Retour

Explorez tous les épisodes du podcast Cybersecurity Headlines

Plongez dans la liste complète des épisodes de Cybersecurity Headlines. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 1,856

TitreDateDurée
The Department of Know: ShinyHunters vs FBI, Kiteworks shutdown, and hundreds of orgs hit by rogue AI02 Oct 202600:38:36

Read all the stories at CISOSeries.com.

This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Nick Espinosa, host, Deep Dive Radio Show.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Big thanks to our sponsor, Intezer.

If you caught our tips this week, they pointed one direction: investigate everything, and keep the evidence. That's a hard promise to make with people. It's an easy one to make with forensics that run in under a minute. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
AI readiness reports, KillSec takedown, OpenAI website scraping02 Oct 202600:08:18

Report suggests AI and quantum threat preparedness is lacking

Authorities seize KillSec extortion group arrest leader

Dozens more prominent websites scraped by OpenAI software

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-readiness-reports-killsec-takedown-openai-website-scraping/

Huge thanks to our episode sponsor, Intezer

Today's tip: treat every false positive like a bug report against a detection rule. Fix the rule, and that noise stops coming back. Intezer does that for you, so your SOC gets quieter over time instead of louder. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware01 Oct 202600:07:28

Gemini 4 starts with cybersecurity

MI5 flags Chinese research funding

Custom GPTs steer users into ClickFix attacks

Get the show notes here:

https://cisoseries.com/cybersecurity-news-october-1-2026/

Huge thanks to our episode sponsor, Intezer

Today's tip: add up the hours your tier-one analysts spent closing alerts that turned out to be nothing. That's your real triage cost. At a hundred and fifty enterprises, that work isn't done by hand. Intezer investigates every alert. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
Star Blizzard, Cloudflare CA, GPT-6.1 scuttled30 Sep 202600:08:11

Microsoft details new Star Blizzard and NeedyMantis activity

Cloudflare to become a public certificate authority

Safety concerns scuttle GPT-6.1

Get the show notes here: https://cisoseries.com/cybersecurity-news-star-blizzard-cloudflare-ca-gpt-6-1-scuttled/ 

Huge thanks to our episode sponsor, Intezer

Today's tip: when an AI calls an alert benign, ask for the evidence. The file, the memory, the command line. If it can't show its work, it's guessing. Intezer shows its work, and your team can argue with it. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents29 Sep 202600:08:28

GPT-6 Astra goes off script in attack simulations

Dutch police arrest "reformed" hacker in ShinyHunters probe

Nvidia builds a browser for AI agents

Get the show notes here:

https://cisoseries.com/cybersecurity-news-september-29-2026/

Huge thanks to our episode sponsor, Intezer

Today's tip: time how long an employee-reported phish waits for a verdict. If it's a day, someone already clicked. Salesforce's incident response team got that down to minutes with Intezer. At their size, one click is plenty. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage28 Sep 202600:07:45

Another Microsoft SharePoint flaw now exploited

Details and doubts emerge regarding OpenAI hack of Australian Health portal

Kiteworks urges customers to stop using platform

Get the show notes here: https://cisoseries.com/cybersecurity-news-new-sharepoint-exploit-australian-openai-hack-developments-kiteworks-urges-stoppage/

Huge thanks to our episode sponsor, Intezer

Today's tip: pull your low-severity alerts and count how many got opened. That's where attackers hide. Intezer investigates every alert, boring ones included, in under a minute. MGM Resorts' CTO has talked about nation-state threats turning up right there. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.
The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan25 Sep 202600:34:13

Read all the stories at CISOSeries.com.

This week's Department of Know is hosted by Rich Stroffolino, with guests Dmitriy Sokolovskiy, senior vice president, information security, Semrush, and Christian Frösch, CISO, CH Media.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Big thanks to our sponsor, Nudge Security.

Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who created it, what it's connected to, and risks like destructive permissions. And, smart automation helps you engage the right person to fix the risk.

OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited25 Sep 202600:07:29

OpenAI program hacks Australia's government health portal

Astrana Health suffers data breach

Ransomware gangs exploiting TeamCity flaw

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-25-2026/

Huge thanks to our episode sponsor, Nudge Security

Here's a question that might make you sweat…how many AI agents are running in your org right now?

Not sure? You're not alone.

But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app.

For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers.

Give it a try for free at nudgesecurity.com/cisoseries

ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon's cyber appetite grows24 Sep 202600:07:01

ShinyHunters peeks at FBI assignments

WordPress flaw wastes no time

Pentagon's cyber appetite grows

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-24-2026/

Huge thanks to our episode sponsor, Nudge Security

Here's a question that might make you sweat…how many AI agents are running in your org right now?

Not sure? You're not alone.

But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app.

For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers.

Give it a try for free at nudgesecurity.com/cisoseries

CAIRN framework, Muse zero-day, BigDiskBuster23 Sep 202600:06:58

Cisco releases open-source CAIRN framework

Muse zero-day opens the door to account takeovers

Microsoft can't wake up from Nightmare Eclipse

Get the show notes here: https://cisoseries.com/cybersecurity-news-cairn-framework-muse-zero-day-bigdiskbuster/ 

Huge thanks to our episode sponsor, Nudge Security

Here's a question that might make you sweat…how many AI agents are running in your org right now?

Not sure? You're not alone.

But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app.

For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers.

Give it a try for free at nudgesecurity.com/cisoseries

ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware22 Sep 202600:07:18

ShinyHunters hijacks Clop's own leak site

Fake LastPass installers kill security tools

Trusted npm release carries GHAPPIER malware

Huge thanks to our episode sponsor, Nudge Security

Here's a question that might make you sweat…how many AI agents are running in your org right now?

Not sure? You're not alone.

But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app.

For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers.

Give it a try for free at nudgesecurity.com/cisoseries

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-22-2026/

OpenAI Codex sandbox escape, President proposes AI Force, Cyber Command suicides21 Sep 202600:08:07

Researchers escape OpenAI Codex sandbox to run commands on host

AI Force proposed to monitor technology

Congress eyes new support for Cyber Command after recent suicide deaths

Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-codex-sandbox-escape-president-proposes-ai-force-cyber-command-suicides/

Huge thanks to our episode sponsor, Nudge Security

Here's a question that might make you sweat…how many AI agents are running in your org right now?

Not sure? You're not alone.

But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app.

For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers.

Give it a try for free at nudgesecurity.com/cisoseries

The Department of Know: Passkeys phished, Cisco hits root, nuclear red lines for AI18 Sep 202600:34:50

Read the full stories at CISOSeries.com.

This week's Department of Know is hosted by Sarah Lane, with guests Jason Thomas, senior director of technology security, governance, and risk at the Cystic Fibrosis Foundation, and Jay Wilson, CISO and CIO at Insurity.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Big thanks to our sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Nuclear-style AI safeguards, AI legislation shelved, CISA's decoy guidance18 Sep 202600:07:16

Nuclear-style safeguards proposed for AI risks

Key lawmaker suggests action on AI safety legislation will wait until 2027

CISA releases cyber decoy guidance for infrastructure defenses

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-18-2026/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Flock gets plucked, OpenAI agents arrived even earlier, inside China's AI spy shop17 Sep 202600:06:30

Flock gets plucked

OpenAI agents arrived early

China's AI spy shop

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-17-2026/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+16 Sep 202600:07:27

Cisco zero-day goes straight to root

BambooToken branches into Linux

CenterPoint breach claim hits 7M+

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-16-2026/

Huge thanks to our episode sponsor, Vanta

Risk and regulation are ramping up, and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure and keeps your deals moving. Learn more at vanta.com/ciso.

