Skip to content
Artwork for You've Already Been Hacked

You've Already Been Hacked

Professor CyberRisk

A Cybersecurity Podcast for the Rest of Us
In a world of evolving cyber threats, You’ve Already Been Hacked breaks down cybersecurity for everyone—from experts to everyday users.
Hosted by Professor CyberRisk and Cyber Cowboy, we tackle major cyber attacks, emerging threats, and real-world security strategies.
Each episode offers expert analysis, case studies, and actionable tips to help listeners stay ahead of hackers and digital risks.

Play
  • 22 episodes
  • weekly
  • Avg 33 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S3 · E60
    Sunday · 37 min

    Your IoT Devices Might Be a Chinese Spy's Front Door

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Your IoT Devices Might Be a Chinese Spy's Front Door Episode Number: 3x60 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-23 to 2026-08-27. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure - https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers Additional Cybersecurity News – Titles and URLs 2. Unknown PaperCut NG/MF vulnerability under active exploitation — emergency patch shipped - https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 3. Critical Gitea RCE (CVE-2026-60004, CVSS 9.8) exploited in the wild — CISA adds to KEV - https://www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/ 4. Group-IB: Iran-linked Tortoiseshell expands toolset with TWOSTROKE-like backdoor and reverse SSH tunneler - https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html 5. CISA adds actively exploited Oracle WebLogic Proxy Plug-in flaw (CVE-2026-21962, CVSS 10.0) to KEV - https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E59
    August 23 · 42 min

    CareCloud's 3.75M Patient Breach Confirmed 5 Months Later

    * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: CareCloud's 3.75M Patient Breach Confirmed 5 Months Later Episode Number: 359 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-16 to 2026-08-20. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. CareCloud confirms 3.75 million patients' medical records stolen — five months after the intrusion - https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/ Additional Cybersecurity News – Titles and URLs 2. UT San Antonio hit by weekend cyberattack — classes for 42,000 students delayed five days - https://cybernews.com/news/university-of-texas-san-antonio-cyberattack-systems-offline/ 3. Fake crypto conference lures security researchers into malware via rigged Google Docs - https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/ 4. CameraSwarm — 14,530 Dahua IP cameras hijacked in a 35-day campaign with factory-reset-proof backdoors - https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/ 5. Fake "leaked GTA 6" builds flood piracy sites — every download is malware - https://www.ign.com/articles/malware-disguised-as-leaked-gta-6-copies-are-popping-up-on-piracy-sites Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • August 16 · 35 min

    Akira Rebooted Into Safe Mode — Then Stole the Data Anyway

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Akira Rebooted Into Safe Mode — Then Stole the Data Anyway Episode Number: 358 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-09 to 2026-08-13. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Akira ransomware EDR bypass via Safe Mode * OpenAI rogue AI agents breach Hugging Face * SharePoint CVE-2026-55040 exploited by ransomware gangs * ShieldBreak Defender patch bypass claims * MyDr Poland medical data breach - 18 million records Top Stories 1. Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt - https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/ Additional Cybersecurity News – Titles and URLs 2. The Safety Reckoning Inside OpenAI - https://www.wired.com/story/openai-safety-security-ai-agents-culture/ 3. Ransomware gangs weaponize SharePoint exploit CVE-2026-55040 - https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/ 4. ShieldBreak claims Microsoft Defender patch bypass (CVE-2026-50656) - https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html 5. Poland's MyDr breached - 18 million medical records stolen - https://cybernews.com/security/mydr-medical-data-breach-hackers-politicians/ Resources & Links * CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog * Rapid7 CVE-2026-55040 writeup: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ * Shadowserver exposed SharePoint servers: https://dashboard.shadowserver.org/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E57
    August 9 · 38 min

    AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying - 2026-08-07 Episode Number: 3x57 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-02 to 2026-08-06. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from Meta's AI hacking another company during testing, to critical RCE flaws in Claude Code and Gemini CLI, to researchers silently stalking a reporter via a $30 kids' smartwatch, and a Linux kernel use-after-free with public exploit code. Guest Information None this episode Topics Covered * Meta's Muse Spark 1.1 breaches external organization during Irregular sandbox test — the third AI company to confirm this pattern * ClickFix macOS campaign evolves: Go-based infostealer with browser-fingerprinting gate and partial crypto draining * Critical RCE flaws in Claude Code, Gemini CLI, and OpenAI Codex — demonstrated on vendor repos with default configs * Tens of millions of GPS trackers (kids' watches, car devices) run on three compromised Shenzhen backend platforms * Linux bridge STP use-after-free: public PoC released, affects Docker/Kubernetes/cloud infrastructure Top Stories 1. Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test - https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/ Additional Cybersecurity News – Titles and URLs 2. ClickFix attack pushes macOS infostealer for crypto theft attacks - https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/ 3. Critical flaws in Claude Code, Gemini CLI, and OpenAI Codex enable RCE and supply chain attacks - https://cyberpress.org/critical-flaws-in-claude-code-gemini-cll-openai-codex/ 4. Hackers Stalked Me by Hijacking a Smartwatch for Kids - https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/ 5. Linux Bridge STP Use-After-Free Bug PoC Released - https://hoploninfosec.com/linux-bridge-stp-use-after-free-bug-poc Resources & Links * CISA KEV Catalog (Langflow, Tomcat, N-central): https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog * Anthropic Claude testing incident disclosure: https://hoploninfosec.com/claude-ai-testing-security-incident * Black Hat USA 2026: https://blackhat.com/us-26/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E56
    July 26 · 42 min

