Back

Explore every episode of the podcast Daily Cyber Briefing

Dive into the complete episode list for Daily Cyber Briefing. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 69

TitlePub. DateDuration
Airstalk, AI Hijacks, and Cargo Theft in the Supply Chain03 Nov 202500:08:21

Today, we dissect how a suspected Chinese APT used the new 'Airstalk' malware to compromise BPOs in targeted supply chain attacks, and why the Claude AI model was successfully tricked into exfiltrating user data. Plus, we look at the rising threat of cybercriminals exploiting legitimate RMM tools to steal physical cargo from logistics networks.

KEV Alert: China-Linked Zero-Days, WSUS Exploits, and the Diplomats' Digital Woes31 Oct 202500:07:45

CISA issued urgent warnings, adding exploited VMware and XWiki flaws to the KEV catalog and requiring federal agencies to patch immediately. We break down the Chinese threat actor exploiting an unpatched Windows shortcut vulnerability targeting European diplomats and examine the active exploitation of the critical Windows WSUS flaw.

PhantomRaven, Supply Chain Bombs, and the $35 Million Insider Threat30 Oct 202500:09:14

 We dive into two major software supply chain campaigns, including the "PhantomRaven" operation, which delivered infostealers via 136 malicious NPM packages downloaded 100,000 times. Then, we look at why vetting dependencies is no longer enough and examine the shocking case of a US defense contractor executive who sold $35 million in cyber trade secrets to a Russian exploit broker.

DELMIA Exploits, Copilot Confusion, and Qilin's Evasive Maneuvers29 Oct 202500:10:12

Today we dive into critical industrial cyber threats as CISA warns of active exploitation in DELMIA factory software. We also examine Google's move to make HTTPS the default for all public sites and review the massive lawsuit alleging Microsoft tricked millions of users into pricey Copilot subscriptions.

Agentic AI Risks, Industrial Hacks, and the Death of the Privacy Light28 Oct 202500:08:26

Today we dive into the inevitability of prompt injection as agentic AI takes over enterprise functions, and reviews massive credential theft data circulating online. Plus, learn why industrial giants are falling victim to Oracle EBS exploits and how a $60 mod is killing privacy protections on smart glasses.

AI Jailbreaks, Hacking Team Spyware, and the Million-Dollar Exploit That Wasn't27 Oct 202500:12:10

Today, we dive into critical AI browser vulnerabilities, including a trick that weaponizes the OpenAI Atlas omnibox, and analyze the spectacular flop of a promised $1 million WhatsApp exploit at Pwn2Own. Plus, we cover active exploitation of a critical Windows Server WSUS vulnerability and the shifting economics of ransomware.

High-Severity Zero-Days, Cache Poisoning, and the AI Code Judgment Crisis23 Oct 202500:09:59

Today we dive into critical updates for BIND against high-severity cache poisoning flaws, the zero-day exploitation of Lanscope Endpoint Manager that requires immediate federal attention, and the serious governance concerns raised by "vibe coding" and AI-generated code's lack of judgment. We also examine Verizon’s latest Mobile Security Index, highlighting soaring mobile device attacks and the alarming rise of AI-powered threats like deepfakes and SMS phishing.

 

Patch Wars: Russian APT Evasions, Chinese Espionage, and the Critical Windows SMB Flaw22 Oct 202500:08:32

CISA is ringing the alarm on actively exploited Windows SMB flaws while Chinese threat actors leverage a recently patched SharePoint vulnerability for espionage. We also detail how the Russian APT Star Blizzard rapidly changed tactics after researchers exposed their prior malware, and review critical vulnerabilities affecting TP-Link Omada Gateways.

Patch Panic, Deceptive AI, and Unsinkable C&C:21 Oct 202500:09:04

 CISA confirms multiple zero-day exploits, including a critical Oracle EBS vulnerability being leveraged by groups tied to Cl0p, necessitating immediate action from federal agencies and private enterprises. Meanwhile, we examine how threat actors are distributing global malware disguised as legitimate AI productivity tools and explore a highly sophisticated supply chain attack using the Solana blockchain for an untakeable command-and-control infrastructure.

