Skip to content
Cybersecurity Today artwork

Cybersecurity TodayRanked number 14 in the Top 15

David Shipley

Show details

Cadence
Daily
Typical episode
~13 min
Established
Since 2018
Latest episode
Sep 9, 2026

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

Classification

Latest episodes

  • Microsoft patches record 966 flaws, Cybercriminals return $265 million in BitcoinSep 9, 2026Episode length: · 08:24Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), including 105 critical issues, two actively exploited Windows zero-days, and a surge tied to AI-assisted bug discovery—raising defenders' triage and testing burden. The episode also covers a Liquid network theft of nearly…
  • IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patchSep 7, 2026Episode length: · 14:25Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale. Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that abuses CrowdStrike's Falcon alongside other zero-days targeting Kaspersky, Avast, and Nvidia. Sansec disclosed an unpatched Magento/Adobe Commerce flaw "Style Smuggler" enabling unauthenticated code execution. Arctic…
  • Surviving and thriving in the AI VulnpocalypseSep 5, 2026Episode length: · 29:36Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems. Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris…
  • FBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinosSep 4, 2026Episode length: · 11:28153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence suggesting near real-time exfiltration tied to
  • 22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global financeSep 2, 2026Episode length: · 08:5122,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911, enabling mailbox takeover, with exploit code circulating and Germany warning most on-prem Exchange remains vulnerable as support deadlines loom. The U.S. DOJ also corrected a press release to say multiple U.S. agencies…
  • ShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid techAug 31, 2026Episode length: · 11:37Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently…
  • How Varonis hacks AIs into snitching on themselvesAug 29, 2026Episode length: · 29:47Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Copilot (including "CoSnitch") and an Atlassian Confluence issue dubbed "RovoBlast" involving prompt injection, bypassing guardrails, and data exfiltration via a web-capable subagent. Vaitsman explains why built-in model…
  • Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platformsAug 28, 2026Episode length: · 11:21Team PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members of Team PCP in connection with a long-running software supply chain campaign that compromised tools like Trivy, Kiks, and LightLLM, potentially affecting over 1,000 organizations and exposing large volumes of credentials…
  • Iranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cardsAug 26, 2026Episode length: · 10:05Iran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked to Iran Nexus hackers, though damage was contained to a single small generator. ReliaQuest confirms ShinyHunters targeted its staff with phone-based social engineering and a fake reliaquest.claims SSO page, gaining only…
  • Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnetAug 24, 2026Episode length: · 08:50Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components…
  • AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoningAug 22, 2026Episode length: · 36:23How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024. They…
  • NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spotAug 21, 2026Episode length: · 14:24NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US critical infrastructure, specifically Siemens S7 PLCs in energy, water, and agriculture, with attackers scanning for exposed controllers and deploying disguised exploitation scripts. The show also covers ThreatFabric's…
  • CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attackAug 19, 2026Episode length: · 12:32Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enabled auto-running prompts, silent data exfiltration via connected apps (e.g., Gmail/Drive/Calendar) using Copilot's own web fetch, and persistent memory poisoning that survives common account cleanup steps until manually…
  • Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schoolsAug 17, 2026Episode length: · 09:22CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, and incident response planning amid shrinking federal support and ongoing school ransomware risk. Attackers are actively exploiting a critical SharePoint authentication bypass (CVE-2026-55040) patched by Microsoft in July,…
  • Cybersecurity Today Weekend Month in Review: August 2026Aug 15, 2026Episode length: · 56:27AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and…
  • Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defensesAug 14, 2026Episode length: · 11:49Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control across Windows 10/11 (including 25H2) and Windows Server 2025, claiming it bypasses Microsoft's patch for their earlier RoguePlanet exploit; a public proof-of-concept app is available, Will Dormann verified it works, and…
  • DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gymAug 12, 2026Episode length: · 09:41DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three…
  • AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackersAug 10, 2026Episode length: · 16:31AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS…
  • Coding for Veterans: Cybersecurity Today on the Weekend with David ShipleyAug 8, 2026Episode length: · 42:30Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at
  • The Era of Cheap Bugs, Water utility attacks spread to 12 states, Coldcard wallet losses could hit 130 millionAug 7, 2026Episode length: · 14:06Passkeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside research showing exploit success against AI agents and weaknesses across agent frameworks, plus notable hardware and supply-chain hacks. The show details BlackHat and Unit 42 findings that passkeys on Windows and Chrome can…
  • Inside the North American Water Utility Hacking CrisisAug 5, 2026Episode length: · 13:46Inside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking attacks on Minnesota systems to Iran and a joint FBI/EPA alert reporting activity in at least seven U.S. states targeting internet-exposed Rockwell MicroLogix PLCs by rewriting configurations, altering passwords, and…
  • Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-FiAug 3, 2026Episode length: · 13:08Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber…
  • Healthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident ReadinessAug 1, 2026Episode length: · 22:51On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes. He emphasizes…
  • OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in ExchangeJul 31, 2026Episode length: · 11:38OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure…
  • AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopensJul 29, 2026Episode length: · 12:56Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began. Researchers…

Show account

@itworldca

For the show’s team

Put this show’s Top 15 rank on your own site.