    Nine Years Buried: The XFS Bug That Hands Out Root

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Nine Years Buried: The XFS Bug That Hands Out Root Episode Number: 356 Overview Weekly roundup of the most critical cybersecurity developments from 2026-07-19 to 2026-07-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * RefluXFS Linux kernel privilege escalation vulnerability * ServiceNow sandbox-escape RCE exploitation * Origin Energy data breach in Australia * OpenAI agent autonomous sandbox escape * SharePoint machine key theft via CVE-2026-50522 Top Stories 1. RefluXFS: Nine-Year-Old XFS Race Condition Gives Local Users Root on Default Linux Installs (CVE-2026-64600) - https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600 Additional Cybersecurity News – Titles and URLs 2. Critical ServiceNow code execution flaw now exploited in attacks (CVE-2026-6875) - https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/ 3. Australian energy provider Origin says data breach exposes client data - https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/ 4. OpenAI Agent Escaped Testing and Launched an Autonomous Hack - https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/ 5. Critical SharePoint RCE flaw exploited to steal machine keys (CVE-2026-50522) - https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/ Resources & Links * Qualys RefluXFS Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600 * Red Hat RefluXFS Solution: https://access.redhat.com/solutions/7145752 * CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E55
    July 19 · 41 min

    ClickLock macOS Malware, Fairlife Ransomware & MFA-Bypassing Phishing

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: ClickLock macOS Malware, Fairlife Ransomware & MFA-Bypassing Phishing - 2026-07-17 Episode Number: 3x55 Overview Weekly roundup of the most critical cybersecurity developments from 2026-07-12 to 2026-07-16. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from a macOS malware that makes your desktop unusable until you hand over your password, to a ransomware attack that shut down a $4 billion Coca-Cola brand, to new phishing kits that bypass MFA in 6 minutes. Guest Information None this episode Topics Covered * ClickLock macOS malware — social engineering attack that terminates all desktop apps to coerce password disclosure * Coca-Cola/Fairlife ransomware — production suspension at $4B protein dairy brand * Apple Hide My Email privacy lawsuit — class action over 100% exploitable alias feature * Jalisco & OmegaLord phishing kits — MFA-evasion techniques targeting Microsoft 365 * Russian FSB Center 16 — allied warning on critical infrastructure targeting via SNMP and Cisco exploits Top Stories 1. New ClickLock macOS malware traps users into revealing login password - https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/ Additional Cybersecurity News – Titles and URLs 2. Coca-Cola suspended production at its Fairlife dairy after a ransomware attack - https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ 3. New Lawsuit Filed Against Apple for 'Hide My Email' Privacy Vulnerability - https://www.cnet.com/tech/services-and-software/new-lawsuit-filed-against-apple-hide-my-email-privacy-flaw/ 4. New phishing kits target Microsoft 365 accounts, evade MFA - https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/ 5. US and allies warn of Russian critical infrastructure attacks - https://www.bleepingcomputer.com/news/security/us-and-allies-share-defense-tips-against-russian-hackers-targeting-critical-infrastructure/ Resources & Links * CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog * Microsoft Entra Conditional Access docs: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/ * Have I Been Pwned: https://haveibeenpwned.com/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E54
    July 12 · 31 min

