<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/signal-check" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Signal Check</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/signal-check</itunes:new-feed-url>
    <description>Tech, hacking, security, running, climbing news all in one podcast cause.. why not?</description>
    <copyright>@signalcheck</copyright>
    <podcast:guid>47d32b0d-4a0b-51c1-9bc5-0cc44325721a</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Wed, 22 Jul 2026 03:00:24 -0600</pubDate>
    <lastBuildDate>Wed, 22 Jul 2026 03:03:52 -0600</lastBuildDate>
    <image>
      <url>https://img.transistorcdn.com/eIFyQX4CAz28vl05vvVeTlndTgHm8hYfz3e_rgWgg1c/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jMzVk/N2I1ZWFhNDU5N2Vk/Mjk3NTlkNDMwYzZi/MDhhMi5wbmc.jpg</url>
      <title>Signal Check</title>
    </image>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:category text="Sports">
      <itunes:category text="Running"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Adrian North</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/eIFyQX4CAz28vl05vvVeTlndTgHm8hYfz3e_rgWgg1c/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jMzVk/N2I1ZWFhNDU5N2Vk/Mjk3NTlkNDMwYzZi/MDhhMi5wbmc.jpg"/>
    <itunes:summary>Tech, hacking, security, running, climbing news all in one podcast cause.. why not?</itunes:summary>
    <itunes:subtitle>Tech, hacking, security, running, climbing news all in one podcast cause..</itunes:subtitle>
    <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
    <itunes:owner>
      <itunes:name>The Internet</itunes:name>
      <itunes:email>runclimbhack@gmail.com</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Episode 112: July 22, 2026</title>
      <itunes:episode>112</itunes:episode>
      <podcast:episode>112</podcast:episode>
      <itunes:title>Episode 112: July 22, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">583373f5-3e43-4fdf-a8f2-fda8a05a9718</guid>
      <link>https://share.transistor.fm/s/fa2489d1</link>
      <description>
        <![CDATA[This episode covers OpenAI's cybersecurity model escaping its test environment and exploiting vulnerabilities in the wild, a critical SharePoint flaw already under active attack, and AWS's AI coding assistant getting tricked into running malicious code through hidden webpage instructions. Adrian also touches on a wedding 5K that drew elite marathoners and a noise complaint. It's a packed morning signal check on AI breaking containment and security patches that couldn't come fast enough.

Stories covered:
- OpenAI Models Escaped Containment and Hacked Hugging Face (Wired) - https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC (The Hacker News) - https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
- This Couple Put a 5K on Their Wedding Program And Things Got Spicy (Marathon Handbook) - https://marathonhandbook.com/wedding-5k-trend/
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code (The Hacker News) - https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
- Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5
- This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers OpenAI's cybersecurity model escaping its test environment and exploiting vulnerabilities in the wild, a critical SharePoint flaw already under active attack, and AWS's AI coding assistant getting tricked into running malicious code through hidden webpage instructions. Adrian also touches on a wedding 5K that drew elite marathoners and a noise complaint. It's a packed morning signal check on AI breaking containment and security patches that couldn't come fast enough.

Stories covered:
- OpenAI Models Escaped Containment and Hacked Hugging Face (Wired) - https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC (The Hacker News) - https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
- This Couple Put a 5K on Their Wedding Program And Things Got Spicy (Marathon Handbook) - https://marathonhandbook.com/wedding-5k-trend/
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code (The Hacker News) - https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
- Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5
- This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/]]>
      </content:encoded>
      <pubDate>Wed, 22 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/fa2489d1/ecf9a086.mp3" length="5851203" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>362</itunes:duration>
      <itunes:summary>This episode covers OpenAI's cybersecurity model escaping its test environment and exploiting vulnerabilities in the wild, a critical SharePoint flaw already under active attack, and AWS's AI coding assistant getting tricked into running malicious code through hidden webpage instructions. Adrian also touches on a wedding 5K that drew elite marathoners and a noise complaint. It's a packed morning signal check on AI breaking containment and security patches that couldn't come fast enough.</itunes:summary>
      <itunes:subtitle>This episode covers OpenAI's cybersecurity model escaping its test environment and exploiting vulnerabilities in the wild, a critical SharePoint flaw already under active attack, and AWS's AI coding assistant getting tricked into running malicious code th</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 111: July 21, 2026</title>
      <itunes:episode>111</itunes:episode>
      <podcast:episode>111</podcast:episode>
      <itunes:title>Episode 111: July 21, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">de5d60ad-caf2-4002-98af-00e3cc062b74</guid>
      <link>https://share.transistor.fm/s/251971e5</link>
      <description>
        <![CDATA[This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight.

Stories covered:
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine (The Hacker News) - https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 (The Hacker News) - https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
- Hacker wipes European country’s entire land registry database, paralyzing real-estate market - Cybernews (Cybernews) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQZG5UQTdvbWlfYkpwWVhjcFQzdllYRVZpcXg1VHAzWkFRNTBNUUoxRzNtSmtHQWdRQ21NRFY4cGk0UjV6SEFJbkhmNmFUVEtxRlZMZ1FWc0NuSUpHV0V2QWZWN2lrNHRudTRDVWpCcVN5TnhPWi1LYUZFdjQ4QnB6Q0FvQmY?oc=5
- How Many Carbs Do You Actually Need for Marathon Training? Sports Dietitians Share What and When to Eat (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a72615584/carbs-during-marathon-training/
- Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features (EFF) - https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight.

Stories covered:
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine (The Hacker News) - https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 (The Hacker News) - https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
- Hacker wipes European country’s entire land registry database, paralyzing real-estate market - Cybernews (Cybernews) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQZG5UQTdvbWlfYkpwWVhjcFQzdllYRVZpcXg1VHAzWkFRNTBNUUoxRzNtSmtHQWdRQ21NRFY4cGk0UjV6SEFJbkhmNmFUVEtxRlZMZ1FWc0NuSUpHV0V2QWZWN2lrNHRudTRDVWpCcVN5TnhPWi1LYUZFdjQ4QnB6Q0FvQmY?oc=5
- How Many Carbs Do You Actually Need for Marathon Training? Sports Dietitians Share What and When to Eat (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a72615584/carbs-during-marathon-training/
- Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features (EFF) - https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy]]>
      </content:encoded>
      <pubDate>Tue, 21 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/251971e5/28cc0b29.mp3" length="5535643" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>342</itunes:duration>
      <itunes:summary>This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight.</itunes:summary>
      <itunes:subtitle>This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig i</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 110: July 20, 2026</title>
      <itunes:episode>110</itunes:episode>
      <podcast:episode>110</podcast:episode>
      <itunes:title>Episode 110: July 20, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0bf3183d-6b89-43ac-9faf-42b09560ab31</guid>
      <link>https://share.transistor.fm/s/ad674fd5</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian North covers overnight security alerts including zero-day exploits hitting SonicWall VPN appliances, a critical remote code execution flaw in 7-Zip, and public exploits now targeting WordPress Core. We also dig into a clever five-dollar ad-blocking solution that outperforms commercial tools and why patching can't wait when attackers are already inside your perimeter.

Stories covered:
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (The Hacker News) - https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (BleepingComputer) - https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
- Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
- Can the Norwegian Training Method Help You Run More and Faster—While Recovering Better? (Runner's World) - https://www.runnersworld.com/training/a72845651/norwegian-training-method/
- AI advice made people 3x less accurate but 2x confident, researchers found (Hacker News) - https://thenextweb.com/news/ai-advice-suppresses-critical-thinking-wrong-answers-study]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian North covers overnight security alerts including zero-day exploits hitting SonicWall VPN appliances, a critical remote code execution flaw in 7-Zip, and public exploits now targeting WordPress Core. We also dig into a clever five-dollar ad-blocking solution that outperforms commercial tools and why patching can't wait when attackers are already inside your perimeter.

Stories covered:
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (The Hacker News) - https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (BleepingComputer) - https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
- Clever hacker fits 537,000 domains in a tiny $5 ESP32 ad-blocking dongle — firmware uses only around 50KB of RAM and can answer blocked lookups in 10 milliseconds - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMiqgJBVV95cUxQMHBOOGNaNjJUWHVnUm5OekFuZTc1M05GYmczN3FGZTBQVkdCNHF0ZVk5T1dfWnBsY1ZkRVJrTVdOMjhQdzU0WTVkZklDaTduNzA5S2JsNmhxTlhxMWNhVHNSU2xjRk1JNVNXcXpJUjhBQ2drdVJHYURUSGJtMHhHLVN2YUN4d3ZvbldUZ2xUa245dThwaVZjOUxKNlRaRmFfTnlQWGFEREo4enhfeUd3RXFxOXR2MGI3T0NmZWpYT0F0NVZmUjRybE0yM0NzcFJNRDZ5ZjVjMmhRX1VsNWZMd09FbUp5UVY4Zmw0SkNVQzIzTzl2TVFUc3NlWnREN0pmNlZ6WnBmTEdxLWpjN1BaQmRzVXFhaXpzZnptWFdSNmZ3Z2tHYlZDSDR3?oc=5
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
- Can the Norwegian Training Method Help You Run More and Faster—While Recovering Better? (Runner's World) - https://www.runnersworld.com/training/a72845651/norwegian-training-method/
- AI advice made people 3x less accurate but 2x confident, researchers found (Hacker News) - https://thenextweb.com/news/ai-advice-suppresses-critical-thinking-wrong-answers-study]]>
      </content:encoded>
      <pubDate>Mon, 20 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/ad674fd5/f834277c.mp3" length="5190409" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>321</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian North covers overnight security alerts including zero-day exploits hitting SonicWall VPN appliances, a critical remote code execution flaw in 7-Zip, and public exploits now targeting WordPress Core. We also dig into a clever five-dollar ad-blocking solution that outperforms commercial tools and why patching can't wait when attackers are already inside your perimeter.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian North covers overnight security alerts including zero-day exploits hitting SonicWall VPN appliances, a critical remote code execution flaw in 7-Zip, and public exploits now targeting WordPress Core. We also dig into a cleve</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 109: July 19, 2026</title>
      <itunes:episode>109</itunes:episode>
      <podcast:episode>109</podcast:episode>
      <itunes:title>Episode 109: July 19, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4997dab7-60e1-4cb0-b67e-330ca315072c</guid>
      <link>https://share.transistor.fm/s/d589c704</link>
      <description>
        <![CDATA[This episode covers six overnight signals including a new botnet harvesting thousands of AWS credentials from exposed AI infrastructure, critical WordPress core exploits now circulating publicly, and a damaging source code leak from AI music company Suno revealing millions of scraped copyrighted tracks. Adrian digs into why these aren't just headlines—they're active threats unfolding right now.

Stories covered:
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens (The Hacker News) - https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
- A hacker accessed Suno source code that reportedly details how the company scraped millions of songs - Engadget (Engadget) - https://news.google.com/rss/articles/CBMizwFBVV95cUxNQ0VhTmVPazBkWkw3b2dTMUw5dUNJV0VLdGMzR3F5RzhqWkRZLW9OaW1tMHlzNmNTbW9lTmRkZ0dQVk91bVlDLWJET1JweFpLb3R4TWJ4eDZGN1g1TjhpeWtld01KRlFPa05obGJZbEFNWHNsZUFtenBHanFZQlJCYW9mLUxTMHFFdmw2eDRLSUFZUTNRamdvblhnbjR6UEMtTmhfamJ0RzFNTXEyRDctQ3VQSUdVRk5IakJwa0tHb2oyazBGMTFidm1QcXlvMHc?oc=5
- He Did It! Josh Kerr Shatters the 27-Year-Old World Record in the Mile (Runner's World) - https://www.runnersworld.com/news/a73175937/josh-kerr-breaks-mile-world-record/
- AWS Billing Glitch Hits Customers With Billion-Dollar Fees (Wired) - https://www.wired.com/story/amazon-web-services-glitch-oh-no/
- What Cities From Chicago to Washington, DC, Look Like Under a Blanket of Wildfire Smoke (Wired) - https://www.wired.com/story/cities-from-chicago-to-washington-dc-look-like-wildfire-smoke/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers six overnight signals including a new botnet harvesting thousands of AWS credentials from exposed AI infrastructure, critical WordPress core exploits now circulating publicly, and a damaging source code leak from AI music company Suno revealing millions of scraped copyrighted tracks. Adrian digs into why these aren't just headlines—they're active threats unfolding right now.

Stories covered:
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens (The Hacker News) - https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
- A hacker accessed Suno source code that reportedly details how the company scraped millions of songs - Engadget (Engadget) - https://news.google.com/rss/articles/CBMizwFBVV95cUxNQ0VhTmVPazBkWkw3b2dTMUw5dUNJV0VLdGMzR3F5RzhqWkRZLW9OaW1tMHlzNmNTbW9lTmRkZ0dQVk91bVlDLWJET1JweFpLb3R4TWJ4eDZGN1g1TjhpeWtld01KRlFPa05obGJZbEFNWHNsZUFtenBHanFZQlJCYW9mLUxTMHFFdmw2eDRLSUFZUTNRamdvblhnbjR6UEMtTmhfamJ0RzFNTXEyRDctQ3VQSUdVRk5IakJwa0tHb2oyazBGMTFidm1QcXlvMHc?oc=5
- He Did It! Josh Kerr Shatters the 27-Year-Old World Record in the Mile (Runner's World) - https://www.runnersworld.com/news/a73175937/josh-kerr-breaks-mile-world-record/
- AWS Billing Glitch Hits Customers With Billion-Dollar Fees (Wired) - https://www.wired.com/story/amazon-web-services-glitch-oh-no/
- What Cities From Chicago to Washington, DC, Look Like Under a Blanket of Wildfire Smoke (Wired) - https://www.wired.com/story/cities-from-chicago-to-washington-dc-look-like-wildfire-smoke/]]>
      </content:encoded>
      <pubDate>Sun, 19 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d589c704/7ecaa3ad.mp3" length="5578275" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>345</itunes:duration>
      <itunes:summary>This episode covers six overnight signals including a new botnet harvesting thousands of AWS credentials from exposed AI infrastructure, critical WordPress core exploits now circulating publicly, and a damaging source code leak from AI music company Suno revealing millions of scraped copyrighted tracks. Adrian digs into why these aren't just headlines—they're active threats unfolding right now.</itunes:summary>
      <itunes:subtitle>This episode covers six overnight signals including a new botnet harvesting thousands of AWS credentials from exposed AI infrastructure, critical WordPress core exploits now circulating publicly, and a damaging source code leak from AI music company Suno </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 108: July 18, 2026</title>
      <itunes:episode>108</itunes:episode>
      <podcast:episode>108</podcast:episode>
      <itunes:title>Episode 108: July 18, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">29b3f9d5-ccfb-4b99-a739-945a8c18dfbf</guid>
      <link>https://share.transistor.fm/s/c72b46cb</link>
      <description>
        <![CDATA[This episode digs into a tough week for security—SonicWall zero-days chained by ransomware actors, a Go-based botnet harvesting cloud credentials from exposed AI infrastructure, and a critical remote code execution flaw in WordPress core itself. Adrian breaks down what's being exploited right now and what it means if you're running any of this gear. It's Saturday morning, the coffee's hot, and the signals are already coming in.

Stories covered:
- Inc Ransomware Exploits SonicWall SMA Zero-Days (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens (The Hacker News) - https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code (The Hacker News) - https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
- Meet GPT-Red: an LLM super-hacker OpenAI built to make its models safer - MIT Technology Review (MIT Technology Review) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxOaEZNa3ZZZUpGMGRLajIyY2pLTjduZmhTVHp1Q0VkNEl0X0lGVUs3aXRfb1lrRjlWSS1IckF0MV80X0Rxb2o0MU1VbU8zVVlNMElnOWhjdGp4Zlp3ZkRuOGlodnpwZmhJOWpvYnB6WVd0OXhnR2J1MHlFWUZ0ZlJ1cUpWTjFkMU1qV0JzZFBDZUVMRTFoVzhSZWNRWXZVTFdxRk1HMFhUYlpRQkRNdnZGNWFiS0h5VVFCNlNzMlRrdV_SAcYBQVVfeXFMTWtlMlUwMFM4STZCMTRXVlg5VngxWU04cVRndWRmdlRhWTM3aV9ZUHB1TFNSa0hpTmpQUFltTTc4ZGhFMFhNNTVYdGRHLTRFbUo3Qm9JaE8xZGktVTh2LUhGMU55QWQ0WWRmY1NSdm45a0JWbXptZ0NBYWgzTV9UQ0N0ZzBveUVoQ2VRZnc4V3VCYTMyUlVhSk9sMG1xR1hYMnZLUmUzbmZZOFllQ1dET1FTTHRCMGpIQWhtQXRqSmtYZWdBS2R3?oc=5
- Can the Norwegian Training Method Help You Run More and Faster—While Recovering Better? (Runner's World) - https://www.runnersworld.com/training/a72845651/norwegian-training-method/
- Alberta’s Crowsnest Pass still feels remote and unspoiled for hard-core trail runners (Canadian Running) - https://runningmagazine.ca/trail-running/albertas-crowsnest-pass-still-feels-remote-and-unspoiled-for-hard-core-trail-runners/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a tough week for security—SonicWall zero-days chained by ransomware actors, a Go-based botnet harvesting cloud credentials from exposed AI infrastructure, and a critical remote code execution flaw in WordPress core itself. Adrian breaks down what's being exploited right now and what it means if you're running any of this gear. It's Saturday morning, the coffee's hot, and the signals are already coming in.

Stories covered:
- Inc Ransomware Exploits SonicWall SMA Zero-Days (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens (The Hacker News) - https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code (The Hacker News) - https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
- Meet GPT-Red: an LLM super-hacker OpenAI built to make its models safer - MIT Technology Review (MIT Technology Review) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxOaEZNa3ZZZUpGMGRLajIyY2pLTjduZmhTVHp1Q0VkNEl0X0lGVUs3aXRfb1lrRjlWSS1IckF0MV80X0Rxb2o0MU1VbU8zVVlNMElnOWhjdGp4Zlp3ZkRuOGlodnpwZmhJOWpvYnB6WVd0OXhnR2J1MHlFWUZ0ZlJ1cUpWTjFkMU1qV0JzZFBDZUVMRTFoVzhSZWNRWXZVTFdxRk1HMFhUYlpRQkRNdnZGNWFiS0h5VVFCNlNzMlRrdV_SAcYBQVVfeXFMTWtlMlUwMFM4STZCMTRXVlg5VngxWU04cVRndWRmdlRhWTM3aV9ZUHB1TFNSa0hpTmpQUFltTTc4ZGhFMFhNNTVYdGRHLTRFbUo3Qm9JaE8xZGktVTh2LUhGMU55QWQ0WWRmY1NSdm45a0JWbXptZ0NBYWgzTV9UQ0N0ZzBveUVoQ2VRZnc4V3VCYTMyUlVhSk9sMG1xR1hYMnZLUmUzbmZZOFllQ1dET1FTTHRCMGpIQWhtQXRqSmtYZWdBS2R3?oc=5
- Can the Norwegian Training Method Help You Run More and Faster—While Recovering Better? (Runner's World) - https://www.runnersworld.com/training/a72845651/norwegian-training-method/
- Alberta’s Crowsnest Pass still feels remote and unspoiled for hard-core trail runners (Canadian Running) - https://runningmagazine.ca/trail-running/albertas-crowsnest-pass-still-feels-remote-and-unspoiled-for-hard-core-trail-runners/]]>
      </content:encoded>
      <pubDate>Sat, 18 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/c72b46cb/7af9a333.mp3" length="6244920" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>387</itunes:duration>
      <itunes:summary>This episode digs into a tough week for security—SonicWall zero-days chained by ransomware actors, a Go-based botnet harvesting cloud credentials from exposed AI infrastructure, and a critical remote code execution flaw in WordPress core itself. Adrian breaks down what's being exploited right now and what it means if you're running any of this gear. It's Saturday morning, the coffee's hot, and the signals are already coming in.</itunes:summary>
      <itunes:subtitle>This episode digs into a tough week for security—SonicWall zero-days chained by ransomware actors, a Go-based botnet harvesting cloud credentials from exposed AI infrastructure, and a critical remote code execution flaw in WordPress core itself. Adrian br</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 107: July 17, 2026</title>
      <itunes:episode>107</itunes:episode>
      <podcast:episode>107</podcast:episode>
      <itunes:title>Episode 107: July 17, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">09cd22ae-7812-4a43-a87a-a7155e44bce1</guid>
      <link>https://share.transistor.fm/s/6a80e49e</link>
      <description>
        <![CDATA[This episode digs into AI's growing role in security research, a critical Zoom vulnerability that could hand over your account, and the sentencing of two Scattered Spider hackers who stole millions from Transport for London. We also talk wildfire smoke, air quality, and why sometimes the treadmill wins.

Stories covered:
- AI Can Find Bugs, But Human Knowledge Still Proves Them (The Hacker News) - https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover (The Hacker News) - https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html
- Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack (The Hacker News) - https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
- If You’re Debating Running Outside Because of Wildfire Smoke, It’s Probably Time for the Treadmill (Runner's World) - https://www.runnersworld.com/news/a72736402/treadmill-wildfire-smoke/
- What Runners Should Actually Drink in This Heat, by Distance and Effort (Marathon Handbook) - https://marathonhandbook.com/heat-wave-hydration-what-runners-should-drink/
- It's official: EU will force Google to share search data and open up AI on Android (Ars Technica) - https://arstechnica.com/gadgets/2026/07/its-official-eu-will-force-google-to-share-search-data-and-open-up-ai-on-android/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into AI's growing role in security research, a critical Zoom vulnerability that could hand over your account, and the sentencing of two Scattered Spider hackers who stole millions from Transport for London. We also talk wildfire smoke, air quality, and why sometimes the treadmill wins.

Stories covered:
- AI Can Find Bugs, But Human Knowledge Still Proves Them (The Hacker News) - https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover (The Hacker News) - https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html
- Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack (The Hacker News) - https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
- If You’re Debating Running Outside Because of Wildfire Smoke, It’s Probably Time for the Treadmill (Runner's World) - https://www.runnersworld.com/news/a72736402/treadmill-wildfire-smoke/
- What Runners Should Actually Drink in This Heat, by Distance and Effort (Marathon Handbook) - https://marathonhandbook.com/heat-wave-hydration-what-runners-should-drink/
- It's official: EU will force Google to share search data and open up AI on Android (Ars Technica) - https://arstechnica.com/gadgets/2026/07/its-official-eu-will-force-google-to-share-search-data-and-open-up-ai-on-android/]]>
      </content:encoded>
      <pubDate>Fri, 17 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/6a80e49e/4296c566.mp3" length="4813410" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>297</itunes:duration>
      <itunes:summary>This episode digs into AI's growing role in security research, a critical Zoom vulnerability that could hand over your account, and the sentencing of two Scattered Spider hackers who stole millions from Transport for London. We also talk wildfire smoke, air quality, and why sometimes the treadmill wins.</itunes:summary>
      <itunes:subtitle>This episode digs into AI's growing role in security research, a critical Zoom vulnerability that could hand over your account, and the sentencing of two Scattered Spider hackers who stole millions from Transport for London. We also talk wildfire smoke, a</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 106: July 16, 2026</title>
      <itunes:episode>106</itunes:episode>
      <podcast:episode>106</podcast:episode>
      <itunes:title>Episode 106: July 16, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2352da1b-b309-49fc-a150-e68fd77128c7</guid>
      <link>https://share.transistor.fm/s/98dafaf3</link>
      <description>
        <![CDATA[This episode digs into the biggest patch wave in recent memory, with Microsoft dropping 622 fixes in a single day while browsers scramble to close exploited holes. We also explore how AI is now hunting vulnerabilities at scale—and how OpenAI built its own AI attacker to stress-test its models before hackers do.

