
Sign up to save your podcasts
Or


In this week's Security Sprint, Dave and Andy talked about the following topics:
Opening:
• WaterISAC to host H2OEx regional exercise to strengthen sector preparedness & WaterISAC merch!
• The Gate 15 Interview EP 66: Chris Camacho: Cyber Risk, Building Communities, Nirvana, and Peruvian Chicken
• Nerd Out EP 66. Terrorism trends and hacktivism in the current geopolitical environment, plus Nerd Movie review
Main Topics:
Rules of Engagement: safety, security and resilience considerations after Minneapolis and the murder of Alex Pretti
Severe Weather Planning & Resilience:
• Winter storm kills 11, leaves more than 800,000 without power as cold tightens grip
• The massive storm has passed, but deep cold remains a danger
• Storm-related power outages (U.S.)
• PowerOutage.us
AI-Powered Disinformation Swarms Are Coming for Democracy (Wired, 23 Jan 2026; Analysis/Commentary) – Wired examines how coordinated “disinformation swarms” powered by generative AI are shifting influence operations from single narratives to adaptive, multi-persona campaigns that probe, learn, and re-target in real time. Rather than pushing one false claim, these swarms test thousands of micro-messages across platforms, identify which narratives gain traction with which audiences, and dynamically reinforce them using synthetic text, images, and increasingly video. Researchers warn this model overwhelms traditional fact-checking and moderation, exploits algorithmic amplification, and blurs the line between foreign and domestic influence, particularly when paired with real grievances.
Quick Hits:
• CISA budget bill would require agency to maintain ‘sufficient’ staffing levels and Congressional appropriators move to extend information-sharing law, fund CISA
• Acting CISA chief defends workforce cuts, declares agency ‘back on mission’
• What to do when your organization has been compromised by a cyber attack (ITSAP00009)
In the latest Episode of Nerd Out, Dave and Alec talked about the following topics:
Trends in Terrorism: What’s on the Horizon in 2026?
Critical Infrastructure Attacks Became Routine for Hacktivists in 2025
Severe Winter Weather Forecast to Impact Large Portions of the U.S.
Talking Nerd Movies and our excitement level, plus a review of A Knight in the Seven Kingdoms.
In this week's Security Sprint, Dave and Andy covered the following topics:
Opening:
• Cyber Insights 2026: Information Sharing (SecurityWeek, 16 Jan 2026)
• ICYMI: Homeland Republicans underscore importance of strong public-private sector partnerships to deter cyber threats — House Homeland Security Committee (Majority) | Jan 17, 2026
Main Topics:
Pro-Russia hacktivist activity continues to target UK organisations & NCSC warns of hacktivist groups disrupting UK online services (UK National Cyber Security Centre, Jan 2026). The NCSC reports sustained, low-sophistication but high-volume hacktivist campaigns—primarily DDoS and website defacements—linked to pro-Russia narratives and opportunistic targeting of UK public- and private-sector organizations. While technically unsophisticated, the activity is persistent, media-aware, and designed to generate disruption, reputational harm, and psychological impact rather than deep network compromise. The NCSC emphasizes preparedness measures including DDoS resilience, clear incident communications, and executive awareness that “noise” activity can still impose real operational cost.
• Russia-linked APT28 targets energy and defense groups tied to NATO
• UAT-8837 targets critical infrastructure sectors in North America
• A Day Without ICS: The real impact of ICS/OT security threats
Ransomware
• Worldwide ransomware roundup: 2025 end-of-year report
• Global ransomware attacks rose 32% in 2025, as manufacturers emerged as top target
• 2025 Shattered Records: Key takeaways from the GRIT 2026 Ransomware & Cyber Threat Report
• DeadLock Ransomware: Smart Contracts for Malicious Purposes
Domestic Operations: Joint Interagency Task Force-Counter Cartel (JIATF-CC) established & US Northern Command establishes JTF-GOLD
Quick Hits:
• (TLP:CLEAR) Assessing Terrorism Trends on the Horizon in 2026 — WaterISAC — Jan 15, 2026
• UK NCSC: Designing safer links: secure connectivity for operational technology
• NCSC UK: Secure connectivity principles for OT (collection)
• FBI: Secure Connectivity Principles for Operational Technology (OT) (PDF)
• ACSC (Australia): New publication for small businesses managing cyber risks from AI
• Artificial intelligence for small business: Managing cyber security risks
• Developing your IT recovery plan (Canadian Centre for Cyber Security, Jan 2026)
• Improving cyber security resilience through emergency preparedness planning (Canadian Centre for Cyber Security, Jan 2026)
• Developing your incident response plan (Canadian Centre for Cyber Security, Jan 2026)
• Developing your business continuity plan (Canadian Centre for Cyber Security, Jan 2026)
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Chris Camacho. Chris is Abstract Security’s Co-Founder and Chief Operating Officer (COO). In this role, Chris is responsible for the go-to-market strategy, company vision, growth, collaboration, and client engagement. He is a leader, innovator and community builder. Before co-founding Abstract Security, Chris served as both Chief Strategy Officer and Chief Revenue Officer at Flashpoint and was responsible for helping grow the company to an acquisition by Audax PE and supporting three acquisitions to Flashpoint’s portfolio, which helped the company be an industry market leader in the information security market. Before his time at vendors like Abstract Security and Flashpoint, Chris was the Senior Vice President of Information Security at Bank of America, where he oversaw the Threat Management Program. An entrepreneur, Chris also served as CEO for NinjaJobs, a career-matching community for elite cybersecurity talent. As he continues to build trust and relationships throughout the cybersecurity community, he’s now building C2 Corner, a space for security leaders to share stories, connect through experience, and build what’s next together. Chris on LinkedIn.
