
We unpack a joint alert from the US and eight allied nations regarding Russian state-sponsored hackers targeting vulnerable routers to penetrate critical infrastructure networks. This highlights the ongoing threat to network edge devices and the necessity of robust patching and configuration management, even for non-critical entities.We also dive into a sophisticated new version of RedHook Android malware, which now leverages Android Wireless Debugging to gain remote shell-level privileges without a physical connection. This evolution in mobile malware capabilities demands increased vigilance over app permissions and device settings. On a more optimistic note, we explore recent advancements in AI, including OpenAI's temporary relaxation of GPT-5.6 Sol usage limits and compelling reports on its performance and cost efficiency. Google Cloud Tech's insights into agentic skills for developers and analytics further illustrate how intelligent agents are streamlining operations and automating tasks.Key takeaways include prioritizing router security with timely updates and strong configurations, meticulously reviewing Android device permissions and Wireless ADB settings, and actively exploring the integration of AI and agentic tooling to enhance operational efficiency and client delivery. The practical actions outlined will help fortify your defenses against evolving threats while leveraging cutting-edge technologies for business advantage.
Jul 13
3 min

We begin with a stark reminder of insider threats, as a former ransomware negotiator receives a significant sentence for BlackCat attacks. The supply chain remains a critical vulnerability, highlighted by a malicious npm package compromising Injective Labs SDK and a new group, Helix, leveraging vishing and MFA abuse to target SharePoint data. We also discuss Iran's expanding cyber crosshairs, emphasizing that any internet-facing system is a potential target. Microsoft's swift action on a Windows Defender zero-day, "RoguePlanet," underscores the constant need for patching.Shifting to AI and automation, we explore Google Cloud Tech's guidance on agentic skills for developers and production architectures for AI agents, alongside Kaseya's insights on AI-driven automation for security operations during summer staffing shortages. However, we also address the emerging risk of AI agents as new identities that organizations are ill-equipped to manage, requiring a fundamentally different approach to identity and access management.Our practical takeaways for today include auditing your supply chain security, particularly for developer tools, and intensifying user training against vishing and MFA bypass techniques. Furthermore, evaluate AI automation for consistent security operations during staff shortages, but critically, begin developing a strategy for managing AI agent identities to prevent them from becoming your next insider threat.
Jul 10
2 min

Today's briefing highlights a massive data breach at AssuranceAmerica affecting nearly 7 million drivers and a data deletion incident at Mount Royal University. These incidents underscore the pervasive threat landscape across all sectors. We also discuss an urgent Microsoft Defender zero-day vulnerability, "RoguePlanet," requiring immediate patching to prevent exploitation. On a positive note, global law enforcement agencies have achieved a significant win against fraud, seizing $293 million and arresting over 5,800 suspects in a 97-country operation.Practical takeaways include prioritizing the "RoguePlanet" patch, reviewing exposure to open-source projects like "Chatto," and evaluating how AI agent tools can enhance internal automation or client delivery. We explore advancements in AI for development and operations, with Google Cloud Tech's guides on deploying AI agents and Databricks' benchmarks on coding agents. The episode also touches on AI's role in cybersecurity, from Cloudflare and SentinelOne's discussions to Microsoft Security's prompt injection protection for email in Defender
Jul 9
4 min

We dive into urgent CISA alerts, including actively exploited, max-severity flaws in Langflow and Adobe ColdFusion, demanding immediate patching. Ubiquiti UniFi OS users also receive a crucial warning about command injection vulnerabilities.The episode further explores the ripple effects of a confirmed Accenture breach involving 35 gigabytes of stolen source code, highlighting persistent supply chain risks for all organizations. Shifting to AI, we discuss the security implications of tools like GitHub's AI agent, 'GitLost,' which reportedly leaked private repositories, underscoring the challenges of data boundaries with AI integration. However, it's not all threats; we also cover innovations in secure AI, including Google Cloud Tech's agentic AI strategies and the open-source, local-first Claude Desktop alternative, Rowboat, emphasizing data control and privacy.Key takeaways include prioritizing immediate patching for identified vulnerabilities, thoroughly reviewing supply chain security, and conducting robust data privacy and security assessments before deploying any AI agents or tools. Understand where your data goes and ensure strong access controls to prevent sensitive information exposure.
Jul 8
3 min

Key risks discussed include the urgent need to patch maximum-severity vulnerabilities in Adobe ColdFusion (CVE-2026-48282) and Citrix NetScaler products, both under active exploitation. We also highlight the persistent threat of social engineering, with attackers abusing Microsoft Teams voice calls to push EtherRAT malware, and the rise of "BusySnake" infostealer targeting government agencies and critical infrastructure. For virtualized environments, a guest-to-host escape vulnerability in KVM/x86 (Januscape, CVE-2026-53359) poses a serious risk of full system takeover.On the innovation front, we explore Google Cloud's push into agentic AI, showcasing its potential to break down data silos and transform enterprise data into real-time action. Discussions cover agentic coding with tools like Claude Code and Fable 5, OpenTelemetry's role in speeding up AI agents, and new MCP concepts for connecting AI to systems beyond traditional APIs. We also cover the AI-powered cybersecurity partnership between Cloudflare and SentinelOne, and strategies for maximizing AI investments to achieve real productivity gains.
Jul 7
3 min

