Épisodes

  • Episode 176: September 24, 2026
    Sep 24 2026
    This episode digs into the hidden risks lurking in everyday dev tools, AI-powered malware that votes on its next move, and a massive cyberattack where hackers weaponized AI agents to hit a hundred companies at once. Adrian North walks through GitLab's accidental credential leak, malware with a committee structure, and why your security team might not be fast enough anymore. Stories covered: - A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You (The Hacker News) - https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html - This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move (The Hacker News) - https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html - Chinese hacker deployed Anthropic and Deepseek and Moonshot AI agents in massive 100-company cyberattack - oodaloop.com (oodaloop.com) - https://news.google.com/rss/articles/CBMi1gFBVV95cUxQNTZZYno2YXpVQjNEeFJlM3FDMDdiRlkzMjZYZV9hb2V4aWd2WGRPeERnUmwwdFRpNlRMWXNQdUhPSkVKNWdHSFJMel9MR3hrX3I5NmU5TnpGSXNOZGxtMElSNTlYMW13WHlwZlVZTl9mbTMwa3paNWtOSE1yOGVJUTB2R0tETzcweU9EcXhmcXg5bm5EOWlJdzM2V19oWGkwNU9HT2VsWVEza09fT3JXbnNfaGQta0tLMGFPMzQ3RnFaMlZHeG8ybWdudThNWi1jQ3Y5dHdR?oc=5 - This 13-Year-Old from Ecuador is Mountain Running’s Rising Star (Trail Runner Mag) - https://www.trailrunnermag.com/people/pema-franchi-is-a-wunderkind-mountain-runner/ - FBI investigating hacking group’s claim of massive breach of agent info - NBC News (NBC News) - https://news.google.com/rss/articles/CBMiswFBVV95cUxQa1E1aVFGdEZMdFVFcjdwRWFvcEFsQ3ZaQjdvcEx5QmdRZlBmYWpDdmptZ3JNUElxSkk5aldBODBWbnpJWlIzTm5wV2FySzc0eGxrTmFoNW5CZDd1S0lneFRjMlNVdVRqYXRoMHRSSTZGQ2x1RGNLMHlOWENyQ0xGbl9sV3NpcU02bWc5VFBmOEpESmo1dVZILV96MXNPb2NJTVFQWGFPZ2U5RVdOUDk4RVR6OA?oc=5 - Check Point warns of hackers exploiting Security Gateway VPN RCE flaw (BleepingComputer) - https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
    Afficher plus Afficher moins
    6 min
  • Episode 175: September 23, 2026
    Sep 23 2026
    This episode digs into a claimed FBI breach by ShinyHunters using an Oracle zero-day, Microsoft's takedown of an AI-powered phishing service that bypassed multi-factor authentication, and a new zero-day proof of concept that stops Defender from updating by filling disk space. We also hit a surprisingly relevant marathon recovery guide that showed up in the security feed — because sometimes rest days matter in this field too. Stories covered: - ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach (BleepingComputer) - https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/ - Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises (The Hacker News) - https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html - Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates (The Hacker News) - https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html - This 4-Week Reverse Taper Plan Helps You Ease Back Into Running After a Marathon (Runner's World) - https://www.runnersworld.com/training/a73622064/marathon-recovery-reverse-taper-plan/ - Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data (TechCrunch) - https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/ - GPT-6 Sol and Luna (Hacker News) - https://openai.com/index/introducing-gpt-6-sol-and-luna/
    Afficher plus Afficher moins
    5 min
  • Episode 174: September 22, 2026
    Sep 22 2026