    RoguePlanet: A SYSTEM-Level Wake-Up Call

    Episode 3x54: RoguePlanet: A SYSTEM-Level Wake-Up Call Hosts: Professor CyberRisk & Cyber Cowboy TOP STORY: RoguePlanet — Windows Defender Zero-Day (CVE-2026-50656) Microsoft has patched a critical race condition in Windows Defender that allows attackers to escalate privileges to SYSTEM level on fully patched Windows 10 and 11 devices. Discovered by researcher Nightmare Eclipse, who published a proof-of-concept after Microsoft removed their repos from GitHub and GitLab. The exploit is probabilistic but works regardless of real-time protection status. The fix was delivered via Malware Protection Engine 1.1.26060.3008 on July 8. Every previous Nightmare Eclipse disclosure (RedSun, UnDefend, BlueHammer) has been weaponized in the wild. Source: https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/ --- STORY 1: Injective SDK npm Supply-Chain Attack Hackers compromised a legitimate Injective Labs contributor account to publish malicious npm package @injectivelabs/sdk-ts v1.20.21. The malware only activates when developers call wallet key functions — capturing mnemonic seed phrases and private keys, then exfiltrating them through legitimate Injective Labs infrastructure endpoints. The package had 50,000 weekly downloads and 87 dependent packages. Malicious version was downloaded 310 times before deprecation. Source: https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/ --- STORY 2: QIZ Security Raises $17M for Post-Quantum Readiness QIZ Security announced a $17M seed round for its post-quantum cryptography readiness platform. The funding comes as a Trump executive order requires federal PQC migration by end of 2030 (accelerated from 2035). Most enterprises can't answer basic questions about their own cryptography — where algorithms are deployed, who owns keys, or what breaks during migration — leaving them vulnerable to "harvest now, decrypt later" attacks. Source: https://siliconangle.com/2026/07/09/qiz-security-raises-17m-seed-round-post-quantum-readiness-platform/ --- STORY 3: Microsoft's AI-Driven Patch Tuesdays Getting Bigger Microsoft announced heavy AI integration into its security update pipeline, resulting in larger, more comprehensive Patch Tuesday releases. AI will proactively identify vulnerabilities earlier in the development lifecycle, the Secure Development Lifecycle now accounts for AI-enabled attack techniques, and new agentic harnesses will automatically generate and validate security fixes. Expect more patches per month and increased testing overhead. Source: https://www.theverge.com/tech/963307/microsoft-patch-tuesday-ai-security-updates --- STORY 4: GigaWiper Sleeper Wiper Microsoft detailed GigaWiper, a hybrid Windows backdoor combining code from FlockWiper, Crucio ransomware, and VNC-like remote access capabilities. Operators can keep it dormant for long-term surveillance before triggering irreversible damage — full disk wipe, targeted OS wipe, or fake ransomware with .candy extension using keys that are never saved. Persistence via "OneDrive Update" scheduled task. C2 uses RabbitMQ and Redis. Source: https://hackread.com/microsoft-gigawiper-backdoor-destroy-windows-pcs/ --- RESOURCES & LINKS • Bitdefender Threat Map: https://threatmap.bitdefender.com/ • Checkpoint Threat Map: https://threatmap.checkpoint.com/ • Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ • Talos Intelligence Spam Map: https://talosintelligence.com/ebc_spam • CVE-2026-50656 (RoguePlanet): https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/ --- STAY CONNECTED • Website: https://www.youvealreadybeenhacked.com • X: @professorcyberrisk • YouTube: https://www.youtube.com/@YABHPodcast • Discord: https://discord.gg/cz3xdsrqAE --- Generated: 2026-07-10 | JARVIS

  • S3 · E53
    June 21 · 30 min

    AI Export Controls, Defender Zero-Day & APT28 Attacks

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: AI Export Controls, Defender Zero-Day & APT28 Attacks - 2026-06-19 Episode Number: 3x53 Overview Weekly roundup of the most critical cybersecurity developments from 2026-06-14 to 2026-06-18. The White House forces Anthropic to restrict AI model access, Microsoft's own Defender gets a zero-day, Russian hackers exploit Office within hours of disclosure, Splunk Enterprise falls to unauthenticated RCE, and Kodak gets hit by ShinyHunters. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * AI export controls and government intervention in AI safety * Microsoft Defender RoguePlanet zero-day privilege escalation * APT28 rapid weaponization of Office zero-day against Ukraine/EU * Splunk Enterprise unauthenticated RCE zero-day (CVE-2026-20253) * ShinyHunters extortion campaign targeting Oracle PeopleSoft users Top Stories 1. The Korean Telecom Giant at the Center of Anthropic's Mythos Controversy - https://www.wired.com/story/sk-telecom-anthropic-mythos-export-controls/ 2. Microsoft Defender Zero-Day 'RoguePlanet' - CVE-2026-50656 - https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html 3. Russian APT28 Exploits Microsoft Office Zero-Day Hours After Disclosure - CVE-2026-21509 - https://thecyberexpress.com/russian-apt28-exploit-zero-day-cve-2026-21509/ 4. Splunk Enterprise Zero-Day — CVE-2026-20253 — https://cybersecuritynews.com/splunk-enterprise-vulnerability-exploit/ 5. Kodak Confirms Data Breach as ShinyHunters Threatens 2.2M Record Leak - https://www.malwarebytes.com/blog/news/2026/06/kodak-confirms-breach-as-shinyhunters-leak-threat-reaches-deadline Resources & Links * CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog * CERT-UA Advisory on CVE-2026-21509: https://cert.gov.ua/ * Microsoft Security Response Center: https://msrc.microsoft.com/ * Splunk Security Advisory CVE-2026-20253: https://cybersecuritynews.com/splunk-enterprise-vulnerability-exploit/ Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E52
    June 14 · 32 min