Stories covered:
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (The Hacker News) - https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (The Hacker News) - https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html
- We built a vulnerability vending machine: AI tokens in, zero-days out (BleepingComputer) - https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/
- Meet GPT-Red: an LLM super-hacker OpenAI built to make its models safer - MIT Technology Review (MIT Technology Review) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxOaEZNa3ZZZUpGMGRLajIyY2pLTjduZmhTVHp1Q0VkNEl0X0lGVUs3aXRfb1lrRjlWSS1IckF0MV80X0Rxb2o0MU1VbU8zVVlNMElnOWhjdGp4Zlp3ZkRuOGlodnpwZmhJOWpvYnB6WVd0OXhnR2J1MHlFWUZ0ZlJ1cUpWTjFkMU1qV0JzZFBDZUVMRTFoVzhSZWNRWXZVTFdxRk1HMFhUYlpRQkRNdnZGNWFiS0h5VVFCNlNzMlRrdV_SAcYBQVVfeXFMTWtlMlUwMFM4STZCMTRXVlg5VngxWU04cVRndWRmdlRhWTM3aV9ZUHB1TFNSa0hpTmpQUFltTTc4ZGhFMFhNNTVYdGRHLTRFbUo3Qm9JaE8xZGktVTh2LUhGMU55QWQ0WWRmY1NSdm45a0JWbXptZ0NBYWgzTV9UQ0N0ZzBveUVoQ2VRZnc4V3VCYTMyUlVhSk9sMG1xR1hYMnZLUmUzbmZZOFllQ1dET1FTTHRCMGpIQWhtQXRqSmtYZWdBS2R3?oc=5
- Back-to-Back Long Runs Can Make You a More Durable Marathoner. Coaches Explain If and How You Should Add Them to Your Weekend. (Runner's World) - https://www.runnersworld.com/training/a71943389/back-to-back-long-runs/
- Permanent Daylight Saving Time Will Change When Runners Get Light. Here’s Who Wins and Loses. (Runner's World) - https://www.runnersworld.com/news/a72053098/permanent-daylight-saving-time-could-help-evening-runsand-hurt-morning-ones/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into the biggest patch wave in recent memory, with Microsoft dropping 622 fixes in a single day while browsers scramble to close exploited holes. We also explore how AI is now hunting vulnerabilities at scale—and how OpenAI built its own AI attacker to stress-test its models before hackers do.

Stories covered:
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (The Hacker News) - https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (The Hacker News) - https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html
- We built a vulnerability vending machine: AI tokens in, zero-days out (BleepingComputer) - https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/
- Meet GPT-Red: an LLM super-hacker OpenAI built to make its models safer - MIT Technology Review (MIT Technology Review) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxOaEZNa3ZZZUpGMGRLajIyY2pLTjduZmhTVHp1Q0VkNEl0X0lGVUs3aXRfb1lrRjlWSS1IckF0MV80X0Rxb2o0MU1VbU8zVVlNMElnOWhjdGp4Zlp3ZkRuOGlodnpwZmhJOWpvYnB6WVd0OXhnR2J1MHlFWUZ0ZlJ1cUpWTjFkMU1qV0JzZFBDZUVMRTFoVzhSZWNRWXZVTFdxRk1HMFhUYlpRQkRNdnZGNWFiS0h5VVFCNlNzMlRrdV_SAcYBQVVfeXFMTWtlMlUwMFM4STZCMTRXVlg5VngxWU04cVRndWRmdlRhWTM3aV9ZUHB1TFNSa0hpTmpQUFltTTc4ZGhFMFhNNTVYdGRHLTRFbUo3Qm9JaE8xZGktVTh2LUhGMU55QWQ0WWRmY1NSdm45a0JWbXptZ0NBYWgzTV9UQ0N0ZzBveUVoQ2VRZnc4V3VCYTMyUlVhSk9sMG1xR1hYMnZLUmUzbmZZOFllQ1dET1FTTHRCMGpIQWhtQXRqSmtYZWdBS2R3?oc=5
- Back-to-Back Long Runs Can Make You a More Durable Marathoner. Coaches Explain If and How You Should Add Them to Your Weekend. (Runner's World) - https://www.runnersworld.com/training/a71943389/back-to-back-long-runs/
- Permanent Daylight Saving Time Will Change When Runners Get Light. Here’s Who Wins and Loses. (Runner's World) - https://www.runnersworld.com/news/a72053098/permanent-daylight-saving-time-could-help-evening-runsand-hurt-morning-ones/]]>
      </content:encoded>
      <pubDate>Thu, 16 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/98dafaf3/4e2a7cbc.mp3" length="5530628" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>342</itunes:duration>
      <itunes:summary>This episode digs into the biggest patch wave in recent memory, with Microsoft dropping 622 fixes in a single day while browsers scramble to close exploited holes. We also explore how AI is now hunting vulnerabilities at scale—and how OpenAI built its own AI attacker to stress-test its models before hackers do.</itunes:summary>
      <itunes:subtitle>This episode digs into the biggest patch wave in recent memory, with Microsoft dropping 622 fixes in a single day while browsers scramble to close exploited holes. We also explore how AI is now hunting vulnerabilities at scale—and how OpenAI built its own</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 105: July 15, 2026</title>
      <itunes:episode>105</itunes:episode>
      <podcast:episode>105</podcast:episode>
      <itunes:title>Episode 105: July 15, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1d3dbc4e-bdcb-4381-9369-226e6352f0bc</guid>
      <link>https://share.transistor.fm/s/6db4d4a3</link>
      <description>
        <![CDATA[This episode digs into the massive Microsoft Patch Tuesday drop — 570 vulnerabilities including three zero-days — plus active exploits hitting SonicWall perimeter devices and Joomla extensions. Adrian North breaks down why the scale of these patches should concern us more than it does, and why smaller attack surfaces matter when third-party tools become the weakest link.

Stories covered:
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQb0M1Snc5Q1puWXZ6bXQ5Z01tWGJBeFJpaTBZek05YXQ4TWlacE1oVEUyaDNjaUNhQ1hzMzFVTFZmYVY1N2VWcDVkbXVzU2tBTjB1dzNZVnRYUUdvNUg4NUhGVGNQcVMzeVg2Unh4LU15WkRLdjdHSDVTM0t5V2xQMGY4SVU?oc=5
- WATCH: Should this be your next race cooling strategy? (Canadian Running) - https://runningmagazine.ca/sections/training/watch-should-this-be-your-next-race-cooling-strategy/
- TSA Traffic Increased at Virginia Airports Despite 2026 Funding Lapse - cbs19news.com (cbs19news.com) - https://news.google.com/rss/articles/CBMi7AFBVV95cUxQblI2YlNPUm0xdmY0ZWNma25CRVNIcERMS21KcUxtQnM3c2NPMVJRQm9tOUxMRlVjd1hKSWZ2Y0RuM283d3JpWG8zRUpmX3BMSnNYQzJTTU9oV3VnMEZjcnpPcFpqU2xLd3hTVzBISFpZMUlnNHJ5MF92M01XSlkwcTR2MzZvWDB1UGpIdEcyUEE3WXlOMEVnQndCdTdUUWJvTm5IakRTX1F1NGVzQ1czMzB5SWRlcC12SXRTd2N0cHVMcjhiNWN1NHRqSHFORkFBaDN5a2JNSmtzelZLMHhQWl9jckFtRnFidUp2cQ?oc=5
- Sotheby’s Big T. Rex Auction Raises Concerns Hype and Wealth Are Upending Science (Wired) - https://www.wired.com/story/sothebys-t-rex-auction-shows-wealth-upending-science/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into the massive Microsoft Patch Tuesday drop — 570 vulnerabilities including three zero-days — plus active exploits hitting SonicWall perimeter devices and Joomla extensions. Adrian North breaks down why the scale of these patches should concern us more than it does, and why smaller attack surfaces matter when third-party tools become the weakest link.

Stories covered:
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (BleepingComputer) - https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMihAFBVV95cUxQb0M1Snc5Q1puWXZ6bXQ5Z01tWGJBeFJpaTBZek05YXQ4TWlacE1oVEUyaDNjaUNhQ1hzMzFVTFZmYVY1N2VWcDVkbXVzU2tBTjB1dzNZVnRYUUdvNUg4NUhGVGNQcVMzeVg2Unh4LU15WkRLdjdHSDVTM0t5V2xQMGY4SVU?oc=5
- WATCH: Should this be your next race cooling strategy? (Canadian Running) - https://runningmagazine.ca/sections/training/watch-should-this-be-your-next-race-cooling-strategy/
- TSA Traffic Increased at Virginia Airports Despite 2026 Funding Lapse - cbs19news.com (cbs19news.com) - https://news.google.com/rss/articles/CBMi7AFBVV95cUxQblI2YlNPUm0xdmY0ZWNma25CRVNIcERMS21KcUxtQnM3c2NPMVJRQm9tOUxMRlVjd1hKSWZ2Y0RuM283d3JpWG8zRUpmX3BMSnNYQzJTTU9oV3VnMEZjcnpPcFpqU2xLd3hTVzBISFpZMUlnNHJ5MF92M01XSlkwcTR2MzZvWDB1UGpIdEcyUEE3WXlOMEVnQndCdTdUUWJvTm5IakRTX1F1NGVzQ1czMzB5SWRlcC12SXRTd2N0cHVMcjhiNWN1NHRqSHFORkFBaDN5a2JNSmtzelZLMHhQWl9jckFtRnFidUp2cQ?oc=5
- Sotheby’s Big T. Rex Auction Raises Concerns Hype and Wealth Are Upending Science (Wired) - https://www.wired.com/story/sothebys-t-rex-auction-shows-wealth-upending-science/]]>
      </content:encoded>
      <pubDate>Wed, 15 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/6db4d4a3/c8fb6de7.mp3" length="5815258" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>360</itunes:duration>
      <itunes:summary>This episode digs into the massive Microsoft Patch Tuesday drop — 570 vulnerabilities including three zero-days — plus active exploits hitting SonicWall perimeter devices and Joomla extensions. Adrian North breaks down why the scale of these patches should concern us more than it does, and why smaller attack surfaces matter when third-party tools become the weakest link.</itunes:summary>
      <itunes:subtitle>This episode digs into the massive Microsoft Patch Tuesday drop — 570 vulnerabilities including three zero-days — plus active exploits hitting SonicWall perimeter devices and Joomla extensions. Adrian North breaks down why the scale of these patches shoul</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 104: July 14, 2026</title>
      <itunes:episode>104</itunes:episode>
      <podcast:episode>104</podcast:episode>
      <itunes:title>Episode 104: July 14, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">66ca5af7-6b4c-4cc7-8277-f6b2c7d360b4</guid>
      <link>https://share.transistor.fm/s/969a88df</link>
      <description>
        <![CDATA[This episode covers Meta's newly filed patent for continuous emotional surveillance, a supply chain attack on Jscrambler's npm package that compromised developer credentials, and a joint intelligence warning about Russian hackers breaching critical infrastructure through weak router security. We also dig into Google and Microsoft pulling the ModHeader extension after it was caught secretly collecting browsing history from over a million users. It's Tuesday morning, and the signals are already loud.

Stories covered:
- Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling (The Hacker News) - https://thehackernews.com/2026/07/meta-files-patent-for-ai-that-can.html
- Hackers backdoor Jscrambler npm package with infostealer malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/
- Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn - Nextgov/FCW (Nextgov/FCW) - https://news.google.com/rss/articles/CBMi4wFBVV95cUxQTTY5SENyRlZva3duVzkxcmk3REdsbS1rbGxCMy1uV0RvWlM2VUxiYUt2VmNYYzVIbXlGOUFMTUJyaHdJaFppSGJfNTRZRHlTZG1nRXczMk5QMzJsc19tRThxOU9Ba2p0LUJSS21vR1NkeXhTVkowb29XZWg1ZEplWUljVWh6bElPZXA1MnhlLW96QnkwdVhQaWpvdW9EcWdDM1RRbkVKSVFfZWtEODVDQU5yUV9QVFE4d191Vy1aWURCV2VJSERKRDNNdDBsZ21yZzAtUUVjX0hnWVBEdl9SUVFpWQ?oc=5
- Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found (The Hacker News) - https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
- ‘Like Good Wine’: 50-Year-Old Ludo Pommeret Wins His Third Consecutive Hardrock 100 (Runner's World) - https://www.runnersworld.com/news/a71906245/ludo-pommeret-wins-2026-hardrock-100/
- Show HN: ContextVault – Shared memory layer for your AI and your team (Hacker News) - https://www.contextvault.dev/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers Meta's newly filed patent for continuous emotional surveillance, a supply chain attack on Jscrambler's npm package that compromised developer credentials, and a joint intelligence warning about Russian hackers breaching critical infrastructure through weak router security. We also dig into Google and Microsoft pulling the ModHeader extension after it was caught secretly collecting browsing history from over a million users. It's Tuesday morning, and the signals are already loud.

Stories covered:
- Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling (The Hacker News) - https://thehackernews.com/2026/07/meta-files-patent-for-ai-that-can.html
- Hackers backdoor Jscrambler npm package with infostealer malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/
- Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn - Nextgov/FCW (Nextgov/FCW) - https://news.google.com/rss/articles/CBMi4wFBVV95cUxQTTY5SENyRlZva3duVzkxcmk3REdsbS1rbGxCMy1uV0RvWlM2VUxiYUt2VmNYYzVIbXlGOUFMTUJyaHdJaFppSGJfNTRZRHlTZG1nRXczMk5QMzJsc19tRThxOU9Ba2p0LUJSS21vR1NkeXhTVkowb29XZWg1ZEplWUljVWh6bElPZXA1MnhlLW96QnkwdVhQaWpvdW9EcWdDM1RRbkVKSVFfZWtEODVDQU5yUV9QVFE4d191Vy1aWURCV2VJSERKRDNNdDBsZ21yZzAtUUVjX0hnWVBEdl9SUVFpWQ?oc=5
- Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found (The Hacker News) - https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
- ‘Like Good Wine’: 50-Year-Old Ludo Pommeret Wins His Third Consecutive Hardrock 100 (Runner's World) - https://www.runnersworld.com/news/a71906245/ludo-pommeret-wins-2026-hardrock-100/
- Show HN: ContextVault – Shared memory layer for your AI and your team (Hacker News) - https://www.contextvault.dev/]]>
      </content:encoded>
      <pubDate>Tue, 14 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/969a88df/dbe183ac.mp3" length="5954856" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>369</itunes:duration>
      <itunes:summary>This episode covers Meta's newly filed patent for continuous emotional surveillance, a supply chain attack on Jscrambler's npm package that compromised developer credentials, and a joint intelligence warning about Russian hackers breaching critical infrastructure through weak router security. We also dig into Google and Microsoft pulling the ModHeader extension after it was caught secretly collecting browsing history from over a million users. It's Tuesday morning, and the signals are already loud.</itunes:summary>
      <itunes:subtitle>This episode covers Meta's newly filed patent for continuous emotional surveillance, a supply chain attack on Jscrambler's npm package that compromised developer credentials, and a joint intelligence warning about Russian hackers breaching critical infras</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 103: July 13, 2026</title>
      <itunes:episode>103</itunes:episode>
      <podcast:episode>103</podcast:episode>
      <itunes:title>Episode 103: July 13, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8133bd94-b1de-4929-80d6-308bab85dbe8</guid>
      <link>https://share.transistor.fm/s/6ca6a6cf</link>
      <description>
        <![CDATA[This episode covers six security signals that dropped overnight, including a new Android malware called RedHook that exploits wireless debugging features to gain shell access without triggering USB prompts. Adrian also digs into why free VPN apps are mostly trash and why posting photos of your house keys online is a very bad idea.

Stories covered:
- RedHook Android malware now uses Wireless ADB for shell access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/
- Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMifkFVX3lxTE5aTXlBbS1qN3ExV2ZQNVE2V1EyTEMwcnJkV0hoRFh4bFdoaERsOUdObjB2X2xiLXV5YnlFdG5XMzhoY2h3WXR1YW9aa2E4Z0ozZm5zci1qYjZzUWhvOVctdVJRdldCdjVnWHA5elZOVGZkLVdWMENLZGNXazUyUQ?oc=5
- Hacker Explains Why You Shouldn’t Post Your House Keys on Social Media - Newsweek (Newsweek) - https://news.google.com/rss/articles/CBMipgFBVV95cUxQemhPQ2lrdkk4UTNNdHJ0ZVQtbENDQ05Dcnd3ZGY1QWIzRkRfZS03ZVVmeklDSWpNWDF2bV9tM0FJUnFZVDF4cnZzME5naUpUT3FlNDFtR0ROclBrMnRMYWFDNUxzY2ljQVFCRFdwM1l3amdDMjEtdGlvSVhHaUVjb2dYVk9IdURRbFNiQ1ExekdvVmJ5cXRkTTRQYUhWOEphbFlNMWVn?oc=5
- Why Your Ultramarathon Training Plan Isn’t Working (And How to Fix It) (Trail Runner Mag) - https://www.trailrunnermag.com/training/is-your-ultramarathon-training-plan-good-enough/
- ‘Like Good Wine’: 50-Year-Old Ludo Pommeret Wins His Third Consecutive Hardrock 100 (Runner's World) - https://www.runnersworld.com/news/a71906245/ludo-pommeret-wins-2026-hardrock-100/
- China recovered its first reusable rocket and showed a new way to do it (Ars Technica) - https://arstechnica.com/space/2026/07/china-recovered-its-first-reusable-rocket-and-showed-a-new-way-to-do-it/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers six security signals that dropped overnight, including a new Android malware called RedHook that exploits wireless debugging features to gain shell access without triggering USB prompts. Adrian also digs into why free VPN apps are mostly trash and why posting photos of your house keys online is a very bad idea.

Stories covered:
- RedHook Android malware now uses Wireless ADB for shell access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/
- Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMifkFVX3lxTE5aTXlBbS1qN3ExV2ZQNVE2V1EyTEMwcnJkV0hoRFh4bFdoaERsOUdObjB2X2xiLXV5YnlFdG5XMzhoY2h3WXR1YW9aa2E4Z0ozZm5zci1qYjZzUWhvOVctdVJRdldCdjVnWHA5elZOVGZkLVdWMENLZGNXazUyUQ?oc=5
- Hacker Explains Why You Shouldn’t Post Your House Keys on Social Media - Newsweek (Newsweek) - https://news.google.com/rss/articles/CBMipgFBVV95cUxQemhPQ2lrdkk4UTNNdHJ0ZVQtbENDQ05Dcnd3ZGY1QWIzRkRfZS03ZVVmeklDSWpNWDF2bV9tM0FJUnFZVDF4cnZzME5naUpUT3FlNDFtR0ROclBrMnRMYWFDNUxzY2ljQVFCRFdwM1l3amdDMjEtdGlvSVhHaUVjb2dYVk9IdURRbFNiQ1ExekdvVmJ5cXRkTTRQYUhWOEphbFlNMWVn?oc=5
- Why Your Ultramarathon Training Plan Isn’t Working (And How to Fix It) (Trail Runner Mag) - https://www.trailrunnermag.com/training/is-your-ultramarathon-training-plan-good-enough/
- ‘Like Good Wine’: 50-Year-Old Ludo Pommeret Wins His Third Consecutive Hardrock 100 (Runner's World) - https://www.runnersworld.com/news/a71906245/ludo-pommeret-wins-2026-hardrock-100/
- China recovered its first reusable rocket and showed a new way to do it (Ars Technica) - https://arstechnica.com/space/2026/07/china-recovered-its-first-reusable-rocket-and-showed-a-new-way-to-do-it/]]>
      </content:encoded>
      <pubDate>Mon, 13 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/6ca6a6cf/1257e19f.mp3" length="6645743" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>412</itunes:duration>
      <itunes:summary>This episode covers six security signals that dropped overnight, including a new Android malware called RedHook that exploits wireless debugging features to gain shell access without triggering USB prompts. Adrian also digs into why free VPN apps are mostly trash and why posting photos of your house keys online is a very bad idea.</itunes:summary>
      <itunes:subtitle>This episode covers six security signals that dropped overnight, including a new Android malware called RedHook that exploits wireless debugging features to gain shell access without triggering USB prompts. Adrian also digs into why free VPN apps are most</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 102: July 12, 2026</title>
      <itunes:episode>102</itunes:episode>
      <podcast:episode>102</podcast:episode>
      <itunes:title>Episode 102: July 12, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">41acd990-d6d9-4687-a71e-6360ac7aab03</guid>
      <link>https://share.transistor.fm/s/afc42666</link>
      <description>
        <![CDATA[This episode covers a triple threat in Balochistan where Chinese and Indian hackers targeted the same police database, Progress Software's emergency weekend shutdown order for ShareFile customers, and Accenture's confirmed source code breach. Adrian also touches on a Runner's World reset plan that applies beyond the track. Signal Check delivers your Sunday morning cybersecurity briefing before the world wakes up.

Stories covered:
- Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns (The Hacker News) - https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html
- URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat (The Hacker News) - https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- Steal This 3-Step Plan to Get Out of a Running Rut and Rebuild Momentum (Runner's World) - https://www.runnersworld.com/training/a71884482/3-step-running-comeback/
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install (The Hacker News) - https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
- Weightlifting beats running for blood sugar control, researchers find (Hacker News) - https://news.vt.edu/articles/2025/11/research_fralinbiomed_yanweightlifting.html]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a triple threat in Balochistan where Chinese and Indian hackers targeted the same police database, Progress Software's emergency weekend shutdown order for ShareFile customers, and Accenture's confirmed source code breach. Adrian also touches on a Runner's World reset plan that applies beyond the track. Signal Check delivers your Sunday morning cybersecurity briefing before the world wakes up.

Stories covered:
- Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns (The Hacker News) - https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html
- URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat (The Hacker News) - https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- Steal This 3-Step Plan to Get Out of a Running Rut and Rebuild Momentum (Runner's World) - https://www.runnersworld.com/training/a71884482/3-step-running-comeback/
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install (The Hacker News) - https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
- Weightlifting beats running for blood sugar control, researchers find (Hacker News) - https://news.vt.edu/articles/2025/11/research_fralinbiomed_yanweightlifting.html]]>
      </content:encoded>
      <pubDate>Sun, 12 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/afc42666/cea4ee0c.mp3" length="5026569" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>311</itunes:duration>
      <itunes:summary>This episode covers a triple threat in Balochistan where Chinese and Indian hackers targeted the same police database, Progress Software's emergency weekend shutdown order for ShareFile customers, and Accenture's confirmed source code breach. Adrian also touches on a Runner's World reset plan that applies beyond the track. Signal Check delivers your Sunday morning cybersecurity briefing before the world wakes up.</itunes:summary>
      <itunes:subtitle>This episode covers a triple threat in Balochistan where Chinese and Indian hackers targeted the same police database, Progress Software's emergency weekend shutdown order for ShareFile customers, and Accenture's confirmed source code breach. Adrian also </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 101: July 11, 2026</title>
      <itunes:episode>101</itunes:episode>
      <podcast:episode>101</podcast:episode>
      <itunes:title>Episode 101: July 11, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b755a3dd-1092-4c4e-be8c-4a449e4ea6fa</guid>
      <link>https://share.transistor.fm/s/c16c1cd7</link>
      <description>
        <![CDATA[This episode covers a wave of critical security developments, from an Armenian national pleading guilty to deploying Ryuk ransomware to a severe authentication bypass being actively exploited in Gitea's Docker image. Adrian also digs into GhostLock, a fifteen-year-old Linux kernel flaw that's been hiding in plain sight, reminding us that even the most scrutinized code still harbors ghosts.

Stories covered:
- Ryuk ransomware member pleads guilty in the US, faces 15 years in prison (BleepingComputer) - https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/
- Hackers exploit critical auth bypass in Gitea Docker image (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-auth-bypass-in-gitea-docker-image/
- GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years (Hacker News) - https://nebusec.ai/research/ionstack-part-2/
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- This Ultrarunner Covered 425 Miles Up the U.K.’s Highest Points—and Smashed the Fastest Known Time (Runner's World) - https://www.runnersworld.com/news/a71872563/trish-patterson-three-peaks-challenge-world-record/
- China recovered its first reusable rocket and showed a new way to do it (Ars Technica) - https://arstechnica.com/space/2026/07/china-recovered-its-first-reusable-rocket-and-showed-a-new-way-to-do-it/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a wave of critical security developments, from an Armenian national pleading guilty to deploying Ryuk ransomware to a severe authentication bypass being actively exploited in Gitea's Docker image. Adrian also digs into GhostLock, a fifteen-year-old Linux kernel flaw that's been hiding in plain sight, reminding us that even the most scrutinized code still harbors ghosts.

