Talkin' Bout [Infosec] News

Advertise on podcast: Talkin' Bout [Infosec] News

Rating
4.8
from
93 reviews
This podcast has
333 episodes
Language
Explicit
Yes
Date created
2018/07/11
Latest episode
2026/04/22
Average duration
63 min.
Release period
8 days

Description

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Join us live on YouTube, Monday's at 4:30PM ET

Unlock Talkin' Bout [Infosec] News podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check Talkin' Bout [Infosec] News social media presence


Podcast episodes

Check latest episodes from Talkin' Bout [Infosec] News podcast


Tim Cook Announces Apple CEO Exit - 2026-04-20
2026/04/22
This episode covers several major cybersecurity and tech news stories, including a supply chain–related breach at Vercel involving exposed environment variables and compromised third-party AI tooling. The hosts also discuss concerns around AI-driven data risks, including browser extensions and large-scale data collection. Additional topics include a service scraping and republishing Zoom webinar recordings, evolving issues with web cookies and tracking, and industry news such as reports of Apple CEO Tim Cook stepping down. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Watch Out for the Brownies (04:35) - Tim Cook Announces Apple CEO Exit - 2026-04-20 (05:57) - Story # 1: Vercel April 2026 security incident (19:00) - Story # 2: 'Addicted to hacking': Young hacker behind historic breach speaks out for 1st time, before reporting to prison (27:19) - Story # 3: Mythos And The CVSS Problem No One Wants to Talk About (But We Need To) (28:49) - Story # 4: Introducing Claude Opus 4.7 (32:14) - Story # 4b: Identity verification on Claude (36:00) - Story # 5: Tim Cook to become Apple Executive Chairman John Ternus to become Apple CEO (40:18) - Story # 6: Microsoft faces fresh Windows Recall security concerns (44:12) - Story # 7: WebinarTV Secretly Scraped Zoom Meetings of Anonymous Recovery Programs (48:20) - Story # 8: Google, Microsoft, Meta All Tracking You Even When You Opt Out, According to an Independent Audit (51:12) - Story # 9: Little Caesars Wants ChatGPT to Order Your Pizza for You (53:35) - Story # 10: NIST Updates NVD Operations to Address Record CVE Growth (01:00:08) - Workshop: Rapid Endpoint Investigations for Linux and Mac (01:01:20) - Cyber Threat Intelligence 101 2 Day Version (01:02:24) - ANTI-CAST: How to Break Free from the Cybersecurity Burnout Trap w/ Natalia Samman LinksStory # 1: Vercel April 2026 security incidentStory # 2: ‘Addicted to hacking’: Young hacker behind historic breach speaks out for 1st time, before reporting to prisonStory # 3: Mythos And The CVSS Problem No One Wants to Talk About (But We Need To)Story # 4: Introducing Claude Opus 4.7Story # 4b: Identity verification on ClaudeStory # 5: Tim Cook to become Apple Executive Chairman John Ternus to become Apple CEOStory # 6: Microsoft faces fresh Windows Recall security concernsStory # 7: WebinarTV Secretly Scraped Zoom Meetings of Anonymous Recovery ProgramsStory # 8: Google, Microsoft, Meta All Tracking You Even When You Opt Out, According to an Independent AuditStory # 9: Little Caesars Wants ChatGPT to Order Your Pizza for YouStory # 10: NIST Updates NVD Operations to Address Record CVE GrowthWorkshop: Rapid Endpoint Investigations for Linux and MacCyber Threat Intelligence 101 2 Day VersionANTI-CAST: How to Break Free from the Cybersecurity Burnout Trap w/ Natalia Samman Creators & Guests Corey Ham - Host Ralph May - Host Patterson Cake - Guest Wade Wells - Host Bronwen Aker - Host Meagan Bentley - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
Anthropic’s Project Glasswing is an Infosec Turning Point – 2026-04-13
2026/04/14
This episode dives into Anthropic’s “Project Glasswing” and the broader implications of AI-driven offensive security, including models autonomously discovering vulnerabilities and attempting sandbox escapes. The hosts discuss how agentic AI testing approaches could reshape vulnerability research, while also raising concerns about AI safety, regulation, and real-world risk. Additional topics include the growing impact of AI on security workflows, rising infrastructure costs tied to AI demand, a new infostealer ecosystem overview, and ongoing debates about data collection practices and platform privacy. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — A Real Studio (03:43) - Anthropic’s Project Glasswing is an Infosec Turning Point – 2026-04-13 (05:39) - Story # 1: Project Glasswing (22:20) - Story # 2: AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties (30:36) - Story # 3: Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit (32:39) - WEBCAST: Proxy Execution with Microsoft Edge WebView2 w/ Matthew Eidelberg (51:47) - Story # 4: New "BrowserGate" report claims LinkedIn secretly scans user browsers for installed extensions and collects device data (56:32) - Story # 5: The silent “Storm”: New infostealer hijacks sessions, decrypts server-side (58:46) - ChickenSec: the Chicken Accords of 2026 (01:00:27) - Story # 6: EFF is Leaving X (01:03:01) - Workshop: How to Think Like a Cybersecurity Defender (01:05:49) - AI Security Ops Podcast LinksStory # 1: Project GlasswingStory # 2: AI-Led Remediation Crisis Prompts HackerOne to Pause Bug BountiesStory # 3: Disgruntled researcher leaks “BlueHammer” Windows zero-day exploitWEBCAST: Proxy Execution with Microsoft Edge WebView2 w/ Matthew EidelbergStory # 4: New “BrowserGate” report claims LinkedIn secretly scans user browsers for installed extensions and collects device dataStory # 5: The silent “Storm”: New infostealer hijacks sessions, decrypts server-sideChickenSec: the Chicken Accords of 2026Story # 6: EFF is Leaving XWorkshop: How to Think Like a Cybersecurity DefenderAI Security Ops PodcastCreators & Guests Corey Ham - Host Wade Wells - Host Alex Minster "Belouve" - Guest Bronwen Aker - Host Ralph May - Host John Strand - Host Doc Blackburn - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
