This week’s episode covers a series of cybersecurity stories, including a researcher’s discovery of vulnerabilities in FIFA’s World Cup platform that could have enabled unauthorized administrative access and even the ability to alter live broadcasts. The team also discusses the risks of large-scale identity verification data exposure, supply chain attacks impacting the scientific research community, ongoing fallout from Broadcom’s VMware acquisition, and legal challenges from major organizations facing rising VMware costs. Along the way, the hosts share commentary on AI-related security concerns, access control failures, and the broader impact of vendor decisions on enterprise security.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters

  • (00:00) - PreShow Banter™ — There's always more suppply chain
  • (04:52) - Rickrolling the FIFA World Cup - 2026-06-22
  • (07:59) - Story #1 - Texas Government Data Breach Exposes 3 Million Driver’s License Records
  • (10:56) - Story #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
  • (21:00) - Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure
  • (23:58) - Story #4a - Stakeholder-Specific Vulnerability Categorization (SSVC)
  • (25:44) - Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for Everyone
  • (37:19) - Story #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
  • (43:56) - Story #6 - FBI disrupts massive AI-powered phishing service using a million URLs
  • (46:12) - Story #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
  • (47:12) - Story #8 - AI models that can take down governments and business months away, rare Five Eyes statement warns
  • (48:44) - Story #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURS
  • (58:45) - Story #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”


Links
Story #1 - Texas Government Data Breach Exposes 3 Million Driver’s License Records
Story #2 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Story #3 - FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure
Story #4a - Stakeholder-Specific Vulnerability Categorization (SSVC)
Story #4b - CVSS Is Officially Dead: What CISA's BOD 26-04 Means for Everyone
Story #5 - Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
Story #6 - FBI disrupts massive AI-powered phishing service using a million URLs
Story #7 - Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
Story #8 - AI models that can take down governments and business months away, rare Five Eyes statement warns
Story #9 - ANTHROPIC’S MYTHOS AI BROKE INTO ALMOST ALL NSA CLASSIFIED SYSTEMS IN HOURS
Story #10 - Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”

Creators & Guests

Andy Pettit "Nerf" - Guest Michael "Shecky" Kavka - Guest Ryan Poirier - Producer Corey Ham - Host Ralph May - Host John Strand - Host
Click here to watch this episode on YouTube.

Click here to view the episode transcript.

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

https://poweredbybhis.com


Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

Podden och tillhörande omslagsbild på den här sidan tillhör Black Hills Information Security. Innehållet i podden är skapat av Black Hills Information Security och inte av, eller tillsammans med, Poddtoppen.