Today, we highlight the potential vulnerabilities associated with widespread open-source platforms, using the "Homegames" platform as a timely example. This underscores the necessity for rigorous review of all third-party and open-source software within your environment. Understanding the operational relevance and exposure of these tools, perhaps through a Software Bill of Materials (SBOM), is crucial for preventing unexpected attack vectors.Beyond risk, we explore the transformative potential of agentic AI. Google Cloud Tech’s recent updates showcase how these intelligent agents can convert enterprise data into real-time actions, significantly boost operational speed, and challenge traditional API limitations. We also touch upon AI's role in accelerating design processes, such as generating parametric 3D models. The integration of AI into cybersecurity, as discussed by Cloudflare and SentinelOne, signals a shift towards more intelligent and proactive defense strategies capable of outpacing human response times.
Jul 6
2 min

Today's top risks include Alibaba's ban on Claude AI-generated code due to backdoor concerns, highlighting the need for caution with AI development. Linux users on kernel 6.9+ face a significant data protection oversight as LUKS suspend no longer wipes disk-encryption keys from memory. Cisco confirmed active exploitation of a Unified Communications Manager vulnerability, urging immediate patching. Apple is shifting to compressed patch cycles, a direct response to AI drastically reducing exploit development time. FortiBleed actors are escalating their operations, collaborating with ransomware gangs after exploiting Fortinet firewalls and a Nextcloud zero-day to monetize access.On the AI front, Google Cloud Tech is showcasing agentic AI transforming enterprise data to real-time action, speeding up AI agents by 80% on Gemini. They're also exploring the Multi-agent Communication Protocol (MCP) as a fundamental shift from traditional APIs, enabling complex multi-agent systems and internal collaboration.Practical takeaways include prioritizing patching and reviewing AI policies, verifying Linux LUKS configurations, and securely evaluating agentic AI tools. Patch Cisco Unified CM, Fortinet, and Nextcloud immediately, prepare for faster Apple updates, and review internal policies for AI-generated code. For Linux kernel 6.9+, confirm LUKS suspend behavior for proper key wiping. Assess agentic AI tools with a strong security framework, understanding their data and system connections.
Jul 3
2 min

Today, we cover urgent threats and evolving security landscapes. A high-severity Microsoft SharePoint RCE, patched in May, is now actively exploited, demanding immediate verification of your patch status. New Android malware underscores the critical need for robust mobile device security and enhanced employee awareness regarding app downloads. We also discuss the complexities introduced by Cloudflare's new Monetization Gateway and the supply chain security implications of open-source IoT devices like the Oomwoo robot vacuum.On the AI front, we explore how benchmarks like Senior SWE-Bench raise questions about securing AI-generated code and preventing its malicious use. Crafty, AI-powered phishing campaigns are adapting to device and OS fingerprints, making social engineering attacks more effective. Google Cloud's agentic AI, transforming enterprise data into real-time action, offers efficiency but requires careful consideration of agent permissions and data access.Key takeaways include immediately patching the Microsoft SharePoint RCE, tightening mobile device security with refreshed user training, and evaluating the security and efficiency impact of AI agents.
Jul 2
2 min

Today We discuss the lifting of export controls on powerful AI models like Anthropic's Fable 5 and Mythos 5, highlighting both innovation potential and increased security considerations. The episode then dives into emerging AI threats, including the "BioShocking" prompt injection attack that tricks AI-powered browsers into compromising data, and the discovery of a fake Perplexity AI extension on the Chrome Web Store tracking user activity.A significant traditional data breach at Aflac's Japan subsidiary, compromising 4.38 million customer records, serves as a stark reminder of the ongoing importance of supply chain security and third-party risk management. On a more positive note, we explore advancements in agentic AI and multi-agent systems, showcasing how AI is evolving to actively orchestrate workflows and drive efficiency.This briefing is essential for small-business leaders, cyber professionals, MSPs, CISOs, GovCon leaders, and security operators. Key takeaways include the need to thoroughly review new AI models for operational relevance, educate teams on prompt injection attacks, and reinforce basic cyb
Jul 1
3 min

Today's episode unpacks escalating threats, starting with CISA's confirmation of active exploitation of the Windows BlueHammer privilege escalation vulnerability by ransomware gangs. We also detail the Blackfield gang's $2 million ransom demand from Nidec Corporation, highlighting the significant operational and supply chain risks. Nissan and the National Association of Insurance Commissioners (NAIC) disclose data breaches stemming from an Oracle PeopleSoft vulnerability, underscoring the pervasive threat of zero-day exploits and data theft.Shifting to the future, we explore the rapid evolution of AI in cybersecurity. Discover Ornith-1.0, self-improving open-source models for agentic coding, and Google Cloud Tech's resources for building multi-agent systems. These developments signal a new era of automated defenses and potential attack vectors.Our practical takeaways include urgently reviewing your exposure to critical vulnerabilities like BlueHammer and Oracle PeopleSoft, emphasizing immediate patching and data risk assessment. We also advise evaluating new AI and agentic tooling for internal automation or client delivery, and staying informed on strategic partnerships shaping the future of cloud and AI security.
Jun 30
4 min
Load more