FCC Blocks Foreign-Made Routers – 2026-03-30
2026/04/01
This episode covers the FCC’s move to restrict or ban certain foreign-made networking equipment—especially routers tied to Chinese manufacturers—highlighting the potential cybersecurity risks, supply chain implications, and how the rule could affect ISPs and consumers. The hosts also discuss broader concerns around hardware trust, existing infrastructure, and what qualifies as “approved” devices under FCC guidelines, along with a brief, lighter mention of a viral robot incident making the rounds online. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Robot Handlers (05:11) - FCC Blocks Foreign-Made Routers – 2026-03-30 (06:44) - Story # 1: FCC moves to block new foreign-made routers (17:00) - Story # 2: FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers (20:07) - Story # 3: FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops (24:18) - Story # 4: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign (27:49) - Story # 4b: TeamPCP Supply Chain Campaign (42:45) - Story # 5: Spylandia: How a Stretch of Florida Real Estate Has Become a Covert Corridor for Chinese and Russian Spies (45:51) - Story # 6: Anthropic readies Mythos model with high cybersecurity risk (57:31) - Story # 7: Google Ships WebMCP, The Browser-Based Backbone For The Agentic Web (01:02:24) - Story # 8: DDR5 Memory Prices Just Took a Noticeable Dive for the First Time in Months, and Google’s TurboQuant Might Be Behind It (01:04:03) - Securing the Cloud: Foundations by Andrew Krug (01:04:47) - Incident Response Simplified by Patterson Cake News LinksStory # 1: FCC moves to block new foreign-made routersStory # 2: FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian HackersStory # 3: FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage OpsStory # 4: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaignStory # 4b: TeamPCP Supply Chain CampaignStory # 5: Spylandia: How a Stretch of Florida Real Estate Has Become a Covert Corridor for Chinese and Russian SpiesStory # 6: Anthropic readies Mythos model with high cybersecurity riskStory # 7: Google Ships WebMCP, The Browser-Based Backbone For The Agentic WebStory # 8: DDR5 Memory Prices Just Took a Noticeable Dive for the First Time in Months, and Google’s TurboQuant Might Be Behind ItSecuring the Cloud: Foundations by Andrew KrugIncident Response Simplified by Patterson Cake Creators & Guests Andy Pettit "Nerf" - Guest Andrew Krug - Guest Wade Wells - Host Corey Ham - Host Bronwen Aker - Host Patterson Cake - Guest Ryan Poirier - Producer Ralph May - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
Pentagon Plans to Train AI With Classified Data – 2026-03-23
2026/03/27
This episode covers a range of cybersecurity and AI-related news, including how Pokémon Go players may have unknowingly helped train delivery robots using massive image datasets. The hosts also discuss the Pentagon’s reported plans to train AI systems on classified data and the potential risks of exposing sensitive information. Additional topics include major data breaches (such as a third-party breach impacting Crunchyroll user data), ongoing challenges in cybersecurity practices, evolving AI security concerns, and real-world examples of exploits and vulnerabilities affecting mobile devices and organizations. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Easier Than Printers (05:20) - Pentagon Plans to Train AI With Classified Data – BHIS - Talkin' Bout [infosec] News 2026-03-23 (06:38) - Story # 1: Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web (07:38) - Story # 1b: ALT Link - Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web (15:35) - Story # 2: Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway (24:31) - Story # 3: The Pentagon is planning for AI companies to train on classified data, defense official says (34:04) - Story # 4: CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization (37:50) - Story # 5: Warning: Your AI-Generated Password Is a Major Security Risk. Here’s What to Use Instead (42:21) - Story # 6: CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) (49:57) - Story # 7: Massive China Data Leak: Hackers Access 10 Petabytes of Weapons Testing Data (51:28) - Story # 8: Anime fans' credit cards might be stolen from Sony streamer Crunchyroll (55:03) - Story # 9: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors LinksStory # 1: Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the WebStory # 1b: ALT Link - Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the WebStory # 2: Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anywayStory # 3: The Pentagon is planning for AI companies to train on classified data, defense official saysStory # 4: CISA Urges Endpoint Management System Hardening After Cyberattack Against US OrganizationStory # 5: Warning: Your AI-Generated Password Is a Major Security Risk. Here’s What to Use InsteadStory # 6: CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)Story # 7: Massive China Data Leak: Hackers Access 10 Petabytes of Weapons Testing DataStory # 8: Anime fans’ credit cards might be stolen from Sony streamer CrunchyrollStory # 9: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat ActorsCreators & Guests John Strand - Host Ralph May - Host Chadd Watson - Guest Wade Wells - Host Alex Minster "Belouve" - Guest Hayden Covington - Host Bruce Potter - Guest Ryan Poirier - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
