

Cybersecurity Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

Jan 27, 2026 • 34min
Department of Know: Davos worries, UK-China tensions, calendar concerns
Jason Shockey, CISO at Cenlar FSB, focuses on cybersecurity program maturity and AI governance. Krista Arndt, Associate CISO at St. Luke's, brings hands-on healthcare security and threat modeling experience. They discuss calendar and AI agent risks, LastPass phishing and MFA limits, SmarterMail exploit lessons, UK-China cyber dialogue, AI-generated malware, and selling AI guardrails to the business.

24 snips
Jan 26, 2026 • 8min
Microsoft Patch problems, Sandworm hits Poland, Dresden Museum cyberattack
Outlook PST and Windows 11 boot issues after Microsoft's patches. A destructive Sandworm-linked attack hits Poland's power infrastructure. A Dresden museum's ticketing and phone systems go offline due to a network intrusion. New actively exploited vulnerabilities added to CISA's KEV list and fresh claims of voice-phishing breaches circulate.

16 snips
Jan 23, 2026 • 9min
Multi-stage SharePoint attack, SmarterMail bypass flaw, AI worries Davos
A multi-stage phishing campaign exploiting SharePoint has emerged, prompting serious cybersecurity concerns. Attackers are leveraging a patched SmarterMail vulnerability for unauthorized access. Meanwhile, discussions at Davos highlight fears surrounding AI agents potentially becoming insider threats, stressing the need for monitoring strategies. The recent takedown of a mobile fake tower scam in Greece showcases ongoing fraud battles. Additionally, a new ransomware threat, Osiris, targets defenses through vulnerable drivers, further complicating the security landscape.

9 snips
Jan 22, 2026 • 8min
Tesla hacked at Pwn2Own Automotive, Everest sitting on Under Armour data? PurpleBravo fake jobs campaign targets IP addresses
In a cybersecurity showdown at Pwn2Own, teams showcased 37 zero-day exploits targeting electric vehicle systems, with Synactive successfully hacking Tesla's infotainment. Allegations arise that Everest has stolen and leaked 72.7 million Under Armour accounts. Additionally, the North Korean group Purple Bravo is using fake job interviews to target specific IPs. Meanwhile, phishing threats proliferate ahead of the Milano Cortina Olympics, and a phishing scam linked to LastPass aims to capture master passwords.

16 snips
Jan 21, 2026 • 7min
UK-China forum, Iranian TV hijacked, VoidLink made by AI
Tensions between the UK and China are in focus as a cyber dialogue is established to address incidents. The Iranian state TV faced a bizarre hijacking during a blackout, urging protests. An intriguing report reveals that the VoidLink malware was largely created by AI, showcasing its evolving role in cyber threats. The podcast also highlights a new fraud reporting portal by the City of London Police, aiming to fight fraud with real-time analytics.

8 snips
Jan 20, 2026 • 7min
Gemini prompt injection flaw exposes calendar info, hacker admits to Supreme Court data leak, researchers uncover PDFSIDER malware
Dive into the latest cybersecurity news as a Gemini prompt injection flaw reveals sensitive calendar information. A hacker confesses to leaking confidential Supreme Court data, raising alarms. Researchers unveil the stealthy PDFSIDER malware, which employs DLL sideloading and DNS exfiltration techniques. Also, learn about CISA’s internal leadership disputes and significant breaches affecting thousands, including Ingram Micro. Discover how AI is expanding attack surfaces and the urgency of patching vulnerabilities in connected devices.

10 snips
Jan 20, 2026 • 37min
Department of Know: Easterly helms RSAC, Third party apps report, Self-poisoning AI
Dmitriy Sokolovskiy, a senior VP of information security at SEMrush, and Nick Espinosa, host of The Deep Dive Radio Show, dive deep into the evolving landscape of cybersecurity. They discuss the potential risks of AI hallucinations in risk reporting and explore how ransomware is now leveraging blockchain for command-and-control operations. The duo debates the implications of private firms engaging in offensive cyber operations and highlights alarming findings related to unauthorized third-party access to sensitive data.

8 snips
Jan 19, 2026 • 8min
NSA dual-hat question, third-party report, GhostPoster extension continues
A nominee is set to evaluate the complex dual-hat leadership at Cyber Command and NSA, potentially reshaping cybersecurity strategy. A staggering 64% of third-party apps mishandle sensitive data, raising alarm bells. GhostPoster browser extensions have hit 840,000 installs, with malicious activities lurking within. Meanwhile, law enforcement targets Black Basta operators, and a major phishing breach impacts 750,000 Canadian investors. Grubhub admits to a data theft and extortion incident, further highlighting rising cyber threats.

13 snips
Jan 16, 2026 • 8min
Easterly helms RSAC, Windows update problems, Police Copilot gaffe
Jen Easterly is set to lead the RSA Conference, promising fresh insights. A recent Windows update caused major login issues for Azure Virtual Desktop users, creating headaches for IT teams. Meanwhile, the UK police mistakenly attributed an intelligence error to AI Copilot, sparking debates about AI's reliability. Guidance on securely connecting industrial control systems is highlighted by top agencies, and Kyo-won's ransomware incident has raised alarms over data exposure. Plus, a new technique reveals vulnerabilities in Copilot's session data.

20 snips
Jan 15, 2026 • 8min
U.S. weighs cyberwarfare options, DeadLock uses smart contracts to hide work, China says stop using US and Israeli cybersecurity software
The U.S. is exploring the possibility of allowing private companies to engage in offensive cyber operations, raising intriguing legal questions. Meanwhile, China has ordered its firms to stop using cybersecurity software from the U.S. and Israel. DeadLock is making waves by employing smart contracts to obscure its operations and threaten to sell stolen data. In other news, Microsoft has taken action against fraud stemming from the RedVDS platform, which has impacted real estate transactions severely. Finally, Poland successfully stopped a cyberattack aimed at its power grid, preventing a potential blackout.