China hits fast-forward on AI security, Hacking Cat shows its claws, Vite servers spill cloud secrets15 Sep 202600:09:35

China hits fast-forward on AI security

Hacking Cat shows its claws

Vite servers spill cloud secrets

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-15-2026/

Huge thanks to our episode sponsor, Vanta

Risk and regulation are ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole14 Sep 202600:07:35

Attackers use passkey phishing to hijack Microsoft cloud accounts

Anthropic blockbuster report reveals sophisticated hacks

Airlines compliance with new cybersecurity regulations means fewer passenger conveniences

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-14-2026/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

The Department of Know: Liquid drained, CISA urges change, agentic whistleblowers11 Sep 202600:33:36

Read the full stories at CISOSeries.com

This week's Department of Know is hosted by Rich Stroffolino, with guests Alexandra Landegger, global head of cyber strategy & transformation, RTX, Mark Eggleston, CISO-at-large.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Big thanks to our sponsor, ThreatLocker

This week, we looked at how AI is making attacks faster, less predictable, and easier to execute. But an AI-generated attack still needs permission to run, access data, use trusted applications, and move through the environment. ThreatLocker helps organizations control those actions before they become incidents. Book a demo at threatlocker.com/ciso.

NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malware11 Sep 202600:07:42

Critical NetScaler vulnerability exploited in attacks

AdaptHealth data breach impacts 4.1 million people

MantaxOtax Android malware delivers ransomware and spyware together

Get the show notes here: https://cisoseries.com/cybersecurity-news-netscaler-vulnerability-exploited-adapthealth-suffers-breach-new-android-malware/

Huge thanks to our episode sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

Fortinet auth holes, China distills AI, Mythos vulnerability10 Sep 202600:07:21

Fortinet plugs two critical auth holes

US says China is distilling AI at scale

Mythos vulnerability hits human bottleneck

Get the show notes here: https://cisoseries.com/cybersecurity-news-september-10-2026/

Huge thanks to our episode sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

Florida DMV breach, zero-click WeChat worm, AI whistleblowers09 Sep 202600:07:37

ShinyHunters claimed it breached Florida DMV

Zero-click WeChat worm spreads over incoming calls

AI cheaters and whistleblowers emerge

Get the show notes here: https://cisoseries.com/cybersecurity-news-florida-dmv-breach-zero-click-wechat-worm-ai-whistleblowers/ 

Huge thanks to our episode sponsor, ThreatLocker

Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA08 Sep 202600:08:24

PEEP turns browsers into backdoors

Liquid loses $320M, hackers play hero

BigBear claws past MFA

Get the full show notes here: https://cisoseries.com/cybersecurity-news-september-8-2026/

Huge thanks to our episode sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge07 Sep 202600:07:45

MikroTik routers hijacked through internet-exposed SSH

Russian data centers face new security requirements

UK account-hack losses surge thanks to new reporting system

Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/

Huge thanks to our episode sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

The Department of Know: Astra launches, CISA cuts programs, McKesson breached04 Sep 202600:34:46

Read the full stories at CISOSeries.com

This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.  
Court records breach, Breeze Comet hits Brazil, Aesto records breach04 Sep 202600:08:49

U.S. and Canadian court records breached in Thomson Reuters incident

Cybercrime Breeze Comet causing problems in Brazil

Aesto record system hit by data breach

Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

153M licenses for sale, Anthropic reverses course, Astra enters the red zone03 Sep 202600:07:21

Dark web shop stocks 153 million driver's licenses

Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals. IDScan says it's investigating and hasn't determined the breach's nature or scope. The FBI's New Orleans office has opened an inquiry. (KrebsOnSecurity)

Anthropic puts 30-day data retention in reverse

After customer pushback, Anthropic is revising a policy that stored 30 days of traffic from its Fable and Mythos models. Under new Enterprise Frontier Safeguards, customers can keep data in their own cloud and block Anthropic employees from reviewing it while automated abuse monitoring continues. Anthropic calls that privacy equivalent to zero data retention. Developed with more than 100 customers, including Salesforce, the system is due later this year. (CNBC)

