loader from loading.io

What We’ve Learned from LockBit and Black Basta Leaks (and News) - Ian Gray - PSW #888

Paul's Security Weekly (Audio)

Release Date: 08/21/2025

AI Vulnerability Hunting - PSW #913 show art AI Vulnerability Hunting - PSW #913

Paul's Security Weekly (Audio)

In the security news: Viral AI prompts Things to do in your home security lab I can open your garage door They call me DKnife Beyondtrust RCE Cool AI device Robots need your body Meta is just full of scams, phishing, and malware Claude Opus 4.6 found more than 500 high-severity vulnerabilities Arista next gen firewalls and command injection Secure Boot updates The RCE AMD won't fix and why the article went away End of support means get it off the network Accidentally giving away $44 billion of Bitcoin Visit for all the latest episodes! Show Notes:

info_outline
AI: No One Is Safe - PSW #912 show art AI: No One Is Safe - PSW #912

Paul's Security Weekly (Audio)

In the security news this week: Residential proxy abuse is everywhere this week: from Google’s takedown of IPIDEA to massive Citrix NetScaler scanning and the Badbox 2.0 botnet Supply chain fun time: Notepad++ updates were hijacked Attackers set their sights on: Ivanti EPMM, Dell Unity storage, Fortinet VPNs/firewalls, and ASUSTOR NAS devices Russian state hackers went after Poland’s grid Is ICE on a surveillance shopping spree and into hacking anti-ICE apps? Ukraine’s war-time Starlink problem is turning into a policy and controls experiment The AI security theme is alive and well with...

info_outline
To curmudgeon or not to curmudgeon, that is the question. - PSW #911 show art To curmudgeon or not to curmudgeon, that is the question. - PSW #911

Paul's Security Weekly (Audio)

This week, we get un-curmudgeoned by Mandy, spending a bunch of time talking about regulations, compliance, and even the US federal government's commitment to cybersecurity internally and with the community at large. We even dive into some Microsoft patches, hacking defunct eScooters, and a lively discussion on ADS-B spoofing! Visit for all the latest episodes! Show Notes:

info_outline
We Left It Vulnerable On Purpose - Rob Allen - PSW #910 show art We Left It Vulnerable On Purpose - Rob Allen - PSW #910

Paul's Security Weekly (Audio)

In the security news: Rainbow tables for everyone Lilygo releases a new T-Display that looks awesome AI generated malware for real Detecting BadUSB when its not a dongle A telnetd vulnerability Google Fast Pair and how I took control of your headset Should we make CVE noise? Exploiting the Fortinet patch DIY data diode Bambu NFC reader for your Flipper Payloads in PNG files Don't leave the lab door open - amazing research and new tool release Fixing your breadboards Finding vulnerabilities in AI using AI Then, Rob Allen from ThreatLocker joins us to discuss default allow, and why that is...

info_outline
Digging For Vulnerability Gold - PSW #909 show art Digging For Vulnerability Gold - PSW #909

Paul's Security Weekly (Audio)

In the security news: KVMs are a hacker's dream Hacking an e-scooter Flipper Zero alternatives The best authentication bypass Pwning Claude Code ForiSIEM, vulnerabilities, and exploits Microsoft patches and Secure Boot fun Making Windows great, again? Breaching the Breach Forum Congressional Emails unsolicited Instagram password reset requests - Is Meta doing enough to secure the platform? LLMs are HIPAA compliant? Threat actors target LLM honeypots Visit for all the latest episodes! Show Notes:

info_outline
No FlipperZeros Allowed - PSW #908 show art No FlipperZeros Allowed - PSW #908

Paul's Security Weekly (Audio)

This week in the security news: Supply chain attacks and XSS PS5 leaked keys Claude tips for security pros No Flipper Zeros allowed, or Raspberry PIs for that matter Kimwolf and your local network Linux is good now Removing unremovable apps without root Detecting lag catches infiltrators Defending your KVM Fixing some of the oldest code Deleting websites live on stage in costume It was a honeypot FCC is letting telecoms off easy Don't buy a Haribo power bank Ransomeware scum Fortinet vulns CISA warns about NVRs Patching MongoDB Visit for all the latest episodes! Show Notes:

info_outline
Breaking Into Cybersecurity - PSW #907 show art Breaking Into Cybersecurity - PSW #907

Paul's Security Weekly (Audio)

Our field is booming! Cybersecurity jobs are projected to grow 33 percent through 2033, far outpacing the average 4 percent growth across all jobs. (And yes, those stats could be made up, but they sound nice, eh?) Yet newcomers often feel paralyzed by where to start. The truth? There's no single "right path," but there are proven strategies that work. The field needs people at all levels, and you don't need a four-year degree to break in. We'll discuss all the details, including a list of projects for beginners in Cybersecurity, plus plenty of non-technical suggestions! Visit for all the...

info_outline
Building a Hacking Lab in 2025 - PSW #906 show art Building a Hacking Lab in 2025 - PSW #906

Paul's Security Weekly (Audio)

The crew makes suggestions for building a hacking lab today! We will tackle: What is recommended today to build a lab, given the latest advancements in tech Hardware hacking devices and gadgets that are a must-have Which operating systems should you learn Virtualization technology that works well for a lab build Using AI to help build your lab Visit for all the latest episodes! Show Notes:

info_outline
With AI Nothing Is Safe - PSW #905 show art With AI Nothing Is Safe - PSW #905

Paul's Security Weekly (Audio)

This week in the security news: Linux process injection Threat actors need training too A Linux device "capable of practically anything" The Internet of webcams Hacking cheap devices Automating exploitation with local AI models Lame C2 Smallest SSH backdoor Your RDP is on the Internet These are not the high severity bugs you were looking for Low hanging fruit Your TV is spying on you, again no such thing as "offensive security" MCPs and RCEs Browser extensions collecting your AI chats And flooding TikTok with AI influencers Visit for all the latest episodes! Show Notes:

info_outline
Tech Segment: MITM Automation + Security News - Josh Bressers - PSW #904 show art Tech Segment: MITM Automation + Security News - Josh Bressers - PSW #904

Paul's Security Weekly (Audio)

This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can...

info_outline
 
More Episodes

This segment is sponsored by Flashpoint. Visit https://securityweekly.com/flashpoint to learn more about them!

Recent leaks tied to LockBit and Black Basta have exposed the inner workings of two of the most notorious ransomware groups—revealing their tactics, negotiation strategies, and operational infrastructure. For defenders, this rare window into adversary behavior offers critical intelligence to strengthen incident response and prevention strategies. In this interview, we'll break down what these leaks reveal and how security teams can use this intelligence to proactively harden their defenses, including:

  • Key takeaways from the LockBit and Black Basta leaks—and what they confirm about ransomware operations
  • How leaked playbooks, chats, and toolkits can inform detection and response
  • Practical steps to defend against modern ransomware tactics in 2025

In the security news:

  • Practical exploit code
  • Old vulnerabilities, new attackers
  • AI and web scraping - the battle continues
  • 0-Days: You gotta prove it
  • WinRAR 0-Day
  • LLM patch diffing
  • $20 million bug bounty
  • Your APT is showing
  • Hacking from the routers
  • Its that easy eh?
  • NIST guidance on AI
  • Words have meaning
  • Developers knowingly push vulnerable code
  • My Hackberry PI post is live: https://eclypsium.com/blog/build-the-ultimate-cyberdeck-hackberry-pi/

Resources:

Visit https://www.securityweekly.com/psw for all the latest episodes!

Show Notes: https://securityweekly.com/psw-888