Cybersecurity Today

Jim Love
undefined
Mar 30, 2026 • 20min

Russian State Hackers Go After IoS Devices

Mac malware called Infinity Stealer uses social‑engineering to harvest browser credentials, Keychain items, crypto wallets and developer secrets. A leaked iOS exploit kit named DarkSword is being used in targeted phishing to deliver mobile implants while Apple issues unusual on‑device warnings. A kernel BPFdoor persists inside global telecom infrastructure. A PyPI supply‑chain compromise uses WAV steganography to exfiltrate secrets and target Kubernetes.
undefined
Mar 28, 2026 • 41min

RSAC Recap: Agentic AI and Interview With Commvault CISO Bill O'Connell

Bill O'Connell, Commvault Chief Security Officer with decades in security, talks backup, resilience, and ResOps. He and the hosts discuss agentic AI takeover, AI-driven funding and hiring shifts, and how AI empowers attackers. They also cover translating risk for leaders and why recovery planning and practicing restores matter more than prevention alone.
undefined
Mar 27, 2026 • 11min

Anonymous Tip System Breach May Expose Tipsters

A major tip-submission system reportedly exposed millions of sensitive records and features that could compromise promised anonymity. Google warns quantum computers might break current encryption by 2029, raising urgent risks of archived data being decrypted later. The show also explores AI supply-chain threats from poisoned documentation and upcoming Copilot training policy changes that affect data governance.
undefined
Mar 25, 2026 • 15min

RSAC Presenter Says "Time to Kill One of Cybersecurity's Most Overworked Terms"

A debate over retiring the overused APT label in favor of describing actors by motivation and activity. Trade show trends from RSAC, including fading zero trust talk and a surge in agentic AI hype. The FCC's move to block new non-US-made Wi Fi routers and its supply chain rationale. Reports of public Zoom calls being scraped into AI‑generated podcasts. A Kubernetes supply chain campaign deploying an Iran‑targeting wiper. Treasury weighing cyber terrorism insurance changes.
undefined
Mar 23, 2026 • 13min

Startup Accused Of Helping Fake Privacy and Security Audits

Allegations that a compliance startup produced fabricated audit evidence and exposed sensitive data. A popular security scanner briefly shipped a backdoored release that stole cloud credentials and keys. U.S. agencies warn of social‑engineering attacks that hijack Signal and WhatsApp via malicious QR codes and verification tricks. An Iran‑linked cyberattack disrupted medical implant logistics and delayed surgeries.
undefined
Mar 21, 2026 • 50min

The Fundamental Mistake in Cybersecurity Risk Management

Jeff Gardner, former university CISO and doctoral researcher now at Morgan Stanley, argues cybersecurity has mistaken threat hunting for real risk management. He recounts a TLS epiphany, explains likelihood × impact, and shows simple five-point scales and prioritization. He also discusses training gaps, CISO burnout, and efforts to fold risk thinking into frameworks like NIST.
undefined
Mar 20, 2026 • 9min

FBI Seizes Iran-Linked Handala Leak Site After Stryker Intune Wipe Attack: Cybersecurity Today

A takedown of an Iran-linked leak site tied to a major Stryker attack and mass device wipes. Guidance from CISA and Microsoft on hardening Intune, identity controls, and requiring multi-admin approval. Apple pushes urgent iPhone patches for actively exploited flaws. New research reveals North Korean operatives posing as remote IT workers to infiltrate Western firms.
undefined
Mar 18, 2026 • 14min

Another Medical Device Firm Hit

A rundown of a phishing-led breach at a major medical device firm and why stolen credentials still cause big damage. Coverage of an 11-company pledge to share scam intel and rising AI-driven fraud estimates. A clever font/CSS trick that fools AI assistants gets tested and patched. Reports on Iran-linked cyberattacks, a massive Intune wipe claim, and hacked Denver crosswalk speakers due to default passwords.
undefined
6 snips
Mar 16, 2026 • 18min

Notorious Hacker Group "The Comm," Operation Synergia Takedown, Stryker Cyberattack Update & More

A Canadian hacker allegedly tied to an online crime group was unmasked after a harassment campaign. Interpol’s six-month Operation Synergia disabled thousands of malicious IPs and led to dozens of arrests. A major corporate cyberattack reportedly exploited Intune to wipe devices, disrupting medical operations. Poland says it foiled a suspected hack on its nuclear research center with possible foreign links.
undefined
10 snips
Mar 14, 2026 • 58min

AI Anxiety: Cybersecurity Today with Special Guest Krish Banerjee, Managing Director (Partner) & Canada Lead - Data & AI - Accenture

Krish Banerjee, Managing Director leading Data & AI for Accenture in Canada, offers practical AI leadership and transformation perspective. He covers Gemini in Workspace and how assistants like Copilot are converging. They dig into agent platforms, Nvidia’s enterprise push, why adoption lags capability, and ways to manage AI anxiety with training, guardrails, and task-focused redesign.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app