Iranian Hackers Claim Responsibility for Stryker Attack - 2026-03-16
2026/03/17
This episode covers multiple cybersecurity news stories, including Iranian hackers claiming responsibility for a cyberattack on Stryker, ongoing challenges in attributing nation-state cyber operations, and broader trends in global cyber conflict. The hosts also discuss the reliability of public breach claims, emerging threats targeting critical industries, and how organizations are responding to an increasingly complex threat landscape. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Organizing Family Beets (04:02) - Iranian Hackers Claim Responsibility for Stryker Attack - 2026-03-16 (08:56) - Story # 1: Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker (23:38) - Story # 2: How We Hacked McKinsey's AI Platform (32:30) - Story # 3: Amazon holds engineering meeting following AI-related outages (39:11) - Story # 4: Meta gets into social networks for AI agents with acquisition of viral Moltbook platform (45:24) - Story # 5: Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026 (50:45) - Story # 6: Michelin Confirms Data Breach Linked to Oracle EBS Attack (51:08) - Story # 7: New Dohdoor malware campaign targets education and health care (58:10) - Story # 8: Man's dog was riddled with tumors and dying. He used ChatGPT to design a custom cancer vaccine, stunning researchers LinksStory # 1: Iran-Backed Hackers Claim Wiper Attack on Medtech Firm StrykerStory # 2: How We Hacked McKinsey’s AI PlatformStory # 3: Amazon holds engineering meeting following AI-related outagesStory # 4: Meta gets into social networks for AI agents with acquisition of viral Moltbook platformStory # 5: Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026Story # 6: Michelin Confirms Data Breach Linked to Oracle EBS AttackStory # 7: New Dohdoor malware campaign targets education and health careStory # 8: Man’s dog was riddled with tumors and dying. He used ChatGPT to design a custom cancer vaccine, stunning researchersCreators & Guests Dan Rearden (Haircutfish) - Guest Bronwen Aker - Host Ralph May - Host John Strand - Host Troy Wojewoda - Guest Corey Ham - Host Hayden Covington - Host Wade Wells - Host Meagan Bentley - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
A Nightmare of Vibeware - 2026-03-09
2026/03/10
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — That's Not How It Works (03:40) - A Nightmare of Vibeware – 2026-03-09 (04:54) - Story # 1: APT36: A Nightmare of Vibeware (13:56) - Story # 2: Oracle Layoffs: Tech giant to slash 30,000 jobs as banks pull out from financing AI data centres (16:28) - Story # 3: Iran-linked hacktivist groups target US infrastructure after Feb 28 strikes, cyber activity surges: Report (24:28) - Story # 4: Introducing the First Frontier Suite built on Intelligence + Trust (28:59) - Story # 5: Motorola partners with GrapheneOS for future phones (29:13) - Story # 5b: GrapheneOS: Microsoft Authenticator does not support secure Android OS (29:53) - Story # 6: Western allies form 6G security coalition amid tech rivalry with China (34:01) - Story # 7: ShinyHunters claims ongoing Salesforce Aura data theft attacks (35:47) - Story # 8: Doppelgänger / RRN Disinformation Infrastructure Ecosystem 2026 (44:33) - Story # 9: LexisNexis confirms data breach as hackers leak stolen files (49:10) - Story # 10: Google urges Supreme Court to strike down geofence warrants as unconstitutional (55:59) - ANTI-CAST : How to Detect Malicious Remote Workers w/ James McQuiggan (56:47) - SOC Summit 2026 LinksStory # 1: APT36: A Nightmare of VibewareStory # 2: Oracle Layoffs: Tech giant to slash 30,000 jobs as banks pull out from financing AI data centresStory # 3: Iran-linked hacktivist groups target US infrastructure after Feb 28 strikes, cyber activity surges: ReportStory # 4: Introducing the First Frontier Suite built on Intelligence + TrustStory # 5: Motorola partners with GrapheneOS for future phonesStory # 5b: GrapheneOS: Microsoft Authenticator does not support secure Android OSStory # 6: Western allies form 6G security coalition amid tech rivalry with ChinaStory # 7: ShinyHunters claims ongoing Salesforce Aura data theft attacksStory # 8: Doppelgänger / RRN Disinformation Infrastructure Ecosystem 2026Story # 9: LexisNexis confirms data breach as hackers leak stolen filesStory # 10: Google urges Supreme Court to strike down geofence warrants as unconstitutionalANTI-CAST : How to Detect Malicious Remote Workers w/ James McQuigganTroy & Wade’s Upcoming Things:– Antisyphon Training SOC Summit 2026– Breach Assessment - The Curious Case of the Comburglar w/ Troy Wojewoda– Network Forensics and Incident Response with Troy Wojewoda 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
Pentagon Declares Anthropic a Supply Chain Risk — 2026-03-02
2026/03/06
