You've Already Been Hacked

You've Already Been Hacked

By Professor CyberRiskTechnology
Download on the App Store

You've Already Been Hacked episodes

  • FortiMail Zero-Day Exploited Now — 3 Branches Still Unpatched

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: FortiMail Zero-Day Exploited Now — 3 Branches Still Unpatched

    Episode Number: 364

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-09-27 to 2026-10-01. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * Actively exploited email gateway zero-days and workarounds

    * Government personnel-records breaches and espionage risk

    * Agentic AI attacks on cloud infrastructure

    * Ransomware takedowns and the edge-device attack path


    Top Stories

    1. Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (CVE-2026-104286) - https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/


    Additional Cybersecurity News – Titles and URLs

    2. Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data - https://arstechnica.com/security/2026/10/hacks-of-2-federal-agencies-in-a-month-have-spilled-a-bonanza-of-sensitive-data/

    3. JadePuffer agentic AI attacks target Azure, destroy cloud resources - https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/

    4. Police dismantle KillSec ransomware gang allegedly led by 16-year-old - https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/


    Resources & Links

    None this episode


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE


    37 min
  • ShinyHunters Claims a 2-Terabyte FBI Heist — Powered by a Zero-Day

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: ShinyHunters Claims a 2-Terabyte FBI Heist — Powered by a Zero-Day

    Episode Number: 363

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-09-20 to 2026-09-24. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * PeopleSoft zero-day and the claimed FBI breach

    * Worm-like Docker botnet driven by AI agents

    * Rogue OpenAI agent swarm and government website intrusions

    * macOS infostealer using iCloud calendars as C2

    * $351.6M Bitget crypto exchange theft

    * Windows Defender zero-day that blocks AV updates


    Top Stories

    1. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach - https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/


    Additional Cybersecurity News – Titles and URLs

    2. New Carbonato malware uses AI agents to hijack exposed Docker hosts - https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/

    3. Researchers link more cyberattacks to OpenAI agent swarm - https://siliconangle.com/2026/09/24/researchers-link-more-cyberattacks-to-openai-agent-swarm/

    4. MacSync malware uses public iCloud calendars to deliver new payloads - https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/

    5. Hackers steal $351.6 million in Bitget crypto exchange hack - https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/

    6. New Windows Defender zero-day blocks Microsoft antivirus updates - https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/


    Resources & Links

    * Transluce agent-activity research: https://transluce.org/agent-activity

    * ThreatDown Carbonato analysis: https://www.threatdown.com/blog/carbonato/

    * Kaspersky MacSync writeup: https://securelist.com/macsync-new-version/121383/


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

    37 min
  • Why Your Phone's Accessibility Permission Is the New Infostealer Door

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: Why Your Phone's Accessibility Permission Is the New Infostealer Door

    Episode Number: 362

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-09-13 to 2026-09-17. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * RatHat: AI-driven Android malware that serializes the accessibility tree to a commercial LLM for live device control (Zimperium zLabs, China-linked)

    * Brevo supply-chain attack: stolen Cloudflare API key injected ClickFix scripts into ~100,000 customer sites

    * GitLab CVE-2026-85706: CVSS 10.0 unauthenticated arbitrary file read, CISA KEV, actively exploited

    * CHOSEN BRICK: Iranian state Windows spyware targeting dissidents, activists, and journalists (NCSC + FBI joint advisory)


    Top Stories

    1. New RatHat Android malware uses AI to automate device control - https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/


    Additional Cybersecurity News – Titles and URLs

    2. Brevo supply-chain attack injected ClickFix scripts on customer sites - https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/

    3. GitLab CVE-2026-85706: CVSS 10.0 unauthenticated file read exploited in the wild - https://hoploninfosec.com/cve-2026-85706-gitlab-vulnerability

    4. Iranian hackers use CHOSEN BRICK Windows malware to spy on targets - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/


    Resources & Links

    * Zimperium RatHat analysis (via BleepingComputer): https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/

    * Brevo post-mortem: https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up

    * Sansec Brevo supply-chain report: http://sansec.io/research/brevo-supply-chain-attack

    * GitLab patch release notes (19.3.2): https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

    * CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    * NCSC joint advisory (FBI) on Iranian targeting: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE


    38 min
  • Artifactory's Backdoor: Why Patching Isn't Enough

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: Artifactory's Backdoor: Why Patching Isn't Enough

    Episode Number: 3x61

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-08-30 to 2026-09-03. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * Software supply-chain poisoning via forged admin tokens (CVE-2026-82329)

    * Mass-exposed Exchange servers and mailbox hijack (CVE-2026-62911)

    * GDPR enforcement: French hospital fined €500,000 after 727,000-record breach

    * Stealthit infostealer abusing Node.js Single Executable Applications


    Top Stories

    1. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/


    Additional Cybersecurity News – Titles and URLs

    2. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks - https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/

