- A quick disclaimer: The information in this podcast is for informational purposes only and does not constitute legal or professional advice.
- The AI Double-Edged Sword: We discuss how benign-looking GitHub repositories can trick AI coding agents into running malware, and how threat actors are using fake OpenAI organisations to steal corporate data. On the flip side, we look at how AI can be used as a GRC agent to automate compliance tasks.
- Clean GitHub repo tricks AI coding agents
- Cybersecurity firms targeted by fraudulent OpenAI organization invites
- Your First GRC Agent: A Red Teamer’s Walkthrough
- Phishing’s New Playbook: Russian intelligence-linked hackers are now targeting Signal backup keys to access message histories. Plus, how scammers are abusing the Shopify ‘Shop’ app with fake receipts to launch callback phishing attacks.
- FBI: Russian hackers now target Signal backup recovery keys
- Order-tracking app Shop abused to push callback phishing attacks
- Breaches, Supply Chains, and Takedowns: A massive data breach in Japan exposes up to 14.2 million email logins, highlighting third-party risk. We also cover the $3 million supply-chain attack on Polymarket and a positive law enforcement win against a SIM-swapping gang in Poland.
- Data breach exposes up to 14.2 million email logins at six ISPs
- Polymarket customers lose $3 million in supply-chain attack
- Poland busts SIM-swapping gang
- Patch Now Alert: A warning about an actively exploited vulnerability in Cisco Unified Communications Manager that requires immediate attention.
- CISA sets urgent deadline to fix Cisco flaw

AI’s Deceptive Code and Phishing’s New Playbook
by
Tags:
Leave a Reply