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Kerberoasting Too Hard (05:05) - Pentagon Declares Anthropic a Supply Chain Risk — Talkin’ Bout [infosec] News 2026-03-02 (08:40) - Story # 1: Pentagon Designates Anthropic Supply Chain Risk (17:27) - Story # 2: European Parliament blocks AI on lawmakers’ devices, citing security risks (21:23) - Story # 3: Mexican Government Breach and the Rise of Agentic Cyber Threats (22:58) - Story # 4: 2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface (33:04) - Story # 5: Leak confirms GrapheneOS & Motorola partnership for non-Pixel hardware (38:24) - Story # 5b: Motorola announces a partnership with GrapheneOS Foundation, marking a new chapter in smartphone security and expanding its enterprise portfolio (39:21) - Story # 6: Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems (43:12) - Story # 7: Cops back Dutch telco Odido after second wave of ShinyHunters leaks (45:40) - Story # 8: Discord puts global age verification policy on hold after backlash (46:30) - Story # 9: A new California law says all operating systems, including Linux, need to have some form of age verification at account setup (51:51) - Story # 10: User accidentally gains control of over 6,700 robot vacuums (53:35) - Story # 11: App Warns You if Someone Is Wearing Smart Glasses Nearby (57:32) - Weekly CTF Winners (58:28) - Story # 12: Microsoft is blocking 'Microslop' comments in Copilot's official Discord server (59:01) - Story # 13: New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises LinksStory # 1: Pentagon Designates Anthropic Supply Chain RiskStory # 2: European Parliament blocks AI on lawmakers’ devices, citing security risksStory # 3: Mexican Government Breach and the Rise of Agentic Cyber ThreatsStory # 4: 2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack SurfaceStory # 5: Leak confirms GrapheneOS & Motorola partnership for non-Pixel hardwareStory # 5b: Motorola announces a partnership with GrapheneOS Foundation, marking a new chapter in smartphone security and expanding its enterprise portfolioStory # 6: Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN SystemsStory # 7: Cops back Dutch telco Odido after second wave of ShinyHunters leaksStory # 8: Discord puts global age verification policy on hold after backlashStory # 9: A new California law says all operating systems, including Linux, need to have some form of age verification at account setupStory # 10: User accidentally gains control of over 6,700 robot vacuumsStory # 11: App Warns You if Someone Is Wearing Smart Glasses NearbyStory # 12: Microsoft is blocking ‘Microslop’ comments in Copilot’s official Discord serverStory # 13: New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
The Coming SAAS Apocalypse - 2026-02-23
2026/02/25
In this episode: Agentic AI tools that can autonomously perform tasks like researching and booking flights, raising concerns about automated purchases, fraud, guardrails, and over-trust in AI systems.The idea of a coming “SaaS apocalypse,” where AI tools could replicate or replace many small- and mid-tier SaaS products by crawling and recreating their functionality—potentially disrupting payroll, accounting, and other service platforms.Android’s shift away from its open-platform roots, including concerns about reduced openness, developer anonymity in app stores, and the broader implications for privacy-focused users and alternative operating systems.Ongoing tensions in the tech ecosystem around platform control, openness, and general-purpose computing, particularly involving large vendors like Google, Apple, Oracle, and major cloud providers.Broader security implications of AI adoption, including hallucinations, accountability, and how organizations are integrating AI to cut costs versus innovate.The discussion centers strictly on these current tech news developments and their security, privacy, and market impact. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Take the interstate to Dubai (04:53) - The Coming SAAS Apocalypse - 2026-02-23 (07:39) - Story # 1: Keep Android Open (15:34) - Story # 2: Meta patents AI that takes over a dead person’s account to keep posting and chatting (21:13) - Story # 3: The Coming SaaS Apocalypse... (28:52) - Story # 4: Firm Data on AI (29:43) - Story # 4b: Thousands of CEOs just admitted AI had no impact on employment or productivity—and it has economists resurrecting a paradox from 40 years ago (36:15) - Story # 5: US Defense Secretary Hegseth summons Anthropic CEO for tough talks over military use of Claude, Axios reports (40:41) - Story # 6: Conduent data breach could be largest in U.S. history (43:13) - Story # 6: The Erosion of Agency and the New Burden on Leaders (46:02) - Story # 7: DSA-2026-079: Security Update for RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability (48:30) - Story # 8: AI-augmented threat actor accesses FortiGate devices at scale (51:42) - Story # 9: I hacked ChatGPT and Google's AI - and it only took 20 minutes (01:03:07) - Antisyphon Training SOC Summit, March 25, 2026 (01:03:40) - Antisyphon Training: Attacking, Defending, and Leveraging AI-LLM Systems (01:03:58) - Antisyphon Workshop: Hacking AI-LLM Applications (01:04:27) - Antisyphon Anti-Cast: RED TEAMING AI: OWASP LLM TOP 10 WITH BRIAN AND DEREK (01:04:53) - PODCAST : A.I. Security Ops LinksStory # 1: Keep Android OpenStory # 2: Meta patents AI that takes over a dead person’s account to keep posting and chattingStory # 3: The Coming SaaS Apocalypse…Story # 4: Firm Data on AIStory # 4b: Thousands of CEOs just admitted AI had no impact on employment or productivity—and it has economists resurrecting a paradox from 40 years agoStory # 5: US Defense Secretary Hegseth summons Anthropic CEO for tough talks over military use of Claude, Axios reportsStory # 6: Conduent data breach could be largest in U.S. historyStory # 6: The Erosion of Agency and the New Burden on LeadersStory # 7: DSA-2026-079: Security Update for RecoverPoint for Virtual Machines Hardcoded Credential VulnerabilityStory # 8: AI-augmented threat actor accesses FortiGate devices at scaleStory # 9: I hacked ChatGPT and Google’s AI - and it only took 20 minutesAntisyphon Training SOC Summit, March 25, 2026Antisyphon Training: Attacking, Defending, and Leveraging AI-LLM SystemsAntisyphon Workshop: Hacking AI-LLM ApplicationsAntisyphon Anti-Cast: RED TEAMING AI: OWASP LLM TOP 10 WITH BRIAN AND DEREKPODCAST : A.I. Security Ops🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to watch this episode on YouTube. Click here to view the episode transcript.
