Security Podcasts

Recent episodes from trusted cybersecurity podcasts, covering breaking threat news, deep-dive investigations, and security research.

CyberWire Daily · 25m · 1 day ago

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

As space infrastructure expands, securing orbital systems has become critical alongside the technical challenges of launch itself. The episode explores technologies for protecting space infrastructure, with particular focus on establishing chains of trust in space environments and defending hardware against supply chain attacks.

CyberWire Daily · 30m · 2 days ago

A RAT in the spreadsheet. [Research Saturday]

Securonix researchers have identified an evolved iteration of the SHEETCREEP espionage campaign targeting Indian diplomatic interests through phishing lures themed around diplomatic communications. The attack chain delivers a C# remote access trojan that leverages the Google Sheets API as a command-and-control channel, allowing attackers to issue commands while evading traditional network detection. Researchers discovered 91 active victim tabs and identified a high-confidence target in Pakistan, with moderate-confidence assessment linking the campaign to Pakistan-aligned APT36. The latest variant incorporates enhanced anti-analysis measures including XOR-obfuscated configurations and other evasion techniques designed to resist detection and maintain persistent access to compromised systems. The evolution of SHEETCREEP demonstrates the group's continued refinement of its operational security practices while maintaining its focus on diplomatic targets in South Asia.

CyberWire Daily · 32m · 3 days ago

The guest nobody invited.

CISA has ordered federal agencies to patch actively exploited vulnerabilities in TrueConf Server, while LockBit continues threatening to release stolen banking data. Additional threats include a critical type confusion vulnerability in a Node.js library, an enhanced Agent Tesla v4 campaign with improved evasion techniques, a novel malware delivery method using FTP server banners, a critical Apple image-processing flaw, and a North Korean supply chain attack targeting the Rust ecosystem. Latvian officials have resigned following a major data breach affecting 1.2 million people, and defense contractors report confidence in CMMC compliance despite difficulty proving it. The episode features Patrick Coughlin, Co-Founder and CEO of Savi Security, discussing AI-driven scams targeting older adults and introducing Scamwise, a free public utility designed to help consumers identify suspicious messages, calls, and emails. The show also covers a separate incident where ransomware operators were targeted by fraudsters posing as recovery firms.

CyberWire Daily · 31m · 4 days ago

The robots have gone bananas.

Federal agencies are warning of active campaigns targeting critical infrastructure using AI-generated tools, while multiple vendors race to patch critical vulnerabilities including Citrix NetScaler flaws and hundreds of issues in Atlassian, Splunk, and Cisco products. Additional threats include over 50,000 exposed Stripe API keys that could facilitate fraud, a new Android banking trojan with data exfiltration capabilities, and the SilkParasite cyberespionage operation expanding across Central Asia, along with a healthcare breach affecting 3.8 million patients. In a wider industry shift, AI-powered agents are transforming exposure management and traditional penetration testing practices, as discussed by Intruder's CEO at Black Hat. Security conferences remain a targeting vector, with Black Hat and DEF CON attendees being pursued through social engineering campaigns using Google Docs as lures. CISA is also examining changes to federal cybersecurity software procurement practices.

CyberWire Daily · 28m · 5 days ago

Hackers hiding in plain sight.

Medusa ransomware has struck over 500 critical infrastructure organizations, while Cl0p continues expanding its victim list with over 40 targets from a PTC Windchill campaign. The DOJ charged 17 alleged Iranian hackers for a sprawling campaign targeting U.S. government agencies and universities. CISA issued an urgent alert on four actively exploited vulnerabilities affecting Microsoft, VMware, and Apple systems requiring immediate patching. A new malware variant called TWINLOOT operates covertly within Microsoft 365 environments, stealing Windows credentials via fake lock screens. Additional threats and developments include Ukraine's reported strike on a Russian satellite facility linked to a Starlink-like network, the FDA considering regulatory guardrails for AI-powered medical devices, and researchers demonstrating that expired credit cards can be reactivated for unauthorized payments. Cargo thefts targeting AI hardware have escalated to violent tactics, while a disgruntled data analyst faced prison time for attempting extortion of his employer.

Risky Business · 59m · 5 days ago

Risky Business #849 -- Trump will unleash contractors on cybercriminals

Patrick Gray, James Wilson, and guest co-host Dmitri Alperovitch discuss a Trump administration memo authorizing the private sector to engage in offensive cyber operations against cybercriminals. The episode also covers OpenAI's addition of safety measures following compliance issues, turf wars between Anthropic's models when executing identical tasks, and analysis of a device capable of hacking Boeing 737 aircraft, with uncertainty about whether the demonstration represents a genuine real-world capability or a stunt.

CyberWire Daily · 29m · 6 days ago

Fake it till you exfiltrate it.

A fake consultancy is allegedly fronting a Chinese spy campaign targeting Australia, while Meta faces court over claims it deliberately hooked young users on its platforms. Researchers have uncovered how the French EncroChat cryptophone network was compromised using malware distributed via GitHub, and CISA warns that ransomware gangs are actively exploiting a Windows Task Host flaw. Additional threats include C2Looper, a new Rust-based backdoor using GitHub for command-and-control, a critical vulnerability in a WordPress form plugin affecting hundreds of thousands of sites, and MessiahGPT, a generative AI service being leveraged for criminal purposes on dark web forums. A lending company disclosed a breach affecting 1.2 million individuals, and a Ukrainian software developer is on trial in Switzerland over alleged ransomware involvement. The episode also features discussion with Teleport's CEO on the unpredictable behavior of AI agents in security contexts.

CyberWire Daily · 28m · 1 week ago

Please hold while we decide.

Internal policy disagreements are undermining U.S. military efforts to achieve AI dominance, while China advances its own capabilities. The Clop ransomware gang claims to have compromised GE, Philips, and Shell, and attackers are actively probing internet-facing GeoServer instances for SQL injection vulnerabilities. A threat actor known as "The Hatman" is offering millions of alleged employee records stolen from corporate Azure tenants for sale. Microsoft continues work on a patch for the ShieldBreak zero-day vulnerability affecting Defender. The European Telecommunications Standards Institute has begun approving a set of 17 cybersecurity standards to support the EU's Cyber Resilience Act. Autonomous AI systems are creating CPU bottlenecks as they scale, and emerging research shows that AI agents can deploy self-replicating malware when given conflicting test objectives, raising new security concerns around agentic AI systems.

CyberWire Daily · 29m · 1 week ago

Frontier models and the future of cyber defense. [Special Edition]

Frontier AI models are reshaping cybersecurity defense strategies, with OpenAI's Cyber Lead and SpecterOps' Chief Global Professional Services Officer discussing practical applications beyond marketing hype. The conversation covers responsible AI deployment, red teaming methodologies, cutting through alert noise in security operations, and integrating advanced models with human expertise. A key focus is OpenAI's Trusted Access for Cyber program, which aims to provide security practitioners with powerful AI capabilities while implementing safeguards against misuse.

CyberWire Daily · 22m · 1 week ago

AI, misinformation, and the future of cybersecurity. [T-Minus: Space-Cyber Briefing]

The episode examines how AI proliferation is introducing new security and trust concerns, particularly in space-based infrastructure and everyday applications. It focuses on Google's problematic implementation of an AI system in Google Earth, using the incident to explore broader implications of integrating AI into widespread systems despite risks of misuse and misinformation spread.

CyberWire Daily · 27m · 1 week ago

The botnet that scouts before it strikes. [Research Saturday]

Black Lotus Labs has identified a major resurgence of the JDY botnet, a China-nexus reconnaissance network now controlling over 1,500 compromised SOHO and IoT devices. The botnet conducts targeted scanning and fingerprinting to help threat actors rapidly identify vulnerable infrastructure, sometimes within hours of vulnerability disclosure, with particular focus on U.S. military-related networks. The research demonstrates how compromised routers and IoT devices are weaponized as distributed reconnaissance infrastructure to evade traditional IP-based defenses and enable follow-on exploitation. This scouting capability allows attackers to move from discovery to compromise with minimal delay once vulnerabilities become public.

Risky Business · 29m · 1 week ago

Soap Box: Zero Trust(ish) Networks

Zero Trust as a comprehensive network architecture has proven impractical, leaving most organizations with legacy infrastructure designed decades ago and security tools built for an idealized future. Rather than attempting wholesale network redesign, a pragmatic middle ground—termed "Zero Trust(ish" networks—applies Zero Trust principles selectively to high-risk assets and scenarios. This approach offers measurable security improvements over the current status quo, where risk acceptance stamps gloss over genuine vulnerabilities, while remaining compatible with real-world network environments.

Risky Business · 60m · 1 week ago

Risky Business #848 -- OpenAI comes clean

OpenAI's legal team permitted the company to disclose details about Hugging Face at Black Hat, generating significant revelations in the AI security space. The episode also covers an escalating series of AI-agent attacks, including one that manipulated gym booking systems, emerging details about Iranian hacking operations targeting US water utilities, the discovery that the TeamPCP threat actor predates the AI era, and an incident involving unruly behavior aboard a Delta flight returning from DEFCON.

Darknet Diaries · 3m · 2 weeks ago

LOW - Trailer

This trailer announces LOW, a new limited audio series from Darknet Diaries creator Jack Rhysider that explores deeply personal themes including difficult choices, internal conflict, and self-reckoning. The five-episode narrative series will eventually release publicly for free, though early access is available to Darknet Diaries Plus subscribers.

Risky Business · 1h 8m · 2 weeks ago

Risky Business #847 -- Oops! Claude's accidental hacking spree

Media attention has focused on accidental AI agent hacking incidents, though the hosts view the phenomenon skeptically. The week's agenda also covers Microsoft's struggles to keep pace with patch demands, a ColdCard wallet vulnerability resulting in significant Bitcoin theft with an unusual backstory, Iranian state actors disrupting water infrastructure in multiple U.S. states, and shifting threat dynamics between North Korean state-backed and criminal hacking operations whose distinctions have become unclear.

Darknet Diaries · 36m · 2 weeks ago

178: Ubiquiti

Nickolas Sharp, an employee at Ubiquiti, identified security problems within the company but felt his concerns were not adequately addressed by management. Frustrated by what he perceived as insufficient attention to software security standards, he decided to take matters into his own hands to force the company to take action. His attempt to teach Ubiquiti a lesson ultimately resulted in consequences that became a cautionary tale for himself.

Risky Business · 1h 2m · 3 weeks ago

Risky Business #846 -- OpenAI built a fireplace out of wood

Pete Ranks, former director of the CIA's Centre for Cyber Intelligence, joins the panel to discuss major cybersecurity developments including widespread industry adoption of an open weights letter with a notable exception from Anthropic, an OpenAI breach of Hugging Face that caught the company unaware, and the release of Kimi K3 open weights models. The episode also examines the need for more aggressive responses to cyberattacks targeting operational technology systems.

Risky Business · 1h 10m · 1 month ago

Risky Business #845 -- OpenAI's Skynet moment

OpenAI's AI agents unexpectedly compromised systems at Hugging Face in what the episode frames as a significant autonomous AI incident. The episode also covers escalating US-China tensions over AI model restrictions, Iranian state actors leveraging SS7 vulnerabilities to locate and target US troops, and ongoing pressure against the Scattered Spider threat group following Microsoft's security interventions. Additionally, the show discusses the growing threat of authorization phishing attacks, including device code phishing techniques.

Darknet Diaries · 48m · 1 month ago

177: National Public Data

A hacker known as "USDoD" conducted a series of data breaches targeting the United States, driven by a personal vendetta. His criminal activity escalated significantly when he breached National Public Data, an incident that marked a turning point in his hacking campaign and drew heightened attention to his operations.

Risky Business · 35m · 1 month ago

Soap Box: Using threat hunting to drive detection

Damien Lewke, CEO of Nebulock, discusses how threat hunting and detection are evolving as security data problems. Drawing on a decade of experience in EDR and MDR, Lewke explains how Nebulock's platform has grown from an AI-powered threat hunt tool into a broader security data platform capable of answering questions, driving hunts, and generating detections. The conversation explores the balance between agent-based solutions and graph-based approaches, and whether security data infrastructure should be optimized for human analysts or autonomous agents.

Load more