This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
đź”´live-chat


Chapters

  • (00:00) - PreShow Banter™ — The Next Webcast Thing
  • (00:14) - Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29
  • (03:56) - Story #1 - It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
  • (07:49) - Story #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive users
  • (08:55) - Story #3 - heavener: This is what happens when you can't afford EDR licenses
  • (18:50) - Story #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
  • (31:59) - Story #5 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
  • (36:14) - Story #6 - CISA Adds Four Known Exploited Vulnerabilities to Catalog
  • (37:09) - Story #7 - Victory! 702 has Expired!
  • (37:43) - Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of Trial
  • (40:52) - Story #9 - Polymarket customers lose $3 million in supply-chain attack
  • (44:56) - Story #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general says
  • (49:31) - Story #11 - How Android Earthquake Alerts System Works
  • (53:47) - Story #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invites
  • (59:34) - Story #13a - The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
  • (59:59) - Story #13b - Order-tracking app Shop abused to push callback phishing attacks
  • (01:04:29) - Chinese AI vs. Anthropic Mythos | BHIS [In Focus]


Links
Story #1 - It’s looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
Story #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive users
Story #3 - heavener: This is what happens when you can’t afford EDR licenses
Story #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Story #5 - I Could’ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Story #6 - CISA Adds Four Known Exploited Vulnerabilities to Catalog
Story #7 - Victory! 702 has Expired!
Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Story #9 - Polymarket customers lose $3 million in supply-chain attack
Story #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general says
Story #11 - How Android Earthquake Alerts System Works
Story #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invites
Story #13a - The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
Story #13b - Order-tracking app Shop abused to push callback phishing attacks
Chinese AI vs. Anthropic Mythos | BHIS [In Focus]

Creators & Guests

John Strand - Host Bronwen Aker - Host Corey Ham - Host Meagan Bentley - Producer Wade Wells - Host Ralph May - Host Hayden Covington - Host
Click here to watch this episode on YouTube.

Click here to view the episode transcript.

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

https://poweredbybhis.com


Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

Podden och tillhörande omslagsbild på den här sidan tillhör Black Hills Information Security. Innehållet i podden är skapat av Black Hills Information Security och inte av, eller tillsammans med, Poddtoppen.