『Talkin' Bout [Infosec] News』のカバーアート

Talkin' Bout [Infosec] News

Talkin' Bout [Infosec] News

著者: Black Hills Information Security
無料で聴く

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Join us live on YouTube, Monday's at 4:30PM ETCopyright 2025 Talkin' About [Infosec] News, Powered by Black Hills Information Security 政治・政府
エピソード
  • Iranian Cyberattacks on U.S. Water Systems - 2026-08-03
    2026/08/05
    This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also explore Google’s Android age-verification plans, Chrome protections against hijacking extensions, Microsoft Teams impersonation attacks deploying Chaos ransomware, and Bank of America’s acquisition of MDSec. Additional topics include the GrapheneOS duress-password court case, a DEF CON prediction market, continued Kali365 phishing activity, and credential-stuffing attacks against Chick-fil-A loyalty accounts.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Zuckers(03:43) - Iranian Cyberattacks on U.S. Water Systems - 2026-08-03(07:00) - Story # 1: Anthropic’s Claude Breaches Companies During Security Testing(11:35) - Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident(13:37) - Story # 3: ExfilSquad Claims a Microsoft Cloud Breach(19:34) - Story # 4: Iranian Cyberattacks Target U.S. Water Systems(28:27) - Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud(40:51) - Story # 6: Google Introduces Android Age Verification(43:26) - Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions(47:02) - Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware(48:38) - Story # 9: Bank of America Acquires MDSec(51:15) - Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search(55:25) - Story # 11: Pony Market Takes Bets on DEF CON and Black Hat(58:06) - Story # 12: Kali365 Phishing Platform Remains Active(01:02:26) - ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential StuffingLinksStory # 1: Anthropic’s Claude Breaches Companies During Security TestingStory # 2: Hugging Face Publishes Technical Details of the OpenAI IncidentStory # 3: ExfilSquad Claims a Microsoft Cloud BreachStory # 4: Iranian Cyberattacks Target U.S. Water SystemsStory # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad FraudStory # 6: Google Introduces Android Age VerificationStory # 7: Chrome Targets Tab- and Homepage-Hijacking ExtensionsStory # 8: Fake Microsoft Teams Support Calls Deploy Chaos RansomwareStory # 9: Bank of America Acquires MDSecStory # 10: GrapheneOS Duress Password Wipes Phone During Border SearchStory # 11: Pony Market Takes Bets on DEF CON and Black HatStory # 12: Kali365 Phishing Platform Remains ActiveChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential StuffingInfosec: Age of AI SummitDEATHcon- November 13 - 14, 2026- Univeristy of San Diego5998 Alcala Park Way San Diego, California 92110Creators & Guests Ralph May - HostWade Wells - HostBronwen Aker - HostCorey Ham - HostNick Ascoli - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 7 分
  • OpenAI accidentally Hacked Hugging Face - 2026-07-27
    2026/07/28
    This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴event-live-chatChapters(00:00) - PreShow Banter™ — Sol with a Goal(06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27(09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system(18:33) - Story #2 - Lapsus is shutting down(24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery(31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning(44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25(52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi(55:51) - Ads and Mike at the AI Summit(59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular ImplantsLinksStory #1 - OpenAI says it accidentally hacked Hugging Face with a new AI systemStory #2 - Lapsus is shutting downStory #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent ForgeryAgentForger, Part 2: The Autonomous InsiderStory #4 - Beyond the Terminal: Offensive Security Evals for Embodied ReasoningStory #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-FiAds and Mike at the AI SummitStory #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular ImplantsCreators & Guests Ads Dawson - GuestMike Takahashi - GuestCorey Ham - HostJohn Strand - HostBronwen Aker - HostHayden Covington - HostRalph May - HostClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 5 分
  • Initiative Gold Eagle - 2026-07-20
    2026/07/21
    This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development involving Flock Safety, and the latest wave of AI news. The conversation also explores evolving AI model capabilities, security guardrails, open-weight Chinese models, and how AI is changing offensive and defensive security. Along the way, the hosts examine recent vulnerability research, industry reactions, and other cybersecurity headlines from the week.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Two Jokes(01:58) - Initiative Gold Eagle - 2026-07-20(12:24) - Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination(18:58) - Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat(21:48) - Story #3 - Now, defenders are embracing the prompt injection, too(27:45) - Story #4 - Security incident disclosure — July 2026(33:38) - Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift(44:25) - Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy(47:24) - Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system(48:38) - Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE(51:49) - Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities(53:20) - Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC(58:10) - Paul’s Workshop(01:00:29) - Sign up for the AI Summit to see Matt’s talk(01:02:45) - Bronwen’s Workshop(01:07:10) - Wild West Hackin’ Fest(01:07:25) - DeathCon(01:09:08) - PostShow Banter - Retirement FundsLinksStory #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability CoordinationStory #2 - Microsoft Reins in RoguePlanet Zero-Day ThreatStory #3 - Now, defenders are embracing the prompt injection, tooStory #4 - [Huggingface] Security incident disclosure — July 2026Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shiftStory #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacyStory #7 - Inside Pegasus: The evolution of the world’s most notorious spyware systemStory #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS COREStory #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilitiesStory #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFCPaul’s WorkshopSign up for the AI Summit to see Matt’s talkBronwen’s WorkshopWild West Hackin’ FestDeathConCreators & Guests Corey Ham - HostRalph May - HostJohn Strand - HostPaul Clark - GuestWade Wells - HostMeagan Bentley - ProducerBronwen Aker - HostMatt Franz - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 11 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません