Tech Updates
Tech Updates is your quick-hit source for the latest in enterprise technology—all in 10 minutes or less. From cybersecurity and network connectivity to data center innovation, cloud advancements, and the rise of AI, we cover the updates that matter. Each episode delivers vendor announcements, industry trends, and agnostic insights to keep you informed and ahead of the curve. Whether you’re a tech professional or just tech-curious, this podcast is designed to fit into your busy schedule and fuel your knowledge.
Hacker Summer Camp 2026 Preview — Black Hat, DEF CON & the AI Reckoning
In April, an AI called Claude Mythos found 10,000 high-severity security holes — and flagged 23,000 issues across 1,000+ open-source projects. The punchline nobody's ready for: most still aren't patched. Finding bugs got automated. Fixing them didn't. This is your guide to Hacker Summer Camp 2026 — Black Hat, BSides, and DEF CON — what to watch, what to skip, and the AI reckoning underneath all of it. What you'll hear: • The three back-to-back Vegas cons (Black Hat Aug 1–6, BSides Aug 3–5, DEF CON 34 Aug 6–9) • The Claude Mythos story — autonomous exploits, a 9.1 cert-forgery flaw, and why Anthropic held the full model back • The real race of 2026: AI that attacks vs. AI that...
Ransomware 2026 — Why Crews Stopped Encrypting and Just Steal Now
Last year, ransomware crews launched ~50% more attacks — and made ~8% less money. The lock stopped paying, so they stopped using it. In 2026, 94% of ransomware cases involve stealing your data, and only 68% even bother to encrypt it. Welcome to the exfiltration era, where your backups don't save you. What you'll hear: • The shift to encryptionless extortion — steal and threaten to leak, instead of encrypt • The numbers — payments down ~8% ($820M) as attacks hit records; why the "% who pay" figure (20/28/48%) depends on who's counting • The twist — exfiltration is dominant but NOT a guaranteed payday; victims increasingly call the bluff (~2.5% on one campaign) • The 2026 landscape — post-LockBit reshu...
Wi-Fi 7 Explained — MLO, 6 GHz & the AI-Ready Branch Hype Check (2026)
Wi-Fi 7 promises 46 gigabits per second. Your access point is plugged into a 1-gig switch port. Guess which number wins. The radio is real and genuinely good — the rest needs a closer look. Let's separate the upgrade from the hype. What you'll hear: • The big three — Multi-Link Operation (MLO), 320 MHz channels, 4K-QAM — and why MLO is the only truly new idea • The latency truth — 46 Gbps is a lab fantasy; real-world is 6–15 Gbps/AP (Cisco lab: +47%). The win is reliability, not raw speed • The 6 GHz reality — the US opened it in 2020 (not 2026), the EU only opened half, so full-width Wi-Fi 7 is a US/UK/Korea story ...
Securing AI Agents — MCP, Agentjacking & the New Attack Surface (2026)
In June 2026, researchers took over AI coding agents — Claude Code, Cursor, Codex — with no phishing, no malware, and a public credential developers paste into their own apps. It worked 85% of the time. The vendor's response? "Technically not defensible. We're not fixing it." Welcome to the new attack surface nobody secured. What you'll hear: • What MCP (Model Context Protocol) is — "USB-C for AI" — and why it became an unreviewed internet-facing doorway • The hygiene problem — Knostic verified exposed MCP servers; 100% had no authentication; 8,000+ reported by early 2026 • Agentjacking — how a public Sentry DSN let attackers poison the logs an agent reads (85% success, 2,300+ orgs) • The pattern — prompt...
Passkeys Explained — How They Kill Phishing, Vishing & Password Theft
Every breach in our last episode died the same way it started — with a password. So this week: the fix that's finally winning. On World Passkey Day this May, the FIDO Alliance counted 5 billion passkeys in use. The password isn't dead yet — but we finally have the thing that kills it. What you'll hear: • How a passkey works — public/private keypair, private key never leaves your device, origin-bound signatures • Why passkeys defeat the 2026 attack playbook — phishing, credential stuffing, MFA fatigue, and the help-desk reset scam (CISA advisory AA23-320A names FIDO as the fix) • The numbers — 98% vs 32% sign-in success, ~1M passkeys/day...