Hacking the Skies, Time, and Messaging: NSO Gets Banned & The AI Escalation20 Oct 202500:10:07

Today. we unpack the fallout from a massive Oracle E-Business Suite hack that targeted American Airlines subsidiary Envoy Air, exposing business information from the regional carrier. We also dive into high-stakes cyberwarfare, covering China's accusation that the US attacked its critical National Time Center and Microsoft's report on how foreign adversaries are weaponizing AI.

$15 Billion Scams, CentreStack Zero-Days, and the 17 Million Account Breach Fallout17 Oct 202500:08:35

Today we dive into the industrial scale of cybercrime, discussing the seizure of $15 billion in crypto assets linked to forced-labor scam networks and the staggering 17.6 million accounts impacted by the Prosper data breach. Plus, we analyze urgent patches for exploited zero-days in CentreStack and critical DoS flaws in industrial UPS devices.

Rootkits, State Spies, and the $14 Billion Bitcoin Bust16 Oct 202500:11:28

Today, we dive into Operation ZeroDisco, where threat actors deployed rootkits onto older Cisco routers by exploiting a recent zero-day. We also analyze the consequences of the Discord breach, F5's revelation of a nation-state attack that stole source code, and the massive crypto "pig butchering" scam that led to the seizure of over $14 billion in Bitcoin.

Patch Tuesday Mayhem: Zero-Days, Critical ICS Flaws, and Why Synced Passkeys are a Digital Shenanigan15 Oct 202500:11:02

Today, we unpack the massive October 2025 Patch Tuesday, covering exploited Windows zero-days, critical vulnerabilities in Adobe Connect and major ICS vendors like Red Lion, Siemens, and Rockwell. Plus, a deep dive into why enterprise organizations must ditch synced passkeys for device-bound credentials to prevent sophisticated authentication downgrade attacks.

Hacking Harvard, Pixels, and Patches: The Cl0p, Pixnapping, and RMPocalypse Rundown14 Oct 202500:11:58

This morning, we dive deep into major zero-day exploitation, including the Cl0p campaign targeting Oracle EBS, which has claimed Harvard University as a victim. We also dissect the new Pixnapping attack stealing 2FA codes from Android phones and examine the urgent implications of the RMPocalypse flaw affecting AMD's confidential computing.

Apple's $2 Million Bounty, Payroll Pirates, and the Takedown of GXC Team13 Oct 202500:11:57

Host Mike Housch dissects Apple's massive $2 million bug bounty expansion, focusing on incentives for finding zero-click RCEs, and analyzes the high-stakes Salesforce customer data leaks claimed by the Scattered LAPSUS$ Hunters extortion group. We also cover critical warnings about the "Payroll Pirate" university salary attacks and the dismantling of the global GXC Team Crime-as-a-Service operation.

MS Teams Hack, MFA Hijacking, $2B Crypto Heist, Apple Siri Probe & More10 Oct 202500:09:09

Today we dive into the staggering 2 billion cryptocurrency heist linked to North Korea and explore how sophisticated threat groups are abusing trusted corporate platforms like Microsoft Teams for financial extortion. We also look at the massive pushback against the E.U.'s controversial "Chat Control" proposal and unveil a new, almost unbelievable attack that turns your standard optical mouse into a covert listening device.

Credential Stuffing, Oracle Zero-Days, and Attacking Public Safety08 Oct 202500:09:58

This week on Cyber Scoops & Digital Shenanigans, host Mike Housch delves into the recent credential stuffing campaign targeting DraftKings users and the sophisticated exploitation of a critical Oracle E-Business Suite zero-day flaw. We also examine breaches at military radio manufacturer BK Technologies and beer giant Asahi, emphasizing how even essential and everyday businesses are prime targets for skilled threat actors.

