In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
We love some good vulnerability reporting drama, this time FFmpeg’s got beef with GoogleOpenAI announces its Aardvark bug-gobbling systemTwo US ransomware responders get arrested for… ransomwareMemento (nee HackingTeam) CEO says: Sì, those are totally our tools getting snapped in RussiaHackers help freight theft gangs steal shipments to resellA second Jabber Zeus mastermind gets his comeuppance 15 years onThis week’s episode is sponsored by Nucleus Security, who make a vulnerability information management system. Co-founder Scott Kuffer says that approaches for triaging vulnerabilities have started to fall apart, given there are just. So. Many. And they’re all important!
This episode is also available on Youtube.
Show notes
vx-underground on X: "Yeah, so pretty much this entire drama thing is FFmpeg are a bunch of nerds…"FFmpeg on X: "@DavidEGrayson It's someone's hobby project of an obscure 1990s decoder…"Halvar Flake on X: "Given the extremely big role ffmpeg has played historically..."thaddeus e. grugq on X: "Current drama: Plucky security researcher Google takes on volunteer open source behemoth FFmpeg."Robert Graham on X: "Current status: There's a conflict between Google…"Introducing Aardvark: OpenAI’s agentic security researcher | OpenAIBugcrowd acquires Mayhem Security to advance AI-powered security testing | CyberScoopProsecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks | CyberScoopFormer Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being "Utilized" by Different Broker in South KoreaHow an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia | TechCrunchOperation Zero — A Zero-Day Vulnerability PlatformJohn Scott-Railton on X: "7/ There's a push to scale up America's offensive industry right now…"CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware | TechCrunchExploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed Microsoft Teams Vulnerabilities UncoveredCargo theft gets a boost from hackers using remote monitoring tools | The Record from Recorded Future NewsRemote access, real cargo: cybercriminals targeting trucking and logistics | Proofpoint USAlleged Conti ransomware gang affiliate appears in Tennessee court after Ireland extradition | The Record from Recorded Future NewsThree suspected developers of Meduza Stealer malware arrested in Russia | The Record from Recorded Future NewsAlleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody – Krebs on SecurityWindows Server Update Service exploitation ensnares at least 50 victims | Cybersecurity DivePost by @paulschnack.bsky.social — Bluesky