Cybersecurity Headlines

40 Episodes
Subscribe

By: CISO Series

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

✂️ Turn this podcast into clips
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA episode artwork
Yesterday at 7:00 AM

PEEP turns browsers into backdoors

Liquid loses $320M, hackers play hero

BigBear claws past MFA

Get the full show notes here: https://cisoseries.com/cybersecurity-news-september-8-2026/

Huge thanks to our episode sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.


MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge
MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge episode artwork
Last Monday at 7:00 AM

MikroTik routers hijacked through internet-exposed SSH

Russian data centers face new security requirements

UK account-hack losses surge thanks to new reporting system

Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/

Huge thanks to our episode sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at...


The Department of Know: Astra launches, CISA cuts programs, McKesson breached
Last Friday at 9:04 PM

Read the full stories at CISOSeries.com

This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, KnowBe4

Your employees have always been the...


Court records breach, Breeze Comet hits Brazil, Aesto records breach
Last Friday at 7:00 AM

U.S. and Canadian court records breached in Thomson Reuters incident

Cybercrime Breeze Comet causing problems in Brazil

Aesto record system hit by data breach

Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's...


153M licenses for sale, Anthropic reverses course, Astra enters the red zone
Last Thursday at 7:00 AM

Dark web shop stocks 153 million driver's licenses

Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals. IDScan says it's investigating and hasn't determined the breach's nature or scope. The FBI's New Orleans office has opened an inquiry. (KrebsOnSecurity)

Anthropic puts 30-day...


Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability
Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability episode artwork
09/02/2026

Anthropic announces safety changes and new models

USPS installs "untested" IT systems for mail-in ballots

Thousands of Exchange servers vulnerable to hijacks

Get the full show notes here: https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/ 

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native S...


Claude sessions hijacked, AI jolts global finance, agents get too many keys
09/01/2026

Claude sessions get hijacked

Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions. (BleepingComputer)

AI could jolt global finance

Bank of England governor Andrew Bailey is warning G20 officials that frontier AI could destabilize...


ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach
08/31/2026

ServiceNow warns of three maximum severity security vulnerabilities

PaperCut zero-day exploited in attacks

Healthcare giant McKesson discloses breach

Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/

Huge thanks to our episode sponsor, KnowBe4

Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.

KnowBe4's AI-native Security Awareness Training (SAT) fights back...


The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report
08/28/2026

Read the full stories at CISOSeries.com. 

This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, ThreatDown

Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size b...


Manchester Airports breach, ATF agency breach, clothier Carhartt breach
08/28/2026

Manchester Airports Group suffers cyber incident

ATF suffers data breach

Clothing retailer Carhartt suffers data breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-manchester-airports-breach-atf-agency-breach-clothier-carhartt-breach/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business.

ThreatDown. Enterprise-grade defense. Built for businesses like y...


Chinese hackers hit US agencies, Ring locks out police, Boston Scientific feels cyber pain
08/27/2026

China contractor hack hits US agencies

Ring throws away the key

Boston Scientific feels cyber pain

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-27-2026/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business.

ThreatDown. Enterprise-grade defense. Built for...


China's hackers pick DeepSeek, OpenAI blocks Russian influence push, webpages mess with local AI
08/26/2026

China's hackers pick DeepSeek

OpenAI blocks a Russian influence push

A webpage can mess with local AI

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-26-2026/

Huge thanks to our episode sponsor, ThreatDown

If your current security posture is struggling to keep pace with fast-moving, identity-based threats, your business is exposed.

Today's security expertise gap is real, but it doesn't have to be a permanent vulnerability. ThreatDown helps SMBs move from reactive defense to proactive, 24/7 intelligence, delivering enterprise-grade protection without the headcount. Enterprise-grade...


SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing
08/25/2026

SynkLoader throws in the kitchen sink

NIST flags multi-cloud sprawl

ReliaQuest blocks a ShinyHunters swing

Get the show notes here:
https://cisoseries.com/cybersecurity-news-august-25-2026/

Huge thanks to our episode sponsor, ThreatDown

Managing an enterprise-sized attack surface without a dedicated SOC?

As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7...


UK power plant hack, AI zero click, children's hospital breach
08/24/2026

UK power plant disabled for four days by Iran-linked hackers

Zero-click Grok and Gemini chat history theft possible through cryptographic context injection

Canada's Hospital for Sick Children suffers another cyberattack

Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/

Huge thanks to our episode sponsor, ThreatDown

SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected.

ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR t...


The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks
08/21/2026

Read the full sotry at CISOSeries.com

This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, Vanta

  Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and pr...


CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach
08/21/2026

CISA warns of hackers exploiting critical MLflow vulnerability

ICS operators warned of AI-driven attacks on Siemens PLCs

Electronic health record company CareCloud confirms millions affected by breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/

Huge thanks to our sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and...


OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed
08/20/2026

OpenAI rewrites safety rules after threshold warning

US charges 17 in Iranian hacking campaign

Microsoft fixes Windows Defender crash bug

Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust...


AI "mind virus," malware living off Azure, an Irregular post-mortem
AI "mind virus," malware living off Azure, an Irregular post-mortem episode artwork
08/19/2026

Persistent prompts prove potentially pernicious 

The malware is coming from inside Microsoft

Irregular releases AI sandbox escape post-mortem

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ 

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, in...


North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down
North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down episode artwork
08/18/2026

Federal agency hires North Korean IT worker

Millions of Azure records allegedly for sale

GitHub outage hits Actions and Copilot

Get the show notes here: https://cisoseries.com/cybersecurity-news-north-korean-it-worker-lands-federal-job-azure-records-go-up-for-sale-github-goes-down/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta...


SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach
08/17/2026

Max severity SAP Commerce Cloud flaw now targeted in attacks

New Mirai variant adds stealth capabilities to botnet code

Shell investigates potential incident after Clop data theft claims

Get the show notes here: https://cisoseries.com/cybersecurity-news-sap-commerce-flaw-exploited-mirai-boosts-capabilities-shell-investigates-breach/

Huge thanks to our sponsor, Vanta

Your GRC team is dealing with more and more frameworks, vendors, and risk.

The board wants it all in one place, but your compliance data lives all over.

Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale...


The Department of Know: Ransomware gangs, Copilot apps, and drones phone home
08/14/2026

Read the full stories at CISOSeries.com

This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

A huge thanks to our sponsor, ThreatLocker

ThreatLocker...


Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy
08/14/2026

Akira affiliate's innovative "crash mode" attack almost worked

WhatsApp rolls out scam alert feature

White House looks to private sector for help against offensive hacking

Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/

Huge thanks to our sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com...


UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON
08/13/2026

UK eyes AI gene-synthesis guardrails

DeadLock puts ransomware on the blockchain

An evil twin flies home from DEF CON

Episode show notes: https://cisoseries.com/uk-tackles-ai-bioweapon-risk-deadlock-goes-on-chain-evil-twin-flies-home-from-def-con/

Huge thanks to our sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.


Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline
08/12/2026

Water systems get a federal cyber lifeline

Hackers jump into Polish power plant

Cyberattacks knock local governments offline

Episode show notes:  https://cisoseries.com/water-systems-cyber-lifeline-hackers-polish-power-plant-local-governments-offline/

Huge thanks to our sponsor, ThreatLocker

Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.


Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits
08/11/2026

OpenAI loosens cyber limits for vetted defenders

Sandworm's fake recruiters plant a poisoned VPN

Royal Navy drones phone home to China

Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/

Huge thanks to our sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com...


OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady
08/10/2026

OpenAI slows release of Astra model citing cyber capabilities

Irregular won't say if there were more rogue incidents

U.S. cyber ambassador nominee Cassady confirmed in Senate

Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/

Huge thanks to our sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker...