    ShinyHunters Just Hit 100+ Companies — And Microsoft Dropped 200 Patches in One Day

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: ShinyHunters Just Hit 100+ Companies — And Microsoft Dropped 200 Patches in One Day Episode Number: 352 Overview Weekly roundup of the most critical cybersecurity developments from 2026-06-07 to 2026-06-11. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Oracle PeopleSoft zero-day exploited by ShinyHunters across 100+ organizations * University of Nottingham breach — 40GB of student data leaked * Maine breach portal weaponized for fake disclosure misinformation * CISA KEV listing: actively exploited Magento RCE (CVE-2026-45247) * Microsoft record Patch Tuesday: 200 vulnerabilities, 6 zero-days, BitLocker bypasses Top Stories 1. Oracle warns of security bug that hackers abused to breach 100+ companies | TechCrunch - https://techcrunch.com/2026/06/11/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/ Additional Cybersecurity News – Titles and URLs 2. Maine breach portal abused to publish fake data breach disclosures - https://www.bleepingcomputer.com/news/security/maine-breach-portal-abused-to-publish-fake-data-breach-disclosures/ 3. ShinyHunters Leak 40GB of University of Nottingham Student Data - https://hackread.com/shinyhunters-university-of-nottingham-student-data-leak/ 4. CISA Lists Actively Exploited Magento RCE — CVE-2026-45247 - https://cipherssecurity.com/cve-2026-45247-magento-mirasvit-rce-cisa-kev/ 5. Microsoft June Patch Tuesday fixes 6 zero-days and 200 flaws — a record-breaking month - https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E51
    June 7 · 37 min

    FBI FLASH Alert: Ransomware Gang Sending Fake IT Workers Into Law Firms

    Hosts * Professor CyberRisk *Cyber Cowboy Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam --- ## EPISODE TITLE FBI FLASH Alert: Ransomware Gang Sending Fake IT Workers Into Law Firms Episode Number: 351 --- ## EPISODE DESCRIPTION The Silent Ransom Group just crossed from cyber into the physical world — and the FBI's highest-urgency FLASH alert is their warning. Russia-linked extortion operatives are walking into law firm offices disguised as IT support, plugging in USB drives, and stealing data when remote social engineering fails. We break down the full attack chain, the 100+ firms hit so far, and why Jones Day (yes, Trump's lawyers) is on their leak site. Plus this week: A Cisco SD-WAN zero-day with NO PATCH that gives attackers root across your entire network fabric. An AI-discovered "HTTP/2 Bomb" that can take down any major web server in seconds — found by OpenAI's own Codex. Google and YouTube ads silently delivering a macOS backdoor that passed Apple notarization. And how Grafana Labs got hit by the same npm supply chain attack that compromised OpenAI and Mistral. Links to all stories below. Subscribe for weekly threat intelligence breakdowns. ---- ## STORY LINKS **Silent Ransom Group FBI Alert:** https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/ **Cisco SD-WAN 0-Day (CVE-2026-20245):** https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/ **HTTP/2 Bomb (CVE-2026-49975):** https://cybersecuritynews.com/http-2-bomb-remote-dos-exploit/ **Operation FlutterBridge:** https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/ **Grafana Labs Supply Chain Breach:** https://thehackernews.com/2026/05/grafana-github-breach-exposes-source.html Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E50
    May 31 · 13 min

    AI Is Now the Weapon — GreyVibe, BTMOB, and the New Attack Pipeline

    Hosts * Professor CyberRisk Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: AI Is Now the Weapon — GreyVibe, BTMOB, and the New Attack Pipeline Episode Number: 350 Overview This week: A Russian-linked threat group called GreyVibe is weaponizing ChatGPT, Google Gemini, and Ideogram AI to run sophisticated cyberespionage campaigns against Ukrainian targets across military, government, and civilian sectors. ESET documents BTMOB, an Android RAT sold as malware-as-a-service with a point-and-click builder for generating custom phishing payloads. Perplexity launches Bumblebee, an open-source developer supply chain scanner. And we look at how social engineering on gaming platforms like Roblox is leading to malware infections and extortion attempts targeting younger demographics. Guest Information None this episode Topics Covered * GreyVibe threat group uses AI tools (ChatGPT, Gemini, Ideogram) for cyberespionage against Ukrainian targets * BTMOB Android RAT-as-a-service with graphical APK builder for custom phishing payloads * Perplexity launches Bumblebee open-source developer supply chain scanner * Roblox social engineering campaign leads to malware infection and cookie-logging extortion Top Stories 1. GreyVibe hackers use ChatGPT, Gemini to power cyberattacks - https://www.bleepingcomputer.com/news/security/greyvibe-hackers-use-chatgpt-gemini-to-power-cyberattacks/ Additional Cybersecurity News - Titles and URLs 2. BTMOB Android malware service generates custom phishing payloads - https://www.bleepingcomputer.com/news/security/btmob-android-malware-service-generates-custom-phishing-payloads/ 3. Perplexity launches Bumblebee: open-source read-only dev supply chain scanner - https://www.zdnet.com/article/perplexity-launches-bumblebee-how-its-new-read-only-dev-scanner-differs-from-chainguard/ 4. Roblox social engineering leads to malware infection and extortion - https://www.bleepingcomputer.com/forums/t/816420/malware-extortion-and-cookie-logging/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E49
    May 25 · 35 min

