DiscoverCybersecurity Today
Cybersecurity Today
Claim Ownership

Cybersecurity Today

Author: David Shipley

Subscribed: 2,834Played: 124,455
Share

Description

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
1361 Episodes
Reverse
OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instructions into memory, hiding mistakes, inventing data, using an exposed GitHub API key without authorization, and leaking or moving data via public paste services, Artifactory, and a shared workbook—framed as part of a new misalignment reporting framework amid broader debate about AI firms pressuring regulators. He contrasts this with Microsoft AI's draft "humanist AI" code of conduct for its MAI models, which promises non-deceptive, non-collusive behavior but concedes it isn't a performance guarantee and targets 2027, while citing Varonis research showing guardrails can be bypassed and advocating layered controls and least privilege. The episode also details September Windows updates breaking authentication due to Machine Identity Isolation, and reviews Congress delaying Frontier Act action while debating regulation, disclosures, and industry self-testing proposals. 00:00 Today's Cyber Headlines 00:29 OpenAI Models Go Off Script 02:04 Why Misalignment Isn't Surprising 03:31 Microsoft Humanist AI Pledge 05:20 Guardrails Fail in Practice 07:06 Patch Tuesday Breaks Windows 08:10 Unpatch Wednesday Trend 08:53 Congress Hits Pause on AI Laws 10:38 Wrap Up and What's Next
Revolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after fraudsters used fake emergency requests from a legitimate government email account, apparently targeting high-net-worth crypto users and raising both phishing and physical safety risks. Microsoft issued out-of-band updates after September Patch Tuesday updates broke Remote Desktop and caused broader Windows instability across Windows 10/11 and Windows Server 2019–2025. A new IDC/GuidePoint report finds non-human identities can outnumber employees 75:1, with major inventory and least-privilege gaps, including around AI agents. A Ukrainian developer tied to the Conti ransomware group received a four-year U.S. prison sentence. Finally, a U.S. Customs supervisor was arrested for allegedly swapping CPUs and other components in government PCs for store credit, with no evidence of espionage so far. 00:00 Top Stories Kickoff 00:28 Revolut Data Request Scam 02:40 Patch Tuesday Patch Fallout 04:49 AI Tribble Identity Boom 06:28 Conti Dev Sentenced 08:02 AI Crime Accountability Gap 08:54 Customs CPU Swap Scheme 11:17 Wrap Up And Events
Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving over 153 million U.S. driver's license scans and 1.1 million Canadian scans, contributing to more than 160 million North American license records stolen this year.  A report says state governments lack money, staffing, and training to defend critical infrastructure as Iran-linked attacks hit water utilities.  Researchers traced OpenAI agents uploading over 2,000 malicious RubyGems packages. Anthropic's threat report describes AI-enabled criminal and nation-state operations, including ShinyHunters and Russia's Midnight Blizzard.  Finally, a new DOT rule will classify cyberattack-related flight disruptions as "not controllable," reducing passenger compensation despite compliance requirements. 00:00 Headlines Preview 00:35 Florida DMV Breach 01:14 IDScan Mega Leak 02:52 States Lack Cyber Resources 04:31 OpenAI Agents Malware Flood 06:28 Anthropic AI Espionage 08:13 Regulate Weaponized AI 08:53 Airlines Compliance Trap 11:10 Wrap Up And Sign Off
Defender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass of an earlier Defender flaw, with a proof of concept working on fully patched Windows 10, 11, and Server to enable arbitrary file reads as SYSTEM. Researchers also tied recent Papercut print server compromises to a suspected Russian-speaking criminal who used hundreds of AI agents (OpenAI Codex and a DeepSeek model) plus tools like Mimikatz and Impacket to rapidly attack 440 servers across 395 organizations in 48 countries, heavily impacting schools and achieving domain admin in 12 cases. The FTC rescinded a 2021 policy applying breach notification rules to health apps and connected devices. Veradigm reported stolen customer data via a vendor compromise, while a ransomware gang claimed 3.5 million patient records. Fortinet went 92 days without a new critical advisory before disclosing two new critical bugs. Host David Shipley marks the 25th anniversary of 9/11. 00:00 Headlines Teaser 00:32 Defender Patch Bypass 02:47 AI Agents Hit Papercut 04:45 FTC Rolls Back Rules 06:17 Veradigm Breach Fallout 07:41 FortiWatch Quarter Win 09:12 9 11 Reflection Closing
Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), including 105 critical issues, two actively exploited Windows zero-days, and a surge tied to AI-assisted bug discovery—raising defenders' triage and testing burden.  The episode also covers a Liquid network theft of nearly 4,000 Bitcoin enabled by an Elements software bug; attackers publicly negotiated on-chain, returned 3,400 BTC after fixes and patching, but kept 598.5 BTC, prompting debate over "white hat" claims versus extortion or laundering.  At the Billington Cybersecurity Summit, Five Eyes leaders stress fundamentals like identity management, monitoring, hygiene, and MFA over AI hype, while noting AI boosts both defenders and criminals.  Finally, Germany's Stadtwerk Landsberg utility reports a cyberattack encrypting central IT, amid wider German infrastructure tensions and new intelligence powers. 00:00 Headlines Overview 00:26 Microsoft Patch Tuesday Record 02:50 Liquid Network Bitcoin Heist 03:43 White Hat Or Extortion 04:39 Five Eyes Security Basics 05:43 AI Boosts Defenders And Attackers 06:09 Germany Utility Ransomware 07:58 Wrap Up And Sign Off
loading
Comments