    This episode covers three critical cybersecurity threats hitting right now—Linux kernel exploits actively in the wild, a WordPress vulnerability that's already public, and a confirmed breach at OpenAI. Adrian North breaks down what's at stake when the infrastructure powering the internet gets compromised, plus a quick detour into protecting what matters most in marathon training. Stories covered: - CISA alerts of active exploitation of three Linux kernel flaws (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/ - WordPress Click2Shell flaw lets hackers execute PHP on the server (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ - Hackers breached OpenAI, adding to fever pitch of security and safety concerns - NBC News (NBC News) - https://news.google.com/rss/articles/CBMiekFVX3lxTE1GR215MXpFWG9NeE9FWEZrNm9wRE1MaXJHdGZrMUQ0NEtUQ1dxb3pKWWtCN25MbURsc0tlN1ItT0FBSk9uaU5mZWx2cGJZLTFNTHRIdGc2bHljUW9GaUJtaGNUWEM5VnJtTHpXTFRPa1BEVnBYeHhxS2x3?oc=5 - Busy Runners Keep Missing Key Workouts. Use This Training Strategy to Keep Your Marathon Progress on Track. (Runner's World) - https://www.runnersworld.com/training/a73741058/marathon-training-busy-runners/ - Ryan Sullivan and Hannah Allgood Break the Run Rabbit Run Course Records (Marathon Handbook) - https://marathonhandbook.com/run-rabbit-run-100-mile-2026-results/ - NASA’s Mars Sample Return mission is dead (Hacker News) - https://www.science.org/content/article/nasa-s-mars-sample-return-mission-dead
    Afficher plus Afficher moins
    5 min
  • Episode 173: September 21, 2026
    Sep 21 2026
    This episode covers an unusual FCC ban on foreign-made routers, a sneaky new supply chain attack hiding in npm packages, and a major Gyazo data breach affecting millions of users. Adrian also digs into how a Google analyst went undercover to infiltrate a notorious hacking gang. It's your morning signal check before the day gets loud. Stories covered: - What You Need to Know About the Foreign-Made Router Ban in the US (Wired) - https://www.wired.com/story/us-government-foreign-made-router-ban-explained/ - Malicious npm packages evade install-script defenses at runtime (BleepingComputer) - https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/ - Gyazo server flaw exploited to steal 23.6 million user records (BleepingComputer) - https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ - An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang - wired.com (wired.com) - https://news.google.com/rss/articles/CBMiqwFBVV95cUxOYnZtZmk4cDZFRm4xS0E4cS1rVUVWX2ZBZUZ0WkYtcXVrYnd1NWtGaG1BLVdsZThaa3c2cEx6LWFvZ2g2WEFkdFRGVGVHbkc2MmtLMmNRcWxqRUs2aHB0dlU5SGpESmMzSDAwcGp2NDlGUG9iUDZhVThOOVpfb3FZR0J5aXRPcjRRQWVIYTRQUzhMeVl6OVY0U3BhRWlhd0xEYWtzRG52bnNqTzQ?oc=5 - Research Shows Runners Have Stronger Brain Connectivity. But Does It Mean That Running Makes You Smarter—or That Smart People Run? (Runner's World) - https://www.runnersworld.com/training/a73747426/running-intelligence-research/ - Run Rabbit Run Will Pay Its 100 Mile Champions $100,000 Each in 2027 and 2028 (Marathon Handbook) - https://marathonhandbook.com/run-rabbit-run-100000-champion-prize/
    Afficher plus Afficher moins
    6 min
  • Episode 172: September 20, 2026
    Sep 20 2026