Astra enters OpenAI's cyber red zone

OpenAI says Astra is its first model to reach a "Critical" cybersecurity threshold, meaning it can find unknown flaws and build exploits across well-defended systems without step-by-step human help. It's due soon, but the advanced cyber capabilities will start with a small test group before expanding through Daybreak Blue. OpenAI says Astra refused 91.5% of cyber jailbreak requests, versus 59% for GPT-5.6 Sol, and monitoring can pause suspicious activity. The Information reports Astra's latent reasoning may hide parts of its process, raising doubts about chain-of-thought monitoring. (WIRED, The Information)

Get the full show notes here: https://cisoseries.com/153m-licenses-for-sale-anthropic-reverses-course-astra-red-zone/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability02 Sep 202600:08:38

Anthropic announces safety changes and new models

USPS installs "untested" IT systems for mail-in ballots

Thousands of Exchange servers vulnerable to hijacks

Get the full show notes here: https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/ 

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

Claude sessions hijacked, AI jolts global finance, agents get too many keys01 Sep 202600:06:06

Claude sessions get hijacked

Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions. (BleepingComputer)

AI could jolt global finance

Bank of England governor Andrew Bailey is warning G20 officials that frontier AI could destabilize the global financial system by making cyberattacks faster, cheaper and easier to scale across borders. Bailey says many countries still lack protocols for how advanced models are developed and released. He also warned that a successful attack on a small number of heavily used technology providers could undermine confidence across the entire system. (The Guardian)

AI agents get too many keys

New research from Cequence Security and Enterprise Management Associates found a sizable confidence gap around AI agent permissions. 94% of surveyed organizations believe their agents don't have more access than necessary, but only 33% actually enforce least privilege. 65% have seen an agent act outside its intended role, and 29% say that caused measurable business impact. (Security Magazine)

Get the full show notes here:
https://cisoseries.com/claude-sessions-hijacked-ai-jolts-global-finance-agents-get-too-many-keys/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach31 Aug 202600:07:31

ServiceNow warns of three maximum severity security vulnerabilities

PaperCut zero-day exploited in attacks

Healthcare giant McKesson discloses breach

Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report28 Aug 202600:33:15

Read the full stories at CISOSeries.com. 

This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, ThreatDown

Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.
Manchester Airports breach, ATF agency breach, clothier Carhartt breach28 Aug 202600:07:55

Manchester Airports Group suffers cyber incident

ATF suffers data breach

Clothing retailer Carhartt suffers data breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-manchester-airports-breach-atf-agency-breach-clothier-carhartt-breach/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business.

ThreatDown. Enterprise-grade defense. Built for businesses like yours.

Chinese hackers hit US agencies, Ring locks out police, Boston Scientific feels cyber pain27 Aug 202600:06:10

China contractor hack hits US agencies

Ring throws away the key

Boston Scientific feels cyber pain

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-27-2026/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business.

ThreatDown. Enterprise-grade defense. Built for businesses like yours.

China's hackers pick DeepSeek, OpenAI blocks Russian influence push, webpages mess with local AI26 Aug 202600:06:39

China's hackers pick DeepSeek

OpenAI blocks a Russian influence push

A webpage can mess with local AI

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-26-2026/

Huge thanks to our episode sponsor, ThreatDown

If your current security posture is struggling to keep pace with fast-moving, identity-based threats, your business is exposed.

Today's security expertise gap is real, but it doesn't have to be a permanent vulnerability. ThreatDown helps SMBs move from reactive defense to proactive, 24/7 intelligence, delivering enterprise-grade protection without the headcount. Enterprise-grade defense. Built for businesses like yours.

SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing25 Aug 202600:06:30

SynkLoader throws in the kitchen sink

NIST flags multi-cloud sprawl

ReliaQuest blocks a ShinyHunters swing

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-25-2026/

Huge thanks to our episode sponsor, ThreatDown

Managing an enterprise-sized attack surface without a dedicated SOC?

As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely.

Enterprise-grade defense. Built for businesses like yours.

