Security This Week
Enterprise security topics are discussed through the lens of current events, which catapult us into a discussion about hacking methods, security measures, and outcomes. Your hosts are Carl Franklin, Patrick Hynds, and Duane LaFlotte
What's up with Fortinet?
FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide
Aesop is Rolling in his Grave
Anthropic rolls out Claude Fable 5, but it's available for a limited time
Book: The Cat's Revenge by Claude Balls.
Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository
Beware of the Landshark!
FBI warns of in-person data theft attacks from extortion gang
Et Tu, M5??
First public macOS kernel memory corruption exploit on Apple M5
Ding Dong! Linux Again!
New Linux 'Dirty Frag' zero-day gives root on all major distros
Every Linux System at Risk!
Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.
Mythos: the Good and the Bad
Anthropic investigates unauthorized Mythos access by Discord group
Shall We Play a Game?
AI chatbots used tactical nuclear weapons in 95% of AI war games, launched strategic strikes three times!
Who's the Domain Master?
$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks
Anthropic Gets Mythical
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Worse Than Log4J?
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
Your Router is Banned!
FCC bans foreign routers, putting enterprise network risk in focus
iSpy
Researchers uncover iPhone spyware capable of penetrating millions of devices.
SQL Server on Fire! Film at 11.
Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges
Claude Balls
Anthropic ditches its core safety promise in the middle of an AI red line fight with the Pentagon
Is Your Password Manager Safe?
Exploitable Flaws Found in Cloud-Based Password Managers
Patrick Was Right!
iPhone Lockdown Mode is so good even the FBI can’t crack it
Is Your Pet AI Molting?
Hacking Moltbook: The AI Social Network Any Human Can Control
The Sound of Doom!
How to get Doom running on a pair of earbuds
GPT, the Uber Hacker
New Study Shows GPT-5.2 Can Reliably Develop Zero-Day Exploits at Scale
Get Off Of My Cloud!
New China Linked VoidLink Linux Malware Targets Major Cloud Providers
Here. Try This!
ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants
Is This Your Mongo?
MongoDB warns admins to patch severe vulnerability immediately
Watch What You Watch!
PornHub extorted after hackers steal Premium member activity data
Over Reacting?
Attackers hit React defect as researchers quibble over proof
iScam?
An ingenious Apple Service hoax is convincing users their account is under attack
Did Claude Go Rogue?
Anthropic claims of Claude AI-automated cyberattacks met with doubt
Should You Disable Hyper-V? Da!
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection
Patrick was Right!
No one pays ransomware demands anymore - so attackers have a new goal. Also: Ransomware Surge in Europe: Cybercriminals Exploit GDPR Penalties, Target Key Sectors
AWS Story Put To Bed
AWS crash causes $2,000 Smart Beds to overheat and get stuck upright
Terminate This!
Skynet-1A: Military Spacecraft Launched 56 Years Ago Has Been Moved By Persons Unknown
Live in Orlando!
Carl, Duane, and Patrick recorded this week's episode in front of a live audience at CyberSecurity Intersection, a cyber conference held at Universal Studio in Orlando, FL the week of October 5.
No! Not the Beer!!
Japan's beer giant Asahi Group cannot resume production after cyberattack
Secret Service FTW!
U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area
Read Your Own Damn Email!
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
The Largest Supply Chain Attack in History!
Hackers left empty-handed after massive NPM supply-chain attack
The End of Privacy?
Salt Typhoon pwned 'nearly every American'
AI-Powered Ransomware: Uh Oh.
Someone Created the First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model
What would you do for nuggets?
Security researcher driven by free nuggets unearths McDonald's security flaw — changing 'login' to 'register' in URL prompted site to issue plain text password for a new account