    3. French hospital fined €500,000 after breach exposes data of 727,000 - https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/

    4. Stealthit infostealer gets a Node.js makeover — fake games and VPNs are the bait - https://hoploninfosec.com/stealit-malware-attacks


    Resources & Links

    * JFrog security advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories

    * Microsoft CVE-2026-62911 advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

    * NCSC-NL Exchange alert: https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-microsoft-exchange-server


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

    32 min
  • Your IoT Devices Might Be a Chinese Spy's Front Door

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: Your IoT Devices Might Be a Chinese Spy's Front Door

    Episode Number: 3x60

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-08-23 to 2026-08-27. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * Main threat analysis and implications

    * Emerging AI security challenges

    * Vulnerability disclosures and patches

    * Threat landscape updates


    Top Stories

    1. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure - https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers


    Additional Cybersecurity News – Titles and URLs

    2. Unknown PaperCut NG/MF vulnerability under active exploitation — emergency patch shipped - https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

    3. Critical Gitea RCE (CVE-2026-60004, CVSS 9.8) exploited in the wild — CISA adds to KEV - https://www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/

    4. Group-IB: Iran-linked Tortoiseshell expands toolset with TWOSTROKE-like backdoor and reverse SSH tunneler - https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html

    5. CISA adds actively exploited Oracle WebLogic Proxy Plug-in flaw (CVE-2026-21962, CVSS 10.0) to KEV - https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html


    Resources & Links

    None this episode


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE


    38 min
  • CareCloud's 3.75M Patient Breach Confirmed 5 Months Later

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: CareCloud's 3.75M Patient Breach Confirmed 5 Months Later

    Episode Number: 359

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-08-16 to 2026-08-20. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * Main threat analysis and implications

    * Emerging AI security challenges

    * Vulnerability disclosures and patches

    * Threat landscape updates


    Top Stories

    1. CareCloud confirms 3.75 million patients' medical records stolen — five months after the intrusion - https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/


    Additional Cybersecurity News – Titles and URLs

    2. UT San Antonio hit by weekend cyberattack — classes for 42,000 students delayed five days - https://cybernews.com/news/university-of-texas-san-antonio-cyberattack-systems-offline/

    3. Fake crypto conference lures security researchers into malware via rigged Google Docs - https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/

    4. CameraSwarm — 14,530 Dahua IP cameras hijacked in a 35-day campaign with factory-reset-proof backdoors - https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/

    5. Fake "leaked GTA 6" builds flood piracy sites — every download is malware - https://www.ign.com/articles/malware-disguised-as-leaked-gta-6-copies-are-popping-up-on-piracy-sites


    Resources & Links

    None this episode


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE


    43 min
  • Akira Rebooted Into Safe Mode — Then Stole the Data Anyway

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: Akira Rebooted Into Safe Mode — Then Stole the Data Anyway

    Episode Number: 358

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-08-09 to 2026-08-13. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * Akira ransomware EDR bypass via Safe Mode

    * OpenAI rogue AI agents breach Hugging Face

    * SharePoint CVE-2026-55040 exploited by ransomware gangs

    * ShieldBreak Defender patch bypass claims

    * MyDr Poland medical data breach - 18 million records


    Top Stories

    1. Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt - https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/


    Additional Cybersecurity News – Titles and URLs

    2. The Safety Reckoning Inside OpenAI - https://www.wired.com/story/openai-safety-security-ai-agents-culture/

    3. Ransomware gangs weaponize SharePoint exploit CVE-2026-55040 - https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/

    4. ShieldBreak claims Microsoft Defender patch bypass (CVE-2026-50656) - https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html

    5. Poland's MyDr breached - 18 million medical records stolen - https://cybernews.com/security/mydr-medical-data-breach-hackers-politicians/


    Resources & Links

    * CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    * Rapid7 CVE-2026-55040 writeup: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/

    * Shadowserver exposed SharePoint servers: https://dashboard.shadowserver.org/


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE


    36 min
  • AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying - 2026-08-07

    Episode Number: 3x57

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-08-02 to 2026-08-06. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from Meta's AI hacking another company during testing, to critical RCE flaws in Claude Code and Gemini CLI, to researchers silently stalking a reporter via a $30 kids' smartwatch, and a Linux kernel use-after-free with public exploit code.


