
Everyone panicked this week over two new Chinese AI models. The economics? Mostly overblown. But buried in the story is a real cybersecurity blind spot, a hacked company that had to turn to a Chinese AI model to defend itself, because American guardrails wouldn't let its own team do the job. Darnley breaks down the panic, the actual strategy behind China's open-source push, and six practical cyber awareness lessons for any team using AI in security operations. Click here to send f...
Jul 22
17 min

A researcher found an unlocked server...and inside it, working VPN credentials for nearly 74,000 corporate firewalls spanning Chevron, Samsung, Foxconn, and thousands more. In this episode of Darnley’s Cyber Café, Darnley breaks down the FortiBleed leak: what was exposed, how attackers allegedly cracked their way in at a billion-attempt scale, and why this story matters even if your organization has never touched a FortiGate. Spoiler: the lesson is bigger than one vendor... Show...
Jul 15
11 min

Amazon just announced it has deployed enough satellites to launch its Leo broadband service later this year, stepping straight into Starlink's territory and kicking off the next phase of the satellite internet race. In this episode of Darnley's Cyber Café, we break down what the milestone really means, how the competition stacks up, and the honest pros and cons of getting your internet from space. Then things take a turn: a $25 hardware hack, a joint government advisory nobody's talking...
Jul 8
22 min

Merck spent six and a half years fighting over a $1.4 billion insurance claim after the NotPetya cyberattack, and walked away with a settlement, not an answer. The question that mattered most never got resolved. This episode, Darnley breaks down why cyber insurance feels like the obvious safety net, why the Merck case proves it isn't one you can fully rely on, and what actually determines whether your business survives a serious incident...with or without a payout. This isn't an anti-insuranc...
Jun 23
27 min

A job offer lands in your inbox on LinkedIn. The company checks out. The money is fine... All they need is a short report on geopolitics or defence policy. You just got flagged by the People's Liberation Army. In this episode we talk about in June 2026, the FBI, MI5, and the intelligence agencies of Canada, Australia, and New Zealand issued what they called an unprecedented joint warning: China's military intelligence services are running systematic recruitment operations on professional netw...
Jun 10
23 min

iPhone users across iOS 16 are having their WhatsApp accounts hijacked...without clicking anything, without approving a login, and without any new device appearing in their Linked Devices list. In this episode, we break down how the attack chain works, why iOS 16 is the specific target surface, what the broader shift of zero-click exploits into financially motivated crime actually means, and what you can and cannot do to protect yourself. If you or someone you know is on an unpatched iP...
Jun 3
22 min

Your AI chatbot just recommended a software download. You clicked it...along with a GPU cryptominer running silently in the background. Darnley breaks down Microsoft Defender Experts' latest findings on a sophisticated cryptojacking campaign that evolved beyond traditional SEO poisoning into AI search result poisoning, a new delivery technique that turns your trusted AI tools into malware recommendation engines. In this episode, we cover how the attack works from ZIP download to process...
May 27
17 min

In May 2026, NYC Health + Hospitals, the largest public health system in the USA, disclosed months long data breach affecting 1.8 million people. Stealing data such as medical records, Social security numbers, passport details, geo-location data, and biometric information. In this episode, Darnley breaks down exactly how third party vendor breaches work, what each category of stolen data means, and why biometric theft is forever. We deliver a 10-step protection playbook to stay protecte...
May 20
21 min

Five Eyes intelligence agencies: CISA, NCSC, CCC, ASD, and NCSC just published their first ever coordinated security guidance on agentic AI, and the message is clear: autonomous AI systems are already operating inside critical infrastructure with excessive access and insufficient governance, and the consequences of getting this wrong are a national security threat. In this episode of Darnley's Cyber Café, we break down the five risk categories the Five Eyes flagged, walk through the exa...
May 14
26 min

Your organization spent money on cybersecurity training. Someone still clicked the link. In this episode of Darnley's Cyber Café, we break down why most security awareness programs fail to change behaviour, and why the gap between knowing about a threat and actually being ready for it is exactly where attackers operate. Drawing on research from ETH Zurich, real-world breach data, and the 2025 Marks & Spencer cyberattack, this episode unpacks the compliance checkbox model, the ...
May 6
12 min
Load more
