Cybersecurity Headlines - podcast cover

Cybersecurity Headlines

CISO Seriescisoseries.com
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Claude Mythos Preview's capabilities, Anodot breached companies face extortion, wolfSSL flaw enables forged certificates

Claude Mythos Preview's cyber capabilities Anodot hack leaves breached companies facing extortion wolfSSL library flaw enables forged certificate use Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-mythos-previews-capabilities-anodot-breached-companies-face-extortion-wolfssl-flaw-enables-forged-certificates/ Huge thanks to our sponsor, Conveyor Three tools to manage customer security reviews is two too many. Most teams start with a trust center, bolt on a questionnaire ...

Apr 14, 20268 min

The Department of Know is Moving to Fridays

Rich Strafalina of Cybersecurity Headlines announces a key schedule change for their 'Department of No' livestream. The show will now be streaming live on Fridays at 4 PM ET/1 PM PT, moving from its previous Monday slot, effective April 17th. Viewers can expect the same engaging format with two security leader guests discussing weekly news implications for security teams, audience comments, and 'no or no' segments. This change aims to cap off the week with insightful cybersecurity discussions.

Apr 13, 20261 min

Adobe patches zero-day, Marimo flaw exploited, Venice flood threat

Adobe patches months-old Reader zero-day Critical Marimo flaw now under active exploitation Hackers claim control over Venice anti-flood pumps Get the show notes here: https://cisoseries.com/cybersecurity-news-adobe-patches-zero-day-marimo-flaw-exploited-venice-flood-threat/ Huge thanks to our sponsor, Conveyor Still manually filling out security questionnaires even though you have a trust center? A starter trust center is table stakes and the best security teams have moved way past that. Convey...

Apr 13, 20267 min

Android API exposure, Acrobat Reader zero-day, Bitcoin Depot cyberattack

Google API keys in Android apps expose Gemini endpoints Acrobat Reader zero-day flaw exploited since December Cryptocurrency ATM company Bitcoin Depot reports cyberattack Check out our show notes here: https://cisoseries.com/cybersecurity-news-android-api-exposure-acrobat-reader-zero-day-bitcoin-depot-cyberattack/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and cus...

Apr 10, 20269 min

ChipSoft popped, APT28 updates, CIA cyber espionage elevation

Ransomware knocks Dutch healthcare vendor offline APT28 is keeping busy CIA quietly elevated its cyber espionage division Check out our show notes here: https://cisoseries.com/cybersecurity-news-chipsoft-popped-apt28-updates-cia-cyber-espionage-elevation/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether ...

Apr 09, 20267 min

Anthropic's Project Glasswing, CISA funding in doubt, routers hijacked for passwords

Anthropic announces Project Glasswing U.S. seeks to slash CISA funding Russia-linked hackers hijack routers for passwords Check out our show notes here: https://cisoseries.com/cybersecurity-news-anthropics-project-glasswing-cisa-funding-in-doubt-routers-hijacked-for-passwords/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered...

Apr 08, 20267 min

Drift blames exploit on North Korea, GitHub attacks target South Korea, Die Linke breach threatens data leak

Drift says exploit was North Korean intelligence operation GitHub used in multi-stage attacks targeting South Korea Data leak threatened after Die Linke attack Check out our show notes here: https://cisoseries.com/cybersecurity-news-drift-blames-exploit-on-north-korea-github-attacks-target-south-korea-die-linke-breach-threatens-data-leak/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings ...

Apr 07, 20268 min

Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer

Link to episode page This week's Department of Know is hosted by Sarah Lane, with guests Jack Kufahl, CISO, Michigan Medicine , and Adam Palmer , CISO, First Hawaiian Bank . Missed the live show? Check it out on YouTube . Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an ...

Apr 06, 202632 min

Malicious npm packages, CISA budget cuts, hackers exploit React2Shell

36 Malicious npm packages exploited to deploy persistent implants Hundreds of millions to be cut from CISA in proposed budget Hackers exploit React2Shell in automated credential theft campaign Check out our show notes here: https://cisoseries.com/cybersecurity-news-malicious-npm-packages-cisa-budget-cuts-hackers-exploit-react2shell/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compli...

Apr 06, 20269 min

Texas hospital breach, CISA orders NetScaler patch, ISO file RAT warning

250,000 affected by data Breach at Texas hospital CISA says, "patch Citrix NetScaler bug by Thursday" Researchers uncover mining operation using ISO lures Get the show notes here: https://cisoseries.com/cybersecurity-news-texas-hospital-breach-cisa-orders-netscaler-patch-iso-file-rat-warning/ Huge thanks to our sponsor, ThreatLocker Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That app...

