Talkin' Bout [Infosec] News

Rickrolling the FIFA World Cup - 2026-06-22


Listen Later

This week’s episode covers a series of cybersecurity stories, including a researcher’s discovery of vulnerabilities in FIFA’s World Cup platform that could have enabled unauthorized administrative access and even the ability to alter live broadcasts. The team also discusses the risks of large-scale identity verification data exposure, supply chain attacks impacting the scientific research community, ongoing fallout from Broadcom’s VMware acquisition, and legal challenges from major organizations facing rising VMware costs. Along the way, the hosts share commentary on AI-related security concerns, access control failures, and the broader impact of vendor decisions on enterprise security.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters

  • (00:00) - PreShow Banter™ — There's always more suppply chain
  • (04:52) - Rickrolling the FIFA World Cup - 2026-06-22
  • (07:59) - Story #1 - Texas Government Data Breach Exposes 3 Million Driver’s License Records
  • (10:56) - Story #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
  • (21:00) - Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure
  • (23:58) - Story #4a - Stakeholder-Specific Vulnerability Categorization (SSVC)
  • (25:44) - Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for Everyone
  • (37:19) - Story #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
  • (43:56) - Story #6 - FBI disrupts massive AI-powered phishing service using a million URLs
  • (46:12) - Story #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
  • (47:12) - Story #8 - AI models that can take down governments and business months away, rare Five Eyes statement warns
  • (48:44) - Story #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURS
  • (58:45) - Story #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”

  • Links
    Story #1 - Texas Government Data Breach Exposes 3 Million Driver’s License Records
    Story #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
    Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure
    Story #4a - Stakeholder-Specific Vulnerability Categorization (SSVC)
    Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for Everyone
    Story #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
    Story #6 - FBI disrupts massive AI-powered phishing service using a million URLs
    Story #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
    Story #8 - AI models that can take down governments and business months away, rare Five Eyes statement warns
    Story #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURS
    Story #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”

    Creators & Guests

  • Andy Pettit "Nerf" - Guest
  • Michael "Shecky" Kavka - Guest
  • Ryan Poirier - Producer
  • Corey Ham - Host
  • Ralph May - Host
  • John Strand - Host

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    Talkin' Bout [Infosec] NewsBy Black Hills Information Security

    • 4.8
    • 4.8
    • 4.8
    • 4.8
    • 4.8

    4.8

    92 ratings


    More shows like Talkin' Bout [Infosec] News

    View all
    Hacked by Hacked

    Hacked

    187 Listeners

    This Week in Tech (Audio) by TWiT

    This Week in Tech (Audio)

    3,063 Listeners

    Security Now (Audio) by TWiT

    Security Now (Audio)

    2,010 Listeners

    Risky Business by Risky Business Media

    Risky Business

    376 Listeners

    Talk Python To Me by Michael Kennedy

    Talk Python To Me

    583 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    649 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    316 Listeners

    Click Here by Recorded Future News

    Click Here

    422 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,058 Listeners

    The Jordan Harbinger Show by Jordan Harbinger

    The Jordan Harbinger Show

    11,988 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    313 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    136 Listeners

    The 404 Media Podcast by 404 Media

    The 404 Media Podcast

    398 Listeners