Digital Dominoes: The New Chain Reaction of Cyber Chaos07 Oct 202500:08:00

In this episode of Cyber Scoops & Digital Shenanigans, host Mike Housch unpacks the week’s most critical cyber incidents shaking enterprises worldwide, from SharePoint zero-days and AI-powered phishing campaigns to rising healthcare ransomware, industrial control system breaches, and mobile malware stealing bank credentials. With billions in crypto losses and attackers outpacing EDR defenses, Mike dives into how state-sponsored actors, misconfigured containers, and compromised supply chains are forming a perfect storm in cybersecurity. Tune in for sharp insights, real-world examples, and the strategies organizations must deploy now to survive the evolving digital battlefield.

Breaches, Bugs, and Blind Spots: Cyber Chaos Unfolds02 Oct 202500:12:05

Mike and Angela break down a massive Motility dealership software breach impacting 766,000 people, a wiretap-style attack that cracks Intel’s SGX, hackers raiding Oracle ERP customers, and a critical Red Hat OpenShift AI bug. They also dig into cybercriminals bragging about 28,000 new victims and why detection gaps still leave organizations blind. Real stories, real impact, and a few laughs along the way.

The $50 Hack That Broke Intel & Why AI Still Needs its Meatbags01 Oct 202500:10:05

 Autonomous AI is crashing against the rocks of reality, stalled by a massive trust crisis and fears over governance, while chip giants brush off a $50 hardware hack that breaks their confidential computing promises. We also dissect Broadcom's zero-day silence and the never-ending nightmare of identity theft for major corporations like WestJet.

Policy Lapses, Sudo Root, and the Ransom of the Ryes30 Sep 202500:08:38

The feds are nuking essential threat sharing programs just as core security legislation lapses, leaving state and local governments scrambling for defenses and exposed to novel threats. Plus, we explore a critical Sudo flaw exploited in the wild, and ask why international brewing giant Asahi couldn't keep its production lines—and its delicious beer—safe from digital shenanigans.

Episode 23 (9/29/202529 Sep 202500:06:49

Today we dissect the new wave of low-profile, high-impact cybercrime, starting with Akira ransomware operators leveraging legitimate IT tools to blend in, giving defenders only hours to respond. Then, we scrutinize the UK government's massive financial intervention following the JLR attack, asking: Did that £1.5 billion bailout just paint a giant target on the UK?

Episode 22 (9/26/2025)26 Sep 202500:11:08

Today, we expose nation-state spies playing the 400-day waiting game and the pure negligence of major vendors dragging their feet while zero-days rip through critical infrastructure. Plus, we talk North Korean identity theft rings recruiting Western devs and how a $5 domain hijacked Salesforce's high-tech AI agents.

Episode 21 (9/25/2025)25 Sep 202500:09:11

Forget your exotic zero-days; today, we break down how basic security failures are wiping centuries-old businesses off the map because of one weak password. We also dig into the massive, hidden telecom network in New York City that could have crippled 911 services right when world leaders gathered for the U.N. General Assembly.

 

Episode 20 (9/23/2025)23 Sep 202500:05:20

Today, we break down the latest cyber chaos, from a massive ransomware attack crippling major European airports into a manual check-in nightmare, to the systemic risks of relying on outsourced trust in the Stellantis data breach. Plus, Host Mike Housch dives into the silent epidemic of ‘digital ghosts’—the rogue AI agents and non-human identities taking over your company’s attack surface

Episode 19 (9/19/2025)19 Sep 202500:05:47

This week on Cyber Scoops & Digital Shenanigans, we expose the "One Token to Rule Them All" Microsoft flaw that could have unlocked nearly every tenant worldwide. Plus, we dive into how AI is solving CAPTCHAs and leaking secrets from your Gmail via hidden, white-on-white text instructions.

Episode 18 (9/18/2025)18 Sep 202500:09:05

This episode of Cyber Scoops & Digital Shenanigans covers significant cybersecurity incidents, including Google Chrome patching its sixth zero-day vulnerability of 2025, a ransomware attack impacting over 12,000 individuals at venture capital firm Insight Partners, and data breaches at Tiffany & Company and Medical Associates of Brevard affecting thousands of customers and nearly 250,000 individuals, respectively. Furthermore, the episode discusses SonicWall prompting password resets after hackers obtained backup firewall configurations via brute force attacks and highlights the alarming development of threat actors like RevengeHotels using AI to generate malware for attacks on hotels.

