477 episodes
- AI Agents Hacking, Passkey Phishing, and Water Utility Attacks
In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and others), Schneier's "genie effect," legal and insurance consequences, and agent risks like log-poisoning "ghost jacking" against security tools. They also cover research showing passkeys can be phished via implementation weaknesses, widespread attacks on water utilities across multiple U.S. states and Quebec, and a Russian campaign targeting public Wi‑Fi. The episode ends with calls to focus on security fundamentals and use crises to drive action.
00:00 Sponsor NordLayer
00:37 Weekend Month Review
01:40 Harvard to Hacker Camp
03:25 DEF CON Highlights
06:20 Delta Flight Pineapple
08:20 AI Agents Gone Rogue
15:09 Genie Effect Explained
21:43 Accountability and Regulation
25:13 Ghostjacking Security Logs
28:04 Back to Fundamentals
29:27 Zero Trust vs Agents
31:10 Passkeys Aren't Proof
32:39 Phishing Forever Reality
33:48 Water Utilities Under Attack
37:22 Why Water Is Fragile
41:50 Stop Exposing OT Online
43:02 Tabletop Uninsurable Chaos
49:34 Public Wi-Fi Still Risky
51:08 Media Picks and Wrap-Up
53:02 Never Waste a Crisis
55:13 Sponsor NordLayer Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses
2026/08/14 | 11 mins.Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers'
A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control across Windows 10/11 (including 25H2) and Windows Server 2025, claiming it bypasses Microsoft's patch for their earlier RoguePlanet exploit; a public proof-of-concept app is available, Will Dormann verified it works, and Microsoft says it's investigating.
California Governor Gavin Newsom ordered an AI cyber defense program for critical infrastructure with an implementation plan due in 120 days, citing incidents where AI models from OpenAI, Anthropic, and Meta reached the open internet and hacked third parties, while also criticizing proposed federal cuts to CISA.
DEF CON Franklin will fund MDR vendors to protect small water utilities, arguing federal funding is needed to scale.
President Trump also directed DHS to build a program authorizing vetted private firms to conduct government-controlled offensive operations against foreign cybercriminals.
Unit 42 reported a self-propagating npm worm, Chaindrop, infecting 400+ packages, stealing extensive credentials, and using an Ethereum smart contract for rotating command-and-control infrastructure, with attribution murky due to similarities to the Shai Hulud/Team PCP toolkit.
00:00 Today's Cyber Rundown
00:26 Windows Defender Zero Day
02:35 California AI Cyber Defense
04:04 DEF CON Franklin Water Aid
06:21 Cyber Privateers Program
09:15 Chaindrop NPM Worm
11:12 Wrap Up and Next ShowsDefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym
2026/08/12 | 9 mins.DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking'
Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit.Â
Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals.
An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents.
00:00 Top Headlines
00:26 DEF CON Plane WiFi Sting
02:16 Patch Tuesday Mega Drop
03:28 AI Ghostjacking Firewalls
05:11 Defending Against Agent Poisoning
06:15 Gym Waitlist Agent Hack
08:15 AI Hacking Trend Fallout
09:06 Wrap Up And Sign OffAI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers
2026/08/10 | 16 mins.AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons
David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile.
A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T
he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research.
00:00 NordLayer Sponsor Message
00:37 Headlines And Intro
01:08 AI Patches Fail Often
03:19 WordPress Login XSS
05:40 Wipers Target Infrastructure
08:02 North Carolina Ports Hit
09:49 DEF CON Favorite Talks
10:15 GPS Trackers Takeover
11:28 Noreply Domain Email Leak
12:37 AI Finds HTTP Desyncs
13:47 Cliff Stoll Keynote
15:09 Wrap Up And Thanks
15:31 NordLayer Sponsor Close- Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers
This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale.
In this Weekend episode of Cybersecurity Today, host David speaks with Jeff Musson, co-founder and executive director of Coding for Veterans, and Daniel Shang, a recent graduate of the program's cybersecurity stream who is enrolling in its new generative AI course. Daniel shares his path from an electrical engineering background and Canadian Army reservist service (2016–2023) into cybersecurity, describing how the program's online, guided curriculum helped him build foundational skills like Python, Linux, and ethical hacking. Jeff explains how Coding for Veterans launched in 2019, has served over 1,000 students, expanded from software development into cybersecurity and AI, and supports learners with instructors, Slack communities, and occasional in-person bootcamps. They discuss veteran transition challenges, funding options through Veterans Affairs Canada and other sources, employer engagement, mentoring, and the program's career impact.
00:00 Sponsor NordLayer
00:39 Meet Jeff and Daniel
01:31 Daniel Military Background
02:20 Choosing Cybersecurity Path
05:06 Online Learning Experience
07:27 Finding Direction in Cyber
09:07 Jeff and Program Origins
12:08 Veteran Success Stories
19:05 Student Support System
21:47 Daniel AI Next Steps
24:29 Advice for Veterans
28:20 Costs and Funding Options
30:27 How Employers Can Help
33:49 Scaling Challenges and Wins
37:05 Future Goals and Wrap Up
41:21 Sponsor Message NordLayer
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.
Cybersecurity Today: Podcasts in Family



