Faked bug reports, Meta's rogue AI, China investigates Palo Alto
08/07/2026

Apple's bug bounty program overwhelmed by fake AI generated reports

China launches cybersecurity review into Palo Alto Networks products

Meta AI hacks external systems during cybersecurity testing

Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/

Huge thanks to our episode sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you...


AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon
08/06/2026

AI safety tests spill onto the real internet

Private Relay flaw unmasks IP addresses

Weak telcos left door open for Salt Typhoon

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/

Huge thanks to our episode sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker...


ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa
08/05/2026

ChainDrop attack hits npm

Pass-ta-key attacks target passkeys 

AI accounts for most cybercrime in Africa

Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/ 

Huge thanks to our episode sponsor, ThreatLocker

Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

 


License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window
08/04/2026

When license plate readers become stalking tools

ExfilSquad dumps UK police contact data

China-linked hackers shrink the patch window

Get the show notes here: https://cisoseries.com/cybersecurity-news-license-plate-readers-as-stalking-tools-exfilsquad-dumps-uk-police-data-the-ever-shrinking-patch-window/

Huge thanks to our episode sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker...


UK investments agency breach, CISA water warning, Anthropic rogue threesome
08/03/2026

UK's state investments agency suffers data breach

CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks

Anthropic says its AI hacked real-world companies in three incidents

Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/

Huge thanks to our episode sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat...


The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face
07/31/2026

This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, Pindrop

A finance worker joined a video call with their CFO and wired $25 million to attackers.

This isn't fiction—it happened. Deepfake v...


Analog Devices breach, Copilot AI worm, Teams ransomware vishing
07/31/2026

Semiconductor firm Analog Devices discloses data breach

Copilot for Word POC copies hidden prompts into new documents

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/

Huge thanks to our sponsor, Pindrop

A finance worker joined a video call with their CFO and wired $25 million to attackers.   This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing.   It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done...


OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
07/30/2026

OpenAI agent's escape reaches a Modal customer

Hackers hit Minnesota water systems

Fake Russian companies, real stolen money

Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/

Huge thanks to our sponsor, Pindrop

TIME named Pindrop one of the 10 Most Influential Software Companies of 2026.   Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended.   Don't wait for an incident report. Visit pindrop.com.  


Leaky BMCs, Claude finds encryption flaws, Google's new names
07/29/2026

Thousands of server BMCs leak password hashes

Claude finds flaws in encryption

Google gives old threat actors new names

Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/ 

Huge thanks to our sponsor, Pindrop

AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up?   Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report.   Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.  


Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
07/28/2026

Nvidia opens the AI security tent

Microsoft puts a cyber sprinter in MDASH

Fairlife ransomware spills data

Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/

Huge thanks to our sponsor, Pindrop

A finance worker joined a video call with their CFO and wired $25 million to attackers.   This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing.   It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.  


Iran infrastructure warning, ChatGPT global outage, self-assembling malware
07/27/2026

U.S. agencies warn of Iran-linked actors targeting water and energy control systems

ChatGPT suffered brief global outage on Saturday

Malvertising sends malware in pieces for an unsuspecting browser to build

Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/

Huge thanks to our sponsor, Pindrop

Your hiring processes are the newest entry point for security risks.    Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings.    Catch deepfakes, AI voices, and spoofed locations in real time...


The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown
07/24/2026

This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission l...


AI agents risk, Upbound Group breach, Dolphin X Stealer
07/24/2026

AI Agents become fastest growing exposed attack surface

Consumer finance company Upbound Group blames data breach for millions in losses

Dolphin X Stealer uses AI profiling to prioritize targets

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you...


OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp
07/23/2026

OpenAI behind Hugging Face hack

TrickBot tunnels through DNS

Acrobat extension opens WhatsApp

Get the show notes here:

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.