
Sign up to save your podcasts
Or


In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• WaterISAC – EPA: National Security Information Sharing Bulletin – Q4 2025 & Access the PDF
• Canadian Centre for Cyber Security: The cyber threat to Canada’s water systems: Assessment and mitigation
• Canadian Centre for Cyber Security: Don't take the bait: Recognize and avoid phishing attacks - ITSAP.00.101
• How cannabis businesses can go digital while thwarting hackers
Main Topics:
• Semperis Warns That Holiday & Weekend Gaps Leave Critical Infrastructure Open to Ransomware Attacks
• FBI San Diego Warns Shoppers to Be Aware of Scams During the 2025 Holiday Season
• FBI PSA: Account Takeover Fraud via Impersonation of Financial Institution Support
• Take9: Cyber threats are everywhere. And getting sneakier. What can you do to protect yourself, your community and our nation? Take a 9-second pause and think before you click, download, share. A short pause goes a long way.
• JCAT First Responder's Toolbox: Tech Sector Outreach: Identifying Violent Extremist Indicators and Reporting Mechanisms for Online Service Providers
Quick Hits:
• OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide
• CISA: Mobile Communications Best Practice Guidance
• CISA: Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
On this week's Security Sprint, Dave and Andy get ready for hte holidays with a full menu of topics that include:
Warm Open:
· Happy23rd birthday to DHS!
· WaterISAC’s Quarterly Water SectorIncident Summary, April to June 2025 – Executive Summary
· GridEx VIII – Surge in ParticipationReflects Importance of Exercising Emergency Preparedness
· Cloudflare outage on November 18, 2025
Main Topics:
Insider Threats: Former contractor admits to hackingemployer in retaliation for termination
· CrowdStrike catches insider feeding information to hackers
· Rising cost of trust as insider behavior becomes a weak link in critical infrastructure cyber defense
Blended Threats, you say? AWS: New Amazon Threat Intelligence findings: Nation-state actors bridging cyber and kinetic warfare & Amazon details Iranian “cyber-enabled kinetic targeting” operations
Quick Hits:
· House AI terrorism bill spotlights extremist use of generative AI for propaganda and training
· Obscura Ransomware: A Case Study in Ransomware Data Loss
· Overconfidence is the new zero-day as teams stumble through cyber simulations
· The SANS 2025 State of ICS Security Report: Progress, Pressure, and the Path to Resilience
· CISA Releases New Guides to Safeguard Critical Infrastructure from Unmanned Aircraft SystemsThreats
· Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers
· United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• Happy Birthday to CISA! The Cybersecurity and Infrastructure Security Agency turned seven on Sunday.
• Government funding bill temporarily revives cybersecurity information-sharing law
• The Gate 15 Interview EP 64: Cody Barrow, CEO, EclecticlQ. “Nothing in cyber happens without a reason.”
• Faith-Based (U.S.): FB-ISAO Newsletter, v7, Issue 10
Main Topics:
Cybersecurity!
• OWASP Top Ten. Welcome to the 8th installment of the OWASP Top Ten!
• ASD: Annual Cyber Threat Report 2024-2025
• Checkout.com: Protecting Our Merchants: Standing Up to Extortion: “We will not be extorted by criminals. We will not pay this ransom.”
Holidays & Hostile Events!
• Europol: 10 years on: remembering the victims of the 13 November terrorist attack in Paris
• DOJ: New Jersey Man Charged with Cyberstalking in Connection with Violent Network ‘764’
• Indiana Republican called out by Trump on redistricting is swatted
• Marjorie Taylor Greene Says She Received Pipe Bomb Threat: What We Know
• Terror plot arrests reveal ‘more dangerous’ online pathway to ISIS radicalization in America
• Suspects charged in alleged Michigan Halloween terror plot eyed attack on Chicago Pride Parade: Docs
• Racists are now openly targeting Indian Americans
• Is left-wing terrorism returning?
Quick Hits:
• Blended Threats! Risky Biz News - German TV station hacked: A cyberattack has disrupted the broadcast of German radio station Radio Nordseewelle. Hardware components were damaged in the attack and had to be replaced. The broadcaster said it had to rebuild large parts of its IT network. The hack took place days after a similar incident crippled the transmission of Dutch radio and TV station RTV Noord. [Tarnkappe]
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Cody Barrrow, CEO, EclecticlQ. Cody is a cybersecurity industry leader with over 20 years of public and private sector experience in the US and EU, holding leadership positions within the Pentagon, National Security Agency/US Cyber Command, Fortune 25, and commercial vendors as well as a number of other positions with the US Government and across the cybersecurity community. Since 2019, he has been with EclecticIQ, the Amsterdam-based European leader in cybersecurity technologies servicing central governments and large enterprises, where he took over as Chief Executive Officer in 2024. Cody has a Bachelor of Science in Political Science from the University of Maryland. Learn more about Cody on LinkedIn.In the discussion Cody and Andy cover:
Selected links:
In the latest episode of Nerd Out, Dave and Alec are joined by Joe Levy who talks about his role and the day to day of managing a venue. Then the group talks about outdoor venue security and other preparedness activities incorporating drone threat and building lasting partnerships. The gang then talked about winter weather preparedness before wrapping up their security talk with a look back to the recent elections and a look ahead to 2026.
