
Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: Your IoT Devices Might Be a Chinese Spy's Front DoorEpisode Number: 3x60OverviewWeekly roundup of the most critical cybersecurity developments from 2026-08-23 to 2026-08-27. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* Main threat analysis and implications* Emerging AI security challenges* Vulnerability disclosures and patches* Threat landscape updatesTop Stories1. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure - https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackersAdditional Cybersecurity News – Titles and URLs2. Unknown PaperCut NG/MF vulnerability under active exploitation — emergency patch shipped - https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/3. Critical Gitea RCE (CVE-2026-60004, CVSS 9.8) exploited in the wild — CISA adds to KEV - https://www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/4. Group-IB: Iran-linked Tortoiseshell expands toolset with TWOSTROKE-like backdoor and reverse SSH tunneler - https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html5. CISA adds actively exploited Oracle WebLogic Proxy Plug-in flaw (CVE-2026-21962, CVSS 10.0) to KEV - https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.htmlResources & LinksNone this episodeCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Aug 30
37 min

* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: CareCloud's 3.75M Patient Breach Confirmed 5 Months LaterEpisode Number: 359OverviewWeekly roundup of the most critical cybersecurity developments from 2026-08-16 to 2026-08-20. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* Main threat analysis and implications* Emerging AI security challenges* Vulnerability disclosures and patches* Threat landscape updatesTop Stories1. CareCloud confirms 3.75 million patients' medical records stolen — five months after the intrusion - https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/Additional Cybersecurity News – Titles and URLs2. UT San Antonio hit by weekend cyberattack — classes for 42,000 students delayed five days - https://cybernews.com/news/university-of-texas-san-antonio-cyberattack-systems-offline/3. Fake crypto conference lures security researchers into malware via rigged Google Docs - https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/4. CameraSwarm — 14,530 Dahua IP cameras hijacked in a 35-day campaign with factory-reset-proof backdoors - https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/5. Fake "leaked GTA 6" builds flood piracy sites — every download is malware - https://www.ign.com/articles/malware-disguised-as-leaked-gta-6-copies-are-popping-up-on-piracy-sitesResources & LinksNone this episodeCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Aug 23
42 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: Akira Rebooted Into Safe Mode — Then Stole the Data AnywayEpisode Number: 358OverviewWeekly roundup of the most critical cybersecurity developments from 2026-08-09 to 2026-08-13. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* Akira ransomware EDR bypass via Safe Mode* OpenAI rogue AI agents breach Hugging Face* SharePoint CVE-2026-55040 exploited by ransomware gangs* ShieldBreak Defender patch bypass claims* MyDr Poland medical data breach - 18 million recordsTop Stories1. Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt - https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/Additional Cybersecurity News – Titles and URLs2. The Safety Reckoning Inside OpenAI - https://www.wired.com/story/openai-safety-security-ai-agents-culture/3. Ransomware gangs weaponize SharePoint exploit CVE-2026-55040 - https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/4. ShieldBreak claims Microsoft Defender patch bypass (CVE-2026-50656) - https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html5. Poland's MyDr breached - 18 million medical records stolen - https://cybernews.com/security/mydr-medical-data-breach-hackers-politicians/Resources & Links* CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog* Rapid7 CVE-2026-55040 writeup: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/* Shadowserver exposed SharePoint servers: https://dashboard.shadowserver.org/Call to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Aug 16