Stories covered:
- Ryuk ransomware member pleads guilty in the US, faces 15 years in prison (BleepingComputer) - https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/
- Hackers exploit critical auth bypass in Gitea Docker image (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-auth-bypass-in-gitea-docker-image/
- GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years (Hacker News) - https://nebusec.ai/research/ionstack-part-2/
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- This Ultrarunner Covered 425 Miles Up the U.K.’s Highest Points—and Smashed the Fastest Known Time (Runner's World) - https://www.runnersworld.com/news/a71872563/trish-patterson-three-peaks-challenge-world-record/
- China recovered its first reusable rocket and showed a new way to do it (Ars Technica) - https://arstechnica.com/space/2026/07/china-recovered-its-first-reusable-rocket-and-showed-a-new-way-to-do-it/]]>
      </content:encoded>
      <pubDate>Sat, 11 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/c16c1cd7/463ab826.mp3" length="5963216" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>369</itunes:duration>
      <itunes:summary>This episode covers a wave of critical security developments, from an Armenian national pleading guilty to deploying Ryuk ransomware to a severe authentication bypass being actively exploited in Gitea's Docker image. Adrian also digs into GhostLock, a fifteen-year-old Linux kernel flaw that's been hiding in plain sight, reminding us that even the most scrutinized code still harbors ghosts.</itunes:summary>
      <itunes:subtitle>This episode covers a wave of critical security developments, from an Armenian national pleading guilty to deploying Ryuk ransomware to a severe authentication bypass being actively exploited in Gitea's Docker image. Adrian also digs into GhostLock, a fif</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 100: July 10, 2026</title>
      <itunes:episode>100</itunes:episode>
      <podcast:episode>100</podcast:episode>
      <itunes:title>Episode 100: July 10, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">28338626-4ac8-4e5d-8126-6898dc0effc4</guid>
      <link>https://share.transistor.fm/s/aeba553e</link>
      <description>
        <![CDATA[This episode covers a Microsoft Defender patch that came dangerously late, how Windows telemetry helped nab a cybercriminal, and a supply chain attack that hit the Web3 ecosystem hard. We also dig into an Accenture data breach that could ripple across their massive client base, plus a quick detour into ultramarathon training strategy that's all about working smarter, not harder.

Stories covered:
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges (The Hacker News) - https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html
- Arrest and extradition of Scattered Spider hacker shines light on how Windows telemetry GDIDs can identify and track users — Microsoft device identifier is just one digital fingerprint in a software world rife with them - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMi_gJBVV95cUxNMVI1NVZ4emxVYWtuZlFIdU9OTTEtVlRxUENPUUVDWHZKLUJOVHZOV1hnSk9IRjd3clVza0pSRE8wYjVWdUxET1hOemp1ZHp0Z2wzYmMzVG9mU1o3OXJyb3N6c3dON01zUzFNSTVOQlh0aHVrdmVCUEhTMlFiUmhRLTUxZC13S2tpVmFpTXlkbU45b2NBVnhZb0trZUczeEp6ZFo0NFJKb01YM0NVNG9BWDJsRkp5dUY3aGk4RmExalFjUzFFOE5zYTFkOEdhVXhMRGRzWlhaSzdneTJ1dWd5R0Z5bFp3ekhBZjczN2stUjNJNUNFbzRGb2ZGeFFaczlyRF9ibjJ0N1ZCSFVsRFpDNjF5dVIzc2dmRTBoODNJRXpxSC1XeVFrTElrR2ZqbDJ0UnU2c09rYm9LOGh6aUVEWDROd1hDeHpxeTJoQmdUQ0NDcTlwNXNiU3ItS1VkRkJrQU10d0RJVDI2ZFY1VjA4bFVuOUdiVEZWX0p2enpn?oc=5
- Injective SDK on npm infected with cryptocurrency wallet stealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- Why Your Ultramarathon Training Plan Isn’t Working (And How to Fix It) (Trail Runner Mag) - https://www.trailrunnermag.com/training/is-your-ultramarathon-training-plan-good-enough/
- This Ultrarunner Covered 425 Miles Up the U.K.’s Highest Points—and Smashed the Fastest Known Time (Runner's World) - https://www.runnersworld.com/news/a71872563/trish-patterson-three-peaks-challenge-world-record/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a Microsoft Defender patch that came dangerously late, how Windows telemetry helped nab a cybercriminal, and a supply chain attack that hit the Web3 ecosystem hard. We also dig into an Accenture data breach that could ripple across their massive client base, plus a quick detour into ultramarathon training strategy that's all about working smarter, not harder.

Stories covered:
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges (The Hacker News) - https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html
- Arrest and extradition of Scattered Spider hacker shines light on how Windows telemetry GDIDs can identify and track users — Microsoft device identifier is just one digital fingerprint in a software world rife with them - Tom's Hardware (Tom's Hardware) - https://news.google.com/rss/articles/CBMi_gJBVV95cUxNMVI1NVZ4emxVYWtuZlFIdU9OTTEtVlRxUENPUUVDWHZKLUJOVHZOV1hnSk9IRjd3clVza0pSRE8wYjVWdUxET1hOemp1ZHp0Z2wzYmMzVG9mU1o3OXJyb3N6c3dON01zUzFNSTVOQlh0aHVrdmVCUEhTMlFiUmhRLTUxZC13S2tpVmFpTXlkbU45b2NBVnhZb0trZUczeEp6ZFo0NFJKb01YM0NVNG9BWDJsRkp5dUY3aGk4RmExalFjUzFFOE5zYTFkOEdhVXhMRGRzWlhaSzdneTJ1dWd5R0Z5bFp3ekhBZjczN2stUjNJNUNFbzRGb2ZGeFFaczlyRF9ibjJ0N1ZCSFVsRFpDNjF5dVIzc2dmRTBoODNJRXpxSC1XeVFrTElrR2ZqbDJ0UnU2c09rYm9LOGh6aUVEWDROd1hDeHpxeTJoQmdUQ0NDcTlwNXNiU3ItS1VkRkJrQU10d0RJVDI2ZFY1VjA4bFVuOUdiVEZWX0p2enpn?oc=5
- Injective SDK on npm infected with cryptocurrency wallet stealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5
- Why Your Ultramarathon Training Plan Isn’t Working (And How to Fix It) (Trail Runner Mag) - https://www.trailrunnermag.com/training/is-your-ultramarathon-training-plan-good-enough/
- This Ultrarunner Covered 425 Miles Up the U.K.’s Highest Points—and Smashed the Fastest Known Time (Runner's World) - https://www.runnersworld.com/news/a71872563/trish-patterson-three-peaks-challenge-world-record/]]>
      </content:encoded>
      <pubDate>Fri, 10 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/aeba553e/63636df5.mp3" length="4322308" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>267</itunes:duration>
      <itunes:summary>This episode covers a Microsoft Defender patch that came dangerously late, how Windows telemetry helped nab a cybercriminal, and a supply chain attack that hit the Web3 ecosystem hard. We also dig into an Accenture data breach that could ripple across their massive client base, plus a quick detour into ultramarathon training strategy that's all about working smarter, not harder.</itunes:summary>
      <itunes:subtitle>This episode covers a Microsoft Defender patch that came dangerously late, how Windows telemetry helped nab a cybercriminal, and a supply chain attack that hit the Web3 ecosystem hard. We also dig into an Accenture data breach that could ripple across the</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 99: July 09, 2026</title>
      <itunes:episode>99</itunes:episode>
      <podcast:episode>99</podcast:episode>
      <itunes:title>Episode 99: July 09, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8d12f565-d407-4471-bb9a-a29788a098b8</guid>
      <link>https://share.transistor.fm/s/2172fc8f</link>
      <description>
        <![CDATA[This episode covers critical security patches from Ubiquiti for UniFi gear, a fifteen-year-old Linux kernel flaw called GhostLock that allows privilege escalation, and a solo attacker who breached AWS in just seventy-two hours using AI and cloud misconfigurations. We also touch on sustainable optimization strategies and John Deere's landmark right-to-repair settlement with the FTC.

Stories covered:
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS (The Hacker News) - https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros (The Hacker News) - https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
- Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours (Dark Reading) - https://www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
- Is High Mileage Right for You? Experts Break Down How to Find Your Volume Sweet Spot (Runner's World) - https://www.runnersworld.com/training/a71841267/low-mileage-vs-high-mileage-runner/
- John Deere owners will get the right to repair equipment under FTC settlement (Hacker News) - https://apnews.com/article/john-deere-right-to-repair-agriculture-equipment-cb7514ffedb95c130a976af661f2bc02
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers critical security patches from Ubiquiti for UniFi gear, a fifteen-year-old Linux kernel flaw called GhostLock that allows privilege escalation, and a solo attacker who breached AWS in just seventy-two hours using AI and cloud misconfigurations. We also touch on sustainable optimization strategies and John Deere's landmark right-to-repair settlement with the FTC.

Stories covered:
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS (The Hacker News) - https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros (The Hacker News) - https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
- Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours (Dark Reading) - https://www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
- Is High Mileage Right for You? Experts Break Down How to Find Your Volume Sweet Spot (Runner's World) - https://www.runnersworld.com/training/a71841267/low-mileage-vs-high-mileage-runner/
- John Deere owners will get the right to repair equipment under FTC settlement (Hacker News) - https://apnews.com/article/john-deere-right-to-repair-agriculture-equipment-cb7514ffedb95c130a976af661f2bc02
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek (SecurityWeek) - https://news.google.com/rss/articles/CBMinwFBVV95cUxOaThuTEIyMF9sRV85UnpwMlBneHY2ZHhral94MS1ETXRhMUZGS3pwaXBPUmtzdHprUFBuVk1YQjF6SnM2UFNHQmpWdDg0STFuSjNpNkZBX1ZDbEhMNFFmZTZGSlJseXRSSm1VdDBTamhBSDdEQXdldnY4MzR2cFVubV8wcTdRV0FHUjJMUDhfTnUxckVMalRScGVIMG1DRknSAaQBQVVfeXFMTUNsbVlvOVhoUE5nNEY2SEl1b3JpbjA5R3JIbWJfX0JKVDAxNXBldVJQandxRWwtdUFkSVBUMkRhV2pDLXNJbm1DVXRsMGZjYk54clR6ZFFOUmIyWTA1TU1pSDQ5cmhySF90RmJDWE5KTDhkUDE1eU1UY3FXekNLRF9PZ0ZObURBdVljUFg5QXRGT0VlbDR1YXZyTjAzeHoxWGFiek0?oc=5]]>
      </content:encoded>
      <pubDate>Thu, 09 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/2172fc8f/a3b1daa7.mp3" length="4649568" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>287</itunes:duration>
      <itunes:summary>This episode covers critical security patches from Ubiquiti for UniFi gear, a fifteen-year-old Linux kernel flaw called GhostLock that allows privilege escalation, and a solo attacker who breached AWS in just seventy-two hours using AI and cloud misconfigurations. We also touch on sustainable optimization strategies and John Deere's landmark right-to-repair settlement with the FTC.</itunes:summary>
      <itunes:subtitle>This episode covers critical security patches from Ubiquiti for UniFi gear, a fifteen-year-old Linux kernel flaw called GhostLock that allows privilege escalation, and a solo attacker who breached AWS in just seventy-two hours using AI and cloud misconfig</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 98: July 08, 2026</title>
      <itunes:episode>98</itunes:episode>
      <podcast:episode>98</podcast:episode>
      <itunes:title>Episode 98: July 08, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">06ec7e1d-a27c-49fd-b8f0-0473d78f2939</guid>
      <link>https://share.transistor.fm/s/eae5fd84</link>
      <description>
        <![CDATA[This episode digs into a sixteen-year-old Linux kernel flaw that's been lurking in virtualized systems, Accenture's messy data breach with source code now up for sale, and a hidden backdoor baked into Tenda router firmware. We also cover GitHub's GitLost vulnerability that lets attackers pull private data through public repos, plus the usual reminder that scale and reputation don't make anyone immune.

Stories covered:
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems (The Hacker News) - https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html
- Accenture confirms breach after hacker offers stolen data for sale (BleepingComputer) - https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
- Hidden backdoor in Tenda router firmware grants admin access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
- 'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows (Dark Reading) - https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
- Everything You Need To Know About The 2026 Hardrock 100 (Marathon Handbook) - https://marathonhandbook.com/everything-you-need-to-know-about-the-2026-hardrock-100/
- He Took 26 Days to Run the London Marathon—and Made Marathons Harder on Purpose (Runner's World) - https://www.runnersworld.com/news/a71855030/a-diving-suit-a-300-pound-dragon-and-the-remarkable-running-career-of-lloyd-scott/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a sixteen-year-old Linux kernel flaw that's been lurking in virtualized systems, Accenture's messy data breach with source code now up for sale, and a hidden backdoor baked into Tenda router firmware. We also cover GitHub's GitLost vulnerability that lets attackers pull private data through public repos, plus the usual reminder that scale and reputation don't make anyone immune.

Stories covered:
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems (The Hacker News) - https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html
- Accenture confirms breach after hacker offers stolen data for sale (BleepingComputer) - https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
- Hidden backdoor in Tenda router firmware grants admin access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
- 'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows (Dark Reading) - https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
- Everything You Need To Know About The 2026 Hardrock 100 (Marathon Handbook) - https://marathonhandbook.com/everything-you-need-to-know-about-the-2026-hardrock-100/
- He Took 26 Days to Run the London Marathon—and Made Marathons Harder on Purpose (Runner's World) - https://www.runnersworld.com/news/a71855030/a-diving-suit-a-300-pound-dragon-and-the-remarkable-running-career-of-lloyd-scott/]]>
      </content:encoded>
      <pubDate>Wed, 08 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/eae5fd84/73a0291a.mp3" length="5588304" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>346</itunes:duration>
      <itunes:summary>This episode digs into a sixteen-year-old Linux kernel flaw that's been lurking in virtualized systems, Accenture's messy data breach with source code now up for sale, and a hidden backdoor baked into Tenda router firmware. We also cover GitHub's GitLost vulnerability that lets attackers pull private data through public repos, plus the usual reminder that scale and reputation don't make anyone immune.</itunes:summary>
      <itunes:subtitle>This episode digs into a sixteen-year-old Linux kernel flaw that's been lurking in virtualized systems, Accenture's messy data breach with source code now up for sale, and a hidden backdoor baked into Tenda router firmware. We also cover GitHub's GitLost </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 97: July 07, 2026</title>
      <itunes:episode>97</itunes:episode>
      <podcast:episode>97</podcast:episode>
      <itunes:title>Episode 97: July 07, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9f4691e6-26f8-4d63-bb0b-573a4add8f04</guid>
      <link>https://share.transistor.fm/s/f512b15d</link>
      <description>
        <![CDATA[This episode covers a critical Gitea Docker vulnerability exploited just thirteen days after patching, the first fully autonomous LLM-driven ransomware attack called JadePuffer, and a sixteen-year-old KVM hypervisor flaw that lets guest VMs escape to the host. Adrian also digs into how Microsoft used Windows hardware IDs to track down a hacker, proving your device might be less anonymous than you think.

Stories covered:
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure (The Hacker News) - https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html
- JadePuffer: The First Complete LLM-Driven Ransomware Attack (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems (The Hacker News) - https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html
- A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID - PCMag (PCMag) - https://news.google.com/rss/articles/CBMinwFBVV95cUxPR18tcjN4al9USHhMQ01vUHh3dm54MHVjLUZFTGxqWGhiQzdGSjg5VXJ2T1k4TEp4MTM2a2RnalV2U3JnXzc0NUdFRG9GNUM0a29CZ21oVG5mcmpCTFE5N1UtWi15WDJOakRIRjgyQjBtSm00ZnBtRFZSVndJLWtlVjIxNDZBSTM5c09iV3RlNS15bnM0Wl9jUWRkay1FREU?oc=5
- Jess McClain Took a 2-Year Break From Running—and Came Back Faster Than Ever. Here’s What You Can Learn From Her Impressive Return. (Runner's World) - https://www.runnersworld.com/training/a71834305/jess-mcclain-comeback-lessons/
- Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year (TechCrunch) - https://techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Gitea Docker vulnerability exploited just thirteen days after patching, the first fully autonomous LLM-driven ransomware attack called JadePuffer, and a sixteen-year-old KVM hypervisor flaw that lets guest VMs escape to the host. Adrian also digs into how Microsoft used Windows hardware IDs to track down a hacker, proving your device might be less anonymous than you think.

Stories covered:
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure (The Hacker News) - https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html
- JadePuffer: The First Complete LLM-Driven Ransomware Attack (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems (The Hacker News) - https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html
- A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID - PCMag (PCMag) - https://news.google.com/rss/articles/CBMinwFBVV95cUxPR18tcjN4al9USHhMQ01vUHh3dm54MHVjLUZFTGxqWGhiQzdGSjg5VXJ2T1k4TEp4MTM2a2RnalV2U3JnXzc0NUdFRG9GNUM0a29CZ21oVG5mcmpCTFE5N1UtWi15WDJOakRIRjgyQjBtSm00ZnBtRFZSVndJLWtlVjIxNDZBSTM5c09iV3RlNS15bnM0Wl9jUWRkay1FREU?oc=5
- Jess McClain Took a 2-Year Break From Running—and Came Back Faster Than Ever. Here’s What You Can Learn From Her Impressive Return. (Runner's World) - https://www.runnersworld.com/training/a71834305/jess-mcclain-comeback-lessons/
- Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year (TechCrunch) - https://techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/]]>
      </content:encoded>
      <pubDate>Tue, 07 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/f512b15d/64551d1b.mp3" length="5154045" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>319</itunes:duration>
      <itunes:summary>This episode covers a critical Gitea Docker vulnerability exploited just thirteen days after patching, the first fully autonomous LLM-driven ransomware attack called JadePuffer, and a sixteen-year-old KVM hypervisor flaw that lets guest VMs escape to the host. Adrian also digs into how Microsoft used Windows hardware IDs to track down a hacker, proving your device might be less anonymous than you think.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Gitea Docker vulnerability exploited just thirteen days after patching, the first fully autonomous LLM-driven ransomware attack called JadePuffer, and a sixteen-year-old KVM hypervisor flaw that lets guest VMs escape to the </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 96: July 06, 2026</title>
      <itunes:episode>96</itunes:episode>
      <podcast:episode>96</podcast:episode>
      <itunes:title>Episode 96: July 06, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c2c5e5ee-12ed-441e-982c-afe84fe6ce92</guid>
      <link>https://share.transistor.fm/s/5107d175</link>
      <description>
        <![CDATA[This episode covers North Korean hackers flooding developer repositories with over a hundred malicious packages, new credential-stealing tactics like ConsentFix that bypass multi-factor authentication in seconds, and a critical SharePoint vulnerability now being actively exploited two months after its patch. We also dig into what researchers believe is the first fully AI-automated ransomware attack, marking a dangerous new milestone in cyber threats.

Stories covered:
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign (The Hacker News) - https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html
- ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds (BleepingComputer) - https://www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- How ethical hackers with just a $3,000 server found a flaw that could've put $70 billion in crypto at risk - CoinDesk (CoinDesk) - https://news.google.com/rss/articles/CBMi5gFBVV95cUxNSnp0OTJqdUNpN0JSaEZ5bXRFNG5naDNmMDRCdndwUWdSS295Uy1VZU9SaEwtWVZIcHBDWE03ZnNELWdYc05POXA0dHZwWEdnRGZxUEktODNZY1BtSGxtZ1pENlp5cXVLQ3hTSHd4U3lWaW41MmxORUoxM0pQV01FTDAydUd0dUp6SXJCTGcxbkYydng3STM4NTRKOEhOSDZyeUJrRkRKYmxYOWJsNGVfc0lzNDRHcGtvRENQOHVKSTRSNG1ZSmtVUEVKbEJWZ3RNd1dVd1dhRmNpMTRXVTkzZHZtdk5CQQ?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers North Korean hackers flooding developer repositories with over a hundred malicious packages, new credential-stealing tactics like ConsentFix that bypass multi-factor authentication in seconds, and a critical SharePoint vulnerability now being actively exploited two months after its patch. We also dig into what researchers believe is the first fully AI-automated ransomware attack, marking a dangerous new milestone in cyber threats.

Stories covered:
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign (The Hacker News) - https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html
- ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds (BleepingComputer) - https://www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- How ethical hackers with just a $3,000 server found a flaw that could've put $70 billion in crypto at risk - CoinDesk (CoinDesk) - https://news.google.com/rss/articles/CBMi5gFBVV95cUxNSnp0OTJqdUNpN0JSaEZ5bXRFNG5naDNmMDRCdndwUWdSS295Uy1VZU9SaEwtWVZIcHBDWE03ZnNELWdYc05POXA0dHZwWEdnRGZxUEktODNZY1BtSGxtZ1pENlp5cXVLQ3hTSHd4U3lWaW41MmxORUoxM0pQV01FTDAydUd0dUp6SXJCTGcxbkYydng3STM4NTRKOEhOSDZyeUJrRkRKYmxYOWJsNGVfc0lzNDRHcGtvRENQOHVKSTRSNG1ZSmtVUEVKbEJWZ3RNd1dVd1dhRmNpMTRXVTkzZHZtdk5CQQ?oc=5]]>
      </content:encoded>
      <pubDate>Mon, 06 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/5107d175/7399b142.mp3" length="5880040" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>364</itunes:duration>
      <itunes:summary>This episode covers North Korean hackers flooding developer repositories with over a hundred malicious packages, new credential-stealing tactics like ConsentFix that bypass multi-factor authentication in seconds, and a critical SharePoint vulnerability now being actively exploited two months after its patch. We also dig into what researchers believe is the first fully AI-automated ransomware attack, marking a dangerous new milestone in cyber threats.</itunes:summary>
      <itunes:subtitle>This episode covers North Korean hackers flooding developer repositories with over a hundred malicious packages, new credential-stealing tactics like ConsentFix that bypass multi-factor authentication in seconds, and a critical SharePoint vulnerability no</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 95: July 05, 2026</title>
      <itunes:episode>95</itunes:episode>
      <podcast:episode>95</podcast:episode>
      <itunes:title>Episode 95: July 05, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d7b23ed0-960b-4de4-8d99-8c29714a5c3f</guid>
      <link>https://share.transistor.fm/s/84523594</link>
      <description>
        <![CDATA[This episode digs into a Scattered Spider extradition, the first fully AI-driven ransomware attack, and a Tesla bug bounty that uncovered a $243 million flaw. We also cover an actively exploited SharePoint vulnerability and what it means when the tools running half the enterprise become the entry point.

Stories covered:
- Alleged Scattered Spider hacker extradited to the United States (BleepingComputer) - https://www.bleepingcomputer.com/news/security/alleged-scattered-spider-hacker-extradited-to-the-united-states/
- JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
- Tesla paid a Russian hacker $15,000 per bug found — then he cracked open the case that cost them $243 million - Yahoo Finance (Yahoo Finance) - https://news.google.com/rss/articles/CBMilwFBVV95cUxOdnNiS0VBcTZqY3NOVzRjYXFLejRpeDYzRmpCV3J6QUlnRXhjVU80VHh6MXZnYV9pZVhmY0x6X21QcHUzanp5RW1kTkxTLUlMWHFXSGNLWWZiS0ZmZFI0ekpLWk1OczlOTXpCNTF5ZDVrMWwwN196bUFpRFVKNWg0STR6bkNUTlJoQzN4ZnNyNE9idUtHdkxn?oc=5
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- FBI Seizes NetNut Proxy Platform, Popa Botnet (Krebs on Security) - https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a Scattered Spider extradition, the first fully AI-driven ransomware attack, and a Tesla bug bounty that uncovered a $243 million flaw. We also cover an actively exploited SharePoint vulnerability and what it means when the tools running half the enterprise become the entry point.

Stories covered:
- Alleged Scattered Spider hacker extradited to the United States (BleepingComputer) - https://www.bleepingcomputer.com/news/security/alleged-scattered-spider-hacker-extradited-to-the-united-states/
- JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
- Tesla paid a Russian hacker $15,000 per bug found — then he cracked open the case that cost them $243 million - Yahoo Finance (Yahoo Finance) - https://news.google.com/rss/articles/CBMilwFBVV95cUxOdnNiS0VBcTZqY3NOVzRjYXFLejRpeDYzRmpCV3J6QUlnRXhjVU80VHh6MXZnYV9pZVhmY0x6X21QcHUzanp5RW1kTkxTLUlMWHFXSGNLWWZiS0ZmZFI0ekpLWk1OczlOTXpCNTF5ZDVrMWwwN196bUFpRFVKNWg0STR6bkNUTlJoQzN4ZnNyNE9idUtHdkxn?oc=5
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- FBI Seizes NetNut Proxy Platform, Popa Botnet (Krebs on Security) - https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/]]>
      </content:encoded>
      <pubDate>Sun, 05 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/84523594/98402445.mp3" length="5120608" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>316</itunes:duration>
      <itunes:summary>This episode digs into a Scattered Spider extradition, the first fully AI-driven ransomware attack, and a Tesla bug bounty that uncovered a $243 million flaw. We also cover an actively exploited SharePoint vulnerability and what it means when the tools running half the enterprise become the entry point.</itunes:summary>
      <itunes:subtitle>This episode digs into a Scattered Spider extradition, the first fully AI-driven ransomware attack, and a Tesla bug bounty that uncovered a $243 million flaw. We also cover an actively exploited SharePoint vulnerability and what it means when the tools ru</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 94: July 04, 2026</title>
      <itunes:episode>94</itunes:episode>
      <podcast:episode>94</podcast:episode>
      <itunes:title>Episode 94: July 04, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6e47dce8-cf7f-4a20-bbbe-d24c682d7799</guid>
      <link>https://share.transistor.fm/s/eb675585</link>
      <description>
        <![CDATA[This episode covers a critical Linux kernel flaw that gives unprivileged users full root access across billions of devices, a clever macOS credential stealer disguising itself as legitimate software, and the takedown of a massive residential proxy network that secretly compromised two million Android devices. Adrian North walks through the early morning signals that matter before the weekend noise kicks in. It's a quick Saturday security briefing for anyone who needs to know what's actively threatening systems right now.

