Defensive Security Podcast Episode 360
Show notes
Please consider supporting the DefSec podcast here.
1. AI agents broke into 395 organisations, including ones their operator ruled out https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/
2. A nuclear agency lost reactor data to an ownCloud bug patched two years earlier https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
3. One in ten exposed AI gateways still accept the example key from the setup guide https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html
4. Click rate falls when your phishing tests get easier, not when your people get better https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
5. Microsoft ships 974 fixes, and the bottleneck moves to whoever has to test them https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/