Apr 03, 20268 min

New iOS patches over DarkSword, FBI: surveillance hack is major incident, Cisco code stolen in Trivy-linked breach

Apple pushes new patches over DarkSword FBI: US surveillance hack is major incident Cisco code stolen in Trivy-linked breach Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-pushes-new-patches-over-darksword-fbi-us-surveillance-hack-is-major-incident-cisco-code-stolen-in-trivy-linked-breach/ Huge thanks to our sponsor, ThreatLocker Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more ...

Apr 02, 20267 min

Axios poisoned, TeamPCP details, Claude Code leaked

HTTP client introduces malicious dependency TeamPCP testing the open source supply chain Claude source code leaked Get the show notes here: https://cisoseries.com/cybersecurity-news-axios-poisoned-teampcp-details-claude-code-leaked/ Huge thanks to our sponsor, ThreatLocker Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, a...

Apr 01, 20268 min

macOS Terminal ClickFix attacks, Russian court sentences 'Flint', CareCloud probes data breach

macOS Terminal gets ClickFix attacks Russian court sentences 'Flint' over card fraud CareCloud probes data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-macos-terminal-clickfix-attacks-russian-court-sentences-flint-carecloud-probes-data-breach/ Huge thanks to our sponsor, ThreatLocker Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the fir...

Mar 31, 20268 min

Department of Know: Gemini scours dark web, NSA worries about cybersecurity, APIs run loose

Link to episode page This week's Department of Know is hosted by Rich Stroffolino with guests Dennis Pickett , vp, CISO, RTI International , and Jacob Combs , CISO, Tandem Diabetes Care Thanks to our show sponsor, ThreatLocker Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack sur...

Mar 30, 202636 min

FBI email theft, Lloyds Bank glitch, API keys running loose

FBI confirms theft of director's personal emails Lloyds customer data exposed in IT glitch Hundreds of valid API keys discovered on the Web Get the show notes here: https://cisoseries.com/cybersecurity-news-fbi-email-theft-lloyds-bank-glitch-api-keys-running-loose/ Huge thanks to our sponsor, ThreatLocker Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what softw...

Mar 30, 20268 min

Alleged RedLine dev extradited, Red Menshen spies with BPFDoor, is US cybersecurity slipping?

The episode highlights significant cybersecurity developments, including the extradition of a RedLine Info Stealer malware developer and Red Menshen's use of BPFDoor for long-term telecom espionage. Former NSA chiefs express worry over the US's slipping cyber edge amidst threats from China and AI, emphasizing vulnerabilities in critical infrastructure and connected vehicles. Additionally, the FCC introduces new measures against robocalls, while US officials accuse China of exploiting a cyber scam crisis.

Mar 27, 20268 min

Torg Grabber targets crypto, TeamPCP backdoors LiteLLM, GitHub AI bug detection

Torg Grabber targets crypto wallets TeamPCP backdoors LiteLLM GitHub adds AI security bug detection Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-torg-grabber-targets-crypto-teampcp-backdoors-litellm-github-ai-bug-detection/ Huge thanks to our sponsor, ThreatLocker Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — ...

Mar 26, 20268 min

FCC router ban, drone hit AWS, Crunchroll leak

FCC bans foreign routers Drone activity disrupts AWS region Crunchyroll confirmed data leak Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-fcc-router-ban-drone-hit-aws-crunchroll-leak/ Huge thanks to our sponsor, ThreatLocker Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attacker...

Mar 25, 20267 min

DarkSword exploit hits GitHub, Gemini AI agents scour dark web, Trivy supply chain attack expands

New DarkSword exploit hits GitHub Gemini AI agents scour the dark web Trivy supply chain attack expands Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-darksword-exploit-hits-github-gemini-ai-agents-scour-dark-web-trivy-supply-chain-attack-expands/ Huge thanks to our sponsor, ThreatLocker Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing exec...

Mar 24, 20268 min

Department of Know: SaaS apps enable breaches, real-time cyber protection, IoT botnet takedown

Link to episode page This week's Department of Know is hosted by Rich Stroffolino with guests Bil Harmer , CISO, Supabase , and Chris Ray , Field CTO, GigaOm Thanks to our show sponsor, ThreatLocker Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occu...

Mar 23, 202632 min

International botnet takedown, California city ransomed, Azure Monitor phishing

Law enforcement seizes botnet infrastructure California city and LA transit agency report cybersecurity issues Microsoft Azure Monitor alerts used for callback phishing attacks Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-cybersecurity-news-international-botnet-takedown-california-city-ransomed-azure-monitor-phishing/ Huge thanks to our sponsor, ThreatLocker Most breaches don't start with a zero-day — they start because something unexpected was allowed ...