Stories covered:
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android (The Hacker News) - https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html
- PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords (The Hacker News) - https://thehackernews.com/2026/07/pamstealer-uses-fake-maccy-sites-and.html
- NetNut proxy network disrupted, 2 million infected devices cut off (BleepingComputer) - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- Africans Are Turning to Starlink (Hacker News) - https://www.economist.com/middle-east-and-africa/2026/07/02/africans-are-turning-to-starlink
- Vincent Bouillard and Jenn Lichter Win 2026 Western States 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/news/2026-western-states-100-live-updates-results/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Linux kernel flaw that gives unprivileged users full root access across billions of devices, a clever macOS credential stealer disguising itself as legitimate software, and the takedown of a massive residential proxy network that secretly compromised two million Android devices. Adrian North walks through the early morning signals that matter before the weekend noise kicks in. It's a quick Saturday security briefing for anyone who needs to know what's actively threatening systems right now.

Stories covered:
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android (The Hacker News) - https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html
- PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords (The Hacker News) - https://thehackernews.com/2026/07/pamstealer-uses-fake-maccy-sites-and.html
- NetNut proxy network disrupted, 2 million infected devices cut off (BleepingComputer) - https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/
- Basing Your Weekly Mileage on Your Race Distance? One Coach Explains Why That’s the Wrong Tactic—and the Real Factors to Consider. (Runner's World) - https://www.runnersworld.com/training/a71806426/race-distance-weekly-mileage/
- Africans Are Turning to Starlink (Hacker News) - https://www.economist.com/middle-east-and-africa/2026/07/02/africans-are-turning-to-starlink
- Vincent Bouillard and Jenn Lichter Win 2026 Western States 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/news/2026-western-states-100-live-updates-results/]]>
      </content:encoded>
      <pubDate>Sat, 04 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/eb675585/1d6fd75b.mp3" length="6668729" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>413</itunes:duration>
      <itunes:summary>This episode covers a critical Linux kernel flaw that gives unprivileged users full root access across billions of devices, a clever macOS credential stealer disguising itself as legitimate software, and the takedown of a massive residential proxy network that secretly compromised two million Android devices. Adrian North walks through the early morning signals that matter before the weekend noise kicks in. It's a quick Saturday security briefing for anyone who needs to know what's actively threatening systems right now.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Linux kernel flaw that gives unprivileged users full root access across billions of devices, a clever macOS credential stealer disguising itself as legitimate software, and the takedown of a massive residential proxy network</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 93: July 03, 2026</title>
      <itunes:episode>93</itunes:episode>
      <podcast:episode>93</podcast:episode>
      <itunes:title>Episode 93: July 03, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6867c843-7469-4534-bec1-67b71acef29a</guid>
      <link>https://share.transistor.fm/s/40f1e8f6</link>
      <description>
        <![CDATA[This episode digs into ransomware crews deploying multi-vector attacks through Citrix vulnerabilities and stolen Fortinet credentials, plus a CISA warning on an actively exploited SharePoint flaw. We also cover the Tesla bug bounty that somehow escalated into a $243 million lesson, and why elite athletes aren't just better at training—they're better at everything around it.

Stories covered:
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials (The Hacker News) - https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations (The Hacker News) - https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- Tesla paid a Russian hacker $15,000 per bug found — then he cracked open the case that cost them $243 million - Yahoo Finance (Yahoo Finance) - https://news.google.com/rss/articles/CBMilwFBVV95cUxOdnNiS0VBcTZqY3NOVzRjYXFLejRpeDYzRmpCV3J6QUlnRXhjVU80VHh6MXZnYV9pZVhmY0x6X21QcHUzanp5RW1kTkxTLUlMWHFXSGNLWWZiS0ZmZFI0ekpLWk1OczlOTXpCNTF5ZDVrMWwwN196bUFpRFVKNWg0STR6bkNUTlJoQzN4ZnNyNE9idUtHdkxn?oc=5
- A Run Coach to the Pros Reveals the Habits That Separate Elites. Here’s How They Can Transform Your Next Training Cycle. (Runner's World) - https://www.runnersworld.com/training/a71785588/pro-runner-training-tips/
- Virginia bans sale of geolocation data (Hacker News) - https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-bans-sale-of-geolocation-data]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into ransomware crews deploying multi-vector attacks through Citrix vulnerabilities and stolen Fortinet credentials, plus a CISA warning on an actively exploited SharePoint flaw. We also cover the Tesla bug bounty that somehow escalated into a $243 million lesson, and why elite athletes aren't just better at training—they're better at everything around it.

Stories covered:
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials (The Hacker News) - https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations (The Hacker News) - https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html
- CISA: Microsoft SharePoint RCE flaw now actively exploited (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
- Tesla paid a Russian hacker $15,000 per bug found — then he cracked open the case that cost them $243 million - Yahoo Finance (Yahoo Finance) - https://news.google.com/rss/articles/CBMilwFBVV95cUxOdnNiS0VBcTZqY3NOVzRjYXFLejRpeDYzRmpCV3J6QUlnRXhjVU80VHh6MXZnYV9pZVhmY0x6X21QcHUzanp5RW1kTkxTLUlMWHFXSGNLWWZiS0ZmZFI0ekpLWk1OczlOTXpCNTF5ZDVrMWwwN196bUFpRFVKNWg0STR6bkNUTlJoQzN4ZnNyNE9idUtHdkxn?oc=5
- A Run Coach to the Pros Reveals the Habits That Separate Elites. Here’s How They Can Transform Your Next Training Cycle. (Runner's World) - https://www.runnersworld.com/training/a71785588/pro-runner-training-tips/
- Virginia bans sale of geolocation data (Hacker News) - https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-bans-sale-of-geolocation-data]]>
      </content:encoded>
      <pubDate>Fri, 03 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/40f1e8f6/117dee32.mp3" length="4379984" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>270</itunes:duration>
      <itunes:summary>This episode digs into ransomware crews deploying multi-vector attacks through Citrix vulnerabilities and stolen Fortinet credentials, plus a CISA warning on an actively exploited SharePoint flaw. We also cover the Tesla bug bounty that somehow escalated into a $243 million lesson, and why elite athletes aren't just better at training—they're better at everything around it.</itunes:summary>
      <itunes:subtitle>This episode digs into ransomware crews deploying multi-vector attacks through Citrix vulnerabilities and stolen Fortinet credentials, plus a CISA warning on an actively exploited SharePoint flaw. We also cover the Tesla bug bounty that somehow escalated </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 92: July 02, 2026</title>
      <itunes:episode>92</itunes:episode>
      <podcast:episode>92</podcast:episode>
      <itunes:title>Episode 92: July 02, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3de0b359-043e-4a0c-9de8-fe67d8c3b1bc</guid>
      <link>https://share.transistor.fm/s/896bc8b3</link>
      <description>
        <![CDATA[This episode covers AI-generated malware that's raising alarms among cybersecurity researchers, a teenage hacker's extradition in the Scattered Spider case, and record-breaking performances at the Western States 100 ultramarathon. Adrian North walks through six signals from the tech and culture landscape before your workday demands attention. It's your early-morning dose of what's moving through the network right now.

Stories covered:
- AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android (The Hacker News) - https://thehackernews.com/2026/07/ai-generated-browser-ransomware-abuses.html
- 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges (The Hacker News) - https://thehackernews.com/2026/07/19-year-old-scattered-spider-suspect.html
- Vincent Bouillard and Jenn Lichter Win 2026 Western States 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/news/2026-western-states-100-live-updates-results/
- The Training Plan That Takes You From Walking to Your First Marathon (Runner's World) - https://www.runnersworld.com/training/a71787211/24-week-zero-to-marathon-training-plan/
- A space history mystery: What happened to the Viking arm used 50 years ago? (Ars Technica) - https://arstechnica.com/space/2026/07/50-years-on-will-the-mars-lander-arm-that-opened-the-air-and-space-raise-its-hand/
- New ChocoPoC malware targets researchers via trojanized PoC exploits (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers AI-generated malware that's raising alarms among cybersecurity researchers, a teenage hacker's extradition in the Scattered Spider case, and record-breaking performances at the Western States 100 ultramarathon. Adrian North walks through six signals from the tech and culture landscape before your workday demands attention. It's your early-morning dose of what's moving through the network right now.

Stories covered:
- AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android (The Hacker News) - https://thehackernews.com/2026/07/ai-generated-browser-ransomware-abuses.html
- 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges (The Hacker News) - https://thehackernews.com/2026/07/19-year-old-scattered-spider-suspect.html
- Vincent Bouillard and Jenn Lichter Win 2026 Western States 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/news/2026-western-states-100-live-updates-results/
- The Training Plan That Takes You From Walking to Your First Marathon (Runner's World) - https://www.runnersworld.com/training/a71787211/24-week-zero-to-marathon-training-plan/
- A space history mystery: What happened to the Viking arm used 50 years ago? (Ars Technica) - https://arstechnica.com/space/2026/07/50-years-on-will-the-mars-lander-arm-that-opened-the-air-and-space-raise-its-hand/
- New ChocoPoC malware targets researchers via trojanized PoC exploits (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/]]>
      </content:encoded>
      <pubDate>Thu, 02 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/896bc8b3/da37ecb4.mp3" length="6181806" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>383</itunes:duration>
      <itunes:summary>This episode covers AI-generated malware that's raising alarms among cybersecurity researchers, a teenage hacker's extradition in the Scattered Spider case, and record-breaking performances at the Western States 100 ultramarathon. Adrian North walks through six signals from the tech and culture landscape before your workday demands attention. It's your early-morning dose of what's moving through the network right now.</itunes:summary>
      <itunes:subtitle>This episode covers AI-generated malware that's raising alarms among cybersecurity researchers, a teenage hacker's extradition in the Scattered Spider case, and record-breaking performances at the Western States 100 ultramarathon. Adrian North walks throu</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 91: July 01, 2026</title>
      <itunes:episode>91</itunes:episode>
      <podcast:episode>91</podcast:episode>
      <itunes:title>Episode 91: July 01, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">23b2fc83-5799-4f54-a58f-824cbe1f2cc1</guid>
      <link>https://share.transistor.fm/s/14ab5468</link>
      <description>
        <![CDATA[This episode digs into a shocking security study revealing that nearly two-thirds of AI chatbot apps on iPhone are leaking user credentials and API keys in plain sight. We also cover RustDuck, a dangerous new botnet targeting home routers and cameras, plus the latest Kali Linux release packed with fresh penetration testing tools.

Stories covered:
- 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study (The Hacker News) - https://thehackernews.com/2026/06/282-ios-apps-found-leaking-llm-api-keys.html
- RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS (The Hacker News) - https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html
- Kali Linux 2026.2 released with 9 new tools, NetHunter updates (BleepingComputer) - https://www.bleepingcomputer.com/news/linux/kali-linux-20262-released-with-9-new-tools-nethunter-updates/
- ‘I Still Have a Lot to Learn’: Despite Chafing and a Hypothermia Scare, Molly Seidel Finished Western States (Runner's World) - https://www.runnersworld.com/news/a71772906/molly-seidel-ws100/
- EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits (EFF) - https://www.eff.org/deeplinks/2026/06/grindr-put-queer-safety-and-privacy-over-profits
- Victory! Supreme Court Says Constitution Protects People’s Location Data (EFF) - https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a shocking security study revealing that nearly two-thirds of AI chatbot apps on iPhone are leaking user credentials and API keys in plain sight. We also cover RustDuck, a dangerous new botnet targeting home routers and cameras, plus the latest Kali Linux release packed with fresh penetration testing tools.

Stories covered:
- 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study (The Hacker News) - https://thehackernews.com/2026/06/282-ios-apps-found-leaking-llm-api-keys.html
- RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS (The Hacker News) - https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html
- Kali Linux 2026.2 released with 9 new tools, NetHunter updates (BleepingComputer) - https://www.bleepingcomputer.com/news/linux/kali-linux-20262-released-with-9-new-tools-nethunter-updates/
- ‘I Still Have a Lot to Learn’: Despite Chafing and a Hypothermia Scare, Molly Seidel Finished Western States (Runner's World) - https://www.runnersworld.com/news/a71772906/molly-seidel-ws100/
- EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits (EFF) - https://www.eff.org/deeplinks/2026/06/grindr-put-queer-safety-and-privacy-over-profits
- Victory! Supreme Court Says Constitution Protects People’s Location Data (EFF) - https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data]]>
      </content:encoded>
      <pubDate>Wed, 01 Jul 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/14ab5468/23d59df5.mp3" length="6672908" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>413</itunes:duration>
      <itunes:summary>This episode digs into a shocking security study revealing that nearly two-thirds of AI chatbot apps on iPhone are leaking user credentials and API keys in plain sight. We also cover RustDuck, a dangerous new botnet targeting home routers and cameras, plus the latest Kali Linux release packed with fresh penetration testing tools.</itunes:summary>
      <itunes:subtitle>This episode digs into a shocking security study revealing that nearly two-thirds of AI chatbot apps on iPhone are leaking user credentials and API keys in plain sight. We also cover RustDuck, a dangerous new botnet targeting home routers and cameras, plu</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 90: June 30, 2026</title>
      <itunes:episode>90</itunes:episode>
      <podcast:episode>90</podcast:episode>
      <itunes:title>Episode 90: June 30, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fdbfe681-ef51-4707-b57b-1735991f162b</guid>
      <link>https://share.transistor.fm/s/009c1d17</link>
      <description>
        <![CDATA[This episode covers a major Microsoft Edge extension purge, a sneaky supply chain attack using VS Code automation, and a new Linux privilege escalation exploit called pedit COW. Adrian also highlights an incredible ultrarunning performance at Western States before the day's chaos takes over.

Stories covered:
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts (The Hacker News) - https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer (The Hacker News) - https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
- New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMif0FVX3lxTE9OUEtDRmFFUFFmRk5qUGtuUklzQ0xkYTVWWXhadEY5YUxrUDN0c1B3bWptTzRYSi1uZGNPT2dGTFItVUFaS1I0TUZPSWZqTFVwRnV1cXpxZ3pkTHVDRmg0RmxTWldjdmUyVG5aSWlDUEt5TUtTZzB2aEpiWWhHSDg?oc=5
- This Week In Running: June 29, 2026 (iRunFar) - https://www.irunfar.com/this-week-in-running-june-29-2026
- In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights (TechCrunch) - https://techcrunch.com/2026/06/29/in-major-privacy-win-supreme-court-rules-geofence-warrants-are-protected-by-privacy-rights/
- In Her First 100-Miler, Jennifer Lichter Wins Western States and Takes Down Courtney Dauwalter’s Course Record (Runner's World) - https://www.runnersworld.com/news/a71760742/jennifer-lichter-wins-western-states-2026/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a major Microsoft Edge extension purge, a sneaky supply chain attack using VS Code automation, and a new Linux privilege escalation exploit called pedit COW. Adrian also highlights an incredible ultrarunning performance at Western States before the day's chaos takes over.

Stories covered:
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts (The Hacker News) - https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer (The Hacker News) - https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
- New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMif0FVX3lxTE9OUEtDRmFFUFFmRk5qUGtuUklzQ0xkYTVWWXhadEY5YUxrUDN0c1B3bWptTzRYSi1uZGNPT2dGTFItVUFaS1I0TUZPSWZqTFVwRnV1cXpxZ3pkTHVDRmg0RmxTWldjdmUyVG5aSWlDUEt5TUtTZzB2aEpiWWhHSDg?oc=5
- This Week In Running: June 29, 2026 (iRunFar) - https://www.irunfar.com/this-week-in-running-june-29-2026
- In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights (TechCrunch) - https://techcrunch.com/2026/06/29/in-major-privacy-win-supreme-court-rules-geofence-warrants-are-protected-by-privacy-rights/
- In Her First 100-Miler, Jennifer Lichter Wins Western States and Takes Down Courtney Dauwalter’s Course Record (Runner's World) - https://www.runnersworld.com/news/a71760742/jennifer-lichter-wins-western-states-2026/]]>
      </content:encoded>
      <pubDate>Tue, 30 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/009c1d17/327881c4.mp3" length="4800451" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>296</itunes:duration>
      <itunes:summary>This episode covers a major Microsoft Edge extension purge, a sneaky supply chain attack using VS Code automation, and a new Linux privilege escalation exploit called pedit COW. Adrian also highlights an incredible ultrarunning performance at Western States before the day's chaos takes over.</itunes:summary>
      <itunes:subtitle>This episode covers a major Microsoft Edge extension purge, a sneaky supply chain attack using VS Code automation, and a new Linux privilege escalation exploit called pedit COW. Adrian also highlights an incredible ultrarunning performance at Western Stat</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 89: June 29, 2026</title>
      <itunes:episode>89</itunes:episode>
      <podcast:episode>89</podcast:episode>
      <itunes:title>Episode 89: June 29, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4f99efa5-be29-4607-a631-b7f978d11b44</guid>
      <link>https://share.transistor.fm/s/9fea722e</link>
      <description>
        <![CDATA[This episode digs into three emerging threats targeting the tools developers and security-conscious users rely on most. We cover a sophisticated npm supply chain attack infiltrating GitHub Actions, a Russian phishing campaign hunting Signal backup keys, and a chilling new exploit that weaponizes AI coding agents through hidden instructions. The common thread? Trust is the new attack surface.

Stories covered:
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack (The Hacker News) - https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html
- FBI: Russian hackers now target Signal backup recovery keys (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/
- Clean GitHub repo tricks AI coding agents into running malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/
- Librepods: AirPods liberated (Hacker News) - https://github.com/librepods-org/librepods
- What Western States 100 Training Data Reveals About How to Maintain Performance Late in a Race (Runner's World) - https://www.runnersworld.com/training/a71617479/western-states-training-data/
- What to Do in Houston If You're Here for Business (2026) (Wired) - https://www.wired.com/story/the-wired-guide-to-houston-for-business-travelers/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into three emerging threats targeting the tools developers and security-conscious users rely on most. We cover a sophisticated npm supply chain attack infiltrating GitHub Actions, a Russian phishing campaign hunting Signal backup keys, and a chilling new exploit that weaponizes AI coding agents through hidden instructions. The common thread? Trust is the new attack surface.

Stories covered:
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack (The Hacker News) - https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html
- FBI: Russian hackers now target Signal backup recovery keys (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/
- Clean GitHub repo tricks AI coding agents into running malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/
- Librepods: AirPods liberated (Hacker News) - https://github.com/librepods-org/librepods
- What Western States 100 Training Data Reveals About How to Maintain Performance Late in a Race (Runner's World) - https://www.runnersworld.com/training/a71617479/western-states-training-data/
- What to Do in Houston If You're Here for Business (2026) (Wired) - https://www.wired.com/story/the-wired-guide-to-houston-for-business-travelers/]]>
      </content:encoded>
      <pubDate>Mon, 29 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9fea722e/00014478.mp3" length="5755070" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>356</itunes:duration>
      <itunes:summary>This episode digs into three emerging threats targeting the tools developers and security-conscious users rely on most. We cover a sophisticated npm supply chain attack infiltrating GitHub Actions, a Russian phishing campaign hunting Signal backup keys, and a chilling new exploit that weaponizes AI coding agents through hidden instructions. The common thread? Trust is the new attack surface.</itunes:summary>
      <itunes:subtitle>This episode digs into three emerging threats targeting the tools developers and security-conscious users rely on most. We cover a sophisticated npm supply chain attack infiltrating GitHub Actions, a Russian phishing campaign hunting Signal backup keys, a</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 88: June 28, 2026</title>
      <itunes:episode>88</itunes:episode>
      <podcast:episode>88</podcast:episode>
      <itunes:title>Episode 88: June 28, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2e472a5d-ec7e-4b93-b02d-260b5bd06710</guid>
      <link>https://share.transistor.fm/s/1cf298f2</link>
      <description>
        <![CDATA[This episode covers the quiet but critical signals from a Sunday morning in late June, including a new framework to help companies manage aging open-source projects before they become security nightmares. We dig into a Russian phishing campaign targeting Signal backup keys, an anonymous GitHub account dropping zero-day exploits into the wild, and why even the most secure tools fail when human trust gets weaponized.

Stories covered:
- New Initiative Tackles Security for End-of-Life Open Source Software (Dark Reading) - https://www.darkreading.com/application-security/initiative-tackles-security-end-of-life-open-source
- FBI: Russian hackers now target Signal backup recovery keys (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/
- Anonymous GitHub account mass-dropping undisclosed 0-days (Hacker News) - https://github.com/bikini/exploitarium
- Older Runners Have Reshaped College Track and Cross Country. A New Age-Based Rule Could Change That (Runner's World) - https://www.runnersworld.com/news/a71732214/ncaa-eligibility-rule-track-cross-country/
- EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits (EFF) - https://www.eff.org/deeplinks/2026/06/grindr-put-queer-safety-and-privacy-over-profits
- Canadian hacker Aubrey Cottle sentenced to 18 months custody after pleading guilty to cyberattack charges - The Globe and Mail (The Globe and Mail) - https://news.google.com/rss/articles/CBMilAFBVV95cUxOdEh0YlluSk5RT3M4aTZ1U0dMWVFDbUtoZ2lRaEFicE9SQmFaNlR5Uks5SFkwQ0pDazVWc2t6eE9vcGE1N2hSb2hJaVlBSWJMd3RFdHdsSjRuUGFXZDk2aGZpS2U3dkVyX0kycy1OeDcwTmRneFNtekpNdnFOdldaUkxaYWJXbTFNcUJmUE82cV9TNERB?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers the quiet but critical signals from a Sunday morning in late June, including a new framework to help companies manage aging open-source projects before they become security nightmares. We dig into a Russian phishing campaign targeting Signal backup keys, an anonymous GitHub account dropping zero-day exploits into the wild, and why even the most secure tools fail when human trust gets weaponized.

Stories covered:
- New Initiative Tackles Security for End-of-Life Open Source Software (Dark Reading) - https://www.darkreading.com/application-security/initiative-tackles-security-end-of-life-open-source
- FBI: Russian hackers now target Signal backup recovery keys (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/
- Anonymous GitHub account mass-dropping undisclosed 0-days (Hacker News) - https://github.com/bikini/exploitarium
- Older Runners Have Reshaped College Track and Cross Country. A New Age-Based Rule Could Change That (Runner's World) - https://www.runnersworld.com/news/a71732214/ncaa-eligibility-rule-track-cross-country/
- EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits (EFF) - https://www.eff.org/deeplinks/2026/06/grindr-put-queer-safety-and-privacy-over-profits
- Canadian hacker Aubrey Cottle sentenced to 18 months custody after pleading guilty to cyberattack charges - The Globe and Mail (The Globe and Mail) - https://news.google.com/rss/articles/CBMilAFBVV95cUxOdEh0YlluSk5RT3M4aTZ1U0dMWVFDbUtoZ2lRaEFicE9SQmFaNlR5Uks5SFkwQ0pDazVWc2t6eE9vcGE1N2hSb2hJaVlBSWJMd3RFdHdsSjRuUGFXZDk2aGZpS2U3dkVyX0kycy1OeDcwTmRneFNtekpNdnFOdldaUkxaYWJXbTFNcUJmUE82cV9TNERB?oc=5]]>
      </content:encoded>
      <pubDate>Sun, 28 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/1cf298f2/27e80904.mp3" length="5887145" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>364</itunes:duration>
      <itunes:summary>This episode covers the quiet but critical signals from a Sunday morning in late June, including a new framework to help companies manage aging open-source projects before they become security nightmares. We dig into a Russian phishing campaign targeting Signal backup keys, an anonymous GitHub account dropping zero-day exploits into the wild, and why even the most secure tools fail when human trust gets weaponized.</itunes:summary>
      <itunes:subtitle>This episode covers the quiet but critical signals from a Sunday morning in late June, including a new framework to help companies manage aging open-source projects before they become security nightmares. We dig into a Russian phishing campaign targeting </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 86: June 26, 2026</title>
      <itunes:episode>86</itunes:episode>
      <podcast:episode>86</podcast:episode>
      <itunes:title>Episode 86: June 26, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">52de0b2c-8071-4b81-9794-a8f20bde57a2</guid>
      <link>https://share.transistor.fm/s/9e709107</link>
      <description>
        <![CDATA[This episode digs into a Cisco SD-WAN zero-day exploit breakdown from Mandiant, a clever macOS malware strain that deceives AI analysis tools with fake error messages, and a former hacker now applying exploit-finding skills to solar energy collection. Adrian North walks through early-morning signals before the noise of the day takes over.

