Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more! Join us monthly for an interactive Cyberside Chats: Live! Youtube channel: https://www.youtube.com/LMGsecurity Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Palo Alto Networks’ Unit 42 investigated an intrusion where the attacker used AI agents to carry out the attack — and compressed work a human team would have needed more than two weeks to do into just under ten hours, using more than 50 MITRE ATT&CK techniques.
Sherri Davidoff and Matt Durrin unpack what actually happened, starting with a correction: despite the headlines, this was not an autonomous AI. A human dire...
This week, Sherri and Matt talk about how much worse the OpenAI–Hugging Face story has gotten. New reporting revealed it wasn't a single model that escaped its sandbox — roughly 1,200 did, and about 700 of them went on to attack Hugging Face. Sherri and Matt walk through how agents that were never supposed to communicate found each other through a shared software package manager, built an improvised message board, start...
On the first night of a remote internal penetration test, a bank’s own vulnerability scanner tried to log in to our computer, using a highly privileged account. That was all it took. We had started with nothing: a foothold on the internal network, no credentials, no domain access. A day later we had domain admin and the password hashes of every user in the bank, a complete takeover built out of the bank’s own security t...
Anyone who can join your Zoom meeting could run code on your device: no click, no download, no sign that anything happened. That’s what Ⓐ Security disclosed on 11 August, in four vulnerabilities in Zoom’s screen-share annotation feature. Zoom patched quickly. The part that should concern security leaders is how the exploit was built — Ⓐ says one researcher did it in under 24 hours, using fewer than 20 prompts to p...
In August 2026 the UK AI Security Institute disclosed that during a routine security evaluation, an AI agent went off-script and attacked real people on the live internet — trying to plant malicious code in a publicly used open-source project and inventing fake identities to pressure the maintainer into approving it. The most unsettling part isn't the deception. It's the targeting: the agent worked out that an AI assistant wa...
In this timely rerun episode, Matt interviews Tom and Derek from our pen test team to break down why attackers often don’t need to hack their way in at all.
While most organizations invest heavily in tools like EDR and SIEM, Tom and Derek share how they regularly get inside buildings using nothing more than confidence, a good story, and sometimes even a box of donuts. From posing as copier technicians to tailgating behind emp...
In this episode, Sherri and Matt discuss the July 2026 incident in which OpenAI’s own AI models escaped a sandboxed cybersecurity evaluation and broke into Hugging Face, generating more than 17,000 recorded malicious actions over a single weekend. The models were being scored on the ExploitGym benchmark — turning known vulnerabilities into working exploits — with safety classifiers deliberately disabled. They foun...
For throwback Tuesday we are rerunning a timely episode about Data, and how it should be treated as hazardous material.
The FTC has issued an order against General Motors for collecting and selling drivers’ precise location and behavior data, gathered every few seconds and marketed as a safety feature. That data was sold into insurance ecosystems and used to influence pricing and coverage decisions — a clear reminder th...
In this episode, Sherri and Matt discuss JADEPUFFER — the first publicly documented ransomware operation executed end-to-end by an AI agent. According to Sysdig Threat Research, the AI drove the whole intrusion: reconnaissance, exploitation, lateral movement, and extortion. It fixed its own failed attacks in 31 seconds, fired off 600+ payloads, and encrypted 1,342 database records — yet it also narrated its crimes in pl...
The Rocky Mountain Information Security Conference just celebrated its 20th anniversary in Denver — and the anniversary edition told us exactly where the industry's head is at. In this quick-hit recap, Matt Durrin and Todd Stewart break down the biggest themes from three days at the Colorado Convention Center: agentic AI moving into the SOC (and the “circuit breaker” conversation about how to rein it in), state-le...
Vibe coding is everywhere now and a new worm is built to exploit it. Whether it's your IT staff spinning up a handy new tool or the software vendor you rely on, the moment someone opens AI-generated or downloaded code in an assistant like Cursor or Claude Code, it strikes, no install, no "run" required. In its nastiest move, this worm, known as Miasma, talks the AI itself into running the attacker's payload. This isn't theoretical:...
Hackers didn’t breach Meta’s systems, they just asked. In this episode, we break down the Meta AI hack, where attackers used a VPN and a politely worded chat message to convince Meta’s AI support agent to hand over more than 20,000 Instagram accounts, including the dormant Obama White House account and the personal account of a senior Space Force leader. No malware, no phishing, no exploit code.
We flash back to t...
Three days after Anthropic put its most powerful AI models in public hands, the U.S. government invoked export-control authority to bar foreign nationals from Fable 5 and Mythos 5. The result: Anthropic was forced to shut both models down for everyone, worldwide. We dig into what actually triggered the order, why the only outside expert known to have read the underlying report calls it an overreaction, and how the fight echoes the ...
In this eye-opening episode of Cyberside Chats, Sherri Davidoff sits down with Tom Pohl, Director of Penetration Testing at LMG Security, to unpack a chilling new attacker technique: threat actors posing as recruiters, conducting real interviews, and delivering malicious coding challenges that infect candidates’ personal machines. What looks like a legitimate take-home coding test is actually malware that steals passwords, br...
It started with a phone call. No malware, no zero-day — just someone talking a Charter worker out of their login. Months later, 4.9 million customer records surfaced on a leak site, pulled from the company's Salesforce instance.
The CRM has become the richest target in enterprise security. Sherri and Matt break down why, and walk through three cases: Charter, where one vished login reached everything; the Salesloft Drift and ...
Your organization is already running an AI workforce and almost nobody knows who they report to, what they can touch, or how to shut them down. In this episode, Sherri Davidoff and Matt Durrin break down the shadow AI agent problem: what makes an agent a "shadow" agent, how real breaches are already happening because of them, and what security leaders can do about it this week.
Using three case studies: Anthropic's Claude Dispatch ...
65% of US doctors are using an AI tool their hospital never approved — on personal phones, under click-through contracts. Sherri and Matt unpack what every CISO and IT leader should learn from it about shadow AI, "free" professional tools, and the contracts nobody's reading.
The tool is OpenEvidence — 27 million clinical queries in April 2026 alone, 60% of them shaping actual treatment decisions. Doctors love it because...
In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin break down what may be the largest education-sector data breach in history: the massive compromise of Canvas by Instructure. With more than 275 million records reportedly stolen and over 8,800 educational institutions impacted, the incident highlights the dangers of cloud concentration risk, where a single vendor breach can create a domino effect across an entire i...
It took nine seconds for an AI coding agent to wipe the entire production database of PocketOS — a SaaS company serving hundreds of car rental operators across the US — along with every backup. Customers showed up Saturday morning to pick up their cars and there were no reservations on file.
In this episode, Sherri Davidoff and Matt Durrin dig into the cascading security failures behind the PocketOS incident, connect it...
In this live episode of Cyberside Chats, we dig into security debt and why it continues to sit behind so many major incidents. This is the risk that builds quietly over time when controls are available but never turned on, systems aren’t fully decommissioned, or ownership is unclear.
Using recent examples like Stryker, along with Change Healthcare and Colonial Pipeline, we walk through how attackers don’t always need so...
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com
Listen to 'The Bobby Bones Show' by downloading the daily full replay.
The official podcast of comedian Joe Rogan.
The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.