Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.

The Gap Between Security Dashboards and Decisions

Security teams often invest in more dashboards, more alerts, and more visibility. But when does visibility become noise? In this clip, David Clapp explains why security improvements come from actionability, not just awareness, and how organizations can close the gap between findings and decisions.

Report: Americans Lose an Estimated $148 Billion to Scams Each Year

Americans are now losing an estimated $148 billion each year to online scams, a 22% increase compared to 2024, according to a new report from the Consumer Federation of America (CFA). The FBI’s Internet Crime Complaint Center (IC3) tracked $20.8 billion in losses last year, but the CFA notes that the actual losses are much higher.

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.

Securing the Tip of the Spear: Guam's Path to Human and AI Resilience

As the Asia-Pacific and Japan (APJ) region continues its rapid digital acceleration, Guam stands at a unique strategic intersection. Serving as a critical hub for telecommunications, government services and regional defense, the island’s cybersecurity posture is no longer just a local concern, it is a cornerstone of regional stability. I have observed a proactive shift toward onboarding various agencies to a unified security framework.

GitProtect vs. Native Microsoft 365 Backup

Summary Organizations often assume their Microsoft 365 assets are fully protected by native backup tools. However, while Microsoft does offer advanced built-in backup and recovery features, relying solely on a native approach is not a substitute for an independent, enterprise-grade backup strategy. The risks of relying on a single ecosystem for backups are escalating.

AI Isn't Creating New Cyberattacks. It's Changing How They Operate

Artificial Intelligence has quickly become one of the most important conversations in cybersecurity. Much of that conversation focuses on what attackers might create next: AI-generated malware, deepfakes, autonomous attacks, or entirely new categories of threats. Those risks matter, but focusing only on new attack techniques misses a much larger transformation already taking place. The real impact of AI is not only what attackers can create. It is how efficiently they can operate.

AWS Security Live from Black Hat 2026 with Johnny Wong from Veracode

In this episode, hosts Ryan and Brian are joined by Johnny Wong, VP of Solutions Architecture at Veracode, to explore how AI-assisted “vibe coding” is changing the way software gets built—and the new security risks that come with it. While large language models are making developers faster and more productive, studies shared in the discussion show that a significant portion of AI-generated code still contains security vulnerabilities, raising concerns about scale and speed in modern development pipelines.

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents are becoming real users of internal systems. They open pull requests, run queries, and pull and publish artifacts in repositories like JFrog Artifactory.