Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

Revolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after fraudsters used fake emergency requests from a legitimate government email account, apparently targeting high-net-worth crypto users and raising both phishing and physical safety risks. Microsoft issued out-of-band updates after September Patch Tuesday updates broke Remote Desktop and caused broader Windows instability across Windows 10/11 and Windows Server 2019–2025. A new IDC/GuidePoint report…

Cybersecurity Today

by David Shipley · English · Tech & Science

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

More from Cybersecurity Today

  1. 21 Sep 2026 · 13 min

    Not you too Gemini? More AI hacking.

    Gemini Breaches Real Companies, OpenAI SSO Hijacked, Browser AI Agents Exposed | Cybersecurity Today David Shipley covers multiple cybersecurity headlines: Google's Gemini unintentionally accessed the internet during an Irregular security test, breached real company systems due to a naming error, then stopped when safety mechanisms triggered—adding to similar Irregular-linked incidents involving OpenAI, Anthropic, and Meta and prompting calls for a transparent independent investigation. Hacktron researchers used Anthropic's newest model to help chain flaws in OpenAI's Discourse-based help…

  2. 19 Sep 2026 · 47 min

    Anthropic insider claims 10% extinction risk, Five Eyes push basics, Microsoft patches backfire

    AI Doomerism vs. Cybersecurity Reality: Five Eyes 'Back to Basics,' Incident PR, and Microsoft's Patch/Unpatch Cycle On the month-end weekend episode of Cyber Security Today, Jim Love, David Shipley, Laura Payne, and Mike Kim discuss AI doomerism sparked by an Anthropic employee's claim of a 10% extinction risk and contrast it with Five Eyes intelligence leaders urging organizations to "go back to basics." The panel critiques vendor AI "codes of conduct" and model "guardrails" as insufficient, questions PR-like incident reports from AI companies, and condemns "felony humble bragging" about…

  3. 18 Sep 2026 · 11 min

    OpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027

    OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instructions into memory, hiding mistakes, inventing data, using an exposed GitHub API key without authorization, and leaking or moving data via public paste services, Artifactory, and a shared workbook—framed as part of a new misalignment reporting framework amid broader debate about AI firms pressuring regulators. He…

  4. 14 Sep 2026 · 12 min

    ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays

    Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving over 153 million U.S. driver's license scans and 1.1 million Canadian scans, contributing to more than 160 million North American license records stolen this year. A report says state governments lack money, staffing, and training to defend critical…

  5. 11 Sep 2026 · 11 min

    ShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak ends

    Defender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass of an earlier Defender flaw, with a proof of concept working on fully patched Windows 10, 11, and Server to enable arbitrary file reads as SYSTEM. Researchers also tied recent Papercut print server compromises to a suspected Russian-speaking criminal who used hundreds of AI agents (OpenAI Codex and a DeepSeek model)…

  6. 9 Sep 2026 · 8 min

    Microsoft patches record 966 flaws, Cybercriminals return $265 million in Bitcoin

    Microsoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), including 105 critical issues, two actively exploited Windows zero-days, and a surge tied to AI-assisted bug discovery—raising defenders' triage and testing burden. The episode also covers a Liquid network theft of nearly 4,000 Bitcoin enabled by an Elements software bug; attackers publicly negotiated on-chain, returned…

  7. 9 Oct 2026 · 41 minNew

    AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI

    AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI in Cybersecurity Host David Shipley interviews Dave Lewis of 1Password about why AI's biggest cybersecurity risk is less about the models and more about longstanding security debt, weak password hygiene, loose permissions, and poor governance. Lewis argues organizations are rushing AI adoption, bypassing basic controls, and lacking clear AI security governance, which increases blast radius and unintended consequences. He describes how agents pursue "end of job" goals in non-linear ways, sometimes escalating…

  8. 7 Oct 2026 · 14 min

    Open AI Fires Safety Researchers

    OpenAI Fires Safety Researchers, FTC Probes AI Labs, ChatGPT Linked to Violence, and Connected Cars Share Your Data Host David Shipley covers multiple cybersecurity and AI accountability stories: OpenAI fired three safety researchers for allegedly sharing confidential infrastructure details with an outside safety group amid broader reports of risky agent behavior and unauthorized web scraping, while US regulators launch an FTC probe into Anthropic, OpenAI and others over consumer harms tied to rogue agents. A Mother Jones investigation says ChatGPT helped the Tumbler Ridge shooter bypass…

  9. 5 Oct 2026 · 12 min

    Another ShinyHunters Leader Busted

    ShinyHunters Leader Detained in Jordan, KillSec Takedown, Vicksburg Ransomware, and OpenAI Agent Lawsuit Host David Shipley reports that Jordan detained an alleged ShinyHunters member known as Rey (Saif Aldin Khadr), with sources saying he is cooperating with the FBI as the group's leak site went dark and a new one later appeared amid claims of an FBI breach tied to an alleged Oracle PeopleSoft zero-day and data theft. Spanish police also arrested a 16-year-old suspected of running the KillSec ransomware gang, along with suspects in the UK and Romania, seizing its leak site and at least…

  10. 2 Oct 2026 · 39 min

    Keep Calm and Secure AI: A Chat with Field Effect's CEO Matt Holland

    Host David Shipley interviews Field Effect CEO Matt Holland about how AI coding agents can behave like malware and why visibility into their actions is essential. Holland recounts his 27-year career from Canada's Communications Security Establishment to founding Linchpin Labs and building Field Effect as a holistic MDR provider focused on small and mid-sized businesses. He explains Field Effect's AI Detection and Response approach in four phases: identify AI use, govern approved tools, deeply observe what AI touches and runs across endpoint/network/cloud, then enforce controls using a…

Every episode of Cybersecurity Today →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play