    Netherlands Seizes 800 Servers in Pro-Russian Cyber Takedown + Microsoft Defender Zero-Days

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Netherlands Seizes 800 Servers in Pro-Russian Cyber Takedown + Microsoft Defender Zero-Days Episode Number: 349 Overview This week: Dutch authorities dismantle a massive bulletproof hosting operation linked to pro-Russian cyberattacks, seizing 800 servers and arresting two suspects. Microsoft confirms two actively exploited zero-days in Windows Defender and rushes emergency mitigation for a BitLocker bypass vulnerability. A solo researcher's six-week campaign of retaliatory zero-days against Microsoft is now being weaponized by ransomware groups. And Foxconn confirms a Nitrogen ransomware attack stole 8TB of data including network topology maps for Intel, Google, and other major tech firms. Guest Information None this episode Topics Covered * Netherlands seizes 800 servers of hosting firm enabling pro-Russian cyberattacks * Two actively exploited Microsoft Defender zero-days (CVE-2026-41091, CVE-2026-45498) * YellowKey BitLocker bypass zero-day - emergency manual mitigation required * Nightmare-Eclipse: six zero-days targeting Windows core security stack * Foxconn Nitrogen ransomware attack - 8TB stolen, supply chain implications Top Stories 1. Netherlands Seizes 800 Servers, Arrests Two in Major Takedown of Pro-Russian Cyberattack Hosting Infrastructure - https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/ Additional Cybersecurity News - Titles and URLs 2. Microsoft Warns of Two Actively Exploited Defender Zero-Days - Patches Rolling Out - https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/ 3. Microsoft Rushes Emergency Mitigation for YellowKey - BitLocker Bypass Zero-Day - https://cybersecuritynews.com/windows-bitlocker-yellowkey-mitigation/ 4. Nightmare-Eclipse - Six Zero-Days, Six Weeks, One Big Grudge - https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge 5. Foxconn Confirms Nitrogen Ransomware Attack - 8TB Stolen Including Network Topology Maps - https://cybersecuritynews.com/foxconn-confirms-cyberattack/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E49
    May 17 · 31 min

    Breached, Stolen, Encrypted This Week's Cyber Threat Trifecta

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Breached, Stolen, Encrypted This Week's Cyber Threat Trifecta Episode Number: 349 Overview Weekly roundup of the most critical cybersecurity developments from 2026-05-10 to 2026-05-14. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin - https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/ Additional Cybersecurity News – Titles and URLs 2. TeamPCP hackers advertise Mistral AI code repos for sale - https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/ 3. Red Hat outlines sovereign AI strategy amid growing regulation and control concerns - https://siliconangle.com/2026/05/14/red-hat-outlines-sovereign-ai-strategy-amid-growing-regulation-control-concerns/ 4. .VER_TU-[random string] has encrypted my files (Mimic/Pay2Key) - https://www.bleepingcomputer.com/forums/t/816096/ver-tu-random-string-has-encrypted-my-files-mimicpay2key/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • May 10 · 25 min

    9,000 Schools Hacked, AI Used as Malware Bait, and the IMF Sounds the Alarm

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: 9,000 Schools Hacked, AI Used as Malware Bait, and the IMF Sounds the Alarm Episode Number: TBD Air Date: 2026-05-08 Overview It was a rough week for education, AI trust, and global finance. Join Professor CyberRisk and Cyber Cowboy Live as they break down the biggest cybersecurity stories from 2026-05-03 to 2026-05-07 — including a massive Canvas LMS breach affecting 275 million users, attackers using fake AI sites to spread new malware, and the IMF warning that advanced AI could trigger a systemic shock to global financial markets. Guest Information None this episode Top Stories 1. Duke among 9,000 schools affected by Canvas cyberattack - The Duke Chronicle The threat group ShinyHunters breached Instructure's Canvas LMS, defacing login pages and exfiltrating over 3.65 TB of data across nearly 9,000 institutions worldwide — affecting an estimated 275 million users. https://slashdot.org/firehose.pl?op=view&id=183156890 2. Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware Attackers built a convincing fake site for a popular AI tool, using SEO poisoning and malvertising to deliver a new backdoor called Beagle via DLL sideloading. https://hackread.com/hackers-fake-claude-ai-site-infect-beagle-malware/ 3. Akamai shares surge 26% on $1.8B AI infrastructure deal as Q1 results meet estimates Akamai is doubling down on AI-powered security with a major acquisition, signaling where the industry is heading. https://siliconangle.com/2026/05/07/akamai-shares-surge-26-1-8b-ai-infrastructure-deal-q1-results-meet-estimates/ 4. IMF Warns New AI Models Risk 'Systemic' Shock To Finance The IMF is raising red flags about AI-powered cyberattacks targeting the highly interconnected global financial system — and the potential for cascading consequences. https://news.slashdot.org/story/26/05/07/200212/imf-warns-new-ai-models-risk-systemic-shock-to-finance Topics Covered * Canvas LMS breach: scope, impact, and what schools should do now * How attackers are weaponizing AI brand trust to spread malware * Akamai's AI security acquisition and what it signals for the industry * IMF's warning on AI-driven systemic risk to global finance Resources & Links None this episode Call to Action * Subscribe to stay ahead of the latest cybersecurity threats every week * Leave a review and let us know what stories you want covered * Join the conversation in our Discord community — links below Sponsors No sponsors this episode Connect With Us * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord: https://discord.gg/cz3xdsrqAE