The Worst Breaches of 2026 (So Far) — And the 5 Mistakes Behind Them
Six months into 2026 and the breach scoreboard is brutal: 22 million Aflac records, 30 million students locked out during finals, the FBI's own surveillance system breached, four banks knocked offline in an afternoon. But almost none of it was clever. No genius zero-days. Just a phone call, a stolen token, and an open door. This is the 2026 Breach Hall of Shame — we name names, correct the hype, and show you the five failures connecting all of it. What you'll hear: • The vishing wave — Aflac, Carnival, Canvas, Charter — how Scattered Spider & ShinyHunters just called the help desk • Two corrections: OnlyFans was NOT breached (recycled o...
Post-Quantum Cryptography Explained — Harvest Now, Decrypt Later (2026)
Right now, somewhere, an adversary is copying your encrypted VPN traffic. They can't read it today. They're saving it — for the day a quantum computer can crack it open. It's called "harvest now, decrypt later," and in 2026 it stopped being a thought experiment. This episode breaks down the post-quantum migration for people who actually run networks. What you'll hear: • The three NIST post-quantum standards (ML-KEM for key exchange, ML-DSA + SLH-DSA for signatures), finalized August 2024 • What "harvest now, decrypt later" means and why 5+ year data is already exposed • The expert-odds jump — 34% to 49% in one year — that a code-breaking quantum computer arrives within a dec...
Cisco Live 2026 Explained — Cloud Control, AgenticOps, Post-Mythos Security
450%. That's how much more network traffic an AI agent generates than a human doing the same task. Cisco measured it, put it on the big screen at Cisco Live 2026, and then rebuilt its entire company around it. Last week in Las Vegas, Cisco made its biggest platform bet in two decades: every product — Catalyst, Meraki, Nexus, security, collaboration, Splunk — managed from one place, Cisco Cloud Control. This episode tears down what's real, what's vapor, and what it means for your network. What you'll hear: • Cloud Control — what it actually unifies, the AI runbooks, autonomous remediation, and the Codex natural-language agent builder ...
Non-Human Identity Security Explained — The 45:1 NHI Crisis in 2026
45 to 1. In the average enterprise, for every human user there are 45 machine identities. Every API key. Every service account. Every agent token. Every secret in every config file. Your IAM platform probably tracks about 2% of them. That's where the breaches are coming from now — Snowflake, GitHub PATs, Azure IMDS. This episode unpacks the NHI crisis, the vendor landscape, and the three control patterns that actually work this quarter.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📚 WHAT YOU'LL LEARN
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ What counts as a non-human identity (it's more than service accounts)
✅ The 45:1 ratio — and why it's 200:1 in agentic shops
✅ Why "service account" is doing too much work (meet Dave)
✅ How Snowflake, GitHub PAT theft, and Azure IMDS all trace to...
Special · S04: The OT/ICS Defender — Why Volt Typhoon Should Worry You
$140K. When you mess up, the lights go out for real. Final episode of TechUpdates Special Series. The most consequential security job almost nobody talks about — defending the systems that keep the country running. Power grids. Water utilities. Petrochemical plants. Pipelines. What you'll hear: • What OT/ICS defenders actually do — segmentation, SCADA patching, PLC defense, plant-engineer coordination • Comp reality — why OT pays 40–60% less than cloud security at the same companies, and the "purpose tax" • The real stakes: Ukraine 2015 grid attack · Triton 2017 (Saudi Arabia) · Oldsmar 2021 · Aliquippa 2023 · Volt Typhoon pre-positioning across U.S. critical infrastructure • A real day — substations at 6 AM, vendors that still ship Window...
