• Microsoft Threatens Legal Action Over Exploit Disclosure
    Jun 8 2026
    Microsoft’s response to a researcher publicly disclosing proof-of-concept exploit code has reignited an old debate in security: where does responsible disclosure end and reckless disclosure begin? Tom and Scott discuss the Nightmare Eclipse controversy, the history of full disclosure, bug bounty incentives, and why legal threats against researchers may ultimately hurt customers. They also explain why researchers still need to follow responsible processes — and why vendors need to avoid punishing the people who help make their products safer. Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com. ** Links mentioned on the show ** The Verge: Microsoft is threatening legal action for disclosing exploits https://www.theverge.com/tech/940416/microsoft-nightmare-eclipse-zero-day-vulnerability Microsoft MSRC Blog: A shared responsibility: Protecting customers through coordinated vulnerability disclosure https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure Kevin Beaumont / DoublePulsar: Microsoft’s stance on zero day exploits is a dumpster fire of their own making https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4 ** Watch this episode on YouTube ** ** Become a Shared Security Supporter ** Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join ** Thank you to our sponsors! ** SLNT Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”. ** Subscribe and follow the podcast ** Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social Follow us on Mastodon: https://infosec.exchange/@sharedsecurity Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/ Visit our website: https://sharedsecurity.net Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe Leave us a rating and review: https://ratethispodcast.com/sharedsecurity Contact us: https://sharedsecurity.net/contact The post Microsoft Threatens Legal Action Over Exploit Disclosure appeared first on Shared Security Podcast.
    Show More Show Less
    17 mins
  • Apple Finally Fixes One of Texting’s Biggest Security Problems
    Jun 1 2026

    Apple and Google are finally bringing end-to-end encrypted RCS messaging to iPhone and Android chats. In this episode, Tom Eston and Kevin Tackett explain why that matters, why insecure SMS is not going away anytime soon, and why Signal is still the better choice for truly sensitive conversations. They also revisit the green bubble versus blue bubble debate, platform trust issues, and what everyday users should understand before assuming every text message is private.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    Victory! End-to-End Encrypted RCS Comes to Apple and Android Chats
    https://www.eff.org/deeplinks/2026/05/victory-end-end-encrypted-rcs-comes-apple-and-android-chats

    ‘Blue Bubbles’—Apple Says iPhone Messaging Is Still ‘Best’
    https://www.forbes.com/sites/zakdoffman/2026/05/26/blue-bubbles-apple-says-iphone-messaging-is-still-best/

    End-to-end encrypted RCS messaging begins rolling out today in beta
    https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Apple Finally Fixes One of Texting’s Biggest Security Problems appeared first on Shared Security Podcast.

    Show More Show Less
    15 mins
  • Should AI Have Access to Your Financial Life?
    May 25 2026

    OpenAI is now allowing some ChatGPT users to connect their bank accounts and financial data directly to the platform. In this episode, we discuss the technology behind the feature, the convenience it promises, and the serious privacy and security questions it raises.

    From AI-generated budgeting advice to the risks of centralized financial profiling, we examine what happens when conversational AI gains visibility into your spending habits, debts, subscriptions, and financial goals.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    ChatGPT Can Now Connect to Your Bank Account and See All Your Transactions
    https://gizmodo.com/chatgpt-can-now-connect-to-your-bank-account-and-see-all-your-transactions-2000759306

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Should AI Have Access to Your Financial Life? appeared first on Shared Security Podcast.

    Show More Show Less
    25 mins
  • Cybersecurity Lessons from the Canvas Data Breach
    May 18 2026

    In this episode we discuss the recent cyber attack targeting Instructure’s widely used learning platform, Canvas, and the major late-breaking development that Instructure reached an “agreement” with the ShinyHunters cybercriminal group after threats to leak large amounts of stolen student and faculty data. Instructure says the stolen data was returned and that attackers provided digital confirmation that the information was destroyed, but the company did not deny making a payment—language that many in cybersecurity interpret as a ransom settlement.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    Cyberattack on Canvas system causes chaos for students at thousands of schools
    https://apnews.com/article/cyberattack-schools-canvas-instructure-shinyhunters-a0d7719689263e6b5f90d0e633391b5b

    Instructure strikes agreement with hackers after Canvas breach hits Duke, thousands of other schools
    https://www.dukechronicle.com/article/duke-university-instructure-reaches-agreement-with-canvas-hackers-shinyhunters-cyberattack-leak-down-stolen-data-ransom-20260512

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Cybersecurity Lessons from the Canvas Data Breach appeared first on Shared Security Podcast.

