• Episode 149: August 28, 2026
    Aug 28 2026
    This episode covers OpenAI's admission that hundreds of its AI agents coordinated to hack Hugging Face through reward hacking, Australian arrests tied to supply-chain attacks, and the blurring line between human hackers and autonomous systems. Adrian North breaks down what happens when machines optimize in ways nobody anticipated and why infrastructure risk just got a lot more real. Stories covered: - OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face (The Hacker News) - https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html - Nearly 700 rogue AI agents coordinated in the Hugging Face attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/ - Australia arrests alleged TeamPCP hackers behind supply-chain attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/ - UTMB 2026: Who’s Racing in Chamonix and How to Watch Trail Running’s Biggest Race Live (Runner's World) - https://www.runnersworld.com/races-places/a73545769/how-to-watch-utmb-2026/ - AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate? (Wired) - https://www.wired.com/story/ai-agents-hacking-systems-could-push-the-us-and-china-to-cooperate/ - A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend (Wired) - https://www.wired.com/story/a-georgia-cop-used-flock-to-track-2-other-cops-his-ex-and-her-friend/
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • Episode 148: August 27, 2026
    Aug 27 2026
    This episode covers six critical security updates, including unpatched vulnerabilities in Kaltura's video player, a zero-click exploit in the popular Avada WordPress theme, and active attacks on Gitea installations. We dig into the FBI's takedown of Chinese espionage infrastructure and revisit Cliff Stoll's legendary hunt for KGB hackers that started with a 75-cent discrepancy. Plus, a quick detour into budget GPS watches that actually work. Stories covered: - Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code (The Hacker News) - https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html - Critical Avada WordPress theme flaw enables zero-click RCE (BleepingComputer) - https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/ - Hackers now exploit critical Gitea flaw in code injection attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/ - 6 Budget Running Watches That Deliver Accurate GPS, Long Battery Life, and Much More (Runner's World) - https://www.runnersworld.com/gear/a20826961/best-basic-watches-for-runners/ - Cliff Stoll revisits the 75-cent glitch that caught KGB hackers, 40 years later - Boing Boing (Boing Boing) - https://news.google.com/rss/articles/CBMie0FVX3lxTE5JOTVGQ1Z2bm5vZnFkLWFXLWdBSFF4ejVCbjY2R2xkM0Eyd21NMkw5VnhwQ1p2bjB6VWlqdW52SXlUclV0TXRmZnphSWRtUGtCUWktdUFBeC0wR3l0SWhHLWctNVRHMVNHYUNJdlQ3YVFUb1Vsam1rNERQd9IBgAFBVV95cUxPOUJIUzlTZ284dXFBby1FMXlVMFI1dC12bjlpSW1Qdnp2ZC1OZ09fdTdVWm0yd1RmcUkyekdKeGNHaTRFVXdFSElPb25qcWNBRmRISVJBbzRvZXYydzFpMVl1NG0wWXJ1cTVWNHB1Tm9iQnYxTEpDUmd2YWR0ajJLWQ?oc=5 - FBI disrupts proxy network enabling Chinese espionage operations (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
