Florida DMV breach, zero-click WeChat worm, AI whistleblowers

<p>ShinyHunters claimed it breached Florida DMV</p> <p>Zero-click WeChat worm spreads over incoming calls</p> <p>AI cheaters and whistleblowers emerge</p> <p>Get the show notes here: <a href= "https://cisoseries.com/cybersecurity-news-florida-dmv-breach-zero-click-wechat-worm-ai-whistleblowers/"> https://cisoseries.com/cybersecurity-news-florida-dmv-breach-zero-click-wechat-worm-ai-whistleblowers/</a> </p> <p><strong>Huge thanks to our episode sponsor, ThreatLocker</strong></p> <p><a href= "https://www.threatlocker.com/ciso?utm_source=ciso-%20series&amp;utm_medium=sponsor&amp;utm_campaign=ai-cant-stop-ai_q3_26&amp;utm_content=ai-cant-%20stop-ai-&amp;utm_term=podcast"> <img src="https://imgproxy.citrusreader.com/q7lfx-BYEJRP7A5V4TKjGBuYBFgtp3vNC6KOM3iaiqM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9UaHJlYXRMb2NrZXJfQUlfQ2FudF9TdG9wX0FJX0F0dGFja3NfMTkyMHgzMjBfMi5qcGc" alt width="600" height="100"></a></p> <p><em>Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at <a href= "http://threatlocker.com/ciso">threatlocker.com/ciso</a> today.</em></p>

2026/9/9
阅读更多

PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA

<p><strong>PEEP turns browsers into backdoors</strong></p> <p><strong>Liquid loses $320M, hackers play hero</strong></p> <p><strong>BigBear claws past MFA</strong></p> <p>Get the full show notes here: <a href= "https://cisoseries.com/cybersecurity-news-september-8-2026/">https://cisoseries.com/cybersecurity-news-september-8-2026/</a></p> <p><strong>Huge thanks to our episode sponsor, ThreatLocker</strong></p> <p><strong><a href= "https://www.threatlocker.com/ciso?utm_source=ciso-%20series&utm_medium=sponsor&utm_campaign=ai-cant-stop-ai_q3_26&utm_content=ai-cant-%20stop-ai-&utm_term=podcast"> <img src="https://imgproxy.citrusreader.com/q7lfx-BYEJRP7A5V4TKjGBuYBFgtp3vNC6KOM3iaiqM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9UaHJlYXRMb2NrZXJfQUlfQ2FudF9TdG9wX0FJX0F0dGFja3NfMTkyMHgzMjBfMi5qcGc" alt width="600" height="100"></a></strong></p> <p dir="ltr"><em>An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at <a href= "http://threatlocker.com/ciso">threatlocker.com/ciso</a>.</em></p>

2026/9/8
阅读更多

MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge

<p>MikroTik routers hijacked through internet-exposed SSH</p> <p>Russian data centers face new security requirements</p> <p>UK account-hack losses surge thanks to new reporting system</p> <p>Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/</p> <p><strong>Huge thanks to our episode sponsor, ThreatLocker</strong></p> <p><a href= "https://www.threatlocker.com/ciso?utm_source=ciso-%20series&amp;utm_medium=sponsor&amp;utm_campaign=ai-cant-stop-ai_q3_26&amp;utm_content=ai-cant-%20stop-ai-&amp;utm_term=podcast"> <img src="https://imgproxy.citrusreader.com/q7lfx-BYEJRP7A5V4TKjGBuYBFgtp3vNC6KOM3iaiqM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9UaHJlYXRMb2NrZXJfQUlfQ2FudF9TdG9wX0FJX0F0dGFja3NfMTkyMHgzMjBfMi5qcGc" alt width="600" height="100"></a></p> <p dir="ltr"><em>AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at <a href= "http://threatlocker.com/ciso">threatlocker.com/ciso</a>.</em></p>

