Cisco Breached: Source Code Stolen - Cybersecurity Today

Cisco Breached: Source Code Stolen - Cybersecurity Today

Cisco Source Code Stolen in Trivy Fallout, Axios Supply Chain Attack, and Active Exploitation of Fortinet and Citrix Flaws

David Shipley reports multiple major security incidents: attackers used credentials stolen in the Trivy supply-chain attack via a malicious GitHub action to breach Cisco's internal development environment, clone 300+ GitHub repos, steal source code (including AI products) and AWS keys, and impact customer-related code; Cisco contained the breach, re-imaged systems, and rotated credentials. A separate supply-chain attack hit the widely used JavaScript library Axios after its maintainer account was compromised, pushing poisoned NPM versions that installed a dropper/RAT via a fake dependency; users are told to downgrade affected versions, remove the dependency, rotate credentials, and review CI/CD logs. Active exploitation is confirmed for a Fortinet FortiClient EMS SQL injection (CVE-2026-21643) and for critical Citrix NetScaler flaws (CVE-2026-3055, possibly alongside CVE-2026-4368). Anthropic accidentally exposed details of a new model, "Code Mythos," described as highly capable in reasoning, coding, and cybersecurity. Finally, TechCrunch reports escalating allegations that compliance startup Delve helped fabricate audit evidence and worked with weak auditors. The episode also marks show episode 1,500.

00:00 Headlines and Sponsor
00:54 Cisco Trivy Breach
02:28 Axios NPM Attack
04:12 Fortinet SQLi Exploited
06:24 Citrix Bleed Returns
08:05 Anthropic Model Leak
10:24 Fake Compliance Scandal
12:30 Episode 1500 Milestone
14:03 Sponsor Closing Message

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(100)

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—for...

22 Aug 36min

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA ...

21 Aug 14min

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where V...

19 Aug 12min

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 lead...

17 Aug 9min

Cybersecurity Today Weekend Month in Review: August 2026

Cybersecurity Today Weekend Month in Review: August 2026

AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July devel...

15 Aug 56min

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that explo...

14 Aug 11min

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carr...

12 Aug 9min

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulner...

10 Aug 16min

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
aftonbladet-daily
rss-expressen-dok
svenska-fall
flashback-forever
rss-krimstad
rss-vad-fan-hande
motiv
rss-krimreportrarna
rss-sanning-konsekvens
svd-ledarredaktionen
spar
rss-frandfors-horna
rss-flodet
politiken
rss-aftonbladet-krim
fordomspodden
grans
krimmagasinet