In the podcast Chris and Andy discuss:
Selected links:
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• TribalHub Cybersecurity Summit! 17-20 Feb, Jacksonville, Florida
• Crypto ISAC & Crypto Crime Reaches Record High in 2025 as Nation-State Sanctions Evasion Moves On-Chain at Scale (and so many breach and incident reports)
• MFA follow up and the alleged Instagram breach: Instagram user data leak: scraped records from 2022 resurface
Main Topics:
Complex realities for the workplace:
• Venezuela, geopolitics and domestic considerations
• Immigration and ICE-related incidents and protests
• Considerations for leaders in the workplace
Insider Threats:
• Malicious employees for hire: How dark web criminals recruit insiders
• Hiding in plain sight: What the death of Aldrich Ames teaches us about insider threats
The State of Ransomware in the U.S.: Report and Statistics 2025. “Since 2023, the number of globally claimed victims has increased from approximately 5400 annually to over 8000 in 2025… the number of victims has grown, so has the number of ransomware groups… ransomware has become more decentralized, more competitive, and more resilient. As long as affiliates remain plentiful and social engineering remains effective, victim counts are likely to continue rising.”
Quick Hits:
• FBI FLASH: North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities
• How China and Russia are using Maduro’s capture to sway U.S. discourse
• U-Haul truck drives into crowd at Westwood rally against Iranian government
• The Government Cyber Action Plan: strengthening resilience across the UK
• CISA - Secure Your Business; Protect your business, employees and customers with smart cybersecurity practices
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• Trump suggests US used cyberattacks to turn off lights in Venezuela during strikes
• Protests in US cities over Trump’s military intervention in Venezuela
• Trump Ramps Up Incendiary Threats After Venezuela Strike
• White House: RUBIO: This Is Our Hemisphere — and President Trump Will Not Allow Our Security to be Threatened
• PMs of Greenland, Denmark tell Trump to stop U.S. takeover threats
Main Topics:
Leftwing militants claim responsibility for arson attack on Berlin power grid. Protest over climate crisis and AI has cut power to tens of thousands of homes which may take days to fully restore. The Vulkangruppe (Volcano Group) said it had deliberately targeted some of the city’s wealthiest districts.
Ransomware:
• Recorded Future: New ransomware tactics to watch out for in 2026
• Semperis: What CISOs Need to Know About Fighting Ransomware in 2026
• Top 10 Ransomware Groups of 2025
MFA: Dozens of Global Companies Hacked via Cloud Credentials from Infostealer Infections & More at Risk. This report provides a granular reconstruction of the compromised assets. Furthermore, we demonstrate that these catastrophic security failures were not the result of zero-day exploits in the platform architecture, but rather the downstream effect of malware infections on employee devices combined with a critical failure to enforce Multi-Factor Authentication (MFA).
• One criminal, 50 hacked organizations, and all because MFA wasn't turned on. "Because the organizations listed below did not enforce MFA, the attacker walks right in through the front door," the cybersecurity shop said in a Monday report. "No exploits, no cookies – just a password."
• Cloud file-sharing sites targeted for corporate data theft attacks
AI Deepfakes Are Impersonating Pastors to Try to Scam Their Congregations; Religious communities around the US are getting hit with AI depictions of their leaders sharing incendiary sermons and asking for donations.
Quick Hits:
• Bleeping Computer: The biggest cybersecurity and cyberattack stories of 2025
• Infosecurity's Top 10 Cybersecurity Stories of 2025
• Supply chains, AI, and the cloud: The biggest failures (and one success) of 2025.
• Two Americans Plead Guilty to Targeting Multiple U.S. Victims Using ALPHV BlackCat Ransomware
• CISA Known Exploited Vulnerabilities Surged 20% in 2025; CISA’s Known Exploited Vulnerabilities (KEV) Catalog Grew By 20% In 2025, Including 24 Vulnerabilities Exploited By Ransomware Groups
On the latest episode of Nerd Out, Dave and Alec dig into the Bondi Beach attack and what lessons can be learned before looking at the NYE attack that was disrupted. Then the looked at some of the security predictions made earlier in the year to see if they hit the mark. They wrapped up with a prediction of their own for 2026. Then they turned to the other nerd news and talked about some of the latest trailers before talking about their favorite show of the year!
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• Cyware!
• New! The Gate 15 Interview EP 65: Yearend ISAC Extravaganza!