2026/9/7
阅读更多

The Department of Know: Astra launches, CISA cuts programs, McKesson breached

<p></p> <p>Read the full stories at <a href= "https://cisoseries.com/the-department-of-know-astra-launches-cisa-cuts-programs-mckesson-breached/"> CISOSeries.com</a></p> <p>This week's <em>Department of Know</em> is hosted by Rich Stroffolino, with guests <a href= "https://www.linkedin.com/in/montezfitzpatrick/">Montez Fitzpatrick</a>, director, information security, global head of cybersecurity, <a href="https://energizerholdings.com/">Energizer Holdings</a>, and <a href= "https://www.linkedin.com/in/jonathanwaldrop/">Jonathan Waldrop</a>, CISO, <a href= "https://www.acoustic.com/">Acoustic</a>.</p> <p></p> <p>Missed the live show? Check it out <a href= "https://youtube.com/live/u6wpjCkAWzc?feature=share">on YouTube</a>.</p> <p></p> <p><em>The Department of Know</em> is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at <a href="https://cisoseries.com/">CISOSeries.com</a>.</p> <p><strong>A huge thanks to our sponsor, KnowBe4</strong></p> <p><img src="https://imgproxy.citrusreader.com/nJ76OJO8IAaiyBp_hslO5zdvMmNmyFo50_4-nUEEuMM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9DUi0wOTcyX0FJLW5hdGl2ZV9TQVRfY2FtcGFpZ25fLV9iYW5uZXJfYWRzXzFfMTkyMHgzMjAucG5n" alt="https://www.knowbe4.com/ai-native-sat" width="600" height="100"></p> <div class="ql-block" data-block-id="block-f2aWx-Oanq"><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></div> <div class="ql-block" data-block-id="block-QmuT9ueZ8i"> <em>KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a class= "ql-link" href="http://knowbe4.com/" target="_blank" rel= "noopener noreferrer" data-test= "link-preview-plain">KnowBe4.com</a>.</em></div> <div class="ql-block" data-block-id="block-Z1URtAhONX"> </div>

2026/9/4
阅读更多

Court records breach, Breeze Comet hits Brazil, Aesto records breach

<p>U.S. and Canadian court records breached in Thomson Reuters incident</p> <p>Cybercrime Breeze Comet causing problems in Brazil</p> <p>Aesto record system hit by data breach</p> <p>Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/</p> <p>Huge thanks to our episode sponsor, KnowBe4</p> <p><a href= "https://www.knowbe4.com/ai-native-sat?utm_source=podcast&utm_medium=cybersecurityheadlines&utm_campaign=ainativesat"> <img src="https://imgproxy.citrusreader.com/nJ76OJO8IAaiyBp_hslO5zdvMmNmyFo50_4-nUEEuMM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9DUi0wOTcyX0FJLW5hdGl2ZV9TQVRfY2FtcGFpZ25fLV9iYW5uZXJfYWRzXzFfMTkyMHgzMjAucG5n" alt width="600" height="100"></a></p> <p dir="ltr"><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></p> <p dir="ltr"><em><a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4</a>'s AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4.com</a>.</em></p>

2026/9/4
阅读更多

153M licenses for sale, Anthropic reverses course, Astra enters the red zone

<p><strong>Dark web shop stocks 153 million driver's licenses</strong></p> <p>Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals. IDScan says it's investigating and hasn't determined the breach's nature or scope. The FBI's New Orleans office has opened an inquiry. (<a href= "https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/">KrebsOnSecurity</a>)</p> <p><strong>Anthropic puts 30-day data retention in reverse</strong></p> <p>After customer pushback, Anthropic is revising a policy that stored 30 days of traffic from its Fable and Mythos models. Under new Enterprise Frontier Safeguards, customers can keep data in their own cloud and block Anthropic employees from reviewing it while automated abuse monitoring continues. Anthropic calls that privacy equivalent to zero data retention. Developed with more than 100 customers, including Salesforce, the system is due later this year. (<a href= "https://www.cnbc.com/2026/09/01/anthropic-data-retention.html">CNBC</a>)</p> <p><strong>Astra enters OpenAI's cyber red zone</strong></p> <p>OpenAI says Astra is its first model to reach a "Critical" cybersecurity threshold, meaning it can find unknown flaws and build exploits across well-defended systems without step-by-step human help. It's due soon, but the advanced cyber capabilities will start with a small test group before expanding through Daybreak Blue. OpenAI says Astra refused 91.5% of cyber jailbreak requests, versus 59% for GPT-5.6 Sol, and monitoring can pause suspicious activity. The Information reports Astra's latent reasoning may hide parts of its process, raising doubts about chain-of-thought monitoring. (<a href= "https://www.wired.com/story/openai-astra-first-ai-model-with-critical-cyber-abilities/">WIRED</a>, <a href= "https://www.theinformation.com/articles/secret-technique-behind-openais-astra-model-sparks-security-concerns"> The Information</a>)</p> <p>Get the full show notes here: https://cisoseries.com/153m-licenses-for-sale-anthropic-reverses-course-astra-red-zone/</p> <p>Huge thanks to our episode sponsor, KnowBe4</p> <p><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></p> <p><em><a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4</a>'s AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4.com</a>.</em></p>