UK power plant hack, AI zero click, children's hospital breach24 Aug 202600:08:17

UK power plant disabled for four days by Iran-linked hackers

Zero-click Grok and Gemini chat history theft possible through cryptographic context injection

Canada's Hospital for Sick Children suffers another cyberattack

Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business.

ThreatDown. Enterprise-grade defense. Built for businesses like yours.

The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks21 Aug 202600:34:37

Read the full sotry at CISOSeries.com

This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, Vanta

  Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here. 
CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach21 Aug 202600:08:58

CISA warns of hackers exploiting critical MLflow vulnerability

ICS operators warned of AI-driven attacks on Siemens PLCs

Electronic health record company CareCloud confirms millions affected by breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/

Huge thanks to our sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed20 Aug 202600:06:55

OpenAI rewrites safety rules after threshold warning

US charges 17 in Iranian hacking campaign

Microsoft fixes Windows Defender crash bug

Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

AI "mind virus," malware living off Azure, an Irregular post-mortem19 Aug 202600:08:11

Persistent prompts prove potentially pernicious 

The malware is coming from inside Microsoft

Irregular releases AI sandbox escape post-mortem

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ 

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down18 Aug 202600:07:14

Federal agency hires North Korean IT worker

Millions of Azure records allegedly for sale

GitHub outage hits Actions and Copilot

Get the show notes here: https://cisoseries.com/cybersecurity-news-north-korean-it-worker-lands-federal-job-azure-records-go-up-for-sale-github-goes-down/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach17 Aug 202600:08:06

Max severity SAP Commerce Cloud flaw now targeted in attacks

New Mirai variant adds stealth capabilities to botnet code

Shell investigates potential incident after Clop data theft claims

Get the show notes here: https://cisoseries.com/cybersecurity-news-sap-commerce-flaw-exploited-mirai-boosts-capabilities-shell-investigates-breach/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

The Department of Know: Ransomware gangs, Copilot apps, and drones phone home14 Aug 202600:33:20

Read the full stories at CISOSeries.com

This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy14 Aug 202600:08:38

Akira affiliate's innovative "crash mode" attack almost worked

WhatsApp rolls out scam alert feature

White House looks to private sector for help against offensive hacking

Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/

Huge thanks to our sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON13 Aug 202600:07:34

UK eyes AI gene-synthesis guardrails

DeadLock puts ransomware on the blockchain

An evil twin flies home from DEF CON

Episode show notes: https://cisoseries.com/uk-tackles-ai-bioweapon-risk-deadlock-goes-on-chain-evil-twin-flies-home-from-def-con/

Huge thanks to our sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline12 Aug 202600:06:59

Water systems get a federal cyber lifeline

Hackers jump into Polish power plant

Cyberattacks knock local governments offline

Episode show notes:  https://cisoseries.com/water-systems-cyber-lifeline-hackers-polish-power-plant-local-governments-offline/

Huge thanks to our sponsor, ThreatLocker

Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits11 Aug 202600:06:39

OpenAI loosens cyber limits for vetted defenders

Sandworm's fake recruiters plant a poisoned VPN

Royal Navy drones phone home to China

Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/

Huge thanks to our sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady10 Aug 202600:07:44

OpenAI slows release of Astra model citing cyber capabilities

Irregular won't say if there were more rogue incidents

U.S. cyber ambassador nominee Cassady confirmed in Senate

Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/

Huge thanks to our sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso. 

Faked bug reports, Meta's rogue AI, China investigates Palo Alto07 Aug 202600:08:28

Apple's bug bounty program overwhelmed by fake AI generated reports

China launches cybersecurity review into Palo Alto Networks products

Meta AI hacks external systems during cybersecurity testing

Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/

Huge thanks to our episode sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon06 Aug 202600:06:33

AI safety tests spill onto the real internet

Private Relay flaw unmasks IP addresses

Weak telcos left door open for Salt Typhoon

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/

Huge thanks to our episode sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

 

© My Podcast Data · Projet indépendant · Données issues d'Apple & Spotify