Skip to content
Artwork for Cybersecurity Headlines
NewsTech NewsTechnology

Cybersecurity Headlines

CISO Series

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

Play
  • 66 episodes
  • daily
  • Avg 11 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Yesterday · 7 min

    New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage

    Another Microsoft SharePoint flaw now exploited Details and doubts emerge regarding OpenAI hack of Australian Health portal Kiteworks urges customers to stop using platform Get the show notes here: https://cisoseries.com/cybersecurity-news-new-sharepoint-exploit-australian-openai-hack-developments-kiteworks-urges-stoppage/ Huge thanks to our episode sponsor, Intezer Today's tip: pull your low-severity alerts and count how many got opened. That's where attackers hide. Intezer investigates every alert, boring ones included, in under a minute. MGM Resorts' CTO has talked about nation-state threats turning up right there. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines.

  • Friday · 34 min

    The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan

    Read all the stories at CISOSeries.com. This week's Department of Know is hosted by Rich Stroffolino, with guests Dmitriy Sokolovskiy, senior vice president, information security, Semrush, and Christian Frösch, CISO, CH Media. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Big thanks to our sponsor, Nudge Security. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who created it, what it's connected to, and risks like destructive permissions. And, smart automation helps you engage the right person to fix the risk.

  • Friday · 7 min

    OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited

    OpenAI program hacks Australia's government health portal Astrana Health suffers data breach Ransomware gangs exploiting TeamCity flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-september-25-2026/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries

  • Thursday · 7 min

    ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon's cyber appetite grows

    ShinyHunters peeks at FBI assignments WordPress flaw wastes no time Pentagon's cyber appetite grows Get the show notes here: https://cisoseries.com/cybersecurity-news-september-24-2026/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries

  • Wednesday · 6 min

    CAIRN framework, Muse zero-day, BigDiskBuster

    Cisco releases open-source CAIRN framework Muse zero-day opens the door to account takeovers Microsoft can't wake up from Nightmare Eclipse Get the show notes here: https://cisoseries.com/cybersecurity-news-cairn-framework-muse-zero-day-bigdiskbuster/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries

  • September 22 · 7 min

    ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware

    ShinyHunters hijacks Clop's own leak site Fake LastPass installers kill security tools Trusted npm release carries GHAPPIER malware Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries Get the show notes here: https://cisoseries.com/cybersecurity-news-september-22-2026/

  • September 21 · 8 min

    OpenAI Codex sandbox escape, President proposes AI Force, Cyber Command suicides

    Researchers escape OpenAI Codex sandbox to run commands on host AI Force proposed to monitor technology Congress eyes new support for Cyber Command after recent suicide deaths Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-codex-sandbox-escape-president-proposes-ai-force-cyber-command-suicides/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries

  • September 18 · 34 min

    The Department of Know: Passkeys phished, Cisco hits root, nuclear red lines for AI

    Read the full stories at CISOSeries.com. This week's Department of Know is hosted by Sarah Lane, with guests Jason Thomas, senior director of technology security, governance, and risk at the Cystic Fibrosis Foundation, and Jay Wilson, CISO and CIO at Insurity. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Big thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 18 · 7 min

    Nuclear-style AI safeguards, AI legislation shelved, CISA's decoy guidance

    Nuclear-style safeguards proposed for AI risks Key lawmaker suggests action on AI safety legislation will wait until 2027 CISA releases cyber decoy guidance for infrastructure defenses Get the show notes here: https://cisoseries.com/cybersecurity-news-september-18-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 17 · 6 min

    Flock gets plucked, OpenAI agents arrived even earlier, inside China's AI spy shop

    Flock gets plucked OpenAI agents arrived early China's AI spy shop Get the show notes here: https://cisoseries.com/cybersecurity-news-september-17-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 16 · 7 min

    Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+

    Cisco zero-day goes straight to root BambooToken branches into Linux CenterPoint breach claim hits 7M+ Get the show notes here: https://cisoseries.com/cybersecurity-news-september-16-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation are ramping up, and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 15 · 9 min

    China hits fast-forward on AI security, Hacking Cat shows its claws, Vite servers spill cloud secrets

    China hits fast-forward on AI security Hacking Cat shows its claws Vite servers spill cloud secrets Get the show notes here: https://cisoseries.com/cybersecurity-news-september-15-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation are ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 14 · 7 min

    Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole

    Attackers use passkey phishing to hijack Microsoft cloud accounts Anthropic blockbuster report reveals sophisticated hacks Airlines compliance with new cybersecurity regulations means fewer passenger conveniences Get the show notes here: https://cisoseries.com/cybersecurity-news-september-14-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • September 11 · 33 min

    The Department of Know: Liquid drained, CISA urges change, agentic whistleblowers

    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Alexandra Landegger, global head of cyber strategy & transformation, RTX, Mark Eggleston, CISO-at-large. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Big thanks to our sponsor, ThreatLocker This week, we looked at how AI is making attacks faster, less predictable, and easier to execute. But an AI-generated attack still needs permission to run, access data, use trusted applications, and move through the environment. ThreatLocker helps organizations control those actions before they become incidents. Book a demo at threatlocker.com/ciso.

  • September 11 · 7 min

    NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malware

    Critical NetScaler vulnerability exploited in attacks AdaptHealth data breach impacts 4.1 million people MantaxOtax Android malware delivers ransomware and spyware together Get the show notes here: https://cisoseries.com/cybersecurity-news-netscaler-vulnerability-exploited-adapthealth-suffers-breach-new-android-malware/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

  • September 10 · 7 min

    Fortinet auth holes, China distills AI, Mythos vulnerability

    Fortinet plugs two critical auth holes US says China is distilling AI at scale Mythos vulnerability hits human bottleneck Get the show notes here: https://cisoseries.com/cybersecurity-news-september-10-2026/ Huge thanks to our episode sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

  • September 9 · 7 min

    Florida DMV breach, zero-click WeChat worm, AI whistleblowers

    ShinyHunters claimed it breached Florida DMV Zero-click WeChat worm spreads over incoming calls AI cheaters and whistleblowers emerge Get the show notes here: https://cisoseries.com/cybersecurity-news-florida-dmv-breach-zero-click-wechat-worm-ai-whistleblowers/ Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

  • September 8 · 8 min

    PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA

    PEEP turns browsers into backdoors Liquid loses $320M, hackers play hero BigBear claws past MFA Get the full show notes here: https://cisoseries.com/cybersecurity-news-september-8-2026/ Huge thanks to our episode sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

  • September 7 · 7 min

    MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge

    MikroTik routers hijacked through internet-exposed SSH Russian data centers face new security requirements UK account-hack losses surge thanks to new reporting system Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

  • September 4 · 34 min

    The Department of Know: Astra launches, CISA cuts programs, McKesson breached

    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

Showing 1–20 of 66 episodes