Steps
24:29 Advice for Veterans
28:20 Costs and Funding Options
30:27 How Employers Can Help
33:49 Scaling Challenges and Wins
37:05 Future Goals and Wrap Up
41:21 Sponsor Message NordLayer The Era of Cheap Bugs, Water utility attacks spread to 12 states, Coldcard wallet losses could hit 130 million
2026/08/07 | 14 mins.Passkeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw
In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside research showing exploit success against AI agents and weaknesses across agent frameworks, plus notable hardware and supply-chain hacks.
The show details BlackHat and Unit 42 findings that passkeys on Windows and Chrome can be phished or abused through logging, validation gaps, and malware techniques, undermining "phishing-resistant" claims.
It also covers cyber incidents impacting water utilities across at least 12 U.S. states, with manual operations and boil-water advisories but safe drinking water, and Forescout's count of thousands of exposed Rockwell controllers.
Finally, it updates the ColdCard seed-generation flaw with potential losses up to 2,000 BTC and reports indictments tied to a violent crypto "wrench attack."
00:00 Sponsor NordLayer
00:38 Headlines Passkeys Water Crypto
01:07 Black Hat Cheap Offense
02:43 Rogue AI Incidents
03:18 Passkeys Phished Windows
04:55 Chrome Synced Passkeys Flaws
05:53 Water Utilities Under Attack
08:20 ColdCard Wallet Losses
09:59 Wrench Attack Crypto Robbery
12:24 Wrap Up And Thanks
13:05 Sponsor NordLayer Reminder- Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes
This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and manipulating project files, with effects like loss of pressure, flooding, and tampered operator displays.
It also covers a separate Quebec incident in Saint-Noël shared by "Z Pen Test Alliance," where attackers adjusted chlorine settings and the plant entered safe mode without contamination.
The show reviews competing attributions (Cyber Avengers vs. Hondala), procurement and triage challenges for small utilities, an insurance war game simulating a mass water-sector crisis, concerns about uninsurability and act-of-war exclusions, and the DEF CON Franklin volunteer program helping rural utilities implement basics like password resets, MFA, and incident response plans.
00:00 Sponsor NordLayer
00:37 Deep Dive Setup
01:25 Iran Linked Water Hacks
02:27 Attack Mechanics Impact
03:38 Who Did It
04:13 Canadian Utility Breach
04:54 BSides Lessons Learned
05:51 Insurance War Game
07:59 Uninsurable Risk Fixes
09:00 DEF CON Franklin Volunteers
10:11 Franklin Findings Challenges
11:24 Local Sharing Next Steps
11:55 Wrap Up Listener Notes
12:46 Sponsor NordLayer Again
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, Success Made Simple with Dr. Dave Martin and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.
Cybersecurity Today: Podcasts in Family




















