Security News

Cybersecurity news aggregator

HIGH News SC Media

Back to (or Start) Fundamentals? - Rajesh Khazanchi - PSW #923

  • What: Discussion on cybersecurity topics including vulnerability management and AI-driven discovery.
  • Impact: Relevant to IT professionals and security teams.
Read Full Article →

Subscribe Share Full episode and show notes Vulnerability Management , Critical Infrastructure Security , Identity Back to (or Start) Fundamentals? – Rajesh Khazanchi – PSW #923 This week: Larry’s in the host seat and chaos ensues. We dig into: A very questionable story about tracking a warship with a $5 Bluetooth tracker Serial-to-IP devices quietly sitting in critical infrastructure… and full of holes New York regulators mandating MFA and asset inventory—aka CIS Control #1 is now breaking news A ransomware negotiator who decided to double-dip (and landed in prison) “Brand new” hard drives that come preloaded… with someone else’s data The Vercel breach: no zero-day, just shadow IT, stolen tokens, and bad decisions AI-driven vulnerability discovery and the looming “vulnpocalypse” Quantum crypto debates: real threat or just another security boogeyman? Mirai is STILL... April 23, 2026 This episode is sponsored by Full Segment Notes This week: Larry’s in the host seat and chaos ensues. We dig into: A very questionable story about tracking a warship with a $5 Bluetooth tracker Serial-to-IP devices quietly sitting in critical infrastructure… and full of holes New York regulators mandating MFA and asset inventory—aka CIS Control #1 is now breaking news A ransomware negotiator who decided to double-dip (and landed in prison) “Brand new” hard drives that come preloaded… with someone else’s data The Vercel breach: no zero-day, just shadow IT, stolen tokens, and bad decisions AI-driven vulnerability discovery and the looming “vulnpocalypse” Quantum crypto debates: real threat or just another security boogeyman? Mirai is STILL alive—because apparently we still don’t patch routers And yes… Flipper Zero makes an appearance (no, you’re not hacking airplanes… calm down) Then, we rebroadcast an interview from RSAC. Breach Readiness for Measurable Risk Reduction in the Age of AI Cyber leaders no longer debate whether a breach will occur. What has changed is the speed and scale at which AI now enables those breaches. The real question is how far an attacker can move once inside. In this conversation, Rajesh Khazanchi explores why breach readiness, including AI-assisted containment, measurable blast radius reduction, and pervasive microsegmentation, has become mission-critical for business continuity in 2026. This segment is sponsored by ColorTokens. Visit https://securityweekly.com/colortokensrsac to learn more about them! Guest Rajesh Khazanchi CEO and Co-Founder at ColorTokens Rajesh Khazanchi is the CEO and Co-Founder of ColorTokens, Inc., a Bay Area cybersecurity company pioneering the global shift to Zero Trust security architectures. With over 25 years of leadership across enterprise security, cloud infrastructure, and product innovation — and 8 granted patents — he is recognized as a technology visionary who transforms bold ideas into enterprise-grade platforms that shape the future of cybersecurity. At ColorTokens, Rajesh has advanced the company’s mission of delivering Zero Trust Microsegmentation and breach readiness at scale, building a trusted partner ecosystem with Fortune 500 enterprises, global system integrators, and managed service providers. The company’s flagship platform, Xshield, has been consistently recognized by Gartner, Forrester, and GigaOm as a leader in Zero Trust MicroSegmentation. Over the last 10 years journey at ColorTokens, he also acquired two security companies – PureID and Cognore. Previously, Rajesh held senior leadership roles at VMware, HP, and Oracle, where he drove global product innovation, large-scale enterprise adoption, and next-generation security products and solutions. These experiences gave him a unique perspective on aligning technology with business transformation — a principle that continues to anchor ColorTokens’ customer-first approach. A recognized thought leader and innovator, Rajesh regularly engages with C-Level and Fortune 500 executives worldwide, shaping strategies that position security not just as protection, but as a strategic enabler of resilience, agility, and growth in the digital era. Hosts Doug White https://securedigitallife.com/ Jeff Man https://www.obsglobal.com/ Joshua Marpet https://www.cyturus.com Larry Pesce @haxorthematrix https://www.finitestate.io/ https://breakstuffforfun.com/ Lee Neely Mandy Logan @survivatrix#0613 Sam Bowne https://samsclass.info/ List of Articles Jeff Man What would you like to ask Iranians right now if they could get online? Our friend and fellow hacker Chris Kubecka has made contact with certain Iranian hackers that have figured out how to circumvent the Internet blackout in Iran. Interested yet? She's asking what questions you might have for Iranians right now? Admittedly, this is a somewhat different "news" article, but what a fascinating opportunity to understand