State of Cybercrime

State of Cybercrime

By Varonis, Matt Radolec, David GibsonBusinessTechnology
Download on the App Store

State of Cybercrime episodes

  • ShinyHunters Attacks The FBI

    ShinyHunters claims it stole 2-3 TB of FBI data and shared a sample with researchers containing information on employees, applicants, and even family members.

    The FBI has acknowledged unauthorized activity affecting FBIjobs.gov but has not commented on the broader allegations.

    A defaced FBI jobs site. Thousands of alleged employee records. A public ultimatum to the FBI to retract statements made in its May threat advisory.

    Join Matt and David as they unpack one of the boldest cybercrime stories of the year, along with ShinyHunters' apparent takeover of Cl0p's leak site, and an AI security test that targeted a real organization.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    26 min
  • Cl0p's Blueprint Heist


    If your company runs PTC Windchill, Cl0p may already have your blueprints. Forty-plus companies. One unpatched hole in PTC's product lifecycle management software. A custom-built tool that CL0p used to crack every password on the system like a Windchill-shaped skeleton key. Shell, GE, Philips — all on the list. On the next episode of State of Cybercrime, Matt and David break down exactly how this exploitation campaign works, and what it means if your engineering data has ever touched Windchill. Plus: 1,200 rogue OpenAI agents that hacked Hugging Face on their own, the 12th Langflow bug exploited in 2026, and a JFrog flaw letting attackers forge admin access to your software supply chain.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    30 min
  • The Hugging Face Breach


    Out of the sandbox and into the fire. During an OpenAI security evaluation, an AI agent escaped its test environment and breached Hugging Face in search of information that could help it complete its assignment. No attacker. No malicious instructions. This agent independently concluded that breaking into another company’s systems was the fastest path to success. Join Matt and David as they dissect the breach step by step and explore what happens when an AI decides security boundaries are merely suggestions rather than rules.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    27 min
  • The Ransomware That Ran Itself

    More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    39 min
  • Megalodon Poisons Github

    More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    30 min
  • The Canvas Breach

    More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    30 min
  • The Axios Supply Chain Attack

    The Axios supply chain attack proves attackers don’t need vulnerabilities if they can hit the assembly line. By compromising a single npm maintainer account, they were able to slip a trojan into Axios updates that executed automatically inside developer machines and CI/CD pipelines long before security tools could intervene. On this episode of State of Cybercrime, Matt and David examine how the Axios incident marks a shift toward supply chain abuse and what Google’s attribution to a North Korean-linked group reveals about the blurred lines between developer infrastructure, cybercrime, and geopolitics. 

     

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    44 min
  • Salesforce Aura Data Theft

    ShinyHunters has once again placed Salesforce customers in their crosshairs – this time abusing guest user misconfigurations in public-facing Experience Cloud sites. The group claims to have compromised 400 organizations by pairing these overly-permissive settings with a modified version of the AuraInspector auditing tool to query Salesforce CRM objects without authentication. Join Matt and David for the latest episode of State of Cybercrime as they break down how this campaign fits squarely into the ShinyHunters playbook. They will also explore emerging AI security risks and examine the shifting momentum in the race to define the dominant LLM platform.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    30 min
  • OpenClaw & Moltbook (w/ Moriah Hara!)

    OpenClaw – an opensource AI agent dubbed “Claude with hands” – has exploded across GitHub, rocketing from obscurity to 170,000 stars in just two weeks. It’s now the fastest spreading form of shadow IT, with users plugging it into critical environments long before understanding the risks. Combine that with Moltbook, the new social platform where AI agents interact at scale, and you’ve got a volatile new frontier – one where scores of human-controlled agents bury prompt injections in plain sight and create attack surfaces no one has prepared for. In this episode of State of Cybercrime, Matt and David unpack why OpenClaw and Moltbook represent a watershed moment in AI adoption and how easily enthusiasm is outpacing security. They’re joined by Moriah Hara, three-time award-winning Fortune 500 CISO, who brings her seasoned perspective to our new segment: “Voices from the Frontlines.”

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    44 min
  • The React2Shell Crisis
    React2Shell, the zero-click RCE exploit, is rapidly becoming one of the most significant cybersecurity incidents this year.
    From emergency patches causing a massive Cloudflare outage to active exploitation by China and North Korea-linked groups, this flaw may be the next Log4Shell moment for enterprises and developers alike.
    Join Matt and David for an episode of State of Cybercrime that breaks down how attackers are weaponizing this vulnerability and what organizations must do to stay safe. They will also dive into the Shai-hulud 2.0 assault on cloud infrastructure as well as the biggest DDoS attack ever recorded.
    More from Varonis ⬇️
    Visit our website: https://www.varonis.com
    LinkedIn: linkedin.com/company/varonis
    X/Twitter: x.com/varonis
    Instagram: instagram.com/varonislife
    Want to join us live? Save a seat here:
    https://www.varonis.com/state-of-cybercrime
    More from Varonis ⬇️
    Visit our website: https://www.varonis.com
    LinkedIn: https://www.linkedin.com/company/varonis
    X/Twitter: https://twitter.com/varonis
    Instagram: https://www.instagram.com/varonislife/
    23 min

About State of Cybercrime

From the publisher's feed

Join us for State of Cybercrime, where experts discuss the latest trends and developments in the world of cybercrime and provide insights into how organizations can protect themselves from potential threats.