more
Palo Alto Fears China Retaliation – 2026-02-16
2026/02/22
In this episode, the crew dives into reports that Palo Alto Networks allegedly avoided directly attributing a threat campaign to China over fears of retaliation—sparking a broader debate about corporate and government threat attribution, geopolitics, and whether attribution still matters in today’s cyber landscape. They also explore the escalating AI arms race, including Meta’s aggressive (and expensive) talent poaching, the growing rivalry between OpenAI and Anthropic, and what it all means for the future of the industry. Rounding out the episode, the team discusses the unintended consequences of the AI boom—like global hardware shortages stretching beyond GPUs to hard drives—and examines emerging prompt injection attack techniques, highlighting real-world examples and the growing security risks surrounding AI-powered tools. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Threat Actor Age Range (05:37) - Palo Alto Fears China Retaliation – 2026-02-16 (11:28) - Story # 1: Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say (16:01) - Story # 2: Rent a Human (20:39) - Story # 3: OpenClaw creator Peter Steinberger joining OpenAI, Altman says (24:31) - Story # 4: Western Digital runs out of HDD capacity: CEO says massive AI deals secured, price surges ahead (28:30) - Story # 5: GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use (30:32) - Story # 6: Data Exfil from Agents in Messaging Apps (32:15) - Story # 7: AMOS infostealer targets macOS through a popular AI app (39:25) - Story # 8: Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data Breach (46:11) - Story # 9: Vietnam bans unskippable online video ads longer than 5 seconds from next month (49:59) - Story # 10: SolarWinds Web Help Desk Exploitation - February 2026 (54:00) - Story # 11: Devilish devs spawn 287 Chrome extensions to flog your browser history to data brokers (58:13) - Story # 12: Snail mail letters target Trezor and Ledger users in crypto-theft attacks (01:00:59) - Eric's Workshop (01:01:31) - Jennifer's Workshop (01:04:36) - SOC Summit 2026 LinksStory # 1: Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources sayStory # 2: Rent a HumanStory # 3: OpenClaw creator Peter Steinberger joining OpenAI, Altman saysStory # 4: Western Digital runs out of HDD capacity: CEO says massive AI deals secured, price surges aheadStory # 5: GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial UseStory # 6: Data Exfil from Agents in Messaging AppsStory # 7: AMOS infostealer targets macOS through a popular AI appStory # 8: Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data BreachStory # 9: Vietnam bans unskippable online video ads longer than 5 seconds from next monthStory # 10: SolarWinds Web Help Desk Exploitation - February 2026Story # 11: Devilish devs spawn 287 Chrome extensions to flog your browser history to data brokersStory # 12: Snail mail letters target Trezor and Ledger users in crypto-theft attacks01:01:00 - Eric’s Workshop01:01:31 - Jennifer’s Workshop01:04:37 - SOC Summit 2026Creators & Guests Corey Ham - Host Wade Wells - Host Bronwen Aker - Host Ralph May - Host Ched "cheddar" Wiggins - Guest Jennifer Shannon - Guest Eric Kuehn - Guest Click here to watch a video of this episode. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.
more
Live From WWHF Mile High 2026 – 2026-02-11
2026/02/18
Live from Wild West Hackin’ Fest Denver 2026, the Black Hills Information Security crew brings their signature mix of sharp security insight and off-the-cuff banter to a packed in-person audience. This episode centers on a controversial Notepad update that introduced Markdown rendering—along with a potential remote code execution (RCE) issue. The hosts unpack what this says about modern software bloat, “vibe coding,” and the growing push to embed AI into everything—whether it belongs there or not. They also explore the implications of Discord's Age verification requirements, AI-generated code, including OpenAI’s latest Codex model, and debate whether we’re headed toward a wave of AI-assisted vulnerabilities. Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat Chapters (00:00) - PreShow Banter™ — Corey Olympics (02:23) - Story # 1: Critical Notepad vulnerability reignites criticism of Microsoft’s forced AI features (07:42) - Story # 2: Discord will require a face scan or ID for full access next month (10:17) - Story # 3: 2026-01-14: The Day the telnet Died (15:04) - Story # 5: BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution (16:32) - Story # GRITREP: 0APT and the Victims Who Weren’t (20:54) - The advanced advancement of AI models Click here to watch a video of this episode. Creators & Guests John Strand - Host Corey Ham - Host Derek Banks - Guest Andrew Krug - Guest Chadd Watson - Guest Hayden Covington - Host Click here to view the episode transcript. LinksStory # 1: Critical Notepad vulnerability reignites criticism of Microsoft’s forced AI featuresStory # 2: Discord will require a face scan or ID for full access next monthStory # 3: 2026-01-14: The Day the telnet DiedStory # 5: BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code ExecutionStory # GRITREP: 0APT and the Victims Who Weren’t🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