Finally, they continued their holiday kick-off with a run through their favorite holiday food and drinks.
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
Main Topics:
Canadian Centre for Cyber Security: Alert - AL25-016 Internet-accessible industrial control systems (ICS) abused by hacktivists. In recent weeks, the Cyber Centre and the Royal Canadian Mounted Police have received multiple reports of incidents involving internet-accessible ICS. One incident affected a water facility, tampering with water pressure values and resulting in degraded service for its community. Another involved a Canadian oil and gas company, where an Automated Tank Gauge (ATG) was manipulated, triggering false alarms. A third one involved a grain drying silo on a Canadian farm, where temperature and humidity levels were manipulated, resulting in potentially unsafe conditions if not caught on time.
Threat Snapshot: Cyber Threats Remain Heightened Amid Lapse In Information Sharing Authorities, Government Shutdown. As Cybersecurity Awareness Month comes to a close and Critical Infrastructure Security and Resilience Month nears, today, the House Committee on Homeland Security released an updated “Cyber Threat Snapshot,” outlining the heightened threats posed by malign nation-states and criminals to U.S. networks and critical infrastructure since 2024. Read the previous “Cyber Threat Snapshot,” which outlined threats from 2021 through 2024, here.
2 shot dead at Tennessee plastics plant by gunman who was ex-employee. Two employees of a plastics maker were fatally shot Monday morning in Cleveland, Tennessee, by an employee in the process of termination, authorities said. The two men killed at Barku Plastics were Tobias Gleinig and Ivan Aldergot, police said. Both were supervisors at the plant and citizens of Germany, Cleveland Police Capt. Evie West said at a news conference Monday night. Barku is a subsidiary of Barku Kunststofftechnik, a plastics producer established in Germany in 1977, which confirmed the "violent deaths" of Gleinig and Aldergot in a statement.
Quick Hits:
• Hurricane Melissa makes historic landfall in Jamaica as Category 5 storm
• 'Total devastation': Hurricane Melissa leaves trail of destruction, flooding in Jamaica
• ‘Tremendous unprecedented devastation’ in Jamaica from Hurricane Melissa, UN coordinator says
• Hurricane Melissa death toll nears 50 as Jamaica relief efforts intensify and storm heads north
• Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says
On the latest episode of Nerd Out, Dave and Alec welcome back Hunter Headapohl to deep dive into Cybersecurity Awareness Month and cyber threats.
References from the discussion include:
After the security nerd discussions, the trio turned to other nerd news with a little Halloween theme.
On this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open
• H2OSecCon 2026 Call for Presentations
• Critical infrastructure sectors on the most concerning threats – and needed solutions. “With critical infrastructure constantly under myriad threats, sector-focused information sharing and analysis centers and organizations collect, analyze and disseminate actionable cyber and physical threat information to stakeholders and provide them with tools to mitigate risks and enhance resiliency. To mark Cybersecurity Awareness Month, Threat Beat asked: 1) What is the most pressing short-term security concern in your sector? 2) What is one thing the public and/or industry/government can do now to address this?” Responses include DNG-ISAC, E-ISAC, FB-ISAO, Food and Ag-ISAC, Health-ISAC, MS-ISAC, ONE-ISAC, Space ISAC, and WaterISAC.
• CISA’s international, industry and academic partnerships slashed. The cuts “create a dangerous void,” said Errol Weiss, chief security officer for the Health Information Sharing and Analysis Center. “The health sector is one of the most targeted and vulnerable, and this is exactly the wrong time to be pulling back federal support.
• Kristi Noem pledged to boost the nation’s cybersecurity. She gutted it instead
• Trump Administration Cuts Cyberdefense Even as Threats Grow
• U.S. Cyberspace Solarium Commission Annual Assessment: America’s Cyber Resiliency in 2025: Lessons from the Fifth CSC 2.0 Annual Assessment & US ‘slipping’ on cybersecurity, annual Cyberspace Solarium Commission report concludes
Main Topics:
Ransomware recovery perils: 40% of paying victims still lose their data. Paying the ransom is no guarantee of a smooth or even successful recovery of data. But that isn’t even the only issue security leaders will face under fire. Preparation is key.
