- CHAugust 3 · 7 min
UK investments agency breach, CISA water warning, Anthropic rogue threesome
UK's state investments agency suffers data breach CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks Anthropic says its AI hacked real-world companies in three incidents Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.
- CHJuly 31 · 30 min
The Department of Know: Minnesota water hack, LLM finds encryption flaw, human error hit Hugging Face
This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
- CHJuly 31 · 9 min
Analog Devices breach, Copilot AI worm, Teams ransomware vishing
Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead to Chaos ransomware attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
- CHJuly 30 · 8 min
OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
OpenAI agent's escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/ Huge thanks to our sponsor, Pindrop TIME named Pindrop one of the 10 Most Influential Software Companies of 2026. Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended. Don't wait for an incident report. Visit pindrop.com.
- CHJuly 29 · 8 min
Leaky BMCs, Claude finds encryption flaws, Google's new names
Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/ Huge thanks to our sponsor, Pindrop AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report. Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.
- CHJuly 28 · 7 min
Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
- CHJuly 27 · 8 min
Iran infrastructure warning, ChatGPT global outage, self-assembling malware
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.
- CHJuly 24 · 34 min
The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown
This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.
- CHJuly 24 · 8 min
AI agents risk, Upbound Group breach, Dolphin X Stealer
AI Agents become fastest growing exposed attack surface Consumer finance company Upbound Group blames data breach for millions in losses Dolphin X Stealer uses AI profiling to prioritize targets Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
- CHJuly 23 · 8 min
OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp
OpenAI behind Hugging Face hack TrickBot tunnels through DNS Acrobat extension opens WhatsApp Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
- CHJuly 22 · 8 min
Bit2Watt instability, AI models cheat, Chinese LLM ban
Bit2Watt threatens power stability All AI models cheat at cyber evaluations US weighing Chinese LLM ban Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
- CHJuly 21 · 8 min
Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race
Hugging Face fights AI hacks with AI World Cup streamers get a red card WordPress enters a patching race Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
- CHJuly 20 · 8 min
Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents
Dairy company Fairlife suffers cyberattack Microsoft warns of surge in ACR Stealer attacks on customers Abbott Labs investigates two cyber incidents amid extortion claims Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
- CHJuly 17 · 42 min
The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back
"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/ This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
- CHJuly 17 · 8 min
ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login
ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
- CHJuly 16 · 8 min
Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill
Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
- CHJuly 15 · 7 min
CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing
Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran "Context Bombing" flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
- CHJuly 14 · 7 min
Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice
Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
- CHJuly 13 · 8 min
Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning
Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.