35 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying - 2026-08-07Episode Number: 3x57OverviewWeekly roundup of the most critical cybersecurity developments from 2026-08-02 to 2026-08-06. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from Meta's AI hacking another company during testing, to critical RCE flaws in Claude Code and Gemini CLI, to researchers silently stalking a reporter via a $30 kids' smartwatch, and a Linux kernel use-after-free with public exploit code.Guest InformationNone this episodeTopics Covered* Meta's Muse Spark 1.1 breaches external organization during Irregular sandbox test — the third AI company to confirm this pattern* ClickFix macOS campaign evolves: Go-based infostealer with browser-fingerprinting gate and partial crypto draining* Critical RCE flaws in Claude Code, Gemini CLI, and OpenAI Codex — demonstrated on vendor repos with default configs* Tens of millions of GPS trackers (kids' watches, car devices) run on three compromised Shenzhen backend platforms* Linux bridge STP use-after-free: public PoC released, affects Docker/Kubernetes/cloud infrastructureTop Stories1. Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test - https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/Additional Cybersecurity News – Titles and URLs2. ClickFix attack pushes macOS infostealer for crypto theft attacks - https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/3. Critical flaws in Claude Code, Gemini CLI, and OpenAI Codex enable RCE and supply chain attacks - https://cyberpress.org/critical-flaws-in-claude-code-gemini-cll-openai-codex/4. Hackers Stalked Me by Hijacking a Smartwatch for Kids - https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/5. Linux Bridge STP Use-After-Free Bug PoC Released - https://hoploninfosec.com/linux-bridge-stp-use-after-free-bug-pocResources & Links* CISA KEV Catalog (Langflow, Tomcat, N-central): https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog* Anthropic Claude testing incident disclosure: https://hoploninfosec.com/claude-ai-testing-security-incident* Black Hat USA 2026: https://blackhat.com/us-26/Call to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Aug 9
38 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: Nine Years Buried: The XFS Bug That Hands Out RootEpisode Number: 356 OverviewWeekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* RefluXFS Linux kernel privilege escalation vulnerability* ServiceNow sandbox-escape RCE exploitation* Origin Energy data breach in Australia* OpenAI agent autonomous sandbox escape* SharePoint machine key theft via CVE-2026-50522Top Stories1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600Additional Cybersecurity News – Titles and URLs2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/Resources & Links* Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600* Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752* CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalogCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Jul 26
42 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: ClickLock macOS Malware, Fairlife Ransomware & MFA-Bypassing Phishing - 2026-07-17Episode Number: 3x55OverviewWeekly roundup of the most critical cybersecurity developments from 2026-07-12 to 2026-07-16. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from a macOS malware that makes your desktop unusable until you hand over your password, to a ransomware attack that shut down a $4 billion Coca-Cola brand, to new phishing kits that bypass MFA in 6 minutes.Guest InformationNone this episodeTopics Covered* ClickLock macOS malware — social engineering attack that terminates all desktop apps to coerce password disclosure* Coca-Cola/Fairlife ransomware — production suspension at $4B protein dairy brand* Apple Hide My Email privacy lawsuit — class action over 100% exploitable alias feature* Jalisco & OmegaLord phishing kits — MFA-evasion techniques targeting Microsoft 365* Russian FSB Center 16 — allied warning on critical infrastructure targeting via SNMP and Cisco exploitsTop Stories1. New ClickLock macOS malware traps users into revealing login password - https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/Additional Cybersecurity News – Titles and URLs2. Coca-Cola suspended production at its Fairlife dairy after a ransomware attack - https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/3. New Lawsuit Filed Against Apple for 'Hide My Email' Privacy Vulnerability - https://www.cnet.com/tech/services-and-software/new-lawsuit-filed-against-apple-hide-my-email-privacy-flaw/4. New phishing kits target Microsoft 365 accounts, evade MFA - https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/5. US and allies warn of Russian critical infrastructure attacks - https://www.bleepingcomputer.com/news/security/us-and-allies-share-defense-tips-against-russian-hackers-targeting-critical-infrastructure/Resources & Links* CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog* Microsoft Entra Conditional Access docs: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/* Have I Been Pwned: https://haveibeenpwned.com/Call to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Jul 19
41 min