• UK Government: Supply chain resilience against ransomware
• JLR hack is costliest cyber attack in UK history, say analysts
Melissa becomes third Category 5 hurricane of the extraordinary 2025 season
• NHC issuing advisories for the Atlantic on Hurricane Melissa
• Key messages regarding Hurricane Melissa (en Español: Mensajes Claves)
• Melissa leaps from tropical storm to Category 4 hurricane in 18 hours
• Category 5 Hurricane Melissa’s eye is nearing Jamaica and conditions are worsening
Quick Hits:
• Palo Alto Networks: Why Threat Actors Succeed
• LA Metro digital signs taken over by hackers
• Chatbots Are Pushing Sanctioned Russian Propaganda
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• The White House fired 176 CISA employees on Friday, with more layoffs fearedLayoffs, reassignments further deplete CISA
• Top cyber lawmaker wants answers on CISA workforce reductions
• Tech industry unites behind bipartisan effort to urgently reauthorize US cyber threat information sharing law
• What They Are Saying: Technology Stakeholders Urge Passage Of Peters & Rounds Bipartisan Bill To Restore Critical Cybersecurity Protections (CISA 2015)
Main Topics:
F5, AWS, Third Party Risk & Resilience:
• AWS: Operational issue - Multiple services (N. Virginia).
• AWS: Operational issue - Multiple services (N. Virginia). [RESOLVED] Increased Error Rates and Latencies
• What the Huge AWS Outage Reveals About the Internet
• AWS outage exposes Achilles heel: central control plane
• F5: K000154696: F5 Security Incident
• F5, Inc. Form 8K
• ED 26-01: Mitigate Vulnerabilities in F5 Devices
Ransomware & Data Breaches:
• IT-ISAC: Quarterly IT Sector Ransomware Analysis Q3 2025, July -September. PDF.
• BlackFog’s 2025 Q3 Ransomware Report
Arctic Wolf 2025 Human Risk Report Reveals Escalating Breaches, Overconfidence in Phishing Defenses, and Risky AI Behavior. Key findings from the 2025 Human Risk Behavior Snapshot include:
Quick Hits:
• AG Platkin Sets Standards for Active-Shooter Readiness
• Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data
• NCSC Warns Data Centres Face Rising Cybersecurity Threats
• Microsoft Dominates Phishing Impersonations in Q3 2025
• UK NCSC - UK experiencing four 'nationally significant' cyber attacks every week
• UK NPSA: Protecting our Democratic Institutions: Countering Espionage and Foreign Interference
• DDoS Botnet Aisuru Blankets US ISPs in Record DDoS
In this week's Security Sprint, Dave and Andy covered the following topics:
Main Topics:
Russia, China and North Korea are using ChatGPT to influence you — here’s how. A new report from OpenAI found foreign adversaries are increasingly using artificial intelligence to power hacking and influencing operations. The report found they were using OpenAI’s popular tool ChatGPT. The report showed those adversaries include Russia, China and North Korea. “AI-enabled attacks are becoming more capable and harder to detect,” Daryl Lim, affiliate at the Center for Socially Responsible Artificial Intelligence at Penn State University, told Straight Arrow News. “Adversaries can personalize attacks, evade filters and iterate faster than before.”
• The Case for AI Loss of Control Response Planning and an Outline to Get Started
• Can Humans Devise Practical Safeguards That Are Reliable Against an Artificial Superintelligent Agent?
The true cost of cyber attacks - and the business weak spots that allow them to happen. What makes companies like Jaguar Land Rover and Marks & Spencer particularly vulnerable is the way in which their supply chains work.
• UK NCSC: UK experiencing four 'nationally significant' cyber attacks every week
• Cyber attack contingency plans should be put on paper, firms told
• Policyholder Plot Twist: Cyber Insurer Sues Policyholder’s Cyber Pros
• The Ransomware Pricing Paradox: An Empirical Study of the Six Stages of Ransomware Negotiations. PDF
• Paying off cyber criminals no guarantee stolen data won’t be published – study
Severe Weather: Hurricane Season continues
18 Oct: No Kings nationwide protests
Quick Hits:
• Peace in Israel and Gaza?
• Sen. Peters tries another approach to extend expired cyber threat information-sharing law & Peters & Rounds Introduce Bipartisan Bill to Restore Critical Cybersecurity Protections
• Yet another shutdown and its impact on cybersecurity professionals
• Experts: Shutdown Strains Healthcare Cyber Defenses
• Is the government shutdown impacting info sharing for healthcare cyber threats?
• ICYMI! Gate 15 Weekly Security Sprint EP 130. The Evangelist has returned! Cybersecurity Awareness Month and more!
• Poland says cyberattacks on critical infrastructure rising, blames Russia
• Anatomy of a Hacktivist Attack: Russian-Aligned Group Targets OT/ICS
• Critical networks face unprecedented threat as DDoS attacks are getting shorter and more intense
• Belgian PM reported to be among targets of ‘jihad-inspired’ drone plot
• Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign
From the publisher's feed