    Guest Information

    None this episode


    Topics Covered

    * Meta's Muse Spark 1.1 breaches external organization during Irregular sandbox test — the third AI company to confirm this pattern

    * ClickFix macOS campaign evolves: Go-based infostealer with browser-fingerprinting gate and partial crypto draining

    * Critical RCE flaws in Claude Code, Gemini CLI, and OpenAI Codex — demonstrated on vendor repos with default configs

    * Tens of millions of GPS trackers (kids' watches, car devices) run on three compromised Shenzhen backend platforms

    * Linux bridge STP use-after-free: public PoC released, affects Docker/Kubernetes/cloud infrastructure


    Top Stories

    1. Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test - https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/


    Additional Cybersecurity News – Titles and URLs

    2. ClickFix attack pushes macOS infostealer for crypto theft attacks - https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/

    3. Critical flaws in Claude Code, Gemini CLI, and OpenAI Codex enable RCE and supply chain attacks - https://cyberpress.org/critical-flaws-in-claude-code-gemini-cll-openai-codex/

    4. Hackers Stalked Me by Hijacking a Smartwatch for Kids - https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/

    5. Linux Bridge STP Use-After-Free Bug PoC Released - https://hoploninfosec.com/linux-bridge-stp-use-after-free-bug-poc


    Resources & Links

    * CISA KEV Catalog (Langflow, Tomcat, N-central): https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog

    * Anthropic Claude testing incident disclosure: https://hoploninfosec.com/claude-ai-testing-security-incident

    * Black Hat USA 2026: https://blackhat.com/us-26/


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

    39 min
  • Nine Years Buried: The XFS Bug That Hands Out Root

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: Nine Years Buried: The XFS Bug That Hands Out Root

    Episode Number: 356

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


    Guest Information

    None this episode


    Topics Covered

    * RefluXFS Linux kernel privilege escalation vulnerability

    * ServiceNow sandbox-escape RCE exploitation

    * Origin Energy data breach in Australia

    * OpenAI agent autonomous sandbox escape

    * SharePoint machine key theft via CVE-2026-50522


    Top Stories

    1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600


    Additional Cybersecurity News – Titles and URLs

    2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/

    3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/

    4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/

    5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/


    Resources & Links

    * Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600

    * Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752

    * CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

    43 min
  • ClickLock macOS Malware, Fairlife Ransomware & MFA-Bypassing Phishing

    Hosts

    * Professor CyberRisk

    * Cyber Cowboy Live


    Cyber Maps

    * Bitdefender Threat Map: https://threatmap.bitdefender.com/

    * Checkpoint Threat Map: https://threatmap.checkpoint.com/

    * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

    * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


    Episode Information

    Title: ClickLock macOS Malware, Fairlife Ransomware & MFA-Bypassing Phishing - 2026-07-17

    Episode Number: 3x55

    Overview

    Weekly roundup of the most critical cybersecurity developments from 2026-07-12 to 2026-07-16. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from a macOS malware that makes your desktop unusable until you hand over your password, to a ransomware attack that shut down a $4 billion Coca-Cola brand, to new phishing kits that bypass MFA in 6 minutes.


    Guest Information

    None this episode


    Topics Covered

    * ClickLock macOS malware — social engineering attack that terminates all desktop apps to coerce password disclosure

    * Coca-Cola/Fairlife ransomware — production suspension at $4B protein dairy brand

    * Apple Hide My Email privacy lawsuit — class action over 100% exploitable alias feature

    * Jalisco & OmegaLord phishing kits — MFA-evasion techniques targeting Microsoft 365

    * Russian FSB Center 16 — allied warning on critical infrastructure targeting via SNMP and Cisco exploits


    Top Stories

    1. New ClickLock macOS malware traps users into revealing login password - https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/


    Additional Cybersecurity News – Titles and URLs

    2. Coca-Cola suspended production at its Fairlife dairy after a ransomware attack - https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/

    3. New Lawsuit Filed Against Apple for 'Hide My Email' Privacy Vulnerability - https://www.cnet.com/tech/services-and-software/new-lawsuit-filed-against-apple-hide-my-email-privacy-flaw/

    4. New phishing kits target Microsoft 365 accounts, evade MFA - https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/

    5. US and allies warn of Russian critical infrastructure attacks - https://www.bleepingcomputer.com/news/security/us-and-allies-share-defense-tips-against-russian-hackers-targeting-critical-infrastructure/


    Resources & Links

    * CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    * Microsoft Entra Conditional Access docs: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/

    * Have I Been Pwned: https://haveibeenpwned.com/


    Call to Action

    * Subscribe: Stay updated on cybersecurity threats.

    * Leave a Review: Let us know what you think.

    * Join the Conversation: Follow our community and ask questions.


    Sponsor (if applicable)

    No sponsors this episode


    Podcast Socials & Website

    * Website: https://www.youvealreadybeenhacked.com

    * X: @professorcyberrisk

    * YouTube: https://www.youtube.com/@YABHPodcast

    * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

    42 min

About You've Already Been Hacked

From the publisher's feed

A Cybersecurity Podcast for the Rest of Us