Cybersecurity Today cover art

Cybersecurity Today

Cybersecurity Today

By: Jim Love
Listen for free

About this listen

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time. Politics & Government
Episodes
  • CISA Leadership Shakeup, OpenClaw Hijack, Robot Vacuums and More
    Mar 2 2026

    OpenClaw AI Agent Hijack, CISA Leadership Shakeup, Iran Cyber Campaign, Air-Gap Malware, and Robot Vacuum Flaw

    Jim Love covers multiple cybersecurity stories: Oasis Security revealed "ClawJacked," a high-severity OpenClaw AI agent framework flaw caused by missing rate limiting on the local gateway, enabling malicious web pages to brute-force passwords via WebSockets, register a trusted device, and take over agents; OpenClaw patched it within 24 hours and users are urged to update to version 2020 6.2 0.25 and tighten governance for non-human identities. CISA sees a leadership change as acting director Madhu Gottumukkala steps down amid criticism and reports he uploaded sensitive contracting documents to public ChatGPT and canceled key security tool contracts; Nick Anderson becomes acting director. The episode also discusses a coordinated cyber campaign alongside US/Israeli operations against Iran and risks of Iranian retaliation against exposed US critical infrastructure, North Korea's Scarcruft using "Ruby Jumper" to bridge air-gapped networks via USB, and a DJI Romo robot vacuum MQTT flaw that exposed control and camera access across 7,000 devices before being patched.

    00:00 Sponsor Message Meter
    00:19 Headlines And Intro
    00:46 Claw Jacked AI Agents
    02:21 CISA Leadership Shakeup
    06:02 Cyber Front In Iran War
    08:48 North Korea Air Gap Breach
    10:06 Robot Vacuum Takeover
    13:04 Wrap Up And Thanks

    Show More Show Less
    14 mins
  • AI Driven Warfare
    Mar 4 2026

    AI-Driven Warfare, Open-Source Attack Tooling, CISA Shakeups, Healthcare Ransomware, and GPS Jamming Risks

    Host David Shipley covers reports that hacked Tehran traffic cameras and an AI-powered targeting system helped a joint U.S.-Israeli operation ("Epic Fury") track and strike Iran's leadership, highlighting the growing role of compromised infrastructure and AI in modern conflict. Researchers also link the open-source toolkit Cyber Strike AI to automated attacks against Fortinet FortiGate devices, compromising over 600 systems across 55 countries and raising concerns about proliferating offensive AI tools. At CISA, CIO Robert Costello resigns amid leadership turmoil and staffing challenges. Healthcare ransomware disruptions include a University of Hawaii Cancer Center breach affecting nearly 1.2 million people and a major attack on the University of Mississippi Medical Center that shut clinics and disrupted Epic EMR access. Finally, GPS/AIS jamming and spoofing in the Middle East threatens shipping safety and global trade.

    Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst

    00:00 Sponsor Message
    00:17 Headlines Overview
    00:48 Epic Fury AI Warfare
    04:12 Cyber Strike AI Toolkit
    07:06 CISA CIO Resignation
    09:06 Hawaii Cancer Center Breach
    11:27 UMMC Ransomware Shutdown
    13:53 GPS Jamming Shipping Risk
    16:33 Wrap Up And Sponsor

    Show More Show Less
    17 mins
  • Cisco SD-WAN Bug Actively Exploited
    Feb 27 2026

    Cisco SD-WAN Bug Actively Exploited, MCP Azure Takeover Demo, CarGurus Data Leak, and Secret Service Scam Recovery

    Host Jim Love covers four cybersecurity stories: CSA warns a critical Cisco Catalyst SD-WAN controller vulnerability (CVE-2026-20127) has been exploited since 2023, enabling authentication bypass and rogue peering sessions, and orders U.S. federal agencies to inventory systems, collect logs and forensic artifacts, hunt for compromise, and apply Cisco's fixes by 5:00 PM ET on February 27, 2026, with no workarounds. At RSA, researchers show how flaws in Model Context Protocol (MCP)—a key integration layer for agentic AI—could lead to remote code execution and even Azure tenant takeover, highlighting rising enterprise risk. ShinyHunters reportedly published 12.4 million stolen CarGurus records, raising phishing and fraud concerns tied to vehicle shopping and financing context. Finally, an Ontario tech support scam victim recovers funds through coordinated work by Ontario Provincial Police and the U.S. Secret Service, which traced and froze the money in time.

    Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst

    LINKS
    Cisco Advisory
    Cisco Security Advisory – CVE-2026-20127
    Authentication bypass vulnerability in Cisco Catalyst SD-WAN
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk

    CISA Supplemental Hunt and Hardening Guidance (Cisco SD-WAN Systems)
    https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems

    Threat Hunt Guide (Technical PDF)
    Cisco SD-WAN Threat Hunt Guide (jointly referenced in federal guidance)
    https://media.defense.gov/2026/Feb/25/2003880299/-1/-1/0/CISCO_SD-WAN_THREAT_HUNT_GUIDE.PDF


    00:00 Sponsor Message
    00:19 Cisco SD-WAN Under Attack
    02:48 MCP Azure Takeover Demo
    05:28 CarGurus Data Dump
    07:16 Secret Service Scam Recovery
    09:24 Closing Sponsor Thanks

    Show More Show Less
    10 mins
No reviews yet