Episode 17 (9/17/2025)17 Sep 202500:11:27

Today I discuss the persistent threat of the decade-old Pixie Dust Wi-Fi hack, the widespread impact of the self-replicating Shai-Hulud supply chain worm on NPM packages, and the successful disruption of the RaccoonO365 phishing-as-a-service operation. The episode also touches on Apple's recent security patches, a novel Rowhammer attack on DDR5 memory, and new vulnerabilities in ChatGPT's calendar integration.

Episode 16 (9/16/2025)16 Sep 202500:09:29

Today’s episode covers Apple's extensive backports and new OS releases to patch over 50 vulnerabilities, including a critical ImageIO flaw (CVE-2025-43300) exploited in targeted spyware attacks against WhatsApp users. Another significant concern is the "FileFix" social engineering campaign, which leverages deceptive Facebook security alerts to trick victims worldwide into executing StealC information-stealing malware via malicious images downloaded from legitimate platforms like BitBucket. Furthermore, researchers have demonstrated "Phoenix," a novel Rowhammer attack (CVE-2025-6202) capable of achieving root access on DDR5 memory systems in under two minutes, despite advanced in-DRAM refresh mechanisms. Finally, an emerging threat involves ChatGPT's calendar integration, which can be exploited with specially crafted invites to exfiltrate sensitive emails, highlighting broader vulnerabilities in AI assistant integrations with enterprise tools. China's new cybersecurity regulations, demanding incident reporting within one hour, underscore a global trend towards stricter disclosure requirements in the face of these escalating cyber threats.

Episode 15 (9/15/2025)15 Sep 202500:14:49

his episode of Cyber Scoops & Digital Shenanigans highlights the escalating threat of browser-based attacks, encompassing advanced phishing, malicious copy-paste techniques like "ClickFix", dangerous OAuth integrations, and pervasive browser extensions targeting business apps and data. We also examine the critical need for proper data destruction of old hardware to avoid multi-million dollar liabilities, referencing NIST 800-88 guidelines for data sanitization and instances like Morgan Stanley Smith Barney's $155 million in fines. Additionally, the episode covers actively exploited zero-day vulnerabilities in Samsung Android (CVE-2025-21043) and DELMIA Apriso factory software (CVE-2025-5086), the North Korean Kimsuky gang's weaponization of AI for fake IDs and espionage, the emergence of HybridPetya ransomware bypassing UEFI Secure Boot, CISA's controversial push for control over the CVE program, and China's escalating antitrust probe into Nvidia.

Episode 14 (9/12/2025)12 Sep 202500:10:35

Today's podcast we discuss current cybersecurity landscape threats, ranging from large-scale data breaches, such as the one impacting over 100,000 individuals at Cornwell Quality Tools, to critical vulnerabilities in payment systems that take over a year to patch and silent code execution risks in AI-powered code editors. These challenges are compounded by a booming US investment in surveillanceware that undermines government efforts to regulate the market, and new cloud isolation-breaking Spectre attacks devised by academic researchers

New Episode 9/11/2025, 8:17:01 AM11 Sep 202500:07:40

This episode includes:

LNER, the British rail operator, suffering a data breach through a third-party supplier, compromising customer contact and journey details.

Jaguar Land Rover's admission of a data breach following a cyberattack that caused global factory shutdowns, with the Scattered Spider group claiming responsibility.

A critical weakness in the Cursor AI editor, which disables VS Code's "Workspace Trust" feature, allowing automatic execution of malicious code from repositories—a behavior its developers intend to maintain.

A remote CarPlay hack that puts millions of drivers at risk of distraction and surveillance due to unpatched vulnerabilities that allow attackers to take over car screens and eavesdrop.

The Akira ransomware group actively exploiting SonicWall SSL VPN flaws and misconfigurations, particularly targeting the manufacturing and transportation sectors.

