![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
This episode covers a CISA contractor’s accidental exposure of AWS GovCloud credentials and internal system details on GitHub, the FBI’s efforts to patch vulnerable routers, and a critical NGINX vulnerability with public proof-of-concept code. The team also discusses Microsoft’s handling of a disputed Azure Backup security finding, the challenges of vulnerability disclosure and CVE assignment, and GitHub’s ban of security researcher Nightmare Eclipse following the publication of unpatched Windows vulnerability research.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
- (00:00) - PreShow Banter™ — Getting to Chili's
- (05:45) - GitHub bans vindictive security researcher - 2026-05-26
- (07:09) - Story # 1: CISA Admin Leaked AWS GovCloud Keys on Github
- (10:45) - Story # 2 - PoC Code Published for Critical NGINX Vulnerability
- (12:53) - Story # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude Code
- (16:16) - Story # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlist
- (22:37) - Story # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid Exploitation
- (25:52) - Story # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issued
- (28:09) - Story # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
- (30:41) - Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
- (32:16) - Story # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
- (35:21) - Story # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilities
- (37:51) - Story # 11 - Pizza Hut's AI system caused 'cascading' problems and $100M in damages, franchisee alleges in new suit
- (43:55) - Story # 12 - Data Leak at German Hospital
- (45:00) - Story # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
- (47:50) - Story # 14 - Chicken News
- (50:07) - Story # 15 - New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
- (51:04) - Story # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment?
Links
Story # 1 - CISA Admin Leaked AWS GovCloud Keys on Github
Story # 2 - PoC Code Published for Critical NGINX Vulnerability
Story # 3 - Anthropic’s restricted Claude Mythos model may be coming to Claude Code
Story # 4 - The FBI just remotely reset thousands of home and small office routers – and your TP-Link could be on the hitlist
Story # 5 - Drupal to Release Emergency Core Security Updates Amid Fears of Rapid Exploitation
Story # 6 - Microsoft rejects critical Azure vulnerability report, no CVE issued
Story # 7 - GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
Story # 8a - A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
Story # 8b - TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
Story # 10 - Ubiquiti patches three max severity UniFi OS vulnerabilities
Story # 11 - Pizza Hut’s AI system caused ‘cascading’ problems and $100M in damages, franchisee alleges in new suit
Story # 12 - Data Leak at German Hospital
Story # 13 - Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
Story # 14 - Chicken News
Story # 15 - New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released
Story # 15b - Might someone pass along that Crowdstrike and Nessus are having a moment?
Creators & Guests
Click here to watch this episode on YouTube.
Click here to view the episode transcript.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
Flere episoder fra "Talkin' Bout [Infosec] News"
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
Gå ikke glip af nogen episoder af “Talkin' Bout [Infosec] News” - abonnér på podcasten med gratisapp GetPodcast.
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
![Talkin' Bout [Infosec] News podcast](/assets/images/square.png)