2026/9/3
阅读更多

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability

<p>Anthropic announces safety changes and new models</p> <p>USPS installs "untested" IT systems for mail-in ballots</p> <p>Thousands of Exchange servers vulnerable to hijacks</p> <p>Get the full show notes here: <a href= "https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/"> https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/</a> </p> <p>Huge thanks to our episode sponsor, KnowBe4</p> <p><a href= "https://www.knowbe4.com/ai-native-sat?utm_source=podcast&utm_medium=cybersecurityheadlines&utm_campaign=ainativesat"> <img src="https://imgproxy.citrusreader.com/nJ76OJO8IAaiyBp_hslO5zdvMmNmyFo50_4-nUEEuMM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9DUi0wOTcyX0FJLW5hdGl2ZV9TQVRfY2FtcGFpZ25fLV9iYW5uZXJfYWRzXzFfMTkyMHgzMjAucG5n" alt width="600" height="100"></a></p> <p dir="ltr"><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></p> <p dir="ltr"><em><a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4</a>'s AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4.com</a>.</em></p>

2026/9/2
阅读更多

Claude sessions hijacked, AI jolts global finance, agents get too many keys

<p><strong>Claude sessions get hijacked</strong></p> <p>Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions. (<a href= "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/">BleepingComputer</a>)</p> <p><strong>AI could jolt global finance</strong></p> <p>Bank of England governor Andrew Bailey is warning G20 officials that frontier AI could destabilize the global financial system by making cyberattacks faster, cheaper and easier to scale across borders. Bailey says many countries still lack protocols for how advanced models are developed and released. He also warned that a successful attack on a small number of heavily used technology providers could undermine confidence across the entire system. (<a href= "https://www.theguardian.com/business/2026/aug/31/advanced-frontier-ai-financial-stability-andrew-bailey-g20">The Guardian</a>)</p> <p><strong>AI agents get too many keys</strong></p> <p>New research from Cequence Security and Enterprise Management Associates found a sizable confidence gap around AI agent permissions. 94% of surveyed organizations believe their agents don't have more access than necessary, but only 33% actually enforce least privilege. 65% have seen an agent act outside its intended role, and 29% say that caused measurable business impact. (<a href= "https://www.securitymagazine.com/articles/102543-only-33-of-ai-agents-provisioned-with-least-privilege-access">Security Magazine</a>)</p> <p>Get the full show notes here:<br> <a href= "https://cisoseries.com/claude-sessions-hijacked-ai-jolts-global-finance-agents-get-too-many-keys/"> https://cisoseries.com/claude-sessions-hijacked-ai-jolts-global-finance-agents-get-too-many-keys/</a></p> <p>Huge thanks to our episode sponsor, KnowBe4</p> <p><a href= "https://www.knowbe4.com/ai-native-sat?utm_source=podcast&utm_medium=cybersecurityheadlines&utm_campaign=ainativesat"> <img src="https://imgproxy.citrusreader.com/nJ76OJO8IAaiyBp_hslO5zdvMmNmyFo50_4-nUEEuMM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9DUi0wOTcyX0FJLW5hdGl2ZV9TQVRfY2FtcGFpZ25fLV9iYW5uZXJfYWRzXzFfMTkyMHgzMjAucG5n" alt width="600" height="100"></a></p> <p dir="ltr"><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></p> <p dir="ltr"><em><a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4</a>'s AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4.com</a>.</em></p>