US Defense Chief Uploads Secret Into to ChatGTP - 2026-02-02
2026/02/05
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat This episode breaks down recent reports of sensitive information being shared with AI tools and what that means for security and operations. The discussion covers OPSEC failures, common misuse of ChatGPT in professional environments, how data actually flows through AI systems, and what organizations should (and shouldn’t) worry about. The hosts focus on practical risk, realistic threat models, and actionable lessons for security teams navigating AI adoption. Chapters (00:00) - PreShow Banter™ — Robot Drivers (06:29) - US Defense Chief Uploads Secret Into to ChatGTP - 2026-02-02 (09:54) - Story # 1: US cyber defense chief accidentally uploaded secret government info to ChatGPT (19:03) - Story # 2: Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies (23:01) - Story # 3: Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users (26:30) - Story # 4: Millions of Gmail, Facebook and other account credentials exposed (30:55) - Story # 5: Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site (36:13) - Story # 6: County pays $600,000 to pentesters it arrested for assessing courthouse security (39:12) - Story # 7: Costco reportedly removes RAM from its display PCs to prevent tech-savvy shoplifters, customers claim — GPUs also absent across stores as PC parts become a hot commodity (41:13) - Story # 8: Claude Sonnet 5 Is Imminent — And It Could Be a Generation Ahead of Google (45:09) - Story # 9: Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries (48:49) - Story # 10: Match, Hinge, OkCupid, and Panera Bread breached by ransomware group (52:05) - Story # 11: Hunterbrook says Ubiquiti powering Russian battlefield communications in Ukraine (54:28) - Story # 12: Attack on Renewable Energy Plants (56:26) - Story # 13: Disrupting the World's Largest Residential Proxy Network | Google Cloud Blog LinksStory # 1: US cyber defense chief accidentally uploaded secret government info to ChatGPTStory # 2: Hackers can bypass npm’s Shai-Hulud defenses via Git dependenciesStory # 3: Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select UsersStory # 4: Millions of Gmail, Facebook and other account credentials exposedStory # 5: Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the SiteStory # 6: County pays $600,000 to pentesters it arrested for assessing courthouse securityStory # 7: Costco reportedly removes RAM from its display PCs to prevent tech-savvy shoplifters, customers claim — GPUs also absent across stores as PC parts become a hot commodityStory # 8: Claude Sonnet 5 Is Imminent — And It Could Be a Generation Ahead of GoogleStory # 9: Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 CountriesStory # 10: Match, Hinge, OkCupid, and Panera Bread breached by ransomware groupStory # 11: Hunterbrook says Ubiquiti powering Russian battlefield communications in UkraineStory # 12: Attack on Renewable Energy PlantsStory # 13: Disrupting the World’s Largest Residential Proxy Network | Google Cloud BlogWade & Hayden on Simply Cyber - https://www.youtube.com/live/c_lUP5gR15I Hayden’s Class - https://www.antisyphontraining.com/product/foundations-of-security-operations-with-hayden-covington/ Mishaal’s Class - https://www.antisyphontraining.com/product/next-level-osint-with-mishaal-khan/ 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
TikTok's invasive Privacy Policy - 2026-01-26
2026/01/28
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat In this episode, the hosts break down TikTok’s latest privacy policy and why it’s raising serious red flags. They discuss how the app expands data collection and tracking, what that means for user privacy, and the broader security implications—especially concerns around data access and China. Along the way, the conversation connects these changes to ongoing TikTok ban discussions, real-world risk for individuals and organizations, and what users should consider if they continue using the platform. The episode mixes technical insight with practical takeaways, making the privacy risks easy to understand without losing nuance. Chapters: (00:00) - PreShow Banter™ — Electroshock Therapy (02:28) - 2026-01-26 (07:33) - Story # 1: Fortinet confirms critical FortiCloud auth bypass not fully patched (14:27) - Story # 2: Hackers exploit critical telnetd auth bypass flaw to get root (17:37) - Story # 3: Clara Hawking’s Post on TikTok's Pivacy Policy (24:05) - Story # 4: Supreme Court to hear Facebook pixel tracking case (31:02) - Story # 5: Google accused of grooming kids after child receives this email (34:38) - Story # 6: House of Lords backs legislation to ban social media for children under 16 (35:47) - Story # 6b: Australia has banned social media for kids under 16. How does it work? (42:20) - Story # 7: Why Software Blocks Won’t Stop Illegally 3D Printed Guns (And What Actually Might) (48:29) - Story # 8: 1Password adds pop-up warnings for suspected phishing sites (52:09) - ClawdBot / Moltbot Links:Story # 1: Fortinet confirms critical FortiCloud auth bypass not fully patchedStory # 2: Hackers exploit critical telnetd auth bypass flaw to get rootStory # 3: Clara Hawking’s Post on TikTok’s Pivacy PolicyStory # 4: Supreme Court to hear Facebook pixel tracking caseStory # 5: Google accused of grooming kids after child receives this emailStory # 6: House of Lords backs legislation to ban social media for children under 16Story # 6b: Australia has banned social media for kids under 16. How does it work?Story # 7: Why Software Blocks Won’t Stop Illegally 3D Printed Guns (And What Actually Might)Story # 8: 1Password adds pop-up warnings for suspected phishing sitesClawdBot / MoltbotTroy’s WorkshopANTI-CAST: Effective AI for Practical SecOps Workflows w/ Hayden Covington🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