• 2025 CWE Top 25 Most Dangerous Software Weaknesses
• CISA Unveils Enhanced Cross-Sector Cybersecurity Performance Goals
Main Topics:
Bondi Beach Hanukkah Attack:
• NYT Live Updates: Sydney Gunmen Were Motivated by ISIS, Australia’s Leader Says
• Gunmen kill at least 15 people in attack on Hanukkah celebration on Sydney’s Bondi Beach
• Join FB-ISAO. If you’re involved with a place of worship or charity, please make sure they’re plugged in!
• Gate 15’s Hostile Events Attack Cycle white paper
• Germany foils suspected Islamist car ramming plot targeting Christmas market
• 'F*** the Jews': Gunman fires 20 bullets into Jewish family's hanukkah-decorated home in California
• Virginia mosque attacked, Muslim advocates call for hate crime charges
What we know about the Brown University shooting that killed 2 and injured 9
Cybersecurity Updates:
• ASD: Annual Cyber Threat Report 2024-2025
• 5 lessons we learned from our ransomware attack
• Dragos Industrial Ransomware Analysis: Q3 2025
• Alleged Coupang data leaker had only worked at company for two years, say police
• Users report chaos as Legal Aid Agency stumbles back online after cyberattack
• Canadian Centre for Cyber Security: Ransomware
Quick Hits:
• Opportunistic Pro-Russia Hacktivists Attack US and Global Critical Infrastructure
• CISA warns China has penetrated U.S. infrastructure, threatens 2027 turning point
• New Product! Active Shooter Response – Poster
In this episode of The Gate 15 Interview, Andy Jabbour speaks with leaders from the Information Sharing and Analysis Center (ISAC) community on the Cybersecurity Information Sharing Act, the government shutdown, the role and future of ISACs and what to look forward to in 2026. Experts include:
In the discussion the panel covers:
Selected links:
Congress extends CISA 2015, but path to long-term reauthorization remains murky
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• TribalHub Magazine, Winter 2025: A Publication For Technology Minded Professionals In Tribal Government Tribal Health, Tribal-Gaming And Non-Gaming Tribal Enterprises. Includes Tribal-ISAC happenings!
• React2Shell: Risky Bulletin: APTs go after the React2Shell vulnerability within hours & Critical Security Vulnerability in React Server Components
• We discussed our daily SUN and Weekly Ransomware & Data Breach Digest available via Gate 15’s GRIP: Join the GRIP! Gate 15’s Resilience and Intelligence Portal (GRIP) utilizes the robust capabilities available in Cyware’s Collaborate platform to provide the community with technology-enhanced, human-driven analysis products. Further, our team supports the implementation and use of Cyware Collaborate at the Enterprise level.
Main Topics:
FinCEN Issues Financial Trend Analysis on Ransomware. The U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) is issuing a Financial Trend Analysis on ransomware incidents in Bank Secrecy Act (BSA) data between 2022 and 2024, which totaled more than $2.1 billion in ransomware payments… Previous FinCEN Financial Trend Analyses have focused on reported ransomware payments and incidents by the date the activity was filed with FinCEN. Today’s report shifts the focus to the incident date of each ransomware attack and offers greater visibility into the activities conducted by ransomware actors.
• Reported Ransomware Incidents and Payments Reach All-Time High in 2023
• FinCEN Data Shows Ransomware Payments Top $2.1B in Just Three Years
• Financial Services, Manufacturing, and Healthcare were the Most Impacted Industries
• The Onion Router (TOR) was the Most Common Communication Method Reported
• ALPHV/BlackCat was the Most Prevalent Ransomware Variant Between 2022 and 2024
• FinCEN analysis shows scope of ransomware problem
Five-page draft Trump administration cyber strategy targeted for January release; The six-pillar document covers a lot of ground in a short space, and could be followed by an executive order implementing it, according to sources familiar with the draft. America 250: Presidential Message on the Anniversary of the Monroe Doctrine
• Here’s what the new National Security Strategy says about threats to critical infrastructure
• New US National Security Strategy reveals Trump administration’s latest stance on Taiwan
FBI PSA: Criminals Using Altered Proof-of-Life Media to Extort Victims in Virtual Kidnapping for Ransom Scams. The Federal Bureau of Investigation (FBI) warns the public about criminals altering photos found on social media or other publicly available sites to use as fake proof of life photos in virtual kidnapping for ransom scams. The criminal actors pose as kidnappers and provide seemingly real photos or videos of victims along with demands for ransom payments… Criminal actors typically will contact their victims through text message claiming they have kidnapped their loved one and demand a ransom be paid for their release. Oftentimes, the criminal actor will express significant claims of violence towards the loved one if the ransom is not paid immediately. The criminal actor will then send what appears to be a genuine photo or video of the victim’s loved one, which upon close inspection often reveals inaccuracies when compared to confirmed photos of the loved one. Examples of these inaccuracies include missing tattoos or scars and inaccurate body proportions. Criminal actors will sometimes purposefully send these photos using timed message features to limit the amount of time victims have to analyze the images.
Quick Hits:
• US leader of global neo-Nazi terrorist group signals retribution for arrests
• ASD: Information stealers are on the rise, are you at risk?
• UK NCSC: Prompt injection is not SQL injection (it may be worse)
From the publisher's feed