Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again

Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again

Cybersecurity Today examines a troubling set of new security developments affecting schools, software supply chains, and account security.

Instructure says it reached an "agreement" with the ShinyHunters threat group after the massive Canvas breach that may have affected up to 275 million users across 9,000 educational institutions. Reports indicate attackers exploited multiple cross-site scripting (XSS) vulnerabilities to hijack administrator sessions and post extortion demands.

Checkmarx has been breached again. This time, attackers reportedly inserted a malicious Jenkins Application Security Testing (AST) plugin designed to steal credentials. The same threat actor, believed to be Team46/TeamTNT-linked infrastructure or Team PCP depending on reporting attribution, appears to have reused secrets allegedly stolen in the earlier Trivy supply-chain compromise.

Microsoft and Google are warning organizations not to treat passkeys as a complete security solution. If weaker recovery methods or legacy credentials remain active, attackers can still bypass them.

Google's Threat Intelligence Group also reports what it describes as the first observed evidence of hostile actors using AI to assist in zero-day vulnerability research and exploit development, signalling a new phase in attacker industrialization.

Also in today's show: Santa Clara County sues Meta over alleged scam-ad profits.

Chapters
00:00 Headlines Overview
00:28 Canvas Breach Deal Fallout
01:59 How the XSS Attack Worked
03:15 Checkmarx Supply Chain Attack
05:01 Credential Rotation Lessons
05:37 Why Passkeys Aren't Enough
07:19 Layered Defence Takeaways
08:35 AI-Assisted Zero-Day Development
10:10 Industrialized AI Threats
13:08 Meta Scam Ads Lawsuit
15:19 Wrap Up

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(100)

Revolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four years

Revolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four years

Revolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after f...

16 Syys 12min

ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays

ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays

Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; Shin...

14 Syys 11min

ShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak ends

ShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak ends

Defender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "...

11 Syys 10min

Microsoft patches record 966 flaws, Cybercriminals return $265 million in Bitcoin

Microsoft patches record 966 flaws, Cybercriminals return $265 million in Bitcoin

Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesd...

9 Syys 8min

IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch

IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch

Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sa...

7 Syys 14min

Surviving and thriving in the AI Vulnpocalypse

Surviving and thriving in the AI Vulnpocalypse

Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur...

5 Syys 29min

FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos

FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos

153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S....

4 Syys 11min

22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance

22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance

22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange...

2 Syys 8min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
vallattomat
aikalisa
politiikan-puskaradio
rss-viihde-media
rss-ootsa-kuullut-tasta
ootsa-kuullut-tasta-2
rss-vaalirankkurit-podcast
rss-voi-venaja
tervo-halme
rss-asiastudio
otetaan-yhdet
rss-raha-talous-ja-politiikka
rss-kaikki-uusiksi
rss-pinnalla
the-ulkopolitist
rss-ulkopoditiikkaa
rikosmyytit
linda-maria
rss-girls-finish-f1rst