Episode 12 (9/10/2025)10 Sep 202500:05:33

This morning, we've got an awesome lineup of stories that prove the internet is less like a friendly neighborhood and more like a lawless frontier. We're talking about Apple fighting off state-sponsored snoops, China-backed hackers playing dirty tricks, a Ukrainian ransomware kingpin with an $11 million bounty on his head, and the terrifying rise of 2FA-bypassing phishing kits.

Episode 11 (9/9/2025)09 Sep 202500:06:51

Today we're diving into the chilling reality that your digital life is under siege from every direction imaginable; from the geopolitical chessboard to the very tools designed to keep you safe. Buckle up, because what you don't know can and will hurt you.

Episode 10 (9/8/2025)08 Sep 202500:06:39

The so-called “AI ransomware” turns out the story is not what it seems and last weeks recap, which reads like the apocalypse bingo card for security teams.

Episode 9 (9/5/2025)05 Sep 202500:07:45

Today’s lineup includes school data breaches, misconfigured CMS keys, an AI tool that’s actually useful, malware boosting gambling sites on Google, Microsoft charging rent for Windows 10, and even a $10 million bounty on some very busy Russian hackers.

Episode 7 (9/4/2025)04 Sep 202500:05:42

Welcome back to Cyber Scoops & Digital Shenanigans! I’m your host, Mike Housch, and today we’re diving headfirst into a whirlwind of cyber stories — from false alarms that rattled billions to AI-fueled battles shaping the future, and even a dash of academic espionage. Buckle up. This ride through cybersecurity is going to be equal parts thrilling and exasperating.

Episode 6 (9/3/2025)03 Sep 202500:10:05

Cyber Scoops & Digital Shenanigans dives into a whirlwind of cyber drama—from false Gmail hack rumors and record-breaking DDoS attacks to state-sponsored espionage, phishing campaigns, and major supply chain breaches. Host Mike Housch breaks down the stories shaping today’s digital battlefield and reminds listeners why cyber resilience is more critical than ever.

Episode 5 (9/2/2025)02 Sep 202500:06:54

Compromise of the NX build system infects 1000 developers' popular enterprise web content management systems let attackers remotely execute code. Amazon disrupts a sophisticated multi-factor authentication device code campaign. Salesforce data theft attacks gets worse.

Episode 4 (8/29/2025)29 Aug 202500:16:19

This episode covers the critical cyber events of the last 24 hours. We analyze the cascading impact of the supply chain attack on a Swedish IT provider and discuss the massive data breach at TransUnion. We also dive into a new joint intelligence advisory on the China-linked APT group "Salt Typhoon" and its targeting of critical infrastructure.

Episode 3 (8/28/2025)28 Aug 202500:15:25

Today’s podcast will cover critical vulnerabilities like the Git arbitrary file write (CVE-2025-48384) and an exploited Citrix NetScaler zero-day (CVE-2025-7775), which can lead to remote code execution. These are compounded by widespread data breaches affecting entities such as Farmers Insurance and Salesforce customers, supply chain attacks like the Nx NPM package poisoning, and the emergence of AI-powered ransomware.

Episode 2 (8/27/2025)27 Aug 202500:17:44

Recent security reports reveal several critical vulnerabilities, including a Docker Desktop flaw (CVE-2025-9074), a Git arbitrary file write (CVE-2025-48384), and an exploited zero-day in Citrix NetScaler (CVE-2025-7775), all requiring urgent patching. Furthermore, AI systems are susceptible to prompt injection via image scaling attacks, and real-world incidents encompass a Salesforce data theft campaign (UNC6395), AI-powered ransomware (PromptLock), and disruptive ransomware attacks against public services in Maryland and state offices in Nevada.

Episode 1 (8/26/2025)26 Aug 202500:16:00

This episode includes a major data breach at Farmers Insurance affecting 1.1 million customers due to a Salesforce-targeted hack, a global phishing campaign spreading UpCrypter malware, and a Pakistan-linked group targeting Indian government agencies with malware. It also covers a critical Docker Desktop vulnerability, espionage involving hijacked Wi-Fi logins, and the emergence of AI injection attacks using steganography, alongside a significant Interpol cybercrime operation in Africa.

© My Podcast Data · Independent project · Data from Apple & Spotify