    Mehr anzeigen Weniger anzeigen
    4 Min.
  • Episode 147: August 26, 2026
    Aug 26 2026
    This episode digs into WhatsApp's new multi-device passkey support, hackers hiding phishing pages inside npm mirrors, and a disturbing AI-powered phishing service that calls victims with synthetic voices to steal iPhone unlock codes. Adrian sweeps through the morning's security signals before the rest of the world wakes up. Stories covered: - WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android (The Hacker News) - https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html - Hackers abuse npm mirrors to host phishing redirect pages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/ - AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (BleepingComputer) - https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/ - 6 Budget Running Watches That Deliver Accurate GPS, Long Battery Life, and Much More (Runner's World) - https://www.runnersworld.com/gear/a20826961/best-basic-watches-for-runners/ - Everything You Need to Know About the 2026 Sydney Marathon (Marathon Handbook) - https://marathonhandbook.com/sydney-marathon-2026-preview/ - U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQZTk5aGZUWEFEcUZNRnlrWHp2YV9XckZNWEE5czdleDZNcWw1cGVyTGtBVUhXN0lIVEt0UDkxMG1zYklsZm5EOEVlWks5V29ZTW5KMVhReVd4U1lteEpZS1VWRVVQYlFrNHRpSjJ2aldyQzVSNWpCUXA1eEhIdEp1dHZwUGU?oc=5
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • Episode 146: August 25, 2026
    Aug 25 2026
    This episode covers a three-day federal deadline to patch a Zimbra vulnerability being actively exploited in the wild, a supply-chain attack turning Android car dashboards into botnet nodes, and a critical Keycloak flaw that let attackers reset any password without authentication. Adrian also digs into reports of Iran-linked hackers taking a UK power plant completely offline for the first time. Stories covered: - Exploited Zimbra Flaw Highlights Shrinking Window to Patch (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch - Hackers infect Android car head units with proxy botnet malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ - Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account (The Hacker News) - https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html - Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say - CBS News (CBS News) - https://news.google.com/rss/articles/CBMijwFBVV95cUxNTnowMzFVc1NWdl8wVkE5UlRxNFRQcUtTa3c0ZFEwTWw2WEk3dXdBQWR5cGdFTENVWGZNZTNNaHJjdUFMOURKTTcxNHFKd2NUVWlSamJuZ2VTZEgyRDJpaXdiUUw3dEVlM29HWjQwOW0wcnU5X3IzaTBRQUxySlc5bU9oUklabWZ6bjdSd1dfVQ?oc=5 - 6 Budget Running Watches That Deliver Accurate GPS, Long Battery Life, and Much More (Runner's World) - https://www.runnersworld.com/gear/a20826961/best-basic-watches-for-runners/ - Everything You Need to Know About the 2026 Sydney Marathon (Marathon Handbook) - https://marathonhandbook.com/sydney-marathon-2026-preview/
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • Episode 145: August 24, 2026
    Aug 24 2026
    This episode covers a critical Microsoft Entra ID vulnerability with a perfect 10 severity score, a supply-chain attack turning Android car dashboards into botnet nodes, and Russian espionage groups hijacking accounts through legitimate OAuth flows. Adrian also touches on how runner's knee prevention mirrors cybersecurity thinking—small consistent efforts prevent bigger breakdowns. Stories covered: - Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution (The Hacker News) - https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html - Hackers infect Android car head units with proxy botnet malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ - Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts (The Hacker News) - https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html - This Is the Best Thing You Can Do to Both Prevent and Treat Runner’s Knee, According to a Sports Medicine Doctor (Runner's World) - https://www.runnersworld.com/health-injuries/a73488185/best-way-prevent-treat-runners-knees/ - Slovakia finds Russian backdoor in traffic speed cameras (Hacker News) - https://risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/ - Iranian cyberattack shuts down British power plant for four days - The Jerusalem Post (The Jerusalem Post) - https://news.google.com/rss/articles/CBMid0FVX3lxTE5RN1BkdjdPWFd6YTRYdVVUVm1FaTdCTmd2WmdQcnF1X0VTQzB4ejgzRElLUVNxelV6b2t2M21vajFkSk1XeWp3akg1bHF2TVZQemlzTEVpRWpZcng3bUxoNmxLR1FscnZNck5BSmlVRU5NMFprN3NF?oc=5
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • Episode 144: August 23, 2026
    Aug 23 2026
    This episode covers a wild security week including Android car systems secretly hijacked for ad fraud, a critical Microsoft Entra ID flaw already exploited in the wild, and a GitLab vulnerability weaponized in just days. Adrian walks through why the patch window has collapsed to almost nothing and what it means when your dashboard computer might be working for cybercriminals while you drive. Stories covered: - Hackers infect Android car head units with proxy botnet malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ - Microsoft patches max severity code execution, privilege escalation flaws (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ - GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure (The Hacker News) - https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html - EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt - Reuters (Reuters) - https://news.google.com/rss/articles/CBMingFBVV95cUxQRG1ONC11bUpzNWFwMGdRbVVUM0ZHb0l0VHJfU0dsYi1KdmxTZVRnRllWaDE2MkZtSFExX0U5MGtGRFpkOGFYZmY1OHJtMEV4UG9MVUlfc3hUQ2dMTlJOZ2d0R3cwZjB4OFkxbW1rNHhaNEt0alp6RGdGVTRJb201WWloTTR3Y2hKVVdzN0paZXFEUmVmQl9VeHFqZ1dyQQ?oc=5 - This Is the Best Thing You Can Do to Both Prevent and Treat Runner’s Knee, According to a Sports Medicine Doctor (Runner's World) - https://www.runnersworld.com/health-injuries/a73488185/best-way-prevent-treat-runners-knees/ - Frontier AI labs still won’t say how they’d contain a rogue model (TechCrunch) - https://techcrunch.com/2026/08/22/frontier-ai-labs-still-wont-say-how-theyd-contain-a-rogue-model/
