Patch Tuesday notes: Microsoft sets another record.

New ClickFix technique targets browsers. Business news: NetSPI and Synack to merge.

2026/9/9
阅读更多

Why Threat Actors Love Your RMM

In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Grant, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft.

2026/9/9
阅读更多

The Other Side of the PR Pitch with Pulitzer Prize Winner Yael Grauer

Yael Grauer won a Pulitzer and got laid off in the same year. She is a freelance investigative reporter covering cybersecurity, privacy, and surveillance. She sat down with Gianna to talk about what companies get wrong when journalists come knocking, why lying in that moment makes everything worse, and what it looks like from the other side of every pitch, every breach response, and every "no comment" that ends up in a story anyway.

2026/9/9
阅读更多

Worming its way through WeChat.

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal.

2026/9/8
阅读更多

Threat actors move toward multi-agent AI frameworks.

N-able issues emergency fix for maximum-severity flaw. Stealthy DPRK toolkit targets South Korean organizations.

2026/9/8
阅读更多

Inside the Media Mind of Ken Underhill: eSecurity Planet

On this episode of #IMM, Christine and Madison chat with Ken Underhill to learn more about his role and coverage at eSecurity Planet

2026/9/8
阅读更多

25 Years After 9/11: The CIA's First Moments Behind Enemy Lines in Afghanistan

Retired Colonel Justin Sapp was a Green Beret detailed to the CIA after the September 11th terrorist attacks. He was part of Team Alpha, the first eight Americans to drop behind enemy lines into the mountains of Afghanistan. At 29, Justin was its youngest member. There was no time to onboard him, and he was told he was leaving the next day, departing from the DC area to a base in Uzbekistan, then touching down in northern Afghanistan on a Black Hawk helicopter. Justin would go on to clear the way for follow-on forces to land, secure alliances with warlords to oust the Taliban, interrogate enemy fighters who had been captured. He would also tragically lose his colleague, Johnny “Mike” Spann. Justin takes us back into that historic mission 25 years later.

2026/9/8
阅读更多

Hackers gonna hack back.

Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Dave, Selena, and Keith explore the pros and cons of allowing select U.S. companies to conduct offensive cyber operations under strict government guardrails. They discuss what the proposed framework could mean for private-sector security researchers, how researchers have already been operating in this space for years, and where the line between defense and offense gets blurry. They also look at how adversaries such as China and Russia use proxy companies and other private-sector entities to conduct cyber operations—and consider whether giving trusted U.S. companies similar capabilities could strengthen cyber defenses or create new risks.

2026/9/8
阅读更多

This call may be monitored.

In this Special Episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ are joined by friend of the show, ⁠Brandon Karpf⁠, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem.

2026/9/7
阅读更多

When hackers control the clock.

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and ⁠⁠⁠⁠Andy Davis⁠⁠, Global Research Director at the ⁠NCC Group⁠, discuss the importance of timing in space. The two look at how timing systems have continued to grow more important in everyday life and why attackers have begun to increasingly exploit these critical services.

2026/9/6
阅读更多

推荐订阅