Salt Typhoon Explained — The Chinese Telecom Breach, One Year Later (2026)
In late 2024, Verizon, AT&T, and T-Mobile all admitted the same thing: their lawful-intercept systems — the ones they build for law enforcement — had been compromised by a Chinese state actor called Salt Typhoon. Years of dwell time. Wiretap infrastructure for politicians, including a presidential campaign. Sixteen months later, what have we actually fixed? Plus — why Volt Typhoon is the warning shot nobody's responding to, and why OT networks are still flat.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📚 WHAT YOU'LL LEARN
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ The Salt / Volt / Flax Typhoon lineup — who they are, what they do
✅ How Salt Typhoon abused CALEA — the FBI's own backdoor
✅ Why Volt Typhoon is military pre-positioning, not espionage
✅ CISA's Feb 2026 lessons-learn...
Special · S03: The AI Security Engineer — The Job Nobody Knew Existed
$450K. The job didn't exist 24 months ago. Every Fortune 500 is hiring. Episode three of TechUpdates Special Series. AI bug bounties have crossed six figures for a single prompt injection. Frontier labs run model evaluation contests with prize pools in the hundreds of thousands. Two years ago the title "AI Security Engineer" was on zero org charts. Today it's on most of them. What you'll hear: • What an AI security engineer actually does — red-team LLMs, secure RAG pipelines, defend training data and weights, write guardrails • Compensation in price discovery — Fortune 500 $180–250K, big tech $350–500K, frontier labs $700K–$1M+ • The full attack surface: prompt...
AI Data Center Power Crisis 2026 — Microsoft, Amazon, Meta Go Nuclear
In 2024, Microsoft signed a 20-year power purchase agreement to restart Three Mile Island. The nuclear plant. The one from the disaster. In 2025, Amazon bought a small modular reactor. In 2026, Meta locked up 20 years of natural gas at a cost nobody will put on record. We are watching hyperscalers become utilities. This episode covers the numbers, the deals, the grid bottleneck, the green accounting scandal, and the policy fight coming to your electric bill.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📚 WHAT YOU'LL LEARN
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ The 2020 → 2030 data center power trajectory (spoiler: vertical)
✅ Training energy costs for GPT-4 class vs GPT-5 class models
✅ The PPA deals board — Microsoft/TMI, Amazon/SMR, Google/geo, Meta/gas
✅ Why the US grid can't take it...
Special · S02: The Detection Engineer — How $240K Roles Replaced the SOC
$240K. No degree required. The SOC analyst is dead. Episode two of TechUpdates Special Series. The SOC industry quietly restructured itself in the last 18 months — tier-one analyst headcount shrinking, SIEM vendors pivoting their pitch — and one role pulled away with software-engineer-grade compensation. The Detection Engineer. What you'll hear: • What detection engineers actually do (write detections, tune false positives, hunt, partner with the red team) • The pay reality — tier-1 SOC $80K vs. principal detection engineer $350K+ at top tech • Detection-as-code: why "80 alert categories become 800 detections" with the same headcount • A real day — standup, tuning, hunt, purple team, coffee. No on-call rotation at well-run shop...
npm Supply Chain Attack Hit 47K Apps — What Happened and How to Defend
In February, a maintainer of a widely-used npm package pushed a release that shipped malware to 47,000 downstream applications. The maintainer's GitHub account had been compromised four months earlier. Nobody noticed. It happened again in March. Again in early April. This episode is the supply chain security story the vendors aren't telling you correctly.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📚 WHAT YOU'LL LEARN
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ The 4 Q1 2026 supply chain incidents you may have missed
✅ Maintainer takeover — the 5-step playbook attackers actually use
✅ Why SBOM (Software Bill of Materials) doesn't prevent this
✅ SLSA (pronounced "salsa") levels — and why
Special · S01: The CISO Under Fire — $1.4M Comp, SEC Subpoena, Same Job
$1.4M comp. SEC subpoena. Same job. Welcome to TechUpdates Special Series — four episodes on the cybersecurity roles people actually want to hear about. We start with the only C-suite job in tech where doing it right can still get you indicted: the CISO. What you'll hear: • What a CISO actually does (and what they delegate) • The real comp ladder — Series B startup $250K → Fortune 500 $800K → big tech $1.4M+ • The Tim Brown and Joe Sullivan reckoning: why CISOs now face personal SEC and DOJ exposure • A composite 24-hour day, from 7 AM board prep to a 3 AM pager • The 15-year path to the seat — and the...