Stories covered:
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/
- New macOS malware embeds fake errors to confuse AI analysis tools (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-macos-malware-embeds-fake-errors-to-confuse-ai-analysis-tools/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- Fifty Years On, New York Honors the Five Who Took the NYC Marathon Out of Central Park (Marathon Handbook) - https://marathonhandbook.com/fifty-years-on-new-york-honors-the-five-who-took-the-nyc-marathon-out-of-central-park/
- An entire Herculaneum scroll has been read for the first time (Hacker News) - https://scrollprize.org/firstscroll
- Mother Nature has a Weird and Nasty Way of Welcoming You to the Trail - The Trek (The Trek) - https://news.google.com/rss/articles/CBMiqwFBVV95cUxOR2xiOWV3d2tIMGlaUVc4ODFVcGtoLWt3cElsSkZIMUdIRndzMHRPdG83UVk0bG0tRlNLZllIT3Ftc21FT1Njc3pmUVhDOEtjU29vdU1YRkJzd1pQb3cwZmowbm5sWTF5OWREZmlXUnV2dWNZZXVPQUU3WFpjSE1DQTBZNFpxQkxDZkgtU19TOUhVWDZSb0l2RnJFY3dxYlY2LVdJbkE1UXp1R00?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a Cisco SD-WAN zero-day exploit breakdown from Mandiant, a clever macOS malware strain that deceives AI analysis tools with fake error messages, and a former hacker now applying exploit-finding skills to solar energy collection. Adrian North walks through early-morning signals before the noise of the day takes over.

Stories covered:
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/
- New macOS malware embeds fake errors to confuse AI analysis tools (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-macos-malware-embeds-fake-errors-to-confuse-ai-analysis-tools/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- Fifty Years On, New York Honors the Five Who Took the NYC Marathon Out of Central Park (Marathon Handbook) - https://marathonhandbook.com/fifty-years-on-new-york-honors-the-five-who-took-the-nyc-marathon-out-of-central-park/
- An entire Herculaneum scroll has been read for the first time (Hacker News) - https://scrollprize.org/firstscroll
- Mother Nature has a Weird and Nasty Way of Welcoming You to the Trail - The Trek (The Trek) - https://news.google.com/rss/articles/CBMiqwFBVV95cUxOR2xiOWV3d2tIMGlaUVc4ODFVcGtoLWt3cElsSkZIMUdIRndzMHRPdG83UVk0bG0tRlNLZllIT3Ftc21FT1Njc3pmUVhDOEtjU29vdU1YRkJzd1pQb3cwZmowbm5sWTF5OWREZmlXUnV2dWNZZXVPQUU3WFpjSE1DQTBZNFpxQkxDZkgtU19TOUhVWDZSb0l2RnJFY3dxYlY2LVdJbkE1UXp1R00?oc=5]]>
      </content:encoded>
      <pubDate>Fri, 26 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9e709107/e60973b3.mp3" length="6201868" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>384</itunes:duration>
      <itunes:summary>This episode digs into a Cisco SD-WAN zero-day exploit breakdown from Mandiant, a clever macOS malware strain that deceives AI analysis tools with fake error messages, and a former hacker now applying exploit-finding skills to solar energy collection. Adrian North walks through early-morning signals before the noise of the day takes over.</itunes:summary>
      <itunes:subtitle>This episode digs into a Cisco SD-WAN zero-day exploit breakdown from Mandiant, a clever macOS malware strain that deceives AI analysis tools with fake error messages, and a former hacker now applying exploit-finding skills to solar energy collection. Adr</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 85: June 25, 2026</title>
      <itunes:episode>85</itunes:episode>
      <podcast:episode>85</podcast:episode>
      <itunes:title>Episode 85: June 25, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0e42e34c-4c91-4733-a982-cfa7428c7ed8</guid>
      <link>https://share.transistor.fm/s/dc3ddd10</link>
      <description>
        <![CDATA[This episode digs into two actively exploited Cisco vulnerabilities that are making waves — including a zero-day that gave attackers root access to SD-WAN devices. We also cover a new website publicly shaming companies that still don't support passkeys, and a reformed hacker with an unexpected new mission.

Stories covered:
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- New website names and shames companies that still don’t offer passkeys to users (TechCrunch) - https://techcrunch.com/2026/06/24/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- There’s an IKEA Marathon Happening This Year—and You May Have to Self-Assemble Your Medal (Of Course) (Runner's World) - https://www.runnersworld.com/news/a71679229/ikea-marathon/
- Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies - bgr.com (bgr.com) - https://news.google.com/rss/articles/CBMigAFBVV95cUxOUy1rd0FqTk1EcF9qaDNtSjg0OUpLR1ZXWTZlM1hRU2xockRCMTF6U1FMZTFDZEw2UUxJTFlnZUpsVlFsa0tLZkRSUTlMRWJKVjhpNmhKNnVGSkp0Z1pNSlRBRDNrN2NYQ083a1NpeFVIMXVZLTVUSWc5blFZNHlJNg?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into two actively exploited Cisco vulnerabilities that are making waves — including a zero-day that gave attackers root access to SD-WAN devices. We also cover a new website publicly shaming companies that still don't support passkeys, and a reformed hacker with an unexpected new mission.

Stories covered:
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) - https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- New website names and shames companies that still don’t offer passkeys to users (TechCrunch) - https://techcrunch.com/2026/06/24/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- There’s an IKEA Marathon Happening This Year—and You May Have to Self-Assemble Your Medal (Of Course) (Runner's World) - https://www.runnersworld.com/news/a71679229/ikea-marathon/
- Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies - bgr.com (bgr.com) - https://news.google.com/rss/articles/CBMigAFBVV95cUxOUy1rd0FqTk1EcF9qaDNtSjg0OUpLR1ZXWTZlM1hRU2xockRCMTF6U1FMZTFDZEw2UUxJTFlnZUpsVlFsa0tLZkRSUTlMRWJKVjhpNmhKNnVGSkp0Z1pNSlRBRDNrN2NYQ083a1NpeFVIMXVZLTVUSWc5blFZNHlJNg?oc=5]]>
      </content:encoded>
      <pubDate>Thu, 25 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/dc3ddd10/e76a8125.mp3" length="5454557" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>337</itunes:duration>
      <itunes:summary>This episode digs into two actively exploited Cisco vulnerabilities that are making waves — including a zero-day that gave attackers root access to SD-WAN devices. We also cover a new website publicly shaming companies that still don't support passkeys, and a reformed hacker with an unexpected new mission.</itunes:summary>
      <itunes:subtitle>This episode digs into two actively exploited Cisco vulnerabilities that are making waves — including a zero-day that gave attackers root access to SD-WAN devices. We also cover a new website publicly shaming companies that still don't support passkeys, a</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 84: June 24, 2026</title>
      <itunes:episode>84</itunes:episode>
      <podcast:episode>84</podcast:episode>
      <itunes:title>Episode 84: June 24, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4021393b-c977-4227-ba0f-3439d6806de3</guid>
      <link>https://share.transistor.fm/s/27245bf2</link>
      <description>
        <![CDATA[This episode covers active exploitation of a Cisco Unified Communications flaw, LastPass confirming another breach through stolen OAuth tokens, and a former hacker who pivoted to solar energy. Adrian digs into why supply chain attacks are now the standard playbook and shares a Runner's World tip on avoiding long-run mistakes.

Stories covered:
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- LastPass confirms data breach in Klue supply chain attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- 8 Ways You’re Sabotaging Your Long Runs and How to Make Them Feel Easier (Runner's World) - https://www.runnersworld.com/training/a71682764/long-run-mistakes-runners/
- On Her Own Path: Lotti Brinks and the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/on-her-own-path-lotti-brinks-and-the-2026-western-states-100
- The NO FAKES Act Could Silence Satire, Commentary, And News (EFF) - https://www.eff.org/deeplinks/2026/06/no-fakes-act-could-silence-satire-commentary-and-news]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers active exploitation of a Cisco Unified Communications flaw, LastPass confirming another breach through stolen OAuth tokens, and a former hacker who pivoted to solar energy. Adrian digs into why supply chain attacks are now the standard playbook and shares a Runner's World tip on avoiding long-run mistakes.

Stories covered:
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- LastPass confirms data breach in Klue supply chain attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/
- This former hacker saw the light—and now wants to collect all of it - Ars Technica (Ars Technica) - https://news.google.com/rss/articles/CBMirgFBVV95cUxNcUlQeG1mWTJSeC1MOFEwZjBKUHZxdFZxTnh6ZmN4UUhHMXBlYVd4SjZhRnoxSnpaRXFIUnotQnYzWThKR3pDWlRwZjNWVHRSZjNhN3pBLXFINHdfSWpjQWtkWE5fdjYxT3o3dXVzT0RlSm5oVUZNVVFWQ3JtXzFQZzh2cl8wYWZ0eXBFXzBrNWJFRnVKZVFCNC1BNVBpZ2ZfSlQxZFBYZnZuUXdGOFE?oc=5
- 8 Ways You’re Sabotaging Your Long Runs and How to Make Them Feel Easier (Runner's World) - https://www.runnersworld.com/training/a71682764/long-run-mistakes-runners/
- On Her Own Path: Lotti Brinks and the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/on-her-own-path-lotti-brinks-and-the-2026-western-states-100
- The NO FAKES Act Could Silence Satire, Commentary, And News (EFF) - https://www.eff.org/deeplinks/2026/06/no-fakes-act-could-silence-satire-commentary-and-news]]>
      </content:encoded>
      <pubDate>Wed, 24 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/27245bf2/2616f5da.mp3" length="5920582" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>366</itunes:duration>
      <itunes:summary>This episode covers active exploitation of a Cisco Unified Communications flaw, LastPass confirming another breach through stolen OAuth tokens, and a former hacker who pivoted to solar energy. Adrian digs into why supply chain attacks are now the standard playbook and shares a Runner's World tip on avoiding long-run mistakes.</itunes:summary>
      <itunes:subtitle>This episode covers active exploitation of a Cisco Unified Communications flaw, LastPass confirming another breach through stolen OAuth tokens, and a former hacker who pivoted to solar energy. Adrian digs into why supply chain attacks are now the standard</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 83: June 23, 2026</title>
      <itunes:episode>83</itunes:episode>
      <podcast:episode>83</podcast:episode>
      <itunes:title>Episode 83: June 23, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">facf5de2-8d5d-482f-955f-51f1270ce621</guid>
      <link>https://share.transistor.fm/s/f89c0fe6</link>
      <description>
        <![CDATA[This episode digs into Canada's unprecedented move to remotely clean malware from citizens' devices without permission, Microsoft's attribution of the Mastra AI supply chain attack to North Korean hackers, and a newly published iPhone exploit that lives in hardware Apple can't patch. We also touch on why your best running mentor is probably the local coach who shows up at dawn, not the influencer with perfect splits.

Stories covered:
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices (The Hacker News) - https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- Your Best Running Mentor Probably Isn’t Who You Think (Marathon Handbook) - https://marathonhandbook.com/your-best-running-mentor-probably-isnt-who-you-think/
- A newbie hacker used "vague, low-skill prompts" in Claude and Codex to breach 14 companies, and the AI Agents did all the legwork - TechRadar (TechRadar) - https://news.google.com/rss/articles/CBMi9wFBVV95cUxQN3dzMmhNd3Y5TzN6OGxsVEI0TEZnZTN2aFY1QkJ2NDZMZWhRZl9EWmI3TjN3RVE1WmlKRWxBd2VBRE9xVHg2VGdEdFJfZmhZTE9xdUxOT2Jid1NRQVQ2RkdlU19PcUJBSFVXVURtWE1fZ1RpVUxjNU93bWdiRjVtdElITDJPRkptcHVmcnQ0Z0k3NDNLMWRJWGV0UlNSN3NVejJoN0NBUldXQzQwOWZRY1RSWk93NkRDLXNQeUlhLTQwOUljR0oyejYtTXhmS2xHT1BNc1hpbHNoZ0hEY1VPLXVEczNUMlRuSGRPTmpsZDZnQjVoNm5r?oc=5
- Linux and Secure Boot certificate expiration (2025) (Hacker News) - https://lwn.net/Articles/1029767/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Canada's unprecedented move to remotely clean malware from citizens' devices without permission, Microsoft's attribution of the Mastra AI supply chain attack to North Korean hackers, and a newly published iPhone exploit that lives in hardware Apple can't patch. We also touch on why your best running mentor is probably the local coach who shows up at dawn, not the influencer with perfect splits.

Stories covered:
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices (The Hacker News) - https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- Your Best Running Mentor Probably Isn’t Who You Think (Marathon Handbook) - https://marathonhandbook.com/your-best-running-mentor-probably-isnt-who-you-think/
- A newbie hacker used "vague, low-skill prompts" in Claude and Codex to breach 14 companies, and the AI Agents did all the legwork - TechRadar (TechRadar) - https://news.google.com/rss/articles/CBMi9wFBVV95cUxQN3dzMmhNd3Y5TzN6OGxsVEI0TEZnZTN2aFY1QkJ2NDZMZWhRZl9EWmI3TjN3RVE1WmlKRWxBd2VBRE9xVHg2VGdEdFJfZmhZTE9xdUxOT2Jid1NRQVQ2RkdlU19PcUJBSFVXVURtWE1fZ1RpVUxjNU93bWdiRjVtdElITDJPRkptcHVmcnQ0Z0k3NDNLMWRJWGV0UlNSN3NVejJoN0NBUldXQzQwOWZRY1RSWk93NkRDLXNQeUlhLTQwOUljR0oyejYtTXhmS2xHT1BNc1hpbHNoZ0hEY1VPLXVEczNUMlRuSGRPTmpsZDZnQjVoNm5r?oc=5
- Linux and Secure Boot certificate expiration (2025) (Hacker News) - https://lwn.net/Articles/1029767/]]>
      </content:encoded>
      <pubDate>Tue, 23 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/f89c0fe6/75962ac5.mp3" length="5030329" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>311</itunes:duration>
      <itunes:summary>This episode digs into Canada's unprecedented move to remotely clean malware from citizens' devices without permission, Microsoft's attribution of the Mastra AI supply chain attack to North Korean hackers, and a newly published iPhone exploit that lives in hardware Apple can't patch. We also touch on why your best running mentor is probably the local coach who shows up at dawn, not the influencer with perfect splits.</itunes:summary>
      <itunes:subtitle>This episode digs into Canada's unprecedented move to remotely clean malware from citizens' devices without permission, Microsoft's attribution of the Mastra AI supply chain attack to North Korean hackers, and a newly published iPhone exploit that lives i</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 82: June 22, 2026</title>
      <itunes:episode>82</itunes:episode>
      <podcast:episode>82</podcast:episode>
      <itunes:title>Episode 82: June 22, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5dfbf0a4-e1e9-4e9f-83a4-c5e3b23c59ed</guid>
      <link>https://share.transistor.fm/s/2b6c7393</link>
      <description>
        <![CDATA[This episode digs into a CISA deadline for a critical Splunk vulnerability that's already being exploited in the wild, a North Korean supply chain attack that poisoned over 140 npm packages, and how a junior hacker used legitimate tools like Tailscale to maintain persistence after losing his primary command server. Adrian breaks down six stories that show how attackers are leveraging trust, timing, and creative tradecraft to stay ahead.

Stories covered:
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday/
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5
- I Hated Running in the Heat. This Training Switch Led Me to Love It—and Faster Times (Runner's World) - https://www.runnersworld.com/training/a71631076/benefits-track-workouts-in-heat/
- Catching Up With Jimmy Chin: Training for Everest, Time, and His Next Big Project (Climbing Magazine) - https://www.climbing.com/culture-climbing/catching-up-with-jimmy-chin-training-for-everest-time-and-his-next-big-project/
- A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a CISA deadline for a critical Splunk vulnerability that's already being exploited in the wild, a North Korean supply chain attack that poisoned over 140 npm packages, and how a junior hacker used legitimate tools like Tailscale to maintain persistence after losing his primary command server. Adrian breaks down six stories that show how attackers are leveraging trust, timing, and creative tradecraft to stay ahead.

Stories covered:
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday/
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5
- I Hated Running in the Heat. This Training Switch Led Me to Love It—and Faster Times (Runner's World) - https://www.runnersworld.com/training/a71631076/benefits-track-workouts-in-heat/
- Catching Up With Jimmy Chin: Training for Everest, Time, and His Next Big Project (Climbing Magazine) - https://www.climbing.com/culture-climbing/catching-up-with-jimmy-chin-training-for-everest-time-and-his-next-big-project/
- A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/]]>
      </content:encoded>
      <pubDate>Mon, 22 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/2b6c7393/176c476e.mp3" length="6237813" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>386</itunes:duration>
      <itunes:summary>This episode digs into a CISA deadline for a critical Splunk vulnerability that's already being exploited in the wild, a North Korean supply chain attack that poisoned over 140 npm packages, and how a junior hacker used legitimate tools like Tailscale to maintain persistence after losing his primary command server. Adrian breaks down six stories that show how attackers are leveraging trust, timing, and creative tradecraft to stay ahead.</itunes:summary>
      <itunes:subtitle>This episode digs into a CISA deadline for a critical Splunk vulnerability that's already being exploited in the wild, a North Korean supply chain attack that poisoned over 140 npm packages, and how a junior hacker used legitimate tools like Tailscale to </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 81: June 21, 2026</title>
      <itunes:episode>81</itunes:episode>
      <podcast:episode>81</podcast:episode>
      <itunes:title>Episode 81: June 21, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3478d9e6-cd2b-4594-b65c-4c58f9848103</guid>
      <link>https://share.transistor.fm/s/6ce44b8f</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian digs into a North Korean supply chain attack that poisoned over 140 npm packages, an unpatchable iPhone exploit targeting Apple's SecureROM, and a scrappy hacker who kept his operation alive using Tailscale and SSH after losing his C2 server. Plus, millions in Brazil received a mysterious unauthorized emergency alert that nobody can quite explain yet.

Stories covered:
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5
- Unauthorized alert sent to cell phones across Brazil (Hacker News) - https://www.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam
- What 50,000 Runners And 76 Studies Teach Us About Racing The NYC Marathon Smarter (Marathon Handbook) - https://marathonhandbook.com/what-50000-runners-and-76-studies-teach-us-about-racing-the-nyc-marathon-smarter/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian digs into a North Korean supply chain attack that poisoned over 140 npm packages, an unpatchable iPhone exploit targeting Apple's SecureROM, and a scrappy hacker who kept his operation alive using Tailscale and SSH after losing his C2 server. Plus, millions in Brazil received a mysterious unauthorized emergency alert that nobody can quite explain yet.

Stories covered:
- Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5
- Unauthorized alert sent to cell phones across Brazil (Hacker News) - https://www.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam
- What 50,000 Runners And 76 Studies Teach Us About Racing The NYC Marathon Smarter (Marathon Handbook) - https://marathonhandbook.com/what-50000-runners-and-76-studies-teach-us-about-racing-the-nyc-marathon-smarter/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </content:encoded>
      <pubDate>Sun, 21 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/6ce44b8f/ca679aaf.mp3" length="6440523" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>399</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian digs into a North Korean supply chain attack that poisoned over 140 npm packages, an unpatchable iPhone exploit targeting Apple's SecureROM, and a scrappy hacker who kept his operation alive using Tailscale and SSH after losing his C2 server. Plus, millions in Brazil received a mysterious unauthorized emergency alert that nobody can quite explain yet.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian digs into a North Korean supply chain attack that poisoned over 140 npm packages, an unpatchable iPhone exploit targeting Apple's SecureROM, and a scrappy hacker who kept his operation alive using Tailscale and SSH after lo</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 80: June 20, 2026</title>
      <itunes:episode>80</itunes:episode>
      <podcast:episode>80</podcast:episode>
      <itunes:title>Episode 80: June 20, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">67747f08-1e9d-4400-9fe1-df81da69fb1f</guid>
      <link>https://share.transistor.fm/s/93cdc2f7</link>
      <description>
        <![CDATA[This episode covers critical security patches for NGINX that can't wait until Monday, a messy OAuth breach at Klue that gave hackers direct access to Salesforce data, and an unpatchable exploit in millions of older iPhones that Apple can't fix with software. Adrian walks through what moved overnight and why it matters before the weekend noise kicks in.

Stories covered:
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution (The Hacker News) - https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html
- Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- I Faded During My First Two Races. This Simple Workout Helped Me Finish the Next One Strong—and Set a PR. (Runner's World) - https://www.runnersworld.com/training/a71631335/fartlek-training-race-stronger/
- A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers critical security patches for NGINX that can't wait until Monday, a messy OAuth breach at Klue that gave hackers direct access to Salesforce data, and an unpatchable exploit in millions of older iPhones that Apple can't fix with software. Adrian walks through what moved overnight and why it matters before the weekend noise kicks in.

Stories covered:
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution (The Hacker News) - https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html
- Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
- I Faded During My First Two Races. This Simple Workout Helped Me Finish the Next One Strong—and Set a PR. (Runner's World) - https://www.runnersworld.com/training/a71631335/fartlek-training-race-stronger/
- A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </content:encoded>
      <pubDate>Sat, 20 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/93cdc2f7/bd7ed7c3.mp3" length="5785163" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>358</itunes:duration>
      <itunes:summary>This episode covers critical security patches for NGINX that can't wait until Monday, a messy OAuth breach at Klue that gave hackers direct access to Salesforce data, and an unpatchable exploit in millions of older iPhones that Apple can't fix with software. Adrian walks through what moved overnight and why it matters before the weekend noise kicks in.</itunes:summary>
      <itunes:subtitle>This episode covers critical security patches for NGINX that can't wait until Monday, a messy OAuth breach at Klue that gave hackers direct access to Salesforce data, and an unpatchable exploit in millions of older iPhones that Apple can't fix with softwa</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 79: June 19, 2026</title>
      <itunes:episode>79</itunes:episode>
      <podcast:episode>79</podcast:episode>
      <itunes:title>Episode 79: June 19, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f489de90-9d7e-4e24-9741-70a9ffb3791f</guid>
      <link>https://share.transistor.fm/s/692c61cc</link>
      <description>
        <![CDATA[This episode digs into a patient cryptocurrency clipper campaign running since February, a French attacker who pivoted to legitimate remote tools when their server died, and why Salesforce integrations are becoming a serious supply chain risk. Adrian pulls signal from the noise before the day gets loud.

Stories covered:
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 (The Hacker News) - https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html
- Salesforce Data Thefts Continue via Klue App Compromise (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/salesforce-data-thefts-klue-app-compromise
- Shoulder and back exercises to improve your running mechanics (Canadian Running) - https://runningmagazine.ca/sections/training/shoulder-and-back-exercises-to-improve-your-running-mechanics/
- Launch HN: TesterArmy (YC P26) – Agents that test web and mobile apps (Hacker News) - https://tester.army
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm (Krebs on Security) - https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a patient cryptocurrency clipper campaign running since February, a French attacker who pivoted to legitimate remote tools when their server died, and why Salesforce integrations are becoming a serious supply chain risk. Adrian pulls signal from the noise before the day gets loud.

Stories covered:
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 (The Hacker News) - https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html
- Salesforce Data Thefts Continue via Klue App Compromise (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/salesforce-data-thefts-klue-app-compromise
- Shoulder and back exercises to improve your running mechanics (Canadian Running) - https://runningmagazine.ca/sections/training/shoulder-and-back-exercises-to-improve-your-running-mechanics/
- Launch HN: TesterArmy (YC P26) – Agents that test web and mobile apps (Hacker News) - https://tester.army
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm (Krebs on Security) - https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/]]>
      </content:encoded>
      <pubDate>Fri, 19 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/692c61cc/4a251d1b.mp3" length="5418613" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>335</itunes:duration>
      <itunes:summary>This episode digs into a patient cryptocurrency clipper campaign running since February, a French attacker who pivoted to legitimate remote tools when their server died, and why Salesforce integrations are becoming a serious supply chain risk. Adrian pulls signal from the noise before the day gets loud.</itunes:summary>
      <itunes:subtitle>This episode digs into a patient cryptocurrency clipper campaign running since February, a French attacker who pivoted to legitimate remote tools when their server died, and why Salesforce integrations are becoming a serious supply chain risk. Adrian pull</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 78: June 18, 2026</title>
      <itunes:episode>78</itunes:episode>
      <podcast:episode>78</podcast:episode>
      <itunes:title>Episode 78: June 18, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8fdd0d0f-5945-40e2-b375-f62bbd23f289</guid>
      <link>https://share.transistor.fm/s/db966db5</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian North walks through six morning signals including the UK's controversial ID-based age verification law for social media, a sophisticated Android banking trojan called Rokarolla targeting hundreds of apps, and a French cyberattack that used legitimate IT tools to maintain persistent access. It's a sharp look at what moved overnight before the inbox explodes.

