In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
L3Harris Trenchant boss accused of selling exploits to Russia once worked at the Australian Signals DirectorateMicrosoft WSUS bug being exploited in the wildDan Kaminsky DNS cache poisoning comes back because of a bad PRNGSpaceX finally starts disabling Starlink terminals used by scammersGarbage HP update deletes certificates that authed Windows systems to EntraThis week’s episode is sponsored by automation company Tines. Field CISO Matt Muller joins to discuss how Tines has embraced LLMs and the agentic-AI future into their workflow automation.
This episode is also available on Youtube.
Show notes
US accuses former L3Harris cyber boss of stealing and selling secrets to Russian buyer | TechCrunchAttackers bypass patch in deprecated Windows Server update tool | CyberScoopCVE-2025-59287 WSUS Unauthenticated RCE | HawkTraceCVE-2025-59287 WSUS Remote Code Execution | HawkTraceCatching Credential Guard Off Guard - SpecterOpsCache poisoning vulnerabilities found in 2 DNS resolving apps - Ars TechnicaUncovering Qilin attack methods exposed through multiple casesSafety on X: "By November 10, we’re asking all accounts that use a security key as their two factor authentication (2FA) method to re-enroll their key to continue accessing X. You can re-enroll your existing security key, or enroll a new one. A reminder: if you enroll a new security key, any" / XSpaceX disables more than 2,000 Starlink devices used in Myanmar scam compounds | The Record from Recorded Future NewsSpaceX: Update Your Inactive Starlink Dishes Now or They'll Be BrickedHow we linked ForumTroll APT to Dante spyware by Memento Labs | SecurelistFormer Polish official indicted over spyware purchase | The Record from Recorded Future NewsHP OneAgent Update Broke Entra Trust on HP AI DevicesWindows' Built-in OpenSSH for Offensive SecurityHow Hacked Card Shufflers Allegedly Enabled a Mob-Fueled Poker Scam That Rocked the NBA | WIRED