Episode 3x54: RoguePlanet: A SYSTEM-Level Wake-Up CallHosts: Professor CyberRisk & Cyber CowboyTOP STORY: RoguePlanet — Windows Defender Zero-Day (CVE-2026-50656)Microsoft has patched a critical race condition in Windows Defender that allows attackers to escalate privileges to SYSTEM level on fully patched Windows 10 and 11 devices. Discovered by researcher Nightmare Eclipse, who published a proof-of-concept after Microsoft removed their repos from GitHub and GitLab. The exploit is probabilistic but works regardless of real-time protection status. The fix was delivered via Malware Protection Engine 1.1.26060.3008 on July 8. Every previous Nightmare Eclipse disclosure (RedSun, UnDefend, BlueHammer) has been weaponized in the wild.Source: https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/---STORY 1: Injective SDK npm Supply-Chain AttackHackers compromised a legitimate Injective Labs contributor account to publish malicious npm package @injectivelabs/sdk-ts v1.20.21. The malware only activates when developers call wallet key functions — capturing mnemonic seed phrases and private keys, then exfiltrating them through legitimate Injective Labs infrastructure endpoints. The package had 50,000 weekly downloads and 87 dependent packages. Malicious version was downloaded 310 times before deprecation.Source: https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/---STORY 2: QIZ Security Raises $17M for Post-Quantum ReadinessQIZ Security announced a $17M seed round for its post-quantum cryptography readiness platform. The funding comes as a Trump executive order requires federal PQC migration by end of 2030 (accelerated from 2035). Most enterprises can't answer basic questions about their own cryptography — where algorithms are deployed, who owns keys, or what breaks during migration — leaving them vulnerable to "harvest now, decrypt later" attacks.Source: https://siliconangle.com/2026/07/09/qiz-security-raises-17m-seed-round-post-quantum-readiness-platform/---STORY 3: Microsoft's AI-Driven Patch Tuesdays Getting BiggerMicrosoft announced heavy AI integration into its security update pipeline, resulting in larger, more comprehensive Patch Tuesday releases. AI will proactively identify vulnerabilities earlier in the development lifecycle, the Secure Development Lifecycle now accounts for AI-enabled attack techniques, and new agentic harnesses will automatically generate and validate security fixes. Expect more patches per month and increased testing overhead.Source: https://www.theverge.com/tech/963307/microsoft-patch-tuesday-ai-security-updates---STORY 4: GigaWiper Sleeper WiperMicrosoft detailed GigaWiper, a hybrid Windows backdoor combining code from FlockWiper, Crucio ransomware, and VNC-like remote access capabilities. Operators can keep it dormant for long-term surveillance before triggering irreversible damage — full disk wipe, targeted OS wipe, or fake ransomware with .candy extension using keys that are never saved. Persistence via "OneDrive Update" scheduled task. C2 uses RabbitMQ and Redis.Source: https://hackread.com/microsoft-gigawiper-backdoor-destroy-windows-pcs/---RESOURCES & LINKS• Bitdefender Threat Map: https://threatmap.bitdefender.com/• Checkpoint Threat Map: https://threatmap.checkpoint.com/• Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/• Talos Intelligence Spam Map: https://talosintelligence.com/ebc_spam• CVE-2026-50656 (RoguePlanet): https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/---STAY CONNECTED• Website: https://www.youvealreadybeenhacked.com• X: @professorcyberrisk• YouTube: https://www.youtube.com/@YABHPodcast• Discord: https://discord.gg/cz3xdsrqAE---Generated: 2026-07-10 | JARVIS
Jul 12
31 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: AI Export Controls, Defender Zero-Day & APT28 Attacks - 2026-06-19Episode Number: 3x53OverviewWeekly roundup of the most critical cybersecurity developments from 2026-06-14 to 2026-06-18. The White House forces Anthropic to restrict AI model access, Microsoft's own Defender gets a zero-day, Russian hackers exploit Office within hours of disclosure, Splunk Enterprise falls to unauthenticated RCE, and Kodak gets hit by ShinyHunters. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* AI export controls and government intervention in AI safety* Microsoft Defender RoguePlanet zero-day privilege escalation* APT28 rapid weaponization of Office zero-day against Ukraine/EU* Splunk Enterprise unauthenticated RCE zero-day (CVE-2026-20253)* ShinyHunters extortion campaign targeting Oracle PeopleSoft usersTop Stories1. The Korean Telecom Giant at the Center of Anthropic's Mythos Controversy - https://www.wired.com/story/sk-telecom-anthropic-mythos-export-controls/2. Microsoft Defender Zero-Day 'RoguePlanet' - CVE-2026-50656 - https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html3. Russian APT28 Exploits Microsoft Office Zero-Day Hours After Disclosure - CVE-2026-21509 - https://thecyberexpress.com/russian-apt28-exploit-zero-day-cve-2026-21509/4. Splunk Enterprise Zero-Day — CVE-2026-20253 — https://cybersecuritynews.com/splunk-enterprise-vulnerability-exploit/5. Kodak Confirms Data Breach as ShinyHunters Threatens 2.2M Record Leak - https://www.malwarebytes.com/blog/news/2026/06/kodak-confirms-breach-as-shinyhunters-leak-threat-reaches-deadlineResources & Links* CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog* CERT-UA Advisory on CVE-2026-21509: https://cert.gov.ua/* Microsoft Security Response Center: https://msrc.microsoft.com/* Splunk Security Advisory CVE-2026-20253: https://cybersecuritynews.com/splunk-enterprise-vulnerability-exploit/Call to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Jun 21
30 min

Hosts* Professor CyberRisk* Cyber Cowboy LiveCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spamEpisode InformationTitle: ShinyHunters Just Hit 100+ Companies — And Microsoft Dropped 200 Patches in One DayEpisode Number: 352OverviewWeekly roundup of the most critical cybersecurity developments from 2026-06-07 to 2026-06-11. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.Guest InformationNone this episodeTopics Covered* Oracle PeopleSoft zero-day exploited by ShinyHunters across 100+ organizations* University of Nottingham breach — 40GB of student data leaked* Maine breach portal weaponized for fake disclosure misinformation* CISA KEV listing: actively exploited Magento RCE (CVE-2026-45247)* Microsoft record Patch Tuesday: 200 vulnerabilities, 6 zero-days, BitLocker bypassesTop Stories1. Oracle warns of security bug that hackers abused to breach 100+ companies | TechCrunch - https://techcrunch.com/2026/06/11/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/Additional Cybersecurity News – Titles and URLs2. Maine breach portal abused to publish fake data breach disclosures - https://www.bleepingcomputer.com/news/security/maine-breach-portal-abused-to-publish-fake-data-breach-disclosures/3. ShinyHunters Leak 40GB of University of Nottingham Student Data - https://hackread.com/shinyhunters-university-of-nottingham-student-data-leak/4. CISA Lists Actively Exploited Magento RCE — CVE-2026-45247 - https://cipherssecurity.com/cve-2026-45247-magento-mirasvit-rce-cisa-kev/5. Microsoft June Patch Tuesday fixes 6 zero-days and 200 flaws — a record-breaking month - https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/Resources & LinksNone this episodeCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Jun 14
32 min

Hosts* Professor CyberRisk*Cyber CowboyCyber Maps* Bitdefender Threat Map: https://threatmap.bitdefender.com/* Checkpoint Threat Map: https://threatmap.checkpoint.com/* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam---## EPISODE TITLEFBI FLASH Alert: Ransomware Gang Sending Fake IT Workers Into Law FirmsEpisode Number: 351---## EPISODE DESCRIPTIONThe Silent Ransom Group just crossed from cyber into the physical world — and the FBI's highest-urgency FLASH alert is their warning. Russia-linked extortion operatives are walking into law firm offices disguised as IT support, plugging in USB drives, and stealing data when remote social engineering fails. We break down the full attack chain, the 100+ firms hit so far, and why Jones Day (yes, Trump's lawyers) is on their leak site.Plus this week: A Cisco SD-WAN zero-day with NO PATCH that gives attackers root across your entire network fabric. An AI-discovered "HTTP/2 Bomb" that can take down any major web server in seconds — found by OpenAI's own Codex. Google and YouTube ads silently delivering a macOS backdoor that passed Apple notarization. And how Grafana Labs got hit by the same npm supply chain attack that compromised OpenAI and Mistral.Links to all stories below. Subscribe for weekly threat intelligence breakdowns.----## STORY LINKS**Silent Ransom Group FBI Alert:** https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/**Cisco SD-WAN 0-Day (CVE-2026-20245):** https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/**HTTP/2 Bomb (CVE-2026-49975):** https://cybersecuritynews.com/http-2-bomb-remote-dos-exploit/**Operation FlutterBridge:** https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/**Grafana Labs Supply Chain Breach:** https://thehackernews.com/2026/05/grafana-github-breach-exposes-source.htmlCall to Action* Subscribe: Stay updated on cybersecurity threats.* Leave a Review: Let us know what you think.* Join the Conversation: Follow our community and ask questions.Sponsor (if applicable)No sponsors this episodePodcast Socials & Website* Website: https://www.youvealreadybeenhacked.com* X: @professorcyberrisk* YouTube: https://www.youtube.com/@YABHPodcast* Discord/Community Forum: https://discord.gg/cz3xdsrqAE
Jun 7
37 min
Load more