Stories covered:
- UK to require ID or face scan before you can make social media accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/uk-to-require-id-or-face-scan-before-you-can-make-social-media-accounts/
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds (The Hacker News) - https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html
- The Performance Booster That Could Help You Push Through Fatigue—If Your Stomach Can Handle It (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a71606411/sodium-bicarbonate-runners-performance/
- European Champion Ciara Mageean Says She Will “Fit as Much Living” Into the Years She Has Left (Marathon Handbook) - https://marathonhandbook.com/european-champion-ciara-mageean-says-she-will-fit-as-much-living-into-the-years-she-has-left/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian North walks through six morning signals including the UK's controversial ID-based age verification law for social media, a sophisticated Android banking trojan called Rokarolla targeting hundreds of apps, and a French cyberattack that used legitimate IT tools to maintain persistent access. It's a sharp look at what moved overnight before the inbox explodes.

Stories covered:
- UK to require ID or face scan before you can make social media accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/uk-to-require-id-or-face-scan-before-you-can-make-social-media-accounts/
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds (The Hacker News) - https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html
- The Performance Booster That Could Help You Push Through Fatigue—If Your Stomach Can Handle It (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a71606411/sodium-bicarbonate-runners-performance/
- European Champion Ciara Mageean Says She Will “Fit as Much Living” Into the Years She Has Left (Marathon Handbook) - https://marathonhandbook.com/european-champion-ciara-mageean-says-she-will-fit-as-much-living-into-the-years-she-has-left/
- The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf]]>
      </content:encoded>
      <pubDate>Thu, 18 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/db966db5/7c84d6bd.mp3" length="5698227" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>353</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian North walks through six morning signals including the UK's controversial ID-based age verification law for social media, a sophisticated Android banking trojan called Rokarolla targeting hundreds of apps, and a French cyberattack that used legitimate IT tools to maintain persistent access. It's a sharp look at what moved overnight before the inbox explodes.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian North walks through six morning signals including the UK's controversial ID-based age verification law for social media, a sophisticated Android banking trojan called Rokarolla targeting hundreds of apps, and a French cyber</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 77: June 17, 2026</title>
      <itunes:episode>77</itunes:episode>
      <podcast:episode>77</podcast:episode>
      <itunes:title>Episode 77: June 17, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">29a90580-36fc-412d-b534-96c102d5ea20</guid>
      <link>https://share.transistor.fm/s/16ef58b2</link>
      <description>
        <![CDATA[This episode digs into a powerful new Android banking trojan hitting over 200 apps, a federal warning about an actively exploited cPanel plugin, and a leaked membership list from Peter Thiel's ultra-exclusive Dialog retreat. Signal Check covers the threats already moving before your coffee gets cold.

Stories covered:
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds (The Hacker News) - https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html
- Humiliating IIS servers for fun and jail time (Hacker News) - https://mll.sh/humiliating-iis-servers-for-fun-and-jail-time/
- CISA warns of another cPanel plugin flaw exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/
- Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society (Wired) - https://www.wired.com/story/leak-exposes-members-of-peter-thiels-secretive-dialog-society/
- The 6 Best Toe Separators That Can Help Prevent Injury and Relieve Pain (Runner's World) - https://www.runnersworld.com/health-injuries/g40457572/best-toe-separators/
- Hacker: 'I Could Have Rickrolled the World Cup' - Bank Info Security (Bank Info Security) - https://news.google.com/rss/articles/CBMiiAFBVV95cUxNODd3SDVpTGV6ZGxCMU9HNS1ycjc3M0JnSDltYmJIOXZkQUEzSEtVTi1hZGVaVW1nc2J5MXJwTTZHZGxDeDBRd2lRd2U2YXd3b0U1UUpEOVd6RjdXRUxoSW01UEFOTk9Jbm1lV1Y0MnNGS2RUNFpFZWQ1Zzctd2t5M0VodlVSZm4w?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a powerful new Android banking trojan hitting over 200 apps, a federal warning about an actively exploited cPanel plugin, and a leaked membership list from Peter Thiel's ultra-exclusive Dialog retreat. Signal Check covers the threats already moving before your coffee gets cold.

Stories covered:
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds (The Hacker News) - https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html
- Humiliating IIS servers for fun and jail time (Hacker News) - https://mll.sh/humiliating-iis-servers-for-fun-and-jail-time/
- CISA warns of another cPanel plugin flaw exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/
- Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society (Wired) - https://www.wired.com/story/leak-exposes-members-of-peter-thiels-secretive-dialog-society/
- The 6 Best Toe Separators That Can Help Prevent Injury and Relieve Pain (Runner's World) - https://www.runnersworld.com/health-injuries/g40457572/best-toe-separators/
- Hacker: 'I Could Have Rickrolled the World Cup' - Bank Info Security (Bank Info Security) - https://news.google.com/rss/articles/CBMiiAFBVV95cUxNODd3SDVpTGV6ZGxCMU9HNS1ycjc3M0JnSDltYmJIOXZkQUEzSEtVTi1hZGVaVW1nc2J5MXJwTTZHZGxDeDBRd2lRd2U2YXd3b0U1UUpEOVd6RjdXRUxoSW01UEFOTk9Jbm1lV1Y0MnNGS2RUNFpFZWQ1Zzctd2t5M0VodlVSZm4w?oc=5]]>
      </content:encoded>
      <pubDate>Wed, 17 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/16ef58b2/b5a3a77e.mp3" length="5263550" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>325</itunes:duration>
      <itunes:summary>This episode digs into a powerful new Android banking trojan hitting over 200 apps, a federal warning about an actively exploited cPanel plugin, and a leaked membership list from Peter Thiel's ultra-exclusive Dialog retreat. Signal Check covers the threats already moving before your coffee gets cold.</itunes:summary>
      <itunes:subtitle>This episode digs into a powerful new Android banking trojan hitting over 200 apps, a federal warning about an actively exploited cPanel plugin, and a leaked membership list from Peter Thiel's ultra-exclusive Dialog retreat. Signal Check covers the threat</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 76: June 16, 2026</title>
      <itunes:episode>76</itunes:episode>
      <podcast:episode>76</podcast:episode>
      <itunes:title>Episode 76: June 16, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ef9dae5d-fda7-44b4-8d76-792c7433dff6</guid>
      <link>https://share.transistor.fm/s/d6e7132e</link>
      <description>
        <![CDATA[This episode digs into a cascade of high-value security breaches, from a three-vulnerability chain in AI gateway infrastructure to a one-click exploit in Microsoft 365 Copilot that exposed entire workspaces. We also cover a year-long Chinese espionage campaign that weaponized Google Workspace forwarding rules and a LinkedIn job scam that sparked hundreds of comments on Hacker News.

Stories covered:
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers (The Hacker News) - https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes (The Hacker News) - https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails (The Hacker News) - https://thehackernews.com/2026/06/chinese-hackers-abused-google-workspace.html
- A backdoor in a LinkedIn job offer (Hacker News) - https://roman.pt/posts/linkedin-backdoor/
- Think Your Best Running Years Are Behind You at 50+? This Mileage Data Says Otherwise. (Runner's World) - https://www.runnersworld.com/training/a71591415/running-after-50-mileage-data/
- A New “Stairway to Heaven” Awaits Broken Arrow Runners This Week (Marathon Handbook) - https://marathonhandbook.com/a-new-stairway-to-heaven-awaits-broken-arrow-runners-this-week/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a cascade of high-value security breaches, from a three-vulnerability chain in AI gateway infrastructure to a one-click exploit in Microsoft 365 Copilot that exposed entire workspaces. We also cover a year-long Chinese espionage campaign that weaponized Google Workspace forwarding rules and a LinkedIn job scam that sparked hundreds of comments on Hacker News.

Stories covered:
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers (The Hacker News) - https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes (The Hacker News) - https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails (The Hacker News) - https://thehackernews.com/2026/06/chinese-hackers-abused-google-workspace.html
- A backdoor in a LinkedIn job offer (Hacker News) - https://roman.pt/posts/linkedin-backdoor/
- Think Your Best Running Years Are Behind You at 50+? This Mileage Data Says Otherwise. (Runner's World) - https://www.runnersworld.com/training/a71591415/running-after-50-mileage-data/
- A New “Stairway to Heaven” Awaits Broken Arrow Runners This Week (Marathon Handbook) - https://marathonhandbook.com/a-new-stairway-to-heaven-awaits-broken-arrow-runners-this-week/]]>
      </content:encoded>
      <pubDate>Tue, 16 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d6e7132e/10934d7d.mp3" length="4907449" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>303</itunes:duration>
      <itunes:summary>This episode digs into a cascade of high-value security breaches, from a three-vulnerability chain in AI gateway infrastructure to a one-click exploit in Microsoft 365 Copilot that exposed entire workspaces. We also cover a year-long Chinese espionage campaign that weaponized Google Workspace forwarding rules and a LinkedIn job scam that sparked hundreds of comments on Hacker News.</itunes:summary>
      <itunes:subtitle>This episode digs into a cascade of high-value security breaches, from a three-vulnerability chain in AI gateway infrastructure to a one-click exploit in Microsoft 365 Copilot that exposed entire workspaces. We also cover a year-long Chinese espionage cam</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 75: June 15, 2026</title>
      <itunes:episode>75</itunes:episode>
      <podcast:episode>75</podcast:episode>
      <itunes:title>Episode 75: June 15, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">eda587c8-f4d7-4983-9f1c-687c31ca405c</guid>
      <link>https://share.transistor.fm/s/c9d8698e</link>
      <description>
        <![CDATA[This episode covers six cybersecurity and tech stories from Monday morning, including a zero-day exploit in Oracle PeopleSoft by ShinyHunters, a massive AUR package compromise affecting Arch Linux users, and a CISA emergency directive on Ivanti Sentry. Adrian also digs into a fascinating DIY project where someone indexed 669 gigabytes of GoPro footage using local machine learning models.

Stories covered:
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- Over 400 Arch Linux packages compromised to push rootkit, infostealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/
- I indexed 669 GB of my GoPro videos using my M1 Max computer and local ML models (Hacker News) - https://news.ycombinator.com/item?id=48528029
- Are You Running More or Less Than Your Peers? New Data Shows the Average Distance by Age Group (Runner's World) - https://www.runnersworld.com/training/a71570890/average-run-distance-by-age/
- She Started Running at 65—and Just 3 Years Later Finished Her First Boston Marathon (Runner's World) - https://www.runnersworld.com/runners-stories/a71550469/sandra-cotterell-boston-marathon/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers six cybersecurity and tech stories from Monday morning, including a zero-day exploit in Oracle PeopleSoft by ShinyHunters, a massive AUR package compromise affecting Arch Linux users, and a CISA emergency directive on Ivanti Sentry. Adrian also digs into a fascinating DIY project where someone indexed 669 gigabytes of GoPro footage using local machine learning models.

Stories covered:
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- Over 400 Arch Linux packages compromised to push rootkit, infostealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/
- I indexed 669 GB of my GoPro videos using my M1 Max computer and local ML models (Hacker News) - https://news.ycombinator.com/item?id=48528029
- Are You Running More or Less Than Your Peers? New Data Shows the Average Distance by Age Group (Runner's World) - https://www.runnersworld.com/training/a71570890/average-run-distance-by-age/
- She Started Running at 65—and Just 3 Years Later Finished Her First Boston Marathon (Runner's World) - https://www.runnersworld.com/runners-stories/a71550469/sandra-cotterell-boston-marathon/]]>
      </content:encoded>
      <pubDate>Mon, 15 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/c9d8698e/64cfdb90.mp3" length="5310779" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>328</itunes:duration>
      <itunes:summary>This episode covers six cybersecurity and tech stories from Monday morning, including a zero-day exploit in Oracle PeopleSoft by ShinyHunters, a massive AUR package compromise affecting Arch Linux users, and a CISA emergency directive on Ivanti Sentry. Adrian also digs into a fascinating DIY project where someone indexed 669 gigabytes of GoPro footage using local machine learning models.</itunes:summary>
      <itunes:subtitle>This episode covers six cybersecurity and tech stories from Monday morning, including a zero-day exploit in Oracle PeopleSoft by ShinyHunters, a massive AUR package compromise affecting Arch Linux users, and a CISA emergency directive on Ivanti Sentry. Ad</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 74: June 14, 2026</title>
      <itunes:episode>74</itunes:episode>
      <podcast:episode>74</podcast:episode>
      <itunes:title>Episode 74: June 14, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7c30e359-faed-4e49-aa34-57b4d3e025b8</guid>
      <link>https://share.transistor.fm/s/9b1f1aab</link>
      <description>
        <![CDATA[This episode covers a major supply chain attack on Arch Linux's AUR, a zero-day exploit in Oracle PeopleSoft used by the ShinyHunters crew to breach universities, and a few unexpected signals about endurance and starting late. Adrian breaks down the technical fallout from both incidents and reminds us that not every signal is a threat—some are just proof that it's never too late to begin. Grab your coffee and get the morning download before the day gets loud.

Stories covered:
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit (The Hacker News) - https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- Over 400 Arch Linux packages compromised to push rootkit, infostealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/
- She Started Running at 65—and Just 3 Years Later Finished Her First Boston Marathon (Runner's World) - https://www.runnersworld.com/runners-stories/a71550469/sandra-cotterell-boston-marathon/
- Intriguing Storylines and Predictions for the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/intriguing-storylines-and-predictions-for-the-2026-western-states-100
- Chinese hackers hijack auth flow, spy on isolated network for a decade (BleepingComputer) - https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a major supply chain attack on Arch Linux's AUR, a zero-day exploit in Oracle PeopleSoft used by the ShinyHunters crew to breach universities, and a few unexpected signals about endurance and starting late. Adrian breaks down the technical fallout from both incidents and reminds us that not every signal is a threat—some are just proof that it's never too late to begin. Grab your coffee and get the morning download before the day gets loud.

Stories covered:
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit (The Hacker News) - https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- Over 400 Arch Linux packages compromised to push rootkit, infostealer (BleepingComputer) - https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/
- She Started Running at 65—and Just 3 Years Later Finished Her First Boston Marathon (Runner's World) - https://www.runnersworld.com/runners-stories/a71550469/sandra-cotterell-boston-marathon/
- Intriguing Storylines and Predictions for the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/intriguing-storylines-and-predictions-for-the-2026-western-states-100
- Chinese hackers hijack auth flow, spy on isolated network for a decade (BleepingComputer) - https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/]]>
      </content:encoded>
      <pubDate>Sun, 14 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9b1f1aab/e0ce8a27.mp3" length="4795854" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>296</itunes:duration>
      <itunes:summary>This episode covers a major supply chain attack on Arch Linux's AUR, a zero-day exploit in Oracle PeopleSoft used by the ShinyHunters crew to breach universities, and a few unexpected signals about endurance and starting late. Adrian breaks down the technical fallout from both incidents and reminds us that not every signal is a threat—some are just proof that it's never too late to begin. Grab your coffee and get the morning download before the day gets loud.</itunes:summary>
      <itunes:subtitle>This episode covers a major supply chain attack on Arch Linux's AUR, a zero-day exploit in Oracle PeopleSoft used by the ShinyHunters crew to breach universities, and a few unexpected signals about endurance and starting late. Adrian breaks down the techn</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 73: June 13, 2026</title>
      <itunes:episode>73</itunes:episode>
      <podcast:episode>73</podcast:episode>
      <itunes:title>Episode 73: June 13, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9dd1c4dd-6551-4f89-afaf-d3d4e22be161</guid>
      <link>https://share.transistor.fm/s/ef8a0a21</link>
      <description>
        <![CDATA[This episode digs into a brutal week for security, starting with over 400 hijacked Arch Linux packages that installed credential stealers and rootkits. We also cover ShinyHunters exploiting a zero-day in Oracle PeopleSoft to hit universities, and an AI-powered cyber defense platform launching with serious funding and even bigger questions.

Stories covered:
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit (The Hacker News) - https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- He Hacked Teslas For Elon Musk. Now He’s Launching A $100 Million AI Cyber Agent. - Forbes (Forbes) - https://news.google.com/rss/articles/CBMiuwFBVV95cUxPeEhOdFU0M2trc1E2Zko0d0pzX2lyQ2RNdExTcno4WWI5cGRHUThGeWQtR3locXZPREwtNkhkVG0yZ2lUQjNVVTJQM0VjVHd3U2k1WHp3S0dwMEc5YlNfN1ZBTll3cTJ2dm14ZWVHZjJ4eTJiWnRVazBJN3FvbU1MM2I1VHh5VlhLNnVROHJaNXR5eDA5UUE2dUVJU25HcU1ITFpZQnV0eUxTS0FxUmpRaVI4TkFrbWdDTEFB?oc=5
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/
- Intriguing Storylines and Predictions for the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/intriguing-storylines-and-predictions-for-the-2026-western-states-100
- Man sues law enforcement alleging AI facial recognition technology led to wrongful arrest - ABC News - Breaking News, Latest News and Videos (ABC News - Breaking News, Latest News and Videos) - https://news.google.com/rss/articles/CBMipgFBVV95cUxNYkxZcmlfd3dZdHRKb0JGdUExZWVmRDlPYkNlczc0LWtfMnU1ektLaWt1a2JtTXRhOGVpYkJUOUJmdG9VXzJVdUxsMnR0UWNRYXdmUUtnQnR6QmhuQUNRc2NpcFQ1ZEZackU2UzJ6SU8wUndvZ1VWUjN0NS0yWVhTRGt5QjZCZmk2QjR0NHQzTmx4Z0Q5MVBEZjdPZDVkbDg2WkRyNDdB0gGrAUFVX3lxTE1ZaGdfR1NQVWZQQVRkXzZDc2tWcl9JVUV4clhPUzlvNUgxdWNyVDFuSkptWjVSWXp1aU5ZOGcxblpWX1JzMGtJalgzUFJhcS1VX2lWNy1fR0tOeGFJY3NnNDhEUGlRazZuT2ZYejdOWGpPOXJBcExnd1paMnhvZkppdjZWU2xCeU9VMk1DeWZiMVNONzdMdHlyOFNpRC01Sm1Zb0RzY2dEY0ROSQ?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a brutal week for security, starting with over 400 hijacked Arch Linux packages that installed credential stealers and rootkits. We also cover ShinyHunters exploiting a zero-day in Oracle PeopleSoft to hit universities, and an AI-powered cyber defense platform launching with serious funding and even bigger questions.

Stories covered:
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit (The Hacker News) - https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- He Hacked Teslas For Elon Musk. Now He’s Launching A $100 Million AI Cyber Agent. - Forbes (Forbes) - https://news.google.com/rss/articles/CBMiuwFBVV95cUxPeEhOdFU0M2trc1E2Zko0d0pzX2lyQ2RNdExTcno4WWI5cGRHUThGeWQtR3locXZPREwtNkhkVG0yZ2lUQjNVVTJQM0VjVHd3U2k1WHp3S0dwMEc5YlNfN1ZBTll3cTJ2dm14ZWVHZjJ4eTJiWnRVazBJN3FvbU1MM2I1VHh5VlhLNnVROHJaNXR5eDA5UUE2dUVJU25HcU1ITFpZQnV0eUxTS0FxUmpRaVI4TkFrbWdDTEFB?oc=5
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/
- Intriguing Storylines and Predictions for the 2026 Western States 100 (iRunFar) - https://www.irunfar.com/intriguing-storylines-and-predictions-for-the-2026-western-states-100
- Man sues law enforcement alleging AI facial recognition technology led to wrongful arrest - ABC News - Breaking News, Latest News and Videos (ABC News - Breaking News, Latest News and Videos) - https://news.google.com/rss/articles/CBMipgFBVV95cUxNYkxZcmlfd3dZdHRKb0JGdUExZWVmRDlPYkNlczc0LWtfMnU1ektLaWt1a2JtTXRhOGVpYkJUOUJmdG9VXzJVdUxsMnR0UWNRYXdmUUtnQnR6QmhuQUNRc2NpcFQ1ZEZackU2UzJ6SU8wUndvZ1VWUjN0NS0yWVhTRGt5QjZCZmk2QjR0NHQzTmx4Z0Q5MVBEZjdPZDVkbDg2WkRyNDdB0gGrAUFVX3lxTE1ZaGdfR1NQVWZQQVRkXzZDc2tWcl9JVUV4clhPUzlvNUgxdWNyVDFuSkptWjVSWXp1aU5ZOGcxblpWX1JzMGtJalgzUFJhcS1VX2lWNy1fR0tOeGFJY3NnNDhEUGlRazZuT2ZYejdOWGpPOXJBcExnd1paMnhvZkppdjZWU2xCeU9VMk1DeWZiMVNONzdMdHlyOFNpRC01Sm1Zb0RzY2dEY0ROSQ?oc=5]]>
      </content:encoded>
      <pubDate>Sat, 13 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/ef8a0a21/c70a172f.mp3" length="5546926" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>343</itunes:duration>
      <itunes:summary>This episode digs into a brutal week for security, starting with over 400 hijacked Arch Linux packages that installed credential stealers and rootkits. We also cover ShinyHunters exploiting a zero-day in Oracle PeopleSoft to hit universities, and an AI-powered cyber defense platform launching with serious funding and even bigger questions.</itunes:summary>
      <itunes:subtitle>This episode digs into a brutal week for security, starting with over 400 hijacked Arch Linux packages that installed credential stealers and rootkits. We also cover ShinyHunters exploiting a zero-day in Oracle PeopleSoft to hit universities, and an AI-po</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 72: June 12, 2026</title>
      <itunes:episode>72</itunes:episode>
      <podcast:episode>72</podcast:episode>
      <itunes:title>Episode 72: June 12, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7cb2555a-7d2f-45e1-9f49-5baed00a2de2</guid>
      <link>https://share.transistor.fm/s/e9c9d999</link>
      <description>
        <![CDATA[This episode covers ShinyHunters exploiting an unpatched Oracle PeopleSoft vulnerability to breach universities, the leaked Miasma worm source code lowering the barrier for supply-chain attacks, and new research showing how AI agents like OpenClaw can be tricked into running malicious code through prompt injection. Adrian breaks down the week's critical signals before the weekend hits.

Stories covered:
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- The ‘Miasma’ worm source code briefly leaked on GitHub (BleepingComputer) - https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/
- New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets (The Hacker News) - https://thehackernews.com/2026/06/new-attacks-trick-openclaw-ai-agent.html
- Why You Have to Run SLOW to Race FAST (The Science of Easy Running) (Marathon Handbook) - https://marathonhandbook.com/why-you-have-to-run-slow-to-race-fast-the-science-of-easy-running/
- Everest 2026: Sherpas and Guides Call For Change (ExplorersWeb) - https://explorersweb.com/everest-2026-summary-sherpas-and-guides-call-for-change/
- Why You Might Already Own SpaceX Shares, Siri’s AI Makeover, and Knicks Owner’s Surveillance Machine (Wired) - https://www.wired.com/story/uncanny-valley-podcast-why-you-might-already-own-spacex-shares-siri-ai-makeover-knicks-owner-surveillance-machine/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers ShinyHunters exploiting an unpatched Oracle PeopleSoft vulnerability to breach universities, the leaked Miasma worm source code lowering the barrier for supply-chain attacks, and new research showing how AI agents like OpenClaw can be tricked into running malicious code through prompt injection. Adrian breaks down the week's critical signals before the weekend hits.