Chinese firms drop US and Israeli cybersecurity software - 2026-01-19
2026/01/20
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –  https://poweredbybhis.com This episode is a rapid-fire cybersecurity news roundup covering multiple headlines and what they mean for defenders. The crew debates reports that Chinese firms are dropping U.S. and Israeli security vendors, then pivots into breach fallout, malware activity, and real-world attacker behavior. Along the way, they unpack how geopolitics affects procurement, why supply-chain dependencies make “bans” messy, and what happens when organizations swap tools fast.  Expect candid takes on ransomware trends, enterprise security operations, and where hype collides with implementation. The hosts also riff on incident response realities, risk management, and what security teams should watch for next—plus plenty of side commentary and humor in between. Chapters (00:00) - PreShow Banter™ — Podcast Banter (04:13) - Chinese firms to stop using US and Israeli cybersecurity software - 2026-01-19 (08:56) - Story # 1: Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say (13:42) - Story # 2: Tennessee man to plead guilty to hacking Supreme Court’s electronic case filing system (16:25) - Story # 3: Hacker gets seven years for breaching Rotterdam and Antwerp ports (18:20) - Story # 4: 33-year-old Dutchman arrested for enableing criminals to test malware for antivirus programs. (20:02) - Story # 5: Army to ‘kill NIPR’ at multiple locations in commercial internet experiment (27:41) - Story # 6: Hungary grants asylum to former Polish minister implicated in spyware probe (29:12) - Story # 7: California orders Elon Musk’s AI company to immediately stop sharing sexual deepfakes (41:47) - Story # 8: ServiceNow BodySnatcher flaw highlights risks of rushed AI integrations (49:30) - Story # 8b: BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow (55:29) - CTF Winners (59:19) - ChickenSec: KFC app 'more secure' than Manage My Health, expert claims LinksStory # 1: Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources sayStory # 2: Tennessee man to plead guilty to hacking Supreme Court’s electronic case filing systemStory # 3: Hacker gets seven years for breaching Rotterdam and Antwerp portsStory # 4: 33-year-old Dutchman arrested for enableing criminals to test malware for antivirus programs.Story # 5: Army to ‘kill NIPR’ at multiple locations in commercial internet experimentStory # 6: Hungary grants asylum to former Polish minister implicated in spyware probeStory # 7: California orders Elon Musk’s AI company to immediately stop sharing sexual deepfakesStory # 8: ServiceNow BodySnatcher flaw highlights risks of rushed AI integrationsStory # 8b: BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNowChickenSec: KFC app ‘more secure’ than Manage My Health, expert claims Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more
BreachForums Doomsday - 2026-01-12
2026/01/14
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat 🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.com In this episode, we break down the “Doomsday” incident: a major breach forum gets breached, reminding everyone that even cybercriminal communities suffer constant OPSEC failures. We cover what leaked, why these underground markets keep imploding, and how infighting, reused infrastructure, weak authentication, and sloppy identity hygiene turn “elite hackers” into easy targets. Then we connect the dots to law enforcement’s latest crypto actions—how DOJ seizures and mixer investigations work, why blockchain tracing matters, and what criminals try (and fail) to do to hide money flows. Finally, we translate the news into practical defense: validate breach intel, monitor for credential stuffing, enable MFA, use unique passwords, and tighten access logs. Whether you’re a defender, creator, or online, this is the real-world cybercrime story behind the headlines. Chapters(00:00) - PreShow Banter™ — Task Overflow (02:29) - BreachForums Doomsday - 2026-01-12 (05:09) - Story # 1; Did DOJ Prosecutors Violate Trump’s Executive Order by Selling the Forfeited Samourai Wallet Bitcoin? (15:42) - Story # 2: Cloudflare defies Italy’s Piracy Shield, won’t block websites on 1.1.1.1 DNS (23:04) - Story # 3: California bans data broker reselling health data of millions (28:13) - Story # 4: Apple picks Google’s Gemini to run AI-powered Siri coming this year (36:00) - Story # 5: Ragebait as a phishing tactic (38:00) - Story # 6: Doomsday For Cybercriminals — Data Breach Of Major Dark Web Forum (40:31) - Story # 7: The Great VM Escape: ESXi Exploitation in the Wild (45:39) - Story # 8: OpenAI says ChatGPT won't use your health information to train its models (46:23) - Story # 8b: Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools (50:15) - Story # 9: Max severity Ni8mare flaw lets hackers hijack n8n servers (53:05) - Story # 10: Instagram Denies Data Breach, Fixes Unsolicited Password Reset Requests (56:49) - Reporter remembers saving animals a year after L.A. wildfires (57:52) - CTF Winners LinksStory # 1; Did DOJ Prosecutors Violate Trump’s Executive Order by Selling the Forfeited Samourai Wallet Bitcoin?Story # 2: Cloudflare defies Italy’s Piracy Shield, won’t block websites on 1.1.1.1 DNSStory # 3: California bans data broker reselling health