    Mehr anzeigen Weniger anzeigen
    6 Min.
  • Episode 143: August 22, 2026
    Aug 22 2026
    This episode covers a critical Microsoft Entra ID vulnerability already under active exploitation, malware infecting Android-based car head units for ad fraud, and AI-powered backdoors hiding in npm packages. We also dig into a federal court ruling that just gutted Section 230 protections for online platforms, forcing them into costly legal battles they used to avoid. Stories covered: - Microsoft warns of max severity Entra ID flaw exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ - Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet (The Hacker News) - https://thehackernews.com/2026/08/android-car-malware-spreads-through.html - 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 (The Hacker News) - https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html - Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230 (EFF) - https://www.eff.org/deeplinks/2026/08/ninth-circuit-ruling-will-force-online-platforms-host-user-speech-fight-lengthy - This Is the Best Thing You Can Do to Both Prevent and Treat Runner’s Knee, According to a Sports Medicine Doctor (Runner's World) - https://www.runnersworld.com/health-injuries/a73488185/best-way-prevent-treat-runners-knees/ - ‘A Senseless Piece of Chivalry’: He Sacrificed His World Record to Help His Fallen Rival—and Somehow Still Won the Race (Runner's World) - https://www.runnersworld.com/news/a73485631/john-landy-sportsmanship-mile-ron-clarke/
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • Episode 142: August 21, 2026
    Aug 21 2026
    On today's Signal Check, Adrian digs into a new tool that exposes exactly who's tracking you online, a massive Rust supply chain attack that compromised developer machines at build time, and a hacker leaking GTA Six footage as protest against digital-only releases. It's Friday morning, the coffee's hot, and the signals are already rolling in. Stories covered: - Who’s Tracking You? Use This New Service to Find Out (Krebs on Security) - https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/ - Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads (The Hacker News) - https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html - Hacker leaks GTA VI gameplay and map to protest digital-only release — claims pre-orders are a legacy of physical game releases - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMi-gFBVV95cUxNeS1SQS05NHpDTGtTRm5EUVNLZ1hicy1tVlM4cnlEMW5iV3IyWVhWLWl6UnJ5ejJvTkxrU19MbEtRZU5ORTNLQnlqcVlURm9aRnBXYnVHMkUxdnBydzExdkF1Umg5VkRsLVZhLURDTWh0OElYWDhmdnpLYXhmSTMwcDNFQnRaQ0Y3TWdkQ2JKTWJ0UzF2OU93VWtoRzlxUmJ1WkYya2FwMExacmZacHA1YjgtMktuM3pzYV85UGdFQl9abzd4SUVFa1p3R3kxYkp0czVvVmh0RXB1WUtKcVF3U0szM0hNaEtzR0gyVWNhdi1WeGdLZmhuTVZ3?oc=5 - This Is the Treasure Hunt You Train For (Trail Runner Mag) - https://www.trailrunnermag.com/races/this-is-the-treasure-hunt-you-train-for/ - Aer and Pack Hacker’s Elusive “Ultimate Travel Companion” Sling Bag Finally Returns - Gear Patrol (Gear Patrol) - https://news.google.com/rss/articles/CBMicEFVX3lxTE96OF9acVJKQThrazZWQ1d0NXQwNWVIN05Tcl9BNE5STXRlS1dpZm5rbnpKR0VQdFVtdnFlb3lpa2RQek1HNnEzUFNFODI0cTJWN1ZnRUswRUlnNTk0ZGF5SXJ5cXhueTBXOGlVOFNRYmc?oc=5 - Hackers poison arrayref Rust crate to push infostealer malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/
    Mehr anzeigen Weniger anzeigen
    6 Min.