Is SaaS Dead? How AI Agents Are Killing Enterprise Software in 2026
"SaaS is dead." Satya Nadella said it on All-In in late 2024. Everyone laughed. Eighteen months later, Klarna went on the record — they fired Salesforce, fired Workday, and replaced them with Python scripts wired to Claude. ~$40M in annual SaaS spend. Gone. This episode breaks down what's actually happening to enterprise software, which layer is getting compressed, which layer is getting bigger, and what IT buyers should do Monday.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📚 WHAT YOU'LL LEARN
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ What Nadella actually predicted vs what sounded absurd at the time
✅ The Klarna playbook — exactly what got replaced, and with what
✅ The 4 layers of every SaaS product (and which 3 are now commodity)
✅ Which SaaS categories are getting compress...
RSAC 2026 Recap: Agentic AI, the Death of the SIEM, and 22-Second Breakouts
In 2022, the median time between initial access and the secondary threat hand-off was 8 hours. At RSAC 2026, Mandiant put the new number on the main stage: 22 seconds. That one stat explains everything that got announced in San Francisco this year.
This episode of Tech Updates is a full RSAC 2026 recap — the product flood, the agentic AI pivot, and the six predictions every CISO and senior engineer should be tracking over the next 12 months.
⏱ CHAPTERS
0:00 — Intro
0:03 — Cold open: the 22-second attacker hand-off
0:31 — Segment 1: Agentic AI, for real this time
2:20 — Agent Identi...
Malware: Viruses, Ransomware, Botnets & How to Fight Back
Malware isn't just "a virus." It's a whole ecosystem of tools designed to damage, steal, spy, and extort — and in 2026 it's more dangerous than ever. This episode is your complete field guide.
WHAT IS MALWARE?
Malware (malicious software) is any program intentionally designed to harm a system, steal data, or gain unauthorized access. It's not accidental — it's engineered.
THE 5 MAJOR TYPES
Viruses & Worms
Viruses attach to clean files and spread when a user runs them. Worms self-replicate without any user interaction — ILOVEYOU (2000) infected 50 million machines in 10 days.
Trojan...
Ransomware in 2026: It's Not About Encryption Anymore
Tech Updates — Ransomware in 2026: Industrial Extortion and How to Fight Back
Ransomware isn't just encryption anymore. In 2026, it's a full extortion operation — and it's getting more aggressive as fewer victims pay up.
What's changed: Ransomware-as-a-Service has effectively lowered the barrier to entry for cybercrime, and in 2026 it's the dominant engine driving the threat landscape. Huntress Groups now layer encryption with data theft, DDoS attacks, and direct victim harassment. Many groups are skipping encryption entirely in 2026 — focusing purely on data exfiltration, which puts organizations under immediate legal and reputational pressure even if systems stay online. Level
T...
Phishing in 2026: From Classic Emails to AI-Enhanced Deepfakes – Technical Breakdown & Defenses
Description / Summary:
Phishing remains the #1 initial access vector in 2026, now supercharged by generative AI, voice cloning, and multimodal deception. This episode dissects classic phishing, spear-phishing, smishing (SMS), vishing (voice), and emerging AI variants (hyper-personalized content, real-time voice synthesis, deepfake video calls).
We walk through realistic attack scenarios with indicators of compromise (IOCs), attack chains, and living-off-the-land techniques—then deliver layered, modern defenses: phishing-resistant MFA, behavioral analytics, zero-trust controls, DMARC enforcement, and AI-native detection.
Key Takeaways:
Modern phishing uses perfect grammar, OSINT personalization, and urgency manipulation—no typos needed.
AI vari...