2026/9/1
阅读更多

ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach

<p>ServiceNow warns of three maximum severity security vulnerabilities</p> <p>PaperCut zero-day exploited in attacks</p> <p>Healthcare giant McKesson discloses breach</p> <p>Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/</p> <p>Huge thanks to our episode sponsor, KnowBe4</p> <p><a href= "https://www.knowbe4.com/ai-native-sat?utm_source=podcast&utm_medium=cybersecurityheadlines&utm_campaign=ainativesat"> <img src="https://imgproxy.citrusreader.com/nJ76OJO8IAaiyBp_hslO5zdvMmNmyFo50_4-nUEEuMM/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9DUi0wOTcyX0FJLW5hdGl2ZV9TQVRfY2FtcGFpZ25fLV9iYW5uZXJfYWRzXzFfMTkyMHgzMjAucG5n" alt width="600" height="100"></a></p> <p dir="ltr"><em>Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.</em></p> <p dir="ltr"><em><a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4</a>'s AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at <a href= "https://www.knowbe4.com/ai-native-sat">KnowBe4.com</a>.</em></p>

2026/8/31
阅读更多

The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

<p class="wp-block-paragraph">Read the full stories at <a href= "https://cisoseries.com/the-department-of-know-power-plant-attack-nsa-hacker-reunion-hugging-face-hack-report/"> CISOSeries.com</a>. </p> <p class="wp-block-paragraph">This week's <em>Department of Know</em> is hosted by Rich Stroffolino, with guests <a href= "https://www.linkedin.com/in/thejasonelrod/">Jason Elrod</a>, CISO, <a href="https://www.multicare.org/">MultiCare Health System</a>, and <a href= "https://www.linkedin.com/in/chris-ray-i4h/">Chris Ray</a>, field CTO, <a href="https://gigaom.com/">GigaOm</a>.</p> <p class="wp-block-paragraph">Missed the live show? Check it out <a href= "https://youtube.com/live/jDxDJCvWwYU?feature=share">on YouTube</a>.</p> <p class="wp-block-paragraph"><em>The Department of Know </em>is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at <a href= "https://cisoseries.com/">CISOSeries.com</a>.</p> <p class="wp-block-paragraph"><strong>A huge thanks to our sponsor, ThreatDown</strong></p> <p class="wp-block-paragraph"><a href= "https://www.threatdown.com/products/managed-detection-and-response/?utm_medium=referral&utm_source=ciso&utm_content=cyber_security_headlines"> <img src="https://imgproxy.citrusreader.com/aYipg6S4Y8WbEatChcoxje6qUR-RTab7-jvrV81Orgo/raw:1/aHR0cHM6Ly9hc3NldHMubGlic3luLmNvbS9zaG93LzI4OTU4MC9URF9DSVNPX1N1cGVyX0N5YmVyX0ZyaWRheV9CYW5uZXJfQWRzXzE5MjB4MzIwLW9wdGlvbjIucG5n" alt width="600" height="100"></a></p> <div class="ql-block" data-block-id="block-XxZjR_5a20"><em>Managing an enterprise-sized attack surface without a dedicated SOC?</em> <em>As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer</em></div> <div class="ql-block" data-block-id="block-ZG4kav2cew"><em>enough. You need the expertise to detect and respond to modern threats, without the overhead of building an</em></div> <div class="ql-block" data-block-id="block-5MSe8L-yju"><em>in-house security team. <a href= "https://www.threatdown.com/products/managed-detection-and-response/?utm_medium=referral&utm_source=ciso&utm_content=cyber_security_headlines"> ThreatDown</a> provides proactive, Managed Detection and Response, 24/7, so your</em></div> <div class="ql-block" data-block-id="block-tEpJcF2Q8n"><em>business can scale safely.</em> <em>Enterprise-grade defense. Built for businesses like yours.</em></div>

2026/8/28
阅读更多

推荐订阅