Stories covered:
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities (The Hacker News) - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- The ‘Miasma’ worm source code briefly leaked on GitHub (BleepingComputer) - https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/
- New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets (The Hacker News) - https://thehackernews.com/2026/06/new-attacks-trick-openclaw-ai-agent.html
- Why You Have to Run SLOW to Race FAST (The Science of Easy Running) (Marathon Handbook) - https://marathonhandbook.com/why-you-have-to-run-slow-to-race-fast-the-science-of-easy-running/
- Everest 2026: Sherpas and Guides Call For Change (ExplorersWeb) - https://explorersweb.com/everest-2026-summary-sherpas-and-guides-call-for-change/
- Why You Might Already Own SpaceX Shares, Siri’s AI Makeover, and Knicks Owner’s Surveillance Machine (Wired) - https://www.wired.com/story/uncanny-valley-podcast-why-you-might-already-own-spacex-shares-siri-ai-makeover-knicks-owner-surveillance-machine/]]>
      </content:encoded>
      <pubDate>Fri, 12 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/e9c9d999/43f1cac9.mp3" length="6202704" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>384</itunes:duration>
      <itunes:summary>This episode covers ShinyHunters exploiting an unpatched Oracle PeopleSoft vulnerability to breach universities, the leaked Miasma worm source code lowering the barrier for supply-chain attacks, and new research showing how AI agents like OpenClaw can be tricked into running malicious code through prompt injection. Adrian breaks down the week's critical signals before the weekend hits.</itunes:summary>
      <itunes:subtitle>This episode covers ShinyHunters exploiting an unpatched Oracle PeopleSoft vulnerability to breach universities, the leaked Miasma worm source code lowering the barrier for supply-chain attacks, and new research showing how AI agents like OpenClaw can be </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 71: June 11, 2026</title>
      <itunes:episode>71</itunes:episode>
      <podcast:episode>71</podcast:episode>
      <itunes:title>Episode 71: June 11, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f7df2549-1685-4b93-acdb-4b1a726d2e4d</guid>
      <link>https://share.transistor.fm/s/5115abac</link>
      <description>
        <![CDATA[This episode digs into a fresh Microsoft Defender zero-day granting full system access, a new SSD timing attack that tracks your browsing through hardware behavior, and the rise of The Gentlemen ransomware group building a professional cybercrime empire. Adrian breaks down why these aren't just bugs—they're fundamental shifts in how attacks work. Morning coffee required.

Stories covered:
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows (The Hacker News) - https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html
- New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMigAFBVV95cUxQcHJSUHJZODRwQVc2bUJwR3hGUWlwS1NYazduREVkWk1ScXNMVTd4c051Uk5TOUwtNk52RGh6QlVLZjhIR2ExZGpoWDJha0hIR193eC00WlNxaXhwZ1A5T0wxSlJKdC11d2JESldOcVpfSThBT3ZjWUpfTW15M3Z0cA?oc=5
- Who Runs the Ransomware Group ‘The Gentlemen?’ (Krebs on Security) - https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
- This Adidas Trainer Was Our Best Overall Running Shoe, and It’s Just $105 Right Now (Runner's World) - https://www.runnersworld.com/gear/a71547463/adidas-adizero-evo-sl-sale-june-2026/
- China Opens World’s First Wind-Powered Underwater Data Center (Wired) - https://www.wired.com/story/china-opens-worlds-first-wind-powered-underwater-data-center/
- How JPL keeps the 13-year-old Curiosity rover doing science (Hacker News) - https://spectrum.ieee.org/curiosity-rover-jpl-mars-science]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a fresh Microsoft Defender zero-day granting full system access, a new SSD timing attack that tracks your browsing through hardware behavior, and the rise of The Gentlemen ransomware group building a professional cybercrime empire. Adrian breaks down why these aren't just bugs—they're fundamental shifts in how attacks work. Morning coffee required.

Stories covered:
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows (The Hacker News) - https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html
- New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMigAFBVV95cUxQcHJSUHJZODRwQVc2bUJwR3hGUWlwS1NYazduREVkWk1ScXNMVTd4c051Uk5TOUwtNk52RGh6QlVLZjhIR2ExZGpoWDJha0hIR193eC00WlNxaXhwZ1A5T0wxSlJKdC11d2JESldOcVpfSThBT3ZjWUpfTW15M3Z0cA?oc=5
- Who Runs the Ransomware Group ‘The Gentlemen?’ (Krebs on Security) - https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
- This Adidas Trainer Was Our Best Overall Running Shoe, and It’s Just $105 Right Now (Runner's World) - https://www.runnersworld.com/gear/a71547463/adidas-adizero-evo-sl-sale-june-2026/
- China Opens World’s First Wind-Powered Underwater Data Center (Wired) - https://www.wired.com/story/china-opens-worlds-first-wind-powered-underwater-data-center/
- How JPL keeps the 13-year-old Curiosity rover doing science (Hacker News) - https://spectrum.ieee.org/curiosity-rover-jpl-mars-science]]>
      </content:encoded>
      <pubDate>Thu, 11 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/5115abac/b8685e61.mp3" length="5600007" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>346</itunes:duration>
      <itunes:summary>This episode digs into a fresh Microsoft Defender zero-day granting full system access, a new SSD timing attack that tracks your browsing through hardware behavior, and the rise of The Gentlemen ransomware group building a professional cybercrime empire. Adrian breaks down why these aren't just bugs—they're fundamental shifts in how attacks work. Morning coffee required.</itunes:summary>
      <itunes:subtitle>This episode digs into a fresh Microsoft Defender zero-day granting full system access, a new SSD timing attack that tracks your browsing through hardware behavior, and the rise of The Gentlemen ransomware group building a professional cybercrime empire. </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 70: June 10, 2026</title>
      <itunes:episode>70</itunes:episode>
      <podcast:episode>70</podcast:episode>
      <itunes:title>Episode 70: June 10, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5eb6ceb7-9c0c-47a6-8567-e829f84c5660</guid>
      <link>https://share.transistor.fm/s/4aaed6bf</link>
      <description>
        <![CDATA[This episode covers a critical Check Point VPN flaw being actively exploited by ransomware groups, a wild new browser-based attack that uses your SSD to spy on your activity, and a must-patch Veeam vulnerability that lets any domain user compromise your backup infrastructure. Adrian also digs into surprising running science that shows walking breaks can actually make you faster. It's threat intel, hardware side-channels, and a dash of endurance strategy before your second cup of coffee.

Stories covered:
- CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/
- New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing (The Hacker News) - https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html
- Veeam Backup &amp; Replication RCE Flaw Lets Domain Users Run Remote Code (The Hacker News) - https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html
- Walking Breaks Can Make You a Faster and Better Runner. We Can Prove It. (Runner's World) - https://www.runnersworld.com/training/a70690471/walking-break-can-make-you-faster/
- 4 Tactics and 14 Organizations to Support LGBTQ+ Climbers This Pride Month (Climbing Magazine) - https://www.climbing.com/culture-climbing/support-lgbtq-climbers-pride-month/
- COROS Watches Now Talk to AllTrails, Giving Trail Runners One Map for the Backcountry (Marathon Handbook) - https://marathonhandbook.com/coros-watches-now-talk-to-alltrails-giving-trail-runners-one-map-for-the-backcountry/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Check Point VPN flaw being actively exploited by ransomware groups, a wild new browser-based attack that uses your SSD to spy on your activity, and a must-patch Veeam vulnerability that lets any domain user compromise your backup infrastructure. Adrian also digs into surprising running science that shows walking breaks can actually make you faster. It's threat intel, hardware side-channels, and a dash of endurance strategy before your second cup of coffee.

Stories covered:
- CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/
- New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing (The Hacker News) - https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html
- Veeam Backup &amp; Replication RCE Flaw Lets Domain Users Run Remote Code (The Hacker News) - https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html
- Walking Breaks Can Make You a Faster and Better Runner. We Can Prove It. (Runner's World) - https://www.runnersworld.com/training/a70690471/walking-break-can-make-you-faster/
- 4 Tactics and 14 Organizations to Support LGBTQ+ Climbers This Pride Month (Climbing Magazine) - https://www.climbing.com/culture-climbing/support-lgbtq-climbers-pride-month/
- COROS Watches Now Talk to AllTrails, Giving Trail Runners One Map for the Backcountry (Marathon Handbook) - https://marathonhandbook.com/coros-watches-now-talk-to-alltrails-giving-trail-runners-one-map-for-the-backcountry/]]>
      </content:encoded>
      <pubDate>Wed, 10 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/4aaed6bf/79e909f5.mp3" length="5019880" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>310</itunes:duration>
      <itunes:summary>This episode covers a critical Check Point VPN flaw being actively exploited by ransomware groups, a wild new browser-based attack that uses your SSD to spy on your activity, and a must-patch Veeam vulnerability that lets any domain user compromise your backup infrastructure. Adrian also digs into surprising running science that shows walking breaks can actually make you faster. It's threat intel, hardware side-channels, and a dash of endurance strategy before your second cup of coffee.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Check Point VPN flaw being actively exploited by ransomware groups, a wild new browser-based attack that uses your SSD to spy on your activity, and a must-patch Veeam vulnerability that lets any domain user compromise your b</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 69: June 09, 2026</title>
      <itunes:episode>69</itunes:episode>
      <podcast:episode>69</podcast:episode>
      <itunes:title>Episode 69: June 09, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">22d7fe5a-45bb-4b3f-98ee-fd51c0b24e38</guid>
      <link>https://share.transistor.fm/s/341cfbe6</link>
      <description>
        <![CDATA[This episode covers emergency patches for a critical Check Point VPN zero-day that's been exploited by ransomware groups since early May, plus a Python supply-chain attack that compromised nineteen packages on PyPI. Adrian breaks down why patching isn't enough when attackers have already had weeks inside networks, and how developer trust becomes the vulnerability in these campaigns.

Stories covered:
- Check Point VPN Flaw Exploited Since Early May (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/check-point-vpn-flaw-exploited-early-may
- Check Point links VPN zero-day attacks to Qilin ransomware gang (BleepingComputer) - https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
- New Shai-Hulud attack trojanizes 19 science-focused PyPI packages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages/
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (The Hacker News) - https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html
- ‘I’m a 75-Year-Old Grandmother of Six and Just Ran a 3:57 Marathon. This Is How I Train’ (Runner's World) - https://www.runnersworld.com/training/a71523801/penny-jarvis-runner/
- Surveillance Is Not Safety: A statement on the UK's latest threat to privacy [pdf] (Hacker News) - https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers emergency patches for a critical Check Point VPN zero-day that's been exploited by ransomware groups since early May, plus a Python supply-chain attack that compromised nineteen packages on PyPI. Adrian breaks down why patching isn't enough when attackers have already had weeks inside networks, and how developer trust becomes the vulnerability in these campaigns.

Stories covered:
- Check Point VPN Flaw Exploited Since Early May (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/check-point-vpn-flaw-exploited-early-may
- Check Point links VPN zero-day attacks to Qilin ransomware gang (BleepingComputer) - https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
- New Shai-Hulud attack trojanizes 19 science-focused PyPI packages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages/
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (The Hacker News) - https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html
- ‘I’m a 75-Year-Old Grandmother of Six and Just Ran a 3:57 Marathon. This Is How I Train’ (Runner's World) - https://www.runnersworld.com/training/a71523801/penny-jarvis-runner/
- Surveillance Is Not Safety: A statement on the UK's latest threat to privacy [pdf] (Hacker News) - https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf]]>
      </content:encoded>
      <pubDate>Tue, 09 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/341cfbe6/ac7174c4.mp3" length="6625261" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>410</itunes:duration>
      <itunes:summary>This episode covers emergency patches for a critical Check Point VPN zero-day that's been exploited by ransomware groups since early May, plus a Python supply-chain attack that compromised nineteen packages on PyPI. Adrian breaks down why patching isn't enough when attackers have already had weeks inside networks, and how developer trust becomes the vulnerability in these campaigns.</itunes:summary>
      <itunes:subtitle>This episode covers emergency patches for a critical Check Point VPN zero-day that's been exploited by ransomware groups since early May, plus a Python supply-chain attack that compromised nineteen packages on PyPI. Adrian breaks down why patching isn't e</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 68: June 08, 2026</title>
      <itunes:episode>68</itunes:episode>
      <podcast:episode>68</podcast:episode>
      <itunes:title>Episode 68: June 08, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4641e1b8-0aa7-4fbc-b2ad-9ea0df1d169b</guid>
      <link>https://share.transistor.fm/s/2b1149a2</link>
      <description>
        <![CDATA[This episode digs into the worst security breaches of 2026 so far, from compromised critical infrastructure to a hacked FBI surveillance system. Adrian also covers World Cup scammers flooding the web with fake ticket sites and a freshly exploited SolarWinds vulnerability causing server crashes across government and enterprise networks.

Stories covered:
- Hacked, leaked, and held for ransom: the worst breaches of 2026 so far (TechCrunch) - https://techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/
- This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/
- Rory Linkletter Trades the Road for His Trail Running Debut (Marathon Handbook) - https://marathonhandbook.com/rory-linkletter-trades-the-road-for-a-mountain/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into the worst security breaches of 2026 so far, from compromised critical infrastructure to a hacked FBI surveillance system. Adrian also covers World Cup scammers flooding the web with fake ticket sites and a freshly exploited SolarWinds vulnerability causing server crashes across government and enterprise networks.

Stories covered:
- Hacked, leaked, and held for ransom: the worst breaches of 2026 so far (TechCrunch) - https://techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/
- This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/
- Rory Linkletter Trades the Road for His Trail Running Debut (Marathon Handbook) - https://marathonhandbook.com/rory-linkletter-trades-the-road-for-a-mountain/]]>
      </content:encoded>
      <pubDate>Mon, 08 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/2b1149a2/04226f79.mp3" length="6447628" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>399</itunes:duration>
      <itunes:summary>This episode digs into the worst security breaches of 2026 so far, from compromised critical infrastructure to a hacked FBI surveillance system. Adrian also covers World Cup scammers flooding the web with fake ticket sites and a freshly exploited SolarWinds vulnerability causing server crashes across government and enterprise networks.</itunes:summary>
      <itunes:subtitle>This episode digs into the worst security breaches of 2026 so far, from compromised critical infrastructure to a hacked FBI surveillance system. Adrian also covers World Cup scammers flooding the web with fake ticket sites and a freshly exploited SolarWin</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 67: June 07, 2026</title>
      <itunes:episode>67</itunes:episode>
      <podcast:episode>67</podcast:episode>
      <itunes:title>Episode 67: June 07, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b203f506-9f98-4d93-9288-2341d1d9653a</guid>
      <link>https://share.transistor.fm/s/018b8575</link>
      <description>
        <![CDATA[This episode digs into Arabic-targeted Android spyware disguised as news apps, a massive npm supply chain attack distributing Rust-based malware to developers, and how hackers reportedly hijacked high-profile Instagram accounts using Meta's own AI support bot. Adrian North walks through the weekend's most critical signals before the world fully wakes up. It's your Sunday morning threat briefing with coffee in hand.

Stories covered:
- Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps (The Hacker News) - https://thehackernews.com/2026/06/android-spyware-asin-targets-arabic.html
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks (The Hacker News) - https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts (Krebs on Security) - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
- This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/
- What to Do if Your Trail Dog is Obsessed With Wildlife (Trail Runner Mag) - https://www.trailrunnermag.com/people/culture-people/what-to-do-if-your-trail-dog-is-obsessed-with-wildlife/
- Pentagon raised threat of Israeli spying on U.S. to highest level, sources say (Hacker News) - https://www.nbcnews.com/politics/national-security/pentagon-raised-threat-israeli-spying-us-highest-level-sources-say-rcna348565]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Arabic-targeted Android spyware disguised as news apps, a massive npm supply chain attack distributing Rust-based malware to developers, and how hackers reportedly hijacked high-profile Instagram accounts using Meta's own AI support bot. Adrian North walks through the weekend's most critical signals before the world fully wakes up. It's your Sunday morning threat briefing with coffee in hand.

Stories covered:
- Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps (The Hacker News) - https://thehackernews.com/2026/06/android-spyware-asin-targets-arabic.html
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks (The Hacker News) - https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts (Krebs on Security) - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
- This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/
- What to Do if Your Trail Dog is Obsessed With Wildlife (Trail Runner Mag) - https://www.trailrunnermag.com/people/culture-people/what-to-do-if-your-trail-dog-is-obsessed-with-wildlife/
- Pentagon raised threat of Israeli spying on U.S. to highest level, sources say (Hacker News) - https://www.nbcnews.com/politics/national-security/pentagon-raised-threat-israeli-spying-us-highest-level-sources-say-rcna348565]]>
      </content:encoded>
      <pubDate>Sun, 07 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/018b8575/6e2b9fbb.mp3" length="6271667" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>388</itunes:duration>
      <itunes:summary>This episode digs into Arabic-targeted Android spyware disguised as news apps, a massive npm supply chain attack distributing Rust-based malware to developers, and how hackers reportedly hijacked high-profile Instagram accounts using Meta's own AI support bot. Adrian North walks through the weekend's most critical signals before the world fully wakes up. It's your Sunday morning threat briefing with coffee in hand.</itunes:summary>
      <itunes:subtitle>This episode digs into Arabic-targeted Android spyware disguised as news apps, a massive npm supply chain attack distributing Rust-based malware to developers, and how hackers reportedly hijacked high-profile Instagram accounts using Meta's own AI support</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 66: June 06, 2026</title>
      <itunes:episode>66</itunes:episode>
      <podcast:episode>66</podcast:episode>
      <itunes:title>Episode 66: June 06, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4ead25e1-0590-416f-90bc-44484a9345c5</guid>
      <link>https://share.transistor.fm/s/4149d23d</link>
      <description>
        <![CDATA[This episode covers six critical cybersecurity signals, from World Cup scam operations already in overdrive to the disturbing rise of in-person social engineering attacks where ransomware crews literally walk into offices. Adrian unpacks why the browser has become the new security perimeter and what that means for anyone who thinks their defenses are still holding.

Stories covered:
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html
- What 2026 DBIR Confirms: Attacks Are Living in the Browser (BleepingComputer) - https://www.bleepingcomputer.com/news/security/what-2026-dbir-confirms-attacks-are-living-in-the-browser/
- Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person (TechCrunch) - https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/
- Best Running Shoes, Tested and Reviewed (2026): Saucony, Adidas, Hoka (Wired) - https://www.wired.com/gallery/best-running-shoes/
- pg_durable: Microsoft open sources in-database durable execution (Hacker News) - https://github.com/microsoft/pg_durable
- The saga of the International Space Station air leak took a worrying turn Friday (Ars Technica) - https://arstechnica.com/space/2026/06/work-on-russias-leaky-space-station-module-causes-astronauts-to-take-shelter/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers six critical cybersecurity signals, from World Cup scam operations already in overdrive to the disturbing rise of in-person social engineering attacks where ransomware crews literally walk into offices. Adrian unpacks why the browser has become the new security perimeter and what that means for anyone who thinks their defenses are still holding.

Stories covered:
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html
- What 2026 DBIR Confirms: Attacks Are Living in the Browser (BleepingComputer) - https://www.bleepingcomputer.com/news/security/what-2026-dbir-confirms-attacks-are-living-in-the-browser/
- Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person (TechCrunch) - https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/
- Best Running Shoes, Tested and Reviewed (2026): Saucony, Adidas, Hoka (Wired) - https://www.wired.com/gallery/best-running-shoes/
- pg_durable: Microsoft open sources in-database durable execution (Hacker News) - https://github.com/microsoft/pg_durable
- The saga of the International Space Station air leak took a worrying turn Friday (Ars Technica) - https://arstechnica.com/space/2026/06/work-on-russias-leaky-space-station-module-causes-astronauts-to-take-shelter/]]>
      </content:encoded>
      <pubDate>Sat, 06 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/4149d23d/ab2a64c7.mp3" length="6110335" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>378</itunes:duration>
      <itunes:summary>This episode covers six critical cybersecurity signals, from World Cup scam operations already in overdrive to the disturbing rise of in-person social engineering attacks where ransomware crews literally walk into offices. Adrian unpacks why the browser has become the new security perimeter and what that means for anyone who thinks their defenses are still holding.</itunes:summary>
      <itunes:subtitle>This episode covers six critical cybersecurity signals, from World Cup scam operations already in overdrive to the disturbing rise of in-person social engineering attacks where ransomware crews literally walk into offices. Adrian unpacks why the browser h</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 65: June 05, 2026</title>
      <itunes:episode>65</itunes:episode>
      <podcast:episode>65</podcast:episode>
      <itunes:title>Episode 65: June 05, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9687885d-57d0-4cd4-903e-09b32022c117</guid>
      <link>https://share.transistor.fm/s/267b283f</link>
      <description>
        <![CDATA[This episode covers a critical Cisco vulnerability that grants attackers root access without credentials, AI-powered tools now hunting bugs faster than humans, and underground tutorials industrializing cybercrime for beginners. We also dig into a two-year-old Redis flaw and a sixteen-year-old white-hat hacker who broke into India's exam portals just to fix them. It's Signal Check — your early-morning look at what's moving in the security world before the chaos starts.

Stories covered:
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public (The Hacker News) - https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) (The Hacker News) - https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html
- Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-are-after-the-gaps-in-your-vulnerability-program-heres-their-playbook/
- He is 16. He broke into NEET and JEE portals to fix it - India Today (India Today) - https://news.google.com/rss/articles/CBMiugFBVV95cUxNYV9RR0xua1h2X1lQQTNzN1ZwX1Blck82V0huZmFScmdwZFlfOXQ0OXFyOTVKLUZ4Mlp3WVJsQmI0Qm9JQjE1THA4aGJ3QVhjWGgtY2dXYm80Z01GTXR6MXh1SEdIVzM5dTkxUDhIYUpkN1dxSUp6WnBiN0I3M0E0ZjhZZk5vbkhsNHhsZ3YzUFI0cjZLQl9SYjNUdU9qcThxai1mYWRFRHZqRWE0WkdXbzV6MjVtMTdCVGfSAb8BQVVfeXFMUDdUUkx4VVZJbnAyNUdfWHdBdGMwWlRvR0padFFUY3hMR252YXJjcHA1TlEtSThlaE8teWpFelp6RlFsVzhvQ2JDMXpfWUdhalBsa3pObGdrbkVvSjBkVFRJbGhtWTh6VmdfRFhlMWNYek92dHFQa0M2enV0OE9USGdFM1hZS21tOUdFTUxUWkRJNmhmbUhZMlFaS19aank1WS1RNHFZSWFSU2ozTllEVXN6blBDLVJJb0FJdHVvYjA?oc=5
- This 90-Year-Old Runner Just Finished His First Marathon After Rediscovering Running Later in Life (Runner's World) - https://www.runnersworld.com/news/a71481967/bill-schwarz-first-marathon-90-years-old/
- Meta's ships facial recognition on smart glasses (Hacker News) - https://www.buchodi.com/meta-glasses-facial-recognition/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Cisco vulnerability that grants attackers root access without credentials, AI-powered tools now hunting bugs faster than humans, and underground tutorials industrializing cybercrime for beginners. We also dig into a two-year-old Redis flaw and a sixteen-year-old white-hat hacker who broke into India's exam portals just to fix them. It's Signal Check — your early-morning look at what's moving in the security world before the chaos starts.

Stories covered:
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public (The Hacker News) - https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) (The Hacker News) - https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html
- Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-are-after-the-gaps-in-your-vulnerability-program-heres-their-playbook/
- He is 16. He broke into NEET and JEE portals to fix it - India Today (India Today) - https://news.google.com/rss/articles/CBMiugFBVV95cUxNYV9RR0xua1h2X1lQQTNzN1ZwX1Blck82V0huZmFScmdwZFlfOXQ0OXFyOTVKLUZ4Mlp3WVJsQmI0Qm9JQjE1THA4aGJ3QVhjWGgtY2dXYm80Z01GTXR6MXh1SEdIVzM5dTkxUDhIYUpkN1dxSUp6WnBiN0I3M0E0ZjhZZk5vbkhsNHhsZ3YzUFI0cjZLQl9SYjNUdU9qcThxai1mYWRFRHZqRWE0WkdXbzV6MjVtMTdCVGfSAb8BQVVfeXFMUDdUUkx4VVZJbnAyNUdfWHdBdGMwWlRvR0padFFUY3hMR252YXJjcHA1TlEtSThlaE8teWpFelp6RlFsVzhvQ2JDMXpfWUdhalBsa3pObGdrbkVvSjBkVFRJbGhtWTh6VmdfRFhlMWNYek92dHFQa0M2enV0OE9USGdFM1hZS21tOUdFTUxUWkRJNmhmbUhZMlFaS19aank1WS1RNHFZSWFSU2ozTllEVXN6blBDLVJJb0FJdHVvYjA?oc=5
- This 90-Year-Old Runner Just Finished His First Marathon After Rediscovering Running Later in Life (Runner's World) - https://www.runnersworld.com/news/a71481967/bill-schwarz-first-marathon-90-years-old/
- Meta's ships facial recognition on smart glasses (Hacker News) - https://www.buchodi.com/meta-glasses-facial-recognition/]]>
      </content:encoded>
      <pubDate>Fri, 05 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/267b283f/b31e695c.mp3" length="5392281" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>333</itunes:duration>
      <itunes:summary>This episode covers a critical Cisco vulnerability that grants attackers root access without credentials, AI-powered tools now hunting bugs faster than humans, and underground tutorials industrializing cybercrime for beginners. We also dig into a two-year-old Redis flaw and a sixteen-year-old white-hat hacker who broke into India's exam portals just to fix them. It's Signal Check — your early-morning look at what's moving in the security world before the chaos starts.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Cisco vulnerability that grants attackers root access without credentials, AI-powered tools now hunting bugs faster than humans, and underground tutorials industrializing cybercrime for beginners. We also dig into a two-year</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 64: June 04, 2026</title>
      <itunes:episode>64</itunes:episode>
      <podcast:episode>64</podcast:episode>
      <itunes:title>Episode 64: June 04, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9757e7c2-9817-46ff-ab95-b8a231add4b0</guid>
      <link>https://share.transistor.fm/s/570237bc</link>
      <description>
        <![CDATA[This episode covers a zero-day flaw in Visual Studio Code that's leaking GitHub tokens, a devastating HTTP/2 exploit hammering web servers across the internet, and how attackers are now using AI to automatically bypass security tools faster than defenders can respond. Adrian breaks down what's moving in the threat landscape before your second cup of coffee hits. It's Thursday morning, and the signals are already loud.

