Episodios

  • Anthropic's Project Glasswing, CISA funding in doubt, routers hijacked for passwords
    Apr 8 2026

    Anthropic announces Project Glasswing

    U.S. seeks to slash CISA funding

    Russia-linked hackers hijack routers for passwords

    Check out our show notes here: https://cisoseries.com/cybersecurity-news-anthropics-project-glasswing-cisa-funding-in-doubt-routers-hijacked-for-passwords/

    Huge thanks to our episode sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    Más Menos
    7 m
  • Drift blames exploit on North Korea, GitHub attacks target South Korea, Die Linke breach threatens data leak
    Apr 7 2026

    Drift says exploit was North Korean intelligence operation

    GitHub used in multi-stage attacks targeting South Korea

    Data leak threatened after Die Linke attack

    Check out our show notes here: https://cisoseries.com/cybersecurity-news-drift-blames-exploit-on-north-korea-github-attacks-target-south-korea-die-linke-breach-threatens-data-leak/

    Huge thanks to our episode sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    Más Menos
    8 m
  • Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer
    Apr 6 2026

    Link to episode page

    This week's Department of Know is hosted by Sarah Lane, with guests Jack Kufahl, CISO, Michigan Medicine, and Adam Palmer, CISO, First Hawaiian Bank.

    Missed the live show? Check it out on YouTube.

    Huge thanks to our sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    Más Menos
    32 m
  • Malicious npm packages, CISA budget cuts, hackers exploit React2Shell
    Apr 6 2026

    36 Malicious npm packages exploited to deploy persistent implants

    Hundreds of millions to be cut from CISA in proposed budget

    Hackers exploit React2Shell in automated credential theft campaign

    Check out our show notes here: https://cisoseries.com/cybersecurity-news-malicious-npm-packages-cisa-budget-cuts-hackers-exploit-react2shell/

    Huge thanks to our episode sponsor, Vanta

    Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

    Más Menos
    9 m
  • Texas hospital breach, CISA orders NetScaler patch, ISO file RAT warning
    Apr 3 2026

    250,000 affected by data Breach at Texas hospital

    CISA says, "patch Citrix NetScaler bug by Thursday"

    Researchers uncover mining operation using ISO lures

    Get the show notes here: https://cisoseries.com/cybersecurity-news-texas-hospital-breach-cisa-orders-netscaler-patch-iso-file-rat-warning/

    Huge thanks to our sponsor, ThreatLocker

    Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That approach allows organizations to reduce risk without overwhelming IT teams or disrupting critical workflows. Learn more at ThreatLocker.com

    Más Menos
    8 m
  • New iOS patches over DarkSword, FBI: surveillance hack is major incident, Cisco code stolen in Trivy-linked breach
    Apr 2 2026

    Apple pushes new patches over DarkSword

    FBI: US surveillance hack is major incident

    Cisco code stolen in Trivy-linked breach

    Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-pushes-new-patches-over-darksword-fbi-us-surveillance-hack-is-major-incident-cisco-code-stolen-in-trivy-linked-breach/

    Huge thanks to our sponsor, ThreatLocker

    Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — stopping unknown execution and unauthorized privilege elevation instead of relying solely on alerts after the fact. Learn more at ThreatLocker.com

    Más Menos
    7 m
  • Axios poisoned, TeamPCP details, Claude Code leaked
    Apr 1 2026

    HTTP client introduces malicious dependency

    TeamPCP testing the open source supply chain

    Claude source code leaked

    Get the show notes here: https://cisoseries.com/cybersecurity-news-axios-poisoned-teampcp-details-claude-code-leaked/

    Huge thanks to our sponsor, ThreatLocker

    Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attackers can't easily escalate access or move laterally across the environment. Learn more at ThreatLocker.com

    Más Menos
    8 m
  • macOS Terminal ClickFix attacks, Russian court sentences 'Flint', CareCloud probes data breach
    Mar 31 2026

    macOS Terminal gets ClickFix attacks

    Russian court sentences 'Flint' over card fraud

    CareCloud probes data breach

    Get the show notes here: https://cisoseries.com/cybersecurity-news-macos-terminal-clickfix-attacks-russian-court-sentences-flint-carecloud-probes-data-breach/

    Huge thanks to our sponsor, ThreatLocker

    Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the first place — controlling applications, scripts, and installers so unauthorized code never gets the chance to run. Learn more at ThreatLocker.com

    Más Menos
    8 m