
Sign up to save your podcasts
Or


Based on Podcast App listening data
Please consider supporting the DefSec podcast here.
1. AI agents broke into 395 organisations, including ones their operator ruled out https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/
2. A nuclear agency lost reactor data to an ownCloud bug patched two years earlier https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
3. One in ten exposed AI gateways still accept the example key from the setup guide https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html
4. Click rate falls when your phishing tests get easier, not when your people get better https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
5. Microsoft ships 974 fixes, and the bottleneck moves to whoever has to test them https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
Please consider supporting the DefSec podcast here.
1. CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html
2. CISA: Most exploited vulnerabilities should have been eradicated decades ago https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194
3. North Korean Fake Employees Move Into Sales, Marketing and Healthcare Roles https://www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/
4. Unit 42 says one attacker chained 50 vulns and attack paths in 10 hours https://www.cybersecuritydive.com/news/frontier-ai-tipping-scales-cyber-adversaries/829088/
5. AI Bug Report Flood Is Cratering Bounty Prices and Triage Queues https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
Please consider supporting the DefSec podcast here.
Stories:
Weak IAM affects up to 98% of cloud environments
https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
China-Linked Storm-1175 Debuts New StormEncryptor Ransomware via N-central Flaw
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
‘City-Forum’ Campaign Quietly Mines Salesforce/ServiceNow Guest Access Since March 2025
https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow
LiteLLM ‘Supply Chain Attack’ Was Mostly Fallout From Trivy Compromise Days Earlier
https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
ChainDrop Worm Spreads Through npm, Slips Past Standard Security Tooling
https://www.theregister.com/security/2026/08/15/chaindrop-worm-crawls-into-npm-supply-chain-evades-standard-defenses/5287958
Please consider supporting the DefSec podcast here.
Stories:
1. Ransomware Gangs Bypass the CEO, Target the 40-Something IT Manager
https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499
2. Ransomware Attacks Spike While Industry Attention Shifts to AI
https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934
3. ChainDrop supply chain compromise: Anatomy of a self-propagating worm
https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
4. AI Agent Tried to Backdoor a Real Open-Source Repo During a Security Test
https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html
5. Cloudflare Ditches Most Third-Party Security Tools — But Says Don’t Copy Them
https://www.theregister.com/security/2026/08/04/cloudflare-has-mostly-ditched-third-party-security-tools-suggests-not-trying-that-at-home/5282600
Please consider supporting the DefSec podcast here.
Stories:
https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
Please consider supporting the DefSec podcast here.
Stories:
https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353
https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924
https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/
https://databreaches.net/2026/07/04/adapthealth-says-attackers-sweet-talked-their-way-into-cloud-systems-and-stole-patient-data
https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html
Please consider supporting the DefSec podcast here.
Links to stories:
https://www.securityweek.com/massive-password-spray-campaign-targeting-azure-cli/
https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html
https://www.cybersecuritydive.com/news/klue-investigating-supply-chain-attack-salesforce-integrations/823532/
https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks
https://www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk
Please consider supporting the DefSec podcast here.
This week’s stories:
https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/
https://www.bleepingcomputer.com/news/security/openclaw-ai-agent-found-falling-for-phishing-attacks-spills-user-data/
https://www.cybersecuritydive.com/news/cisa-vulnerability-remediation-prioritization-directive/822504/
https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/
https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4
Please consider supporting the DefSec podcast here.
Links to this week’s stories:
https://www.theregister.com/cyber-crime/2026/06/05/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks/5251891
https://thehackernews.com/2026/06/only-10-of-socs-say-theyre-getting.html?m=1
https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/
https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/
https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
https://www.cybersecuritydive.com/news/ai-cybersecurity-hype-reality-check-gartner/821867/0:0
From the publisher's feed
Ranked by our users in the last 21 days

192 Listeners

286 Listeners

2,012 Listeners

624 Listeners

375 Listeners

652 Listeners

1,028 Listeners

423 Listeners

8,068 Listeners

180 Listeners

191 Listeners

201 Listeners

73 Listeners

139 Listeners

682 Listeners