Mar 23, 20268 min

Critical SharePoint flaw, real-time cyberattack prevention, CISA's Intune warning

Critical Microsoft SharePoint flaw now exploited in attacks 1stProtect reveals endpoint security platform intended to prevent cyberattacks in real time CISA urges U.S. organizations to secure Microsoft Intune systems following Stryker breach Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-critical-sharepoint-flaw-real-time-cyberattack-prevention-cisas-intune-warning/ Huge thanks to our episode sponsor, Adaptive Security This episode is brought to you by ...

Mar 20, 20268 min

DarkSword emerges, "ShieldGuard" dismantled, NK IT worker army rakes in money

DarkSword emerges from suspected Russian hackers "ShieldGuard" dismantled after malware discovery North Korea's fake IT worker army rakes in $500M/year Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-darksword-emerges-shieldguard-dismantled-nk-it-worker-army-rakes-in-money/ Huge thanks to our episode sponsor, Adaptive Security This episode is brought to you by Adaptive Security , the first security awareness platform built to stop AI-powered social engin...

Mar 19, 20267 min

Energy strategy, scammer accord, font-rendering attack

The episode covers the US Energy Department's new cyber strategy focusing on grid protection and public-private partnerships, alongside tech giants' accord to combat online scams. It also details a novel font-rendering attack fooling AI, Leaknet ransomware's new tactics, and international sanctions against Iranian and Chinese cyber threat actors. Finally, it discusses the UK Cyber Monitoring Center's expansion plans and the Kani Group's targeted attacks via KakaoTalk.

Mar 18, 20267 min

Stryker hospital tools safe, models apply to power AI scams, cybercrime up 245%

Stryker hospital tools safe, digital ordering services down Models apply to be the face of AI scams Cybercrime up 245% since Iran conflict Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-stryker-hospital-tools-safe-models-apply-to-power-ai-scams-cybercrime-up-245/ Huge thanks to our episode sponsor, Adaptive Security This episode is brought to you by Adaptive Security , the first security awareness platform built to stop AI-powered social engineering. To...

Mar 17, 20267 min

Department of Know: OpenAI vulnerability scanner, US new cyber strategy, VPN SEO poisoning

Link to episode page This week's Department of Know is hosted by Rich Stroffolino with guests Jonathan Waldrop , CISO, Acoustic , and Chris Ray, Field CTO, GigaOm Thanks to our show sponsor, Adaptive Security This episode is brought to you by Adaptive Security , the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot...

Mar 16, 202637 min

Royal Bahrain Hospital breach, Canada's Loblaw breached, New York water laws

Payload Ransomware group claims breached of Royal Bahrain Hospital Canadian food retailer Loblaw confirms data breach New York cyber regulations for water organizations launch in 2027 Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-royal-bahrain-hospital-breach-canadas-loblaw-breached-new-york-water-laws/ Huge thanks to our episode sponsor, Adaptive Security This episode is brought to you by Adaptive Security , the first security awareness platform built...

Mar 16, 20268 min

Iran boosts cyberattacks, VENON targets Brazilian banks, England Hockey investigates breach

Iran boosts cyberattacks VENON targets Brazilian banks England Hockey investigates breach Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-iran-boosts-cyberattacks-venon-targets-brazilian-banks-england-hockey-investigates-breach/ Huge thanks to our sponsor, Dropzone AI If you are heading to RSAC next week, here are three things worth seeing at the D ropzone AI Diner. Booth 455, South Expo Hall. One: watch their AI SOC agents investigate real alerts live, ...

Mar 13, 20268 min

Meta apps offer new scam protection, Google's Wiz acquisition finalized, China curbs state-run OpenClaw use

Meta apps offer new scam protection Google's Wiz acquisition finalized China curbs state-run OpenClaw use Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-meta-offers-scam-protection-googles-wiz-acquisition-finalized-china-curbs-openclaw-use/ Huge thanks to our sponsor, Dropzone AI Here is something worth asking any AI security vendor you meet at RSAC. Can you show me exactly what your AI did? Not just the verdict. The reasoning. Every tool it queried, ev...

Mar 12, 20267 min

New Cyber Command chief, Russia targets Signal, Codex Security

NSA and Cyber Command head confirmed Russians targeting encrypted messaging app users OpenAI rolls out vulnerability scanner Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-march-11-2026/ Huge thanks to our sponsor, Dropzone AI Remember yesterday's 3 AM threat intel? Here is how it plays out with Dropzone AI . The intelligence drops. Dropzone picks it up, turns it into a threat hunt, and runs it across your SIEM, EDR, and cloud data while your team sleep...

Mar 11, 20267 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android