    This episode covers AI-powered hacking, a massive image-sharing breach, and the implosion of the PlayStation 5 jailbreak community. Adrian digs into how Claude helped researchers exploit OpenAI, the Gyazo leak exposing 23 million users, and why a prominent PS5 hacker just walked away from the scene. It's Sunday morning signals you need to know before the world wakes up. Stories covered: - Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws (The Hacker News) - https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html - Gyazo server flaw exploited to steal 23.6 million user records (BleepingComputer) - https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ - Drama Around A PS5 Exploit, AI-Coding, Linux, And GTA 6 Has One Popular Hacker Calling It Quits - Kotaku (Kotaku) - https://news.google.com/rss/articles/CBMizwFBVV95cUxNSnh5cHhDR0hXQjFTV004Z25xcHY0VHhJRDl6eDdfZ3lqRnIwRlR0WWV0NmJlMWc0blVUNG8tcVJBRGUzcGNXSlA3V1NXSFhLYWtKV0sybUFYNUVHS1FCYjlKSWxMY0ZiSGVzcjFhR1BIazg1YktHUDdCYkEtZTNROWVpOFFMZUJrZG9udU55VDg2ci1ndkhKXzdxQUgwbTNrUFpxdHc5RXRrT3RkLUVJRXRiMUtBbXAya2d0VWlnU3JGTGFiVjhXVXJEWUxfaDA?oc=5 - Research Shows Runners Have Stronger Brain Connectivity. But Does It Mean That Running Makes You Smarter—or That Smart People Run? (Runner's World) - https://www.runnersworld.com/training/a73747426/running-intelligence-research/ - OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web (The Verge) - https://www.theverge.com/ai-artificial-intelligence/997633/openai-microsoft-chatgpt-ai-new-york-times-doom-loop-theft-google-zero - A Climber and His Rescuer Share Takeaways After Getting Benighted on Pingora Peak (Climbing Magazine) - https://www.climbing.com/news/a-climber-and-his-rescuer-share-takeaways-after-getting-benighted-on-pingora-peak/
    Afficher plus Afficher moins
    7 min
  • Episode 171: September 19, 2026
    Sep 19 2026
    This episode covers fresh exploits targeting Linux kernel vulnerabilities, a brazen breach of OpenAI using Claude-powered tools, and a critical flaw in AI coding assistants called Plugin4Shell. We also dig into Gyazo's massive data breach affecting over 23 million users. It's your Saturday morning security roundup before the world wakes up. Stories covered: - Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root (The Hacker News) - https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html - Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack - Yahoo Tech (Yahoo Tech) - https://news.google.com/rss/articles/CBMimwFBVV95cUxPNnZFYmhYbjEzblc4V0Q0QVM5YXhxaUFzc1I4LXAxQmFSMmtqYW1lYTNUd3dqNG9JVHRfTnNGSWNid3g5RHp4VlFLX1I5MnFLdjVQcGJoTE5UZ1RrZ0ZYTEQtZGJHTnlTWGVIU3dLNS1mbEd2cFUxcE5NREtNNV9oa3ZKTHBLOUQ2U1BRaDdoa0xXYnZlbU03LWliQQ?oc=5 - Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents (The Hacker News) - https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html - Gyazo server flaw exploited to steal 23.6 million user records (BleepingComputer) - https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ - This Zone 2 Playlist Will Keep Your Runs Relaxed, Your Pace Steady, and Your Miles Aerobic (Runner's World) - https://www.runnersworld.com/runners-stories/a73599341/running-playlist-zone-2/ - Hackers rip down Flock camera, steal its data, share findings with media - The Hill (The Hill) - https://news.google.com/rss/articles/CBMijgFBVV95cUxPX0tRUE1oTGdsSXFmNENpRmpuME5fclgzYWtTWXROQThaNFhtbWh0dFAzUU8xSlM4a3ZYUDlrNjRXOXp4MDZjZ3NzUXRSbWpQbFRiMld1aXRSSDhHWUNlR0RSNGZRN3lnQk42NGZTQkdmNlEzUjdSc0J0MFlFS1BxNVc5T2FOQnRfcXZPYWFB0gGTAUFVX3lxTE5MdXhvaHI2VWx3dW1LMGs4LWJTTlpyUXFFQVFRQ3R3aVVWbTYydDUtS3pQdThEdUxQWTJkUUNWMW5rdDU2Y1hjY1BycUJwVlduLXhMRHNCY1Z0Qzd0RjZJeHJBelI2OWZOQW9kN1JEQV9abE9VQU5jZWpBMUdwNTFGZEtLU1RvSUlJQWpyMzNCTTFSWQ?oc=5