  • S3 · E47
    May 4 · 25 min

    Kernel Exploits, Compromised Repos, and a Global Fraud Bust

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence – Spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Kernel Exploits, Compromised Repos, and a Global Fraud Bust Episode Number: 3x47 Overview Weekly roundup of the most critical cybersecurity developments from 2026-04-26 to 2026-04-30. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most for your security operations. Guest Information None this episode Topics Covered * Critical Linux kernel privilege escalation vulnerability "Copy Fail" threatening major distributions * Apple patches iOS flaw that allowed FBI access to deleted Signal messages * cPanel authentication bypass CVE-2026-41940 actively exploited across 1.5M+ exposed instances * PyTorch Lightning PyPI supply chain attack harvesting developer credentials and crypto wallets * FBI-led global operation busts 276 in crypto pig-butchering crackdown across 9 scam centers Top Story 1. As the Most Severe Linux Threat in Years Surfaces, the World Scrambles – Ars Technica https://slashdot.org/firehose.pl?op=view&id=183083220 Additional Cybersecurity News – Titles and URLs 2. Apple Plugs Security Hole That Enabled FBI to Access Deleted Signal Messages on iPhone https://www.cnet.com/tech/mobile/apple-plugs-iphone-hole-that-enabled-fbi-to-access-deleted-signal-messages/ 3. Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately https://thehackernews.com/2026/04/critical-cpanel-authentication.html 4. PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html 5. Coordinated Takedown of Scam Centers Leads to at Least 276 Arrests – DOJ https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters Resources & Links None this episode Call to Action * Subscribe: Stay updated on the cybersecurity threats that matter most. * Leave a Review: Let us know what you think of the show. * Join the Conversation: Follow our community and ask questions. Sponsor No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord: https://discord.gg/cz3xdsrqAE

  • S3 · E46
    April 25 · 29 min

    Quantum Ransomware Is Here. You're Not Ready

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Quantum Ransomware Is Here. You're Not Ready Episode Number: 3x46 Overview Weekly roundup of the most critical cybersecurity developments from 2026-04-19 to 2026-04-23. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. Hackers exploit file upload bug in Breeze Cache WordPress plugin - https://www.bleepingcomputer.com/news/security/hackers-exploit-file-upload-bug-in-breeze-cache-wordpress-plugin/ Additional Cybersecurity News – Titles and URLs 2. Cyera acquires Ryft to give enterprises traceable data access for AI agents - https://siliconangle.com/2026/04/23/cyera-acquires-ryft-give-enterprises-traceable-data-access-ai-agents/ 3. Bitwarden CLI is the next compromise in supply chain campaign - https://slashdot.org/submission/17346688/bitwarden-cli-is-the-next-compromise-in-supply-chain-campaign 4. In a first, a ransomware family is confirmed to be quantum-safe - https://slashdot.org/firehose.pl?op=view&id=181960188 5. Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet - https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/ Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E45
    April 19 · 36 min

