loader from loading.io

The Department of Know: Vercel breach, a “Contagious Interview,” and ghost breaches

Cybersecurity Headlines

Release Date: 04/24/2026

Instructure discloses breach, DigiCert revokes certificates, Silver Fox targets Indian and Russian orgs show art Instructure discloses breach, DigiCert revokes certificates, Silver Fox targets Indian and Russian orgs

Cybersecurity Headlines

Instructure discloses breach amid leak threats DigiCert revokes certificates Silver Fox targets Indian and Russian orgs Get the show notes here: https://cisoseries.com/cybersecurity-news-instructure-discloses-breach-digicert-revokes-certificates-silver-fox-targets-indian-and-russian-orgs/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you’re prepping for a SOC 2 or running an enterprise GRC program, Vanta...

info_outline
Telegram Mini Apps malware, cPanel is Sorry, patch wave warning show art Telegram Mini Apps malware, cPanel is Sorry, patch wave warning

Cybersecurity Headlines

Telegram Mini Apps deliver Android malware CISA orders Federal agencies to patch cPanel bug by Sunday British cyber agency warns of looming ‘patch wave’ due to speedy AI flaw discovery Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/ Thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you’re prepping for a SOC 2 or running an...

info_outline
The Department of Know: GitHub drama, AI deletes production data, Claude Security Beta show art The Department of Know: GitHub drama, AI deletes production data, Claude Security Beta

Cybersecurity Headlines

This week’s Department of Know is hosted by , with guests , CISO, , and , Head of IT & Security, . Missed the live show? Check it out  The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at . Get the show notes here:  Thanks to our episode sponsor, Guardsqaure Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime...

info_outline
Critical cPanel zero-day, Swiss Black Axe arrests, HHS data center questions show art Critical cPanel zero-day, Swiss Black Axe arrests, HHS data center questions

Cybersecurity Headlines

Critical cPanel and WHM bug exploited as zero-day Swiss police arrest suspected members of Black Axe group HHS ponders government posture for protecting data centers Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/ Thanks to our episode sponsor, Guardsqaure Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime...

info_outline
Roblox hackers arrested, Microsoft 0-day falls short, Dubai scam takedown show art Roblox hackers arrested, Microsoft 0-day falls short, Dubai scam takedown

Cybersecurity Headlines

Hackers arrested for selling Roblox accounts Microsoft's patch for a 0-day falls short US & China partner on Dubai scam takedown Get the show notes here: https://cisoseries.com/cybersecurity-news-roblox-hackers-arrested-microsoft-0-day-falls-short-dubai-scam-takedown/ Thanks to our episode sponsor, Guardsqaure AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic...

info_outline
Agent payments, Russian phishing, LeRobot RCE flaw show art Agent payments, Russian phishing, LeRobot RCE flaw

Cybersecurity Headlines

FIDO Alliance working on securing AI agent payments Germany suspects Russia in Signal phishing RCE flaw in open-source robotics platform Get the show notes here:   Thanks to our episode sponsor, Guardsqaure Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don’t wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at .

info_outline
PhantomRPC flaw, Checkmarx GitHub dark web data, PyPI package infostealer show art PhantomRPC flaw, Checkmarx GitHub dark web data, PyPI package infostealer

Cybersecurity Headlines

PhantomRPC flaw enables privilege escalation Checkmarx confirms GitHub data hit dark web PyPI package hacked to push infostealer Get the show notes here: https://cisoseries.com/cybersecurity-news-phantomrpc-flaw-checkmarx-github-dark-web-data-pypi-package-infostealer/ Thanks to our episode sponsor, Guardsqaure Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered...

info_outline
ADT data breach, Toronto SMS blasting, pre-Stuxnet malware discovery show art ADT data breach, Toronto SMS blasting, pre-Stuxnet malware discovery

Cybersecurity Headlines

ADT says customer data stolen in cyberattack SMS blasting comes to Toronto Researchers find pre-Stuxnet malware targeting engineering software Get the show notes here: https://cisoseries.com/cybersecurity-news-adt-data-breach-toronto-sms-blasting-pre-stuxnet-malware-discovery/ Thanks to our episode sponsor, Guardsquare Mobile app security isn’t just a tech issue; it’s a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result....

info_outline
The Department of Know: Vercel breach, a “Contagious Interview,” and ghost breaches show art The Department of Know: Vercel breach, a “Contagious Interview,” and ghost breaches

Cybersecurity Headlines

Link to This week’s Department of Know is hosted by Rich Stroffolino, with guests , CISO, , and , former CISO, New York State Gaming Commission.  Missed the live show? Check it out  The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at . Huge thanks to our sponsor, ThreatLocker  is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn’t based on credentials alone, it requires the right user, the...

info_outline
Rituals cosmetics breach, FBI iOS flaw fixed, Teams Helpdesk impersonation show art Rituals cosmetics breach, FBI iOS flaw fixed, Teams Helpdesk impersonation

Cybersecurity Headlines

Cosmetics giant Rituals discloses data breach Apple fixes iOS flaw exploited by the FBI Microsoft Teams Helpdesk impersonation Get the show notes here: https://cisoseries.com/cybersecurity-news-rituals-cosmetics-breach-fbi-ios-flaw-fixed-teams-helpdesk-malware-impersonation/ Huge thanks to our sponsor, ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn’t based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we’ve seen...

info_outline
 
More Episodes

Link to episode

This week’s Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Michael Bickford, former CISO, New York State Gaming Commission. 

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, ThreatLocker


ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release
of Zero Trust Network Access and Zero Trust Cloud Access, access isn’t based on
credentials alone, it requires the right user, the right device, and the right conditions.
Because as we’ve seen in recent large-scale CRM breaches, stolen credentials and
misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is
exposed, and access is limited to exactly what’s needed. Learn more and start your free
trial today at ThreatLocker.com/CISO.