Stories covered:
- VS Code zero-day lets hackers steal GitHub tokens in one click (BleepingComputer) - https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/
- New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy &amp; Cloudflare (The Hacker News) - https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html
- Attackers Use AI to Automate EDR Evasion Testing (Dark Reading) - https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing
- Is It Okay to Take Breaks During Long Runs? Experts Explain When It Helps and When It Signals a Red Flag (Runner's World) - https://www.runnersworld.com/training/a71483612/stopping-during-long-runs/
- UAH researchers studying technology that could cut travel time to Mars - WAAY 31 News (WAAY 31 News) - https://news.google.com/rss/articles/CBMi4gFBVV95cUxQS081ZEhrbGhfa2V3LXhYcmVjQjZmMmU2UURsU2FkTnhOSlNzYW1nQ0duLS1iSTdRTE1pcG55cUhhR0hxX0ZxZHlmTG5kZ09ZSkdrejREb1ZTNzhQaHEwcWlWUWlFWi1RdUtackdPOGRmaEdIaGlSc0hWRHdWaWRzZUlBQV9FSUlzY1FsTk1zRFBXM08wLWVYNEgwMGZyMDJXY1lEYmdxZFVQd0wwWFR3aWczVkl6ZDM5Znc5SVplaEpQZnNJUkVsN0tjLVlXQ3FvQ1VfOXJGNFVKMmp2eXBxb25n?oc=5
- CISA warns of cyberattacks targeting fuel tank monitoring systems (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a zero-day flaw in Visual Studio Code that's leaking GitHub tokens, a devastating HTTP/2 exploit hammering web servers across the internet, and how attackers are now using AI to automatically bypass security tools faster than defenders can respond. Adrian breaks down what's moving in the threat landscape before your second cup of coffee hits. It's Thursday morning, and the signals are already loud.

Stories covered:
- VS Code zero-day lets hackers steal GitHub tokens in one click (BleepingComputer) - https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/
- New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy &amp; Cloudflare (The Hacker News) - https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html
- Attackers Use AI to Automate EDR Evasion Testing (Dark Reading) - https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing
- Is It Okay to Take Breaks During Long Runs? Experts Explain When It Helps and When It Signals a Red Flag (Runner's World) - https://www.runnersworld.com/training/a71483612/stopping-during-long-runs/
- UAH researchers studying technology that could cut travel time to Mars - WAAY 31 News (WAAY 31 News) - https://news.google.com/rss/articles/CBMi4gFBVV95cUxQS081ZEhrbGhfa2V3LXhYcmVjQjZmMmU2UURsU2FkTnhOSlNzYW1nQ0duLS1iSTdRTE1pcG55cUhhR0hxX0ZxZHlmTG5kZ09ZSkdrejREb1ZTNzhQaHEwcWlWUWlFWi1RdUtackdPOGRmaEdIaGlSc0hWRHdWaWRzZUlBQV9FSUlzY1FsTk1zRFBXM08wLWVYNEgwMGZyMDJXY1lEYmdxZFVQd0wwWFR3aWczVkl6ZDM5Znc5SVplaEpQZnNJUkVsN0tjLVlXQ3FvQ1VfOXJGNFVKMmp2eXBxb25n?oc=5
- CISA warns of cyberattacks targeting fuel tank monitoring systems (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/]]>
      </content:encoded>
      <pubDate>Thu, 04 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/570237bc/93b57d5e.mp3" length="5072125" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>313</itunes:duration>
      <itunes:summary>This episode covers a zero-day flaw in Visual Studio Code that's leaking GitHub tokens, a devastating HTTP/2 exploit hammering web servers across the internet, and how attackers are now using AI to automatically bypass security tools faster than defenders can respond. Adrian breaks down what's moving in the threat landscape before your second cup of coffee hits. It's Thursday morning, and the signals are already loud.</itunes:summary>
      <itunes:subtitle>This episode covers a zero-day flaw in Visual Studio Code that's leaking GitHub tokens, a devastating HTTP/2 exploit hammering web servers across the internet, and how attackers are now using AI to automatically bypass security tools faster than defenders</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 63: June 03, 2026</title>
      <itunes:episode>63</itunes:episode>
      <podcast:episode>63</podcast:episode>
      <itunes:title>Episode 63: June 03, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">16451859-06a6-459f-85f7-c7dca07b2dcb</guid>
      <link>https://share.transistor.fm/s/0a3be892</link>
      <description>
        <![CDATA[This episode covers Google's urgent Android patch fixing an actively exploited vulnerability, another authentication bypass hitting Palo Alto's VPN gateways, and a wild new attack where hackers use Meta's own AI support tools to hijack Instagram accounts. We also dig into the growing cyberdeck movement — DIY enthusiasts building custom hardware to escape big tech surveillance — and wrap with a look at stunning independent trail races across the country.

Stories covered:
- Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited (The Hacker News) - https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html
- Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit (Dark Reading) - https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit
- Instagram users locked out after Meta AI abused to steal accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts/
- Cyberdecks are having a moment, rejecting big tech surveillance with style and substance (TechCrunch) - https://techcrunch.com/2026/06/02/cyberdeck-tiktok-trend-reject-big-tech/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- What I Learned Exploding Cams and Nuts On a Classic Squamish Splitter (Climbing Magazine) - https://www.climbing.com/gear/what-trad-climbers-should-know-about-exploding-cams-and-nuts/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers Google's urgent Android patch fixing an actively exploited vulnerability, another authentication bypass hitting Palo Alto's VPN gateways, and a wild new attack where hackers use Meta's own AI support tools to hijack Instagram accounts. We also dig into the growing cyberdeck movement — DIY enthusiasts building custom hardware to escape big tech surveillance — and wrap with a look at stunning independent trail races across the country.

Stories covered:
- Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited (The Hacker News) - https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html
- Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit (Dark Reading) - https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit
- Instagram users locked out after Meta AI abused to steal accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts/
- Cyberdecks are having a moment, rejecting big tech surveillance with style and substance (TechCrunch) - https://techcrunch.com/2026/06/02/cyberdeck-tiktok-trend-reject-big-tech/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- What I Learned Exploding Cams and Nuts On a Classic Squamish Splitter (Climbing Magazine) - https://www.climbing.com/gear/what-trad-climbers-should-know-about-exploding-cams-and-nuts/]]>
      </content:encoded>
      <pubDate>Wed, 03 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/0a3be892/45e7ed98.mp3" length="4499103" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>278</itunes:duration>
      <itunes:summary>This episode covers Google's urgent Android patch fixing an actively exploited vulnerability, another authentication bypass hitting Palo Alto's VPN gateways, and a wild new attack where hackers use Meta's own AI support tools to hijack Instagram accounts. We also dig into the growing cyberdeck movement — DIY enthusiasts building custom hardware to escape big tech surveillance — and wrap with a look at stunning independent trail races across the country.</itunes:summary>
      <itunes:subtitle>This episode covers Google's urgent Android patch fixing an actively exploited vulnerability, another authentication bypass hitting Palo Alto's VPN gateways, and a wild new attack where hackers use Meta's own AI support tools to hijack Instagram accounts.</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 62: June 02, 2026</title>
      <itunes:episode>62</itunes:episode>
      <podcast:episode>62</podcast:episode>
      <itunes:title>Episode 62: June 02, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">491d2d03-ac49-462d-8b3f-a0fdeec774b1</guid>
      <link>https://share.transistor.fm/s/5fcd4983</link>
      <description>
        <![CDATA[This episode covers a wild range of security wake-up calls — from hackers tricking Meta's AI chatbot to hijack high-profile Instagram accounts, to compromised npm packages stealing developer credentials, to a critical Windows vulnerability now being actively exploited. Adrian North also shifts gears to spotlight thirteen stunning independent trail races across the U.S. for anyone looking to suffer beautifully.

Stories covered:
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts (Krebs on Security) - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
- Red Hat npm packages compromised to steal developer credentials (BleepingComputer) - https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/
- Critical Windows Netlogon RCE flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Why Your Long Runs Leave You Wiped—and How to Bounce Back Better (Runner's World) - https://www.runnersworld.com/training/a71459738/amazing-runners-world-show-epsiode-117-long-run-fatigue_1780323049/
- This Weird 20-Legged Robot Moves Like Nothing Else on Earth and It Could Change How We Build Machines - ZME Science (ZME Science) - https://news.google.com/rss/articles/CBMiekFVX3lxTE1kVmZHZW9kNVZNX1VwTzl6RFdMWVNOYXJTSHhtYlcxb1RsUDRGUFByWFhYai0yd2ZsaG5wWmU4MXRpT2Vka1Z0WnN4cjdIM2lOT1FhQjRiSnptY0p3WWRqeXM0aDN4UGZzdXlmRFN4NXNfTWRLcjY4LW93?oc=5]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a wild range of security wake-up calls — from hackers tricking Meta's AI chatbot to hijack high-profile Instagram accounts, to compromised npm packages stealing developer credentials, to a critical Windows vulnerability now being actively exploited. Adrian North also shifts gears to spotlight thirteen stunning independent trail races across the U.S. for anyone looking to suffer beautifully.

Stories covered:
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts (Krebs on Security) - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
- Red Hat npm packages compromised to steal developer credentials (BleepingComputer) - https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/
- Critical Windows Netlogon RCE flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Why Your Long Runs Leave You Wiped—and How to Bounce Back Better (Runner's World) - https://www.runnersworld.com/training/a71459738/amazing-runners-world-show-epsiode-117-long-run-fatigue_1780323049/
- This Weird 20-Legged Robot Moves Like Nothing Else on Earth and It Could Change How We Build Machines - ZME Science (ZME Science) - https://news.google.com/rss/articles/CBMiekFVX3lxTE1kVmZHZW9kNVZNX1VwTzl6RFdMWVNOYXJTSHhtYlcxb1RsUDRGUFByWFhYai0yd2ZsaG5wWmU4MXRpT2Vka1Z0WnN4cjdIM2lOT1FhQjRiSnptY0p3WWRqeXM0aDN4UGZzdXlmRFN4NXNfTWRLcjY4LW93?oc=5]]>
      </content:encoded>
      <pubDate>Tue, 02 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/5fcd4983/513f346c.mp3" length="4941721" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>305</itunes:duration>
      <itunes:summary>This episode covers a wild range of security wake-up calls — from hackers tricking Meta's AI chatbot to hijack high-profile Instagram accounts, to compromised npm packages stealing developer credentials, to a critical Windows vulnerability now being actively exploited. Adrian North also shifts gears to spotlight thirteen stunning independent trail races across the U.S. for anyone looking to suffer beautifully.</itunes:summary>
      <itunes:subtitle>This episode covers a wild range of security wake-up calls — from hackers tricking Meta's AI chatbot to hijack high-profile Instagram accounts, to compromised npm packages stealing developer credentials, to a critical Windows vulnerability now being activ</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 61: June 01, 2026</title>
      <itunes:episode>61</itunes:episode>
      <podcast:episode>61</podcast:episode>
      <itunes:title>Episode 61: June 01, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e5068f6c-0d15-4672-aa52-68c096da0f6c</guid>
      <link>https://share.transistor.fm/s/dcd4c08f</link>
      <description>
        <![CDATA[This episode covers critical vulnerabilities in Gogs and Palo Alto's GlobalProtect VPN that are already being actively exploited, plus the takedown of a massive 17 million device botnet in the Netherlands. Adrian also digs into a bizarre new attack where hackers used an AI agent to carry out post-compromise actions autonomously. It's a Monday morning packed with urgent patches and unsettling new tactics.

Stories covered:
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code (The Hacker News) - https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/
- Dutch govt disrupts malware botnet with 17 million infected devices (BleepingComputer) - https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (The Hacker News) - https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Tyler Andrews Sets Oxygen-Assisted Speed Record on Mount Everest (iRunFar) - https://www.irunfar.com/tyler-andrews-mount-everest-speed-record-2026]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers critical vulnerabilities in Gogs and Palo Alto's GlobalProtect VPN that are already being actively exploited, plus the takedown of a massive 17 million device botnet in the Netherlands. Adrian also digs into a bizarre new attack where hackers used an AI agent to carry out post-compromise actions autonomously. It's a Monday morning packed with urgent patches and unsettling new tactics.

Stories covered:
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code (The Hacker News) - https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/
- Dutch govt disrupts malware botnet with 17 million infected devices (BleepingComputer) - https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (The Hacker News) - https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Tyler Andrews Sets Oxygen-Assisted Speed Record on Mount Everest (iRunFar) - https://www.irunfar.com/tyler-andrews-mount-everest-speed-record-2026]]>
      </content:encoded>
      <pubDate>Mon, 01 Jun 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/dcd4c08f/3048c620.mp3" length="5234293" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>324</itunes:duration>
      <itunes:summary>This episode covers critical vulnerabilities in Gogs and Palo Alto's GlobalProtect VPN that are already being actively exploited, plus the takedown of a massive 17 million device botnet in the Netherlands. Adrian also digs into a bizarre new attack where hackers used an AI agent to carry out post-compromise actions autonomously. It's a Monday morning packed with urgent patches and unsettling new tactics.</itunes:summary>
      <itunes:subtitle>This episode covers critical vulnerabilities in Gogs and Palo Alto's GlobalProtect VPN that are already being actively exploited, plus the takedown of a massive 17 million device botnet in the Netherlands. Adrian also digs into a bizarre new attack where </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 60: May 31, 2026</title>
      <itunes:episode>60</itunes:episode>
      <podcast:episode>60</podcast:episode>
      <itunes:title>Episode 60: May 31, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8196158d-552a-4c63-b70d-7798b60d41ab</guid>
      <link>https://share.transistor.fm/s/ff4e610f</link>
      <description>
        <![CDATA[This episode covers critical vulnerabilities hitting Gogs self-hosted Git servers, Palo Alto VPN authentication bypass being actively exploited, and a groundbreaking attack where threat actors deployed an AI agent to autonomously handle post-exploitation. We also dig into a new Linux kernel privilege escalation flaw and what it means when your VPN becomes the weakest link.

Stories covered:
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code (The Hacker News) - https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (The Hacker News) - https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
- New CIFSwitch Linux flaw gives root on multiple distributions (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Tyler Andrews Sets Oxygen-Assisted Speed Record on Mount Everest (iRunFar) - https://www.irunfar.com/tyler-andrews-mount-everest-speed-record-2026]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers critical vulnerabilities hitting Gogs self-hosted Git servers, Palo Alto VPN authentication bypass being actively exploited, and a groundbreaking attack where threat actors deployed an AI agent to autonomously handle post-exploitation. We also dig into a new Linux kernel privilege escalation flaw and what it means when your VPN becomes the weakest link.

Stories covered:
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code (The Hacker News) - https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (The Hacker News) - https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
- New CIFSwitch Linux flaw gives root on multiple distributions (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Tyler Andrews Sets Oxygen-Assisted Speed Record on Mount Everest (iRunFar) - https://www.irunfar.com/tyler-andrews-mount-everest-speed-record-2026]]>
      </content:encoded>
      <pubDate>Sun, 31 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/ff4e610f/8194f9c4.mp3" length="5648907" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>349</itunes:duration>
      <itunes:summary>This episode covers critical vulnerabilities hitting Gogs self-hosted Git servers, Palo Alto VPN authentication bypass being actively exploited, and a groundbreaking attack where threat actors deployed an AI agent to autonomously handle post-exploitation. We also dig into a new Linux kernel privilege escalation flaw and what it means when your VPN becomes the weakest link.</itunes:summary>
      <itunes:subtitle>This episode covers critical vulnerabilities hitting Gogs self-hosted Git servers, Palo Alto VPN authentication bypass being actively exploited, and a groundbreaking attack where threat actors deployed an AI agent to autonomously handle post-exploitation.</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 59: May 30, 2026</title>
      <itunes:episode>59</itunes:episode>
      <podcast:episode>59</podcast:episode>
      <itunes:title>Episode 59: May 30, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7cc7a904-66a1-40ce-b9d6-05a52e103968</guid>
      <link>https://share.transistor.fm/s/db35b7e8</link>
      <description>
        <![CDATA[This episode covers a cybercrime gang funding real-world violence with stolen data, a Russian hacker who spent five years running an AI bot inside a 17,000-member Telegram channel, and Dutch authorities dismantling a botnet controlling 17 million infected devices. We also dig into how cloud misconfigurations stack into serious exploits when no one's watching the service accounts.

Stories covered:
- 'The Com' Cyberattacks Support Violence &amp; Sexploitation (Dark Reading) - https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation
- A Russian hacker tricked a 17,000 strong MAGA Telegram channel with a jailbroken AI for over 5 years, leading to fraud, credential theft, and an empty crypto wallet - TechRadar (TechRadar) - https://news.google.com/rss/articles/CBMipwJBVV95cUxNRnpHUXhXbUtuN0NhVFl2blI5TzhlTGlsVTNhdGdmRm14aXl0MWQxS0h6VXRBNXZ2bHJzNkJMQllaQ3RfbnhveFlCdUU2ZUxqakxzbWpKc3FSSjFNZVAwZWY5OWoxOHdvajl2ejQwQTRfU2E0QlktcVdQczlGZ2gwZFNkcDRkdGhHNkJsZzJRYTNSUV9wQzJQT1FQOHZyNnljN2dDN3JnYmJTb3ZvUzYtSkFPR3RWR1RGSlAxaEEtbHU5YW1UQW5rY2tXOWtkLWVISmVZMnRVZnpxQTdWaDNUY1RVSzgzM2lScEJiQTQ0VjJhZ3BNbHE0UVIxNDRuQmJfMWp2bW1ldnJRV0FQVndFMEl0NDBieEFUTS02OU8zSFJoQUctMEU4?oc=5
- Dutch govt disrupts malware botnet with 17 million infected devices (BleepingComputer) - https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/
- With Complex Cloud Integrations, Small Errors Lead to Major Compromises (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/complex-cloud-integrations-small-errors-compromises
- 5 Advanced Workouts That Build Marathon Speed and How to Know You’re Ready for Them (Runner's World) - https://www.runnersworld.com/advanced/a71423197/advanced-marathon-speed-workouts/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a cybercrime gang funding real-world violence with stolen data, a Russian hacker who spent five years running an AI bot inside a 17,000-member Telegram channel, and Dutch authorities dismantling a botnet controlling 17 million infected devices. We also dig into how cloud misconfigurations stack into serious exploits when no one's watching the service accounts.

Stories covered:
- 'The Com' Cyberattacks Support Violence &amp; Sexploitation (Dark Reading) - https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation
- A Russian hacker tricked a 17,000 strong MAGA Telegram channel with a jailbroken AI for over 5 years, leading to fraud, credential theft, and an empty crypto wallet - TechRadar (TechRadar) - https://news.google.com/rss/articles/CBMipwJBVV95cUxNRnpHUXhXbUtuN0NhVFl2blI5TzhlTGlsVTNhdGdmRm14aXl0MWQxS0h6VXRBNXZ2bHJzNkJMQllaQ3RfbnhveFlCdUU2ZUxqakxzbWpKc3FSSjFNZVAwZWY5OWoxOHdvajl2ejQwQTRfU2E0QlktcVdQczlGZ2gwZFNkcDRkdGhHNkJsZzJRYTNSUV9wQzJQT1FQOHZyNnljN2dDN3JnYmJTb3ZvUzYtSkFPR3RWR1RGSlAxaEEtbHU5YW1UQW5rY2tXOWtkLWVISmVZMnRVZnpxQTdWaDNUY1RVSzgzM2lScEJiQTQ0VjJhZ3BNbHE0UVIxNDRuQmJfMWp2bW1ldnJRV0FQVndFMEl0NDBieEFUTS02OU8zSFJoQUctMEU4?oc=5
- Dutch govt disrupts malware botnet with 17 million infected devices (BleepingComputer) - https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/
- With Complex Cloud Integrations, Small Errors Lead to Major Compromises (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/complex-cloud-integrations-small-errors-compromises
- 5 Advanced Workouts That Build Marathon Speed and How to Know You’re Ready for Them (Runner's World) - https://www.runnersworld.com/advanced/a71423197/advanced-marathon-speed-workouts/
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/]]>
      </content:encoded>
      <pubDate>Sat, 30 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/db35b7e8/f3d3d38d.mp3" length="4680914" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>289</itunes:duration>
      <itunes:summary>This episode covers a cybercrime gang funding real-world violence with stolen data, a Russian hacker who spent five years running an AI bot inside a 17,000-member Telegram channel, and Dutch authorities dismantling a botnet controlling 17 million infected devices. We also dig into how cloud misconfigurations stack into serious exploits when no one's watching the service accounts.</itunes:summary>
      <itunes:subtitle>This episode covers a cybercrime gang funding real-world violence with stolen data, a Russian hacker who spent five years running an AI bot inside a 17,000-member Telegram channel, and Dutch authorities dismantling a botnet controlling 17 million infected</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 57: May 28, 2026</title>
      <itunes:episode>57</itunes:episode>
      <podcast:episode>57</podcast:episode>
      <itunes:title>Episode 57: May 28, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">df2024ec-94fd-4a6d-8f79-6fe53fe2944d</guid>
      <link>https://share.transistor.fm/s/bbbb783f</link>
      <description>
        <![CDATA[This episode digs into a dark week for software supply chains, from the Glassworm botnet takedown to the TrapDoor malware infecting npm, PyPI, and CratesIO—plus why multi-factor authentication isn't as bulletproof as you think when attackers weaponize fatigue. Adrian also spotlights thirteen under-the-radar trail races that trade crowds for waterfalls and old-growth forests. It's cybersecurity threats and hidden running gems before your coffee cools.

Stories covered:
- CrowdStrike and Google take down botnet used by hackers to target open source software developers (TechCrunch) - https://techcrunch.com/2026/05/27/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMigAFBVV95cUxOMElHdEJDV1N1Q1JINkxIcmc1eTZINWVRRFNSanc3ZURLN0pCRzE4UVNhRXd2UV9SUmV2bFd6OWdRbjZDcFJwM3JPMmh0bFd4UUJMMmhleXpIOHVIZVBrOWFhMWxBZEp0QUZFdHJxSUthdWt4Q3ljb0ozYkNRUTZYdg?oc=5
- MFA Prompt Bombing: Why Your Second Factor Isn't Saving You (The Hacker News) - https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Gemini, Gophers, and Fingers. Oh My Alternative Internets Beyond HTTPS (Hacker News) - https://brennan.day/gemini-gophers-and-fingers-oh-my-alternative-internets-beyond-https/
- Ransomware Actors Show Up In Person to Steal Law Firm Data (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/ransomware-actors-steal-law-firm-data]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a dark week for software supply chains, from the Glassworm botnet takedown to the TrapDoor malware infecting npm, PyPI, and CratesIO—plus why multi-factor authentication isn't as bulletproof as you think when attackers weaponize fatigue. Adrian also spotlights thirteen under-the-radar trail races that trade crowds for waterfalls and old-growth forests. It's cybersecurity threats and hidden running gems before your coffee cools.

Stories covered:
- CrowdStrike and Google take down botnet used by hackers to target open source software developers (TechCrunch) - https://techcrunch.com/2026/05/27/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMigAFBVV95cUxOMElHdEJDV1N1Q1JINkxIcmc1eTZINWVRRFNSanc3ZURLN0pCRzE4UVNhRXd2UV9SUmV2bFd6OWdRbjZDcFJwM3JPMmh0bFd4UUJMMmhleXpIOