Recent episodes from trusted cybersecurity podcasts, covering breaking threat news, deep-dive investigations, and security research.
Darknet Diaries · 1h 7m · 1 month ago
176: NSL
An internet service provider receives an FBI National Security Letter demanding customer data, but upon examination, the letter appears to contain constitutional violations. Rather than comply, the provider embarks on a legal challenge to change the law governing these letters, raising questions about surveillance overreach and the proper limits of government authority.
The episode explores one person's thirty-year fight against digital surveillance through constitutional challenge and advocacy work, examining how National Security Letters function as a surveillance tool and what legal remedies exist to contest them.
Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban
Anthropic's Fable 5 has been reinstated while OpenAI's GPT-5.6 faces restrictions, as China closes gaps in AI vulnerability development capabilities through distillation techniques and cheaper token usage. The episode also covers Microsoft Edge being weaponized via malicious extensions and an Iranian APT operator's operational security failure during travel, alongside broader weekly cybersecurity developments.
Risky Business #843 -- Fortibleed is kinda awesome, actually
Rob Joyce, former NSA Director of Cybersecurity and 34-year agency veteran who previously led Tailored Access Operations, joins as special guest co-host to discuss the week's cybersecurity developments. The panel examines the Fortibleed campaign, which they characterize as surprisingly sophisticated, along with incidents including stolen Klue OAuth tokens leading to Salesforce data breaches and OpenAI's planetary patching ambitions. The episode also covers runZero's acquisition by Accenture.
Risky Business #842 -- Anthropic needs an adult in the C suite
Anthropic's recently launched Fable 5 and Mythos 5 models faced rapid US government shutdown just four days after release, citing security concerns. The hosts discuss why AI guardrails alone are insufficient safeguards and explore broader implications for AI safety governance.
The episode also covers the expiration of the FISA 702 surveillance statute and its ongoing enforcement, NPM v12's incremental improvements to supply chain attack mitigation, and a series of Microsoft Windows Update bugs that prevent systems from receiving patches.
A decade-long cybercrime operation known as Bayrob began with a fake car listing on eBay and evolved into one of the FBI's most complex cases to unravel. The scheme involved custom malware, sophisticated operational security, and networks of infected computers that mined cryptocurrency for the perpetrators while siphoning millions from unaware victims. The investigation ultimately led American law enforcement to three men from Romania responsible for orchestrating the operation.
Sophos conducted a six-year covert cyber operation against a state-backed hacking group that repeatedly targeted its firewalls, ultimately disrupting nine zero-day attacks and exposing the attackers' identities. The company's aggressive defensive tactics forced the threat actors to change their approach, but the episode explores the ethical and practical implications of this unconventional corporate response to persistent nation-state threats.
In the Dominican Republic, a shadow economy has emerged centered on stolen credit card data, operated by criminals known as tarjeteros who profit from card fraud. This episode follows one group of tarjeteros who traveled to the United States and conducted widespread fraudulent operations in New York City, exploiting stolen payment card information for financial gain.
A researcher named D3ada55 discovered a device promising unlimited movies and TV shows without advertisements, but upon investigation uncovered something darker—the device itself was surveilling its users. The episode explores what D3ada55 found when examining this so-called SuperBox and the implications of the monitoring occurring behind the scenes.
Music streaming platforms contain exploitable loopholes that allow fraudsters to artificially inflate chart rankings and streaming numbers, manufacturing success through manipulation rather than genuine listener engagement. An interview subject named Andrew shares his experience profiting from these vulnerabilities before pivoting to work on the defensive side, helping platforms close the gaps that enable such fraud. The episode explores how these schemes work and their implications for understanding the legitimacy of streaming metrics.
Phrack, the world's oldest and most prestigious underground hacking magazine, has been publishing since 1985 and continues operating today. This episode features interviews with the Phrack staff discussing their experiences running the influential publication over its four-decade history.