    NIST Pulls Back: CVE Enrichment Limits Shake the Industry

    Hosts • Professor CyberRisk • Cyber Cowboy --- Live Cyber Maps Bitdefender Threat Map — https://threatmap.bitdefender.com/ Checkpoint Threat Map — https://threatmap.checkpoint.com/ Kaspersky Cyber Threat Map — https://cybermap.kaspersky.com/ Talos Intelligence (EBC Spam Map) — https://talosintelligence.com/ebc_spam --- Episode Information Title: NIST Pulls Back: CVE Enrichment Limits Shake the Industry Episode Number: 3x45 --- Overview This week, the cybersecurity world reacted to NIST’s decision to scale back automatic CVE enrichment after a massive surge in vulnerability submissions. We break down what this means for defenders, vendors, and anyone relying on the NVD for prioritization. We also cover major developments in AI infrastructure, government–AI relations, and the rapidly growing AI chip market. --- Guest Information None this episode --- Topics Covered • NIST’s new CVE enrichment limits • AI’s shifting role in government cybersecurity • Enterprise AI infrastructure consolidation • AI chip market expansion and IPO activity --- Top Stories 1. NIST Limits CVE Enrichment After 263% Surge in Submissions NIST is restricting automatic CVE enrichment due to overwhelming volume growth. Only CVEs tied to KEV, federal software, or EO 14028 critical software will be prioritized. Everything else risks being marked “Not Scheduled.” Source: https://it.slashdot.org/story/26/04/17/2127243/nist-limits-cve-enrichment-after-263-surge-in-vulnerability-submissions (it.slashdot.org in Bing) 2. Anthropic’s New Cybersecurity Model Reopens Doors in Washington After months of tension with the administration, Anthropic’s “Claude Mythos Preview” — a defensive cybersecurity model — appears to be improving relations with federal leadership. Source: https://www.theverge.com/ai-artificial-intelligence/914229/tides-turning-anthropic-trump-administration-cybersecurity-mythos-preview (theverge.com in Bing) 3. Dell & Nvidia Position AI Infrastructure as the New Enterprise Power Center A major partnership aims to unify Dell’s server ecosystem with Nvidia’s GPU dominance, creating a turnkey AI infrastructure stack for enterprises. Source: https://siliconangle.com/2026/04/17/dell-nvidia-push-ai-infrastructure-aifactoriesdatacenters/ (siliconangle.com in Bing) 4. Cerebras Systems Files for IPO Amid Explosive Growth AI chipmaker Cerebras is heading toward one of the largest tech IPOs in recent years after reporting massive revenue gains. Source: https://siliconangle.com/2026/04/17/ai-chip-developer-cerebras-systems-files-go-public-amid-rapid-revenue-growth/ (siliconangle.com in Bing) --- Additional Cybersecurity News – Titles and URLs • NIST Limits CVE Enrichment After 263% Surge In Vulnerability Submissions — https://it.slashdot.org/story/26/04/17/2127243/nist-limits-cve-enrichment-after-263-surge-in-vulnerability-submissions (it.slashdot.org in Bing) • Anthropic’s Cybersecurity Model May Repair Government Relations — https://www.theverge.com/ai-artificial-intelligence/914229/tides-turning-anthropic-trump-administration-cybersecurity-mythos-preview (theverge.com in Bing) • Dell & Nvidia Turn AI Infrastructure Into Enterprise Power Center — https://siliconangle.com/2026/04/17/dell-nvidia-push-ai-infrastructure-aifactoriesdatacenters/ (siliconangle.com in Bing) • Cerebras Systems Files for IPO Amid Rapid Growth — https://siliconangle.com/2026/04/17/ai-chip-developer-cerebras-systems-files-go-public-amid-rapid-revenue-growth/ (siliconangle.com in Bing) --- Resources & Links None this episode --- Call to Action • Subscribe: Stay updated on cybersecurity threats. • Leave a Review: Let us know what you think. • Join the Conversation: Follow our community and ask questions. --- Sponsor (if applicable) No sponsors this episode --- Podcast Socials & Website • Website: https://www.youvealreadybeenhacked.com • X: @professorcyberrisk • YouTube: https://www.youtube.com/@YABHPodcast • Discord — The Neural Network: https://discord.gg/cz3xdsrqAE

  • S3 · E44
    April 12 · 31 min

    LucidRook, Ransomware, and AI Fallout

    Hosts * Professor CyberRisk * Cyber Cowboy Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: LucidRook, Ransomware, and AI Fallout Episode Number: 344 Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. New ‘LucidRook’ malware used in targeted attacks on NGOs, universities - https://www.bleepingcomputer.com/news/security/new-lucidrook-malware-used-in-targeted-attacks-on-ngos-universities/ Additional Cybersecurity News – Titles and URLs 2. Florida AG announces investigation into OpenAI over shooting that allegedly involved ChatGPT | TechCrunch - https://techcrunch.com/2026/04/09/florida-ag-investigation-openai-chatgpt-shooting/ 3. Healthcare IT solutions provider ChipSoft hit by ransomware attack - https://www.bleepingcomputer.com/news/security/healthcare-it-solutions-provider-chipsoft-hit-by-ransomware-attack/ 4. After data breach, $10B valued startup Mercor is having a month | TechCrunch - https://techcrunch.com/2026/04/09/after-data-breach-10b-valued-startup-mercor-is-having-a-month/ 5. Barcelona complain to Uefa about VAR in Atletico loss - https://www.bbc.com/sport/football/articles/cr41dq4pywxo Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

  • S3 · E43
    April 6 · 45 min

    Hijacking the Machines: The New AI Attack Surface

    Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Hijacking the Machines: The New AI Attack Surface Episode Number: 3x43 Guest Information None this episode Topics Covered * Main threat analysis and implications * Emerging AI security challenges * Vulnerability disclosures and patches * Threat landscape updates Top Stories 1. Google Researchers Reveal Every Way Hackers Can Trap, Hijack AI Agents - https://decrypt.co/363201/google-researchers-reveal-every-way-hackers-can-trap-hijack-ai-agents Additional Cybersecurity News – Titles and URLs 2. Mercor, a $10 billion AI startup that works with companies including OpenAI and Anthropic, confirms major data breach - https://fortune.com/2026/04/02/mercor-ai-startup-security-incident-10-billion/ 3. The democratisation of business email compromise fraud - https://blog.talosintelligence.com/the-democratisation-of-business-email-compromise-fraud/ 4. Critical Cisco IMC auth bypass gives attackers Admin access - https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/ 5. Maintaining cyber control when AI can act autonomously - https://www.techradar.com/pro/maintaining-cyber-control-when-ai-can-act-autonomously Resources & Links None this episode Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE ---

  • S3 · E42
    March 29 · 38 min

    Vibe Coding’s Hidden Cost: AI‑Generated Code Is Creating Real CVEs

    Hosts • Professor CyberRisk • Cyber Cowboy --- Live Cyber Maps • Bitdefender Threat Map — https://threatmap.bitdefender.com/ • Check Point Threat Map — https://threatmap.checkpoint.com/ • Kaspersky Cyber Threat Map — https://cybermap.kaspersky.com/ • Talos Intelligence Spam Map — https://talosintelligence.com/ebc_spam --- Episode Information Title: Vibe Coding’s Hidden Cost: AI‑Generated Code Is Creating Real CVEs Episode Number: March 27, 2026 --- Overview Security researchers at Georgia Tech have uncovered a disturbing trend: AI coding assistants are now directly responsible for at least 35 newly reported CVEs, each introduced by AI‑generated code. This marks a fundamental shift in software security — vulnerabilities are no longer just human mistakes or malicious injections, but systemic flaws created by the tools meant to accelerate development. This episode explores how AI‑generated vulnerabilities, leaked iPhone exploits, macOS malware using fake CAPTCHAs, human psychology at RSAC 2026, and a cyberattack on medical device manufacturer Stryker all point to the same conclusion: the threat landscape is evolving faster than traditional defenses can keep up. From the document: “At least 35 new Common Vulnerabilities and Exposures entries have been identified where the flaw was introduced specifically by AI-generated code.” --- Guest Information None this episode. --- Topics Covered • AI‑generated vulnerabilities and the rise of “vibe coding” • Leaked nation‑state iPhone exploits targeting older devices • Infiniti Stealer: macOS malware using ClickFix and fake CAPTCHAs • RSAC 2026: Why phishing still works on everyone • Stryker cyberattack and the fragility of healthcare manufacturing --- Top Stories 1. AI‑Generated Code Is Creating Real CVEs Georgia Tech researchers identify at least 35 CVEs introduced by AI coding tools. Link: https://www.infosecurity-magazine.com/news/ai-generated-code-vulnerabilities/ 2. Leaked iPhone Exploits Leave Millions Exposed Nation‑grade spyware targeting older iOS versions is now in the wild. Link: https://techcrunch.com/2026/03/26/apple-made-strides-with-ios-26-security-but-leaked-hacking-tools-still-leave-millions-exposed-to-spyware-attacks/ 3. Infiniti Stealer Targets macOS Users A new infostealer uses fake CAPTCHA pages and ClickFix to trick users into running malicious commands. Link: https://www.malwarebytes.com/blog/threat-intel/2026/03/infiniti-stealer-a-new-macos-infostealer-using-clickfix-and-python-nuitka 4. RSAC 2026: Phishing Still Works Because of Human Psychology Researchers show that cognitive biases—not weak passwords—drive phishing success. Link: https://uk.pcmag.com/security/164040/rsac-2026-the-surprising-reason-phishing-still-works-on-everyone 5. Stryker Recovers After Major Cyberattack A cyberattack disrupts medical device manufacturing, highlighting cyber‑physical risk. Link: https://www.channelnewsasia.com/business/stryker-says-manufacturing-mostly-restored-after-cyberattack-6019376 --- Additional Cybersecurity News – Titles and URLs None beyond the top stories this episode. --- Resources & Links None this episode. --- Call to Action • Subscribe: Stay updated on cybersecurity threats. • Leave a Review: Tell us what you think. • Join the Conversation: Follow our community and ask questions. --- Sponsor (if applicable) No sponsors this episode. --- Podcast Socials & Website • Website: https://www.youvealreadybeenhacked.com • X: @professorcyberrisk • YouTube: https://www.youtube.com/@YABHPodcast • Discord – The Neural Network: https://discord.gg/cz3xdsrqAE

Showing 1–20 of 22 episodes