    Afficher plus Afficher moins
    6 min
  • Episode 170: September 18, 2026
    Sep 18 2026
    This episode covers six critical signals from the cybersecurity landscape, including emergency patches for exploited Cisco vulnerabilities, Iranian state malware targeting dissidents, and a devastating Check Point management flaw that grants attackers root access. Adrian also explores what endurance athletes and stolen surveillance software can teach us about resilience and transparency in an always-on digital world. Stories covered: - Cisco warns of max severity ISE zero-day exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/ - Iranian hackers use CHOSEN BRICK Windows malware to spy on targets (BleepingComputer) - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/ - Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root - thehackernews.com (thehackernews.com) - https://news.google.com/rss/articles/CBMigwFBVV95cUxQTE1ZRkpCdUNMYVVmOS0xRlR5ekQ0UldMdVhocGRhTzd3SXdoMW45TWZ4dmlsVVM3TnktSEYtM2xJbU1Ha193N0ZJbEsybnFGWTVTQmxXTko5OS1tX1l4d1pza0J4VlNWaEJwR1V4dGdjSkozc1JNMTRDSmYzdGtZM2hvRQ?oc=5 - 2026 Tor des Géants Results: Katharina Hartmuth and Jia-Ju Zhao Shatter Course Records (iRunFar) - https://www.irunfar.com/2026-tor-des-geants-results - Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People - 404media.co (404media.co) - https://news.google.com/rss/articles/CBMisgFBVV95cUxQRVR3OFBWVmdTUW45cGRLSG5URGc5eEk1T2xvWXoxZUxXb2lGUF9ZYy10cUtwR0c2M2gzamRFNjVDcl9QZVZKNFk3LThXcjVzdGFpMy10Nlp0RHU1QlA4NWxoWm0zaVpTQVBxeVVsMGVYcVBEWWVmTjVMdWdFRENqaUhyVFIyWFBpenFPOEF3VHFteGJUekJpM19JelZiTTdXZWZXNU12bTltc2ZJeXVObVhR?oc=5 - Bend – A language that blocks AI mistakes via proof, on CPU and GPU (Hacker News) - https://bend-lang.com/
    Afficher plus Afficher moins
    5 min
  • Episode 169: September 17, 2026
    Sep 17 2026
    This episode covers a major breach at Flock Safety that exposed how their license plate readers track your movements across time and location, a terrifying browser extension exploit that can hijack AI assistants to feed you manipulated answers, and the takedown of people-search giant Radaris. Adrian breaks down three critical privacy stories that show just how deeply surveillance tech has woven itself into everyday life. Stories covered: - Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People - 404 Media (404 Media) - https://news.google.com/rss/articles/CBMisgFBVV95cUxQRVR3OFBWVmdTUW45cGRLSG5URGc5eEk1T2xvWXoxZUxXb2lGUF9ZYy10cUtwR0c2M2gzamRFNjVDcl9QZVZKNFk3LThXcjVzdGFpMy10Nlp0RHU1QlA4NWxoWm0zaVpTQVBxeVVsMGVYcVBEWWVmTjVMdWdFRENqaUhyVFIyWFBpenFPOEF3VHFteGJUekJpM19JelZiTTdXZWZXNU12bTltc2ZJeXVObVhR?oc=5 - One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude (The Hacker News) - https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html - Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) - https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ - The Marathon Training Mistakes That Send New Runners to Physical Therapy—and How to Avoid Them (Runner's World) - https://www.runnersworld.com/training/a73659219/first-marathon-training-mistakes/ - Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) - https://arstechnica.com/gadgets/2026/09/iran-strikes-on-amazon-data-centers-caused-permanent-loss-of-customer-data/ - Iranian hackers use CHOSEN BRICK Windows malware to spy on targets (BleepingComputer) - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
    Afficher plus Afficher moins
    8 min