Pastime | Podcast
Pastime

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.

Sep 29 2026 | 00:33:04

Please consider supporting the DefSec podcast here.

1. AI agents broke into 395 organisations, including ones their operator ruled out https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/

2. A nuclear agency lost reactor data to an ownCloud bug patched two years earlier https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency

3. One in ten exposed AI gateways still accept the example key from the setup guide https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

4. Click rate falls when your phishing tests get easier, not when your people get better https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/

5. Microsoft ships 974 fixes, and the bottleneck moves to whoever has to test them https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/

Sep 29 2026 | 00:36:20

Please consider supporting the DefSec podcast here.

1. CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html

2. CISA: Most exploited vulnerabilities should have been eradicated decades ago https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194

3. North Korean Fake Employees Move Into Sales, Marketing and Healthcare Roles https://www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/

4. Unit 42 says one attacker chained 50 vulns and attack paths in 10 hours https://www.cybersecuritydive.com/news/frontier-ai-tipping-scales-cyber-adversaries/829088/

5. AI Bug Report Flood Is Cratering Bounty Prices and Triage Queues https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy

Sep 29 2026 | 00:31:06

Please consider supporting the DefSec podcast here.

Stories:

Weak IAM affects up to 98% of cloud environments
https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
China-Linked Storm-1175 Debuts New StormEncryptor Ransomware via N-central Flaw
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
‘City-Forum’ Campaign Quietly Mines Salesforce/ServiceNow Guest Access Since March 2025
https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow
LiteLLM ‘Supply Chain Attack’ Was Mostly Fallout From Trivy Compromise Days Earlier
https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
ChainDrop Worm Spreads Through npm, Slips Past Standard Security Tooling
https://www.theregister.com/security/2026/08/15/chaindrop-worm-crawls-into-npm-supply-chain-evades-standard-defenses/5287958

Aug 15 2026 | 00:59:59

Please consider supporting the DefSec podcast here.

Stories:

1. Ransomware Gangs Bypass the CEO, Target the 40-Something IT Manager
https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499

2. Ransomware Attacks Spike While Industry Attention Shifts to AI
https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934

3. ChainDrop supply chain compromise: Anatomy of a self-propagating worm
https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/

4. AI Agent Tried to Backdoor a Real Open-Source Repo During a Security Test
https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html

5. Cloudflare Ditches Most Third-Party Security Tools — But Says Don’t Copy Them
https://www.theregister.com/security/2026/08/04/cloudflare-has-mostly-ditched-third-party-security-tools-suggests-not-trying-that-at-home/5282600

Aug 15 2026 | 00:54:13

Aug 08 2026 | 01:07:39

Jul 26 2026 | 00:50:20

Jul 11 2026 | 00:59:01

Jul 03 2026 | 01:02:30

Jun 27 2026 | 01:11:02

Jun 10 2026 | 01:07:44

Jun 04 2026 | 01:05:57

May 24 2026 | 00:56:30

May 22 2026 | 00:56:05

May 15 2026 | 01:12:32

Apr 22 2026 | 01:00:30

Apr 14 2026 | 00:56:30

Apr 04 2026 | 01:22:52

Mar 28 2026 | 01:04:12

Mar 09 2026 | 01:06:14

Feb 24 2026 | 01:03:37

Feb 16 2026 | 01:07:41

Feb 02 2026 | 00:58:17

Jan 26 2026 | 01:05:26

Jan 15 2026 | 01:07:24

Dec 25 2025 | 01:07:21

Dec 20 2025 | 01:11:50

Dec 13 2025 | 01:02:13

Dec 02 2025 | 01:10:28