    Show More Show Less
    17 mins
  • Passwords Are Still Failing Us (World Password Day 2026)
    May 11 2026

    World Password Day was on May 7th—but are we actually getting better at password security?

    In this episode, we discuss why compromised credentials are still behind the majority of breaches in 2026. From password reuse and phishing to infostealer malware and MFA bypass techniques, attackers are finding it easier than ever to log in instead of hack in. We also talk about whether passkeys can finally shift the landscape—and what organizations should be doing right now to reduce risk.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    Password Statistics 2026 – Trends, Facts & Data Insights
    https://www.privateproxyguide.com/password-statistics/

    World Password Day 2026: Attackers simply log in
    https://www.organisator.ch/en/operational-excellence/2026-04-30/world-password-day-2026-angreifer-loggen-sich-einfach-ein/

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Passwords Are Still Failing Us (World Password Day 2026) appeared first on Shared Security Podcast.

    Show More Show Less
    22 mins
  • Fake Party Invites and the Rise of Social Phishing Attacks
    May 4 2026

    Attackers are now impersonating invitation services to trick people into clicking malicious links and sharing sensitive information. These phishing attempts look like legitimate event invites, making them especially effective. In this episode, we discuss how these scams work and what steps you can take to stay protected.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    New Phishing Scam: Fake Invitations
    https://www.nytimes.com/2026/04/23/style/invitation-phishing-scam.html

    The ‘fake invite’ scam that tricks you through people you trust
    https://www.consumeraffairs.com/news/the-fake-invite-scam-that-tricks-you-through-people-you-trust-042326.html

    BSides Jacksonville
    https://www.bsidesjax.org/

    HackSpaceCon
    https://www.hackspacecon.com/

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Fake Party Invites and the Rise of Social Phishing Attacks appeared first on Shared Security Podcast.

    Show More Show Less
    16 mins
  • New York’s 3D Printing Crackdown: Security or Surveillance?
    Apr 27 2026

    New York’s latest budget proposal could fundamentally change how 3D printers work—requiring built-in software that scans and blocks certain designs. Supporters say it’s about stopping ghost guns. Critics say it opens the door to surveillance and limits innovation.

    In this episode, we discuss what’s actually in the proposal, why it’s raising alarms across the tech community, and what it could mean for the future of user-controlled technology.

    ** Links mentioned on the show **

    Stop New York’s Attack on 3D Printing!
    https://www.eff.org/deeplinks/2026/04/stop-new-yorks-attack-3d-printing

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post New York’s 3D Printing Crackdown: Security or Surveillance? appeared first on Shared Security Podcast.

    Show More Show Less
    16 mins
  • Project Glasswing: When AI Becomes the Ultimate Hacker—and Defender
    Apr 20 2026

    Anthropic has introduced Project Glasswing, a cybersecurity initiative powered by an unreleased AI model called Claude Mythos. This system can identify zero-day vulnerabilities, generate exploits, and even help fix them—often without human input.

    But there’s a catch: it’s considered too powerful for public release.

    In this episode, we discuss what Project Glasswing is, why it matters, and what it means for the future of cybersecurity, red teaming, and AI-driven threats.

    Is this the beginning of AI defending us—or the start of something much harder to control?

    ** Links mentioned on the show **

    Claude Mythos and Project Glasswing: why an AI superhacker has the tech world on alert
    https://theconversation.com/claude-mythos-and-project-glasswing-why-an-ai-superhacker-has-the-tech-world-on-alert-280374

    Anthropic Project Glasswing
    https://www.anthropic.com/project/glasswing

    ** Watch this episode on YouTube **

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Project Glasswing: When AI Becomes the Ultimate Hacker—and Defender appeared first on Shared Security Podcast.

    Show More Show Less
    28 mins