this conflict from those directly affected. Vercel Employee’s AI Tool Access Led to Data Breach Stolen OAuth tokens, which are at the root of these breaches, "are the new attack surface, the new lateral movement," a researcher notes. Maryland property search tool goes offline after cyber threat This is a little too close to home...I actually use this site! AI arms race: are Anthropic and OpenAI handing hackers the ultimate weapon? "Claims that new AI models can outperform humans at some hacking tasks has sparked widespread alarm about the future of digital security." Ya think??? Claude Mythos and the AI Cybersecurity Wake-Up Call "AI does not create new vulnerabilities, it exposes existing ones, making the chronic underinvestment that boards have tolerated for years an immediate and material business risk." Wait for it.... "The immediate priority is strengthening cybersecurity fundamentals: Strong foundations provide significant protection against AI-enabled attacks, and most organizations urgently need to build those foundations." Genius. How Criminal Data Threatens Trust in AI Giving my friend Chris a second shoutout but why not? Larry Pesce Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers Flipper Zero Transmits APRS With No Extra Parts Vercel April 2026 security incident Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking Vercel OAuth breach analysis: Context.ai compromise, MITRE T1199 trust-chain attack, IOC for Google Workspace admins MacOS Native Tools Enable Stealthy Enterprise Attacks A Tale Of Cheap Hard Drives And Expensive Lessons Lee Neely Dutch navy frigate tracked by mailing it a Bluetooth tracker The location of a Dutch navy vessel was exposed for roughly 24 hours after a postcard containing a Bluetooth tracker was sent to the ship. The Dutch Ministry of Defense had posted instructions for sending mail to sailors and soldiers; journalist Just Vervaart took advantage of that information to send the gadget embedded in the postcard. The tracker reportedly remained active for a day. This story indicates the complexity of maintaining operational security with a backdrop of modern technology. Remember the aircraft carrier and "secret" military bases discovered by the use of fitness trackers used by soldiers running the perimeter? While we may not be conducting sensitive operations, we do have sensitive information, and we need to continuously monitor our controls to ensure it's not easily exfiltrated. I'm remembering claims stating that while information was strongly secured (access, in-transit and storage) one need only take a screenshot with their cell phone, which now often includes OCR capabilities. Also consider the use case of processing corporate information on personally owned devices. Are your protections up to speed with the current risks in either of these scenarios? Cyberattack at French identity document agency may have exposed personal data France's Interior Ministry has disclosed a that cybersecurity incident affecting the country's National Agency for Secure Documents (ANTS) may have compromised personal information. ANTS processes passport, national identity card, residence permit, and driver's license applications. The ANTS compromise is one of metadata rather than the sensitive attached documents themselves. So, while the data can't be used to access ANTS, that data includes sufficient information for ID theft/profiling, and users should take protective steps. Serial-to-IP Devices Hide Thousands of Old & New Bugs Researchers have identified 20 new vulnerabilities in popular models of serial-to-IP converters — devices that sit at the heart of modern industrial networks. Even more worryingly, the same researchers counted thousands of known vulnerabilities in these very same devices' software stacks. The flaws, when assigned a CVE, have high (9.8-10.0) CVSS scores, so we need to make sure everything is properly deployed. These types of devices, which are actually pretty cool for the teams using them, should fall under your IoT/OT protections, and as such should be isolated, not easily reached for any attempted exploit, and particularly not Internet accessible. While you're at it, seek to understand the use cases; it's good to know the problems these are solving. Deadline: New York Banks Attesting to Asset Inventories, MFA Financial institutions conducting business within the state of New York faced a deadline last week for attesting to their adoption of multifactor authentication and affirming that they are keeping accurate inventories of their IT assets, including an up-to-date list of devices and plans for end-of-life management for those devices. The April 15, 2026 deadline is the last of several requirements established by 2023 amendments to New York's Cybersecurity Rule. Cybersecurity requirements already implemented include a 72-hour window for reporting cybersecurity incidents, improved vulnerability management practices, and stronger governance. These requirements should be table stakes for all of us: (phishing resistant) MFA, accurate inventory, lifecycle management, vulnerability management

Share this article