data of millionsStory # 4: Apple picks Google’s Gemini to run AI-powered Siri coming this yearStory # 5: Ragebait as a phishing tacticStory # 6: Doomsday For Cybercriminals — Data Breach Of Major Dark Web ForumStory # 7: The Great VM Escape: ESXi Exploitation in the WildStory # 8: OpenAI says ChatGPT won’t use your health information to train its modelsStory # 8b: Anthropic brings Claude to healthcare with HIPAA-ready Enterprise toolsStory # 9: Max severity Ni8mare flaw lets hackers hijack n8n serversStory # 10: Instagram Denies Data Breach, Fixes Unsolicited Password Reset RequestsReporter remembers saving animals a year after L.A. wildfires Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Traininghttps://www.antisyphontraining.com/ Active Countermeasureshttps://www.activecountermeasures.com Wild West Hackin Fest - Join us for our Hybrid Conference and Pre-Conference Traininghttps://wildwesthackinfest.com
more
US Cyberattacks on Venezuela - 2026-01-05
2026/01/09
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis🔴live-chat 🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.com In this episode, we break down the growing debate around U.S. cyber operations against Venezuela—and what it means for modern cyber warfare, critical infrastructure security, and geopolitics. The conversation explores how nation-state attacks can target a country’s power grid, the challenges of attributing cyberattacks, and why industrial control systems (ICS/SCADA) remain a high-impact battleground. We also discuss the strategic value (and risks) of disrupting energy infrastructure, how these campaigns compare to other real-world incidents, and what defenders can learn to better protect utilities and national systems. Chapters (00:00) - PreShow Banter™ — Undisclosed Closets (09:07) - US Cyberattacks on Venezuela - 2026-01-05 (10:16) - Story # 1:Trump suggests US used cyberattacks to turn off lights in Venezuela during strikes (11:14) - Story # 1b: There Were BGP Anomalies During The Venezuela Blackout (21:06) - Story # 1c: Pizza index of war: Late-night traffic near Pentagon surges again as US strikes Venezuela (32:40) - Story # 2: Finland seizes ship suspected of damaging subsea cable in Baltic Sea (35:11) - Story # 3: US cybersecurity experts plead guilty to BlackCat ransomware attacks (35:46) - Story # 4: MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide (39:06) - Story # 5: Hackers claim to hack Resecurity, firm says it was a honeypot (42:06) - Story # 6: NordVPN denies breach claims, says attackers have "dummy data" (42:35) - Story # 7: Hackers say they have stolen 40 million Condé Nast Records - here's how to stay safe (43:43) - Story # 8: Hacker Dressed As Pink Power Ranger Dismantles Racist Websites Live on Stage (47:13) - Story # 9: NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices (52:18) - Story # 10: Manufacturer issues remote kill command to disable smart vacuum after engineer blocks it from collecting data — user revives it with custom hardware and Python scripts to run offline (55:15) - Story # 11: Ben Jordan Exposes Severe Security Vulnerabilities in Flock Surveillance Cameras (57:26) - Story # 11b: We Tracked Ourselves with Exposed Flock Cameras LinksStory # 1:Trump suggests US used cyberattacks to turn off lights in Venezuela during strikesStory # 1b: There Were BGP Anomalies During The Venezuela BlackoutStory # 1c: Pizza index of war: Late-night traffic near Pentagon surges again as US strikes VenezuelaStory # 2: Finland seizes ship suspected of damaging subsea cable in Baltic SeaStory # 3: US cybersecurity experts plead guilty to BlackCat ransomware attacksStory # 4: MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation WorldwideStory # 5: Hackers claim to hack Resecurity, firm says it was a honeypotStory # 6: NordVPN denies breach claims, says attackers have “dummy data”Story # 7: Hackers say they have stolen 40 million Condé Nast Records - here’s how to stay safeStory # 8: Hacker Dressed As Pink Power Ranger Dismantles Racist Websites Live on StageStory # 9: NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devicesStory # 10: Manufacturer issues remote kill command to disable smart vacuum after engineer blocks it from collecting data — user revives it with custom hardware and Python scripts to run offlineStory # 11: Ben Jordan Exposes Severe Security Vulnerabilities in Flock Surveillance CamerasStory # 11b: We Tracked Ourselves with Exposed Flock Cameras Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
more

Podcast reviews

Read Talkin' Bout [Infosec] News podcast reviews


4.8 out of 5
93 reviews
MoreSporesFarm 2025/01/30
Hack it!
Listen to this every week, so stoked to learn that I can listen on here now instead of YouTube lol!
plpellegrini 2025/06/15
Stop the opinions on topics you know nothing about - language no longer tolerable.
The show is mostly okay, but the chatter on topics the group has no competence with is exceptionally annoying. The group should focus on their streng...
more
[REDACTED] USER 2024/01/20
Out’stinkin’standing!
Update: Out’stinkin’standing! your Monday podcasts are getting updated often and on a regular basis. Y’all my favorite podcasts! Your humor is the r...
more
He5150 2021/04/12
Best cyber security news podcast
You guys are hilarious and it’s a great way to stay up to date on current events in this sector. Only thing I would recommend is if you are explaining...
more
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on Talkin' Bout [Infosec] News & sponsor relevant audience podcasts


What do you want to promote?

Ad Format

Campaign Budget

Business Details