On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.
Mini Shai-Hulud and the TanStack compromise using Github ActionsInstructure pays Canvas elearning platform data extortionistsMore Linux privilege escalation 0days!CISA helping critical infrastructure operators rearchitect their networks so they work offlineThis week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.
This episode is also available on Youtube.
Show notes
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack | CyberScoopHardening TanStack After the npm Compromise | TanStack BlogCanvas Breach Disrupts Schools & Colleges Nationwide – Krebs on SecurityInstructure pays ransom after Canvas incident as Congress announces investigation | The Record from Recorded Future NewsWhen DNSSEC goes wrong: how we responded to the .de TLD outageAdversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Google Cloud BlogMythos smythos! How to find 0day with lesser models - Risky Business MediaGitHub - V4bel/dirtyfrag · GitHubretr0.zipNVD - CVE-2026-42511Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoopIvanti customers confront yet another actively exploited zero-day | CyberScoopPalo Alto warns of critical software bug used in firewall attacks | The Record from Recorded Future NewsWhere Have All the Complex Windows Malware and Their Analyses Gone?Meet Rassvet, Russia’s Answer to Starlink | WIREDDOJ says ransomware gang tapped into Russian government databases | TechCrunchIranian government hackers using Chaos ransomware as cover, researchers say | The Record from Recorded Future NewsFoxconn confirms cyberattack impacting North American factories | The Record from Recorded Future NewsNew CISA initiative aims for critical infrastructure to operate offline during cyberattacks | The Record from Recorded Future News‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the WorldHow to Disable Google's Gemini in Chrome | WIREDFCC pushes ban on security updates for foreign-made routers, drones to 2029 | The Record from Recorded Future News