Urgent Cybersecurity Alerts: Geopolitical Cyber Escalation, VMware Zero-Day Exploitation, and Major Ransomware Breach (March 2026)
Summary:
In this fast-paced technical roundup, we cover three high-impact cybersecurity developments from the last 7 days (Feb 28–Mar 4, 2026): escalating Iranian-linked cyber operations amid U.S.-Israel strikes, CISA's addition of an actively exploited VMware Aria Operations command injection flaw to the KEV catalog, and the University of Hawaiʻi Cancer Center's disclosure of a 2025 ransomware attack exposing up to 1.2 million individuals' sensitive data.
We break down attack vectors, indicators of compromise, exploitation mechanics, and immediate defensive steps—essential listening for SOC teams, incident responders, and risk managers navigating blended threats, virtualization vulnerabilities, and long-tail data extor...
Application-Level Microsegmentation: Granular Zero Trust Enforcement in 2026
Description / Summary:
In this technical deep dive, we examine leading products for microsegmentation at the application and workload level—essential for stopping lateral movement in hybrid, multi-cloud, and containerized environments. As breaches become inevitable, these solutions enforce least-privilege policies based on process identities, behaviors, dependencies, and real-time telemetry, using host-based enforcement, AI-driven recommendations, and dynamic containment.
We cover three standout platforms:
Illumio Zero Trust Segmentation: Host/agentless visibility, AI-powered policy computation, and rapid breach isolation.
Akamai Guardicore Segmentation: Process-level kernel enforcement, automated policy generation, and Osquery threat hunting.
Cisco Se...
The Future of Firewalls: Hybrid Mesh Architectures Take Center Stage in 2026
The Future of Firewalls: Hybrid Mesh Architectures Take Center Stage in 2026
In this episode of Tech Updates, we explore the evolving world of network security as traditional firewalls give way to hybrid mesh architectures. With enterprises operating across on-premises, multi-cloud, edge, and remote environments, unified protection is no longer optional—it's essential.
Gartner formalized the Hybrid Mesh Firewall (HMF) category in its inaugural 2025 Magic Quadrant, predicting that over 60% of organizations will deploy multiple firewall types by 2026. We break down what HMF means technically—multi-deployment firewalls (hardware, virtual, cloud-native, FWaaS) managed from a single cloud-based plane for...
Latest Technical Enhancements in SSE Platforms: Prisma Access, Zscaler, and Cisco Secure Access (2025–2026 Updates)
1. Palo Alto Networks Prisma Access
Feb 2025 (Prisma SD-WAN): Flow visualization, SGT propagation, GCM encryption, ION 9300 support.https://docs.paloaltonetworks.com/prisma-sd-wan/release-notes/new-features/prisma-sd-wan-release-information/prisma-sd-wan-features-introduced-in-2025/features-introduced-in-february-2025Aug 2025 (Strata Cloud Manager): Entity timestamps, region-based config management.https://docs.paloaltonetworks.com/content/techdocs/en_US/strata-cloud-manager/release-notes/new-features-strata-cloud-manager/new-features-in-august-20252. Zscaler
2025 Upgrades (ZIA/ZPA/ZDX): EDM/IDM in email DLP, tenancy restrictions, Sandbox tokens, NSS exclusions.https://help.zscaler.com/zia/release-upgrade-summary-2025https://help.zscaler.com/zpa/release-upgrade-summary-2025Jan/Feb 2026: AI Security Suite, Client Connector 4.7/4.8 (strict enforcement, offload controls, DNS fixes, vuln mitigations). https://www.zscaler.com/press/zscaler-unveils-new-innovations-secure-enterprise-ai-adoptionhttps...How Exploit Kits Are Automating Attacks Against Recent CVEs
🎙️ Tech Updates Weekly
Episode: How Exploit Kits Are Automating Attacks Against Recent CVEs
Exploit kits are transforming how cyberattacks happen — automating vulnerability exploitation at internet scale and dramatically shrinking the window between disclosure and compromise.
