On this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news.
Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on themMeanwhile, researchers are choosing full disclosure instead of engaging MSRCMeta’s AI support agent allowed a staggering 20,000 accounts to be stolen!Apple pulls Russia’s MAX messenger from the App Store and disables notificationsAnthropic gives the public our first Mythos-class model but it won’t do cybersecurity workStripe and Google Tag Manager used in eCommerce website hack campaignAnd much, much more!This week’s show is brought to you by runZero. HD Moore, runZeros’ founder, drops by in this week’s sponsor interview to talk about the AI vibe shift. Everyone is very worried about getting owned all of a sudden, and it’s really changing the cybersecurity business.
This episode is also available on YouTube.
Show notes
Microsoft Hacked to Deliver Malware to Claude and Gemini Users | 404.feed.pressResearcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process | therecord.mediaMicrosoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges | BleepingComputerMicrosoft breaks Patch Tuesday record with 206 vulnerabilities | CyberScoopchompie1337 | XWhatsApp says NSO targeted users with spearfishing attacks in violation of court order | therecord.mediaOver 20,000 Instagram accounts stolen in Meta AI support hack | BleepingComputerNew Apple feature automatically changes your compromised passwords | BleepingComputerApple removes Russia’s state-backed messaging app Max from its store | therecord.mediaExclusive: Anthropic's Mythos can exploit new flaws in hours | Anthropic’s new model is Mythos on a leash | CyberScoopAnthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of You | wired.comOpenClaw AI agent found falling for phishing attacks, spills user data | BleepingComputerOpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks | TechCrunch SecurityHands on with Intelligent Terminal, an AI-powered Windows Terminal | BleepingComputerSeeking Counsel: Ongoing Targeted Campaign Against US Law Firms | MandiantCheck Point warns of zero-day flaw targeted by ransomware affiliate | Cybersecurity DiveServiceNow discloses security incident exposing customer data | BleepingComputerCredit card theft campaign abuses Stripe to host stolen payment info | BleepingComputerCrowdStrike, Palo Alto Networks defy estimates as AI fuels cyber demand | Cybersecurity DiveThe U.S. Military Quietly Turned GPS Into a Global ‘Numbers Station,’ Evidence Suggests | 404.feed.pressNew 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute | BleepingComputerGoogle has quietly cut staff across its Cloud business | businessinsider.com