WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2. Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails. Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration. EY client tax-data exposure via a third-party platform. 00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(100)

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—for...

22 Elo 36min

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA ...

21 Elo 14min

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where V...

19 Elo 12min

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 lead...

17 Elo 9min

Cybersecurity Today Weekend Month in Review: August 2026

Cybersecurity Today Weekend Month in Review: August 2026

AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July devel...

15 Elo 56min

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that explo...

14 Elo 11min

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carr...

12 Elo 9min

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulner...

10 Elo 16min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
otetaan-yhdet
rss-seksicast
rss-podme-livebox
tervo-halme
rss-voi-venaja
rss-asiastudio
rss-pinnalla
et-sa-noin-voi-sanoo-esittaa
rss-vaalirankkurit-podcast
rss-kaikki-uusiksi
nakokulma-oikealta-jussi-halla-ahon-blogin-kommentaarit
rss-diet-woke
rss-mina-ukkola
rss-tyolinjalla-pekka-sauri
linda-maria