In this episode, we break down how exploit kits work, why recent CVEs are being weaponized faster than ever, and what defensive teams must do to stay ahead.
Attackers are no longer relying on manual exploitation. Instead, they’re leveraging automated frameworks that continuously scan the internet, identify vulnerable systems, and deploy payloads within hours of vulnerabi...
The perimeter is no longer just a boundary — it’s the battlefield
This week on Tech Updates:
A critical 9.8 vulnerability in Honeywell CCTV systems.
Ransomware groups increasingly targeting firewalls.
And a surge of high-severity CVEs hitting infrastructure this week alone.
The perimeter is no longer just a boundary — it’s the battlefield.
If you manage firewalls, IoT, or internet-facing systems, this episode breaks down what happened, why it matters, and what you should be doing right now.
Source Links
CVE-2026-1670 — Honeywell CCTV Camera Vulnerability👉 https://www.techradar.com/pro/secur...
Trending Cybersecurity News (February 2026)
Cybersecurity never slows down — and neither should we.
In this week’s Tech Updates episode, we break down three major stories shaping the security landscape right now:
• Microsoft Patch Tuesday fixing 54 vulnerabilities — including 6 zero-days
• Apple’s emergency update addressing an actively exploited zero-day
• New research showing how AI adoption is expanding enterprise attack surfaces
The big takeaway?
Speed and visibility are everything.
Attackers are moving faster, zero-days are more common, and AI is introducing both opportunity and risk. Organizations need strong patch management, mobile endpoin...
Cisco Live EMEA - 2026 Recap
Show Notes — Cisco Live EMEA 2026 Recap
📆 Event Overview
Cisco Live EMEA 2026 took place Feb 9–13 in Amsterdam, bringing together over 21,000 attendees to explore AI-driven infrastructure, security, operations, and collaboration trends at the heart of enterprise tech.🚀 Networking & AI Infrastructure
Cisco unveiled the Silicon One G300, a 102.4 Tbps programmable switching ASIC designed to power AI-scale data centers and accelerate GPU utilization. 🔗 https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m02/cisco-announces-new-silicon-one-g300.htmlThe new G300 powers next-generation Cisco N9000 and 8000 systems with liquid-cooled options and high-density optics, delivering improved energy efficiency and performance...E4 - Agentic AI & AI Autonomy Edition
Financial giant Goldman Sachs is working with AI startup Anthropic to build AI-powered agents to automate internal banking tasks like trade accounting, due diligence, and client onboarding. These autonomous systems — based on Claude models — aim to drastically reduce time spent on operational workflows, though no timeline for deployment has been announced.
Anthropic has introduced Claude Opus 4.6, a significant upgrade for enterprise use with a massive 1 million token context window. New features include Agent Teams — a way for multiple Claude agents to collaborate in parallel — and tighter API controls for adaptive thinking, making agent orchestration more sophisti...
E3 - Zero Trust, what's the latest?
CLUS 25 - AI-Ready Data Centers
AI-Ready Data Centers
• One of the strongest focuses of Cisco Live 2025 was on transforming data center infrastructure to
handle the massive demands of AI workloads.
• Cisco unveiled a series of innovations – spanning hardware, software, and partnerships – to make
modern data centers “AI-ready”: capable of supporting distributed AI training clusters, large-
scale inference, and all the data movement those require, securely and efficiently.
• These announcements recognize that in the AI era, high-bandwidth, low-latency networking
and seamless integration between compute and network are paramount in both cloud and on-
...
CLUS 25 - Cisco's Technology Vision for the Future
Cisco Live 2025 in San Diego showcased Cisco’s strategic vision for the coming era, centered on
the rise of AI and the need for fundamentally new approaches to networking and security.
Cisco executives emphasized that we are entering the “agentic AI” era – a time when AI agents,
bots, and autonomous applications will work alongside humans. This shift demands reimagining
network architecture to handle unprecedented scales of data, automation, and security
challenges.
Cisco’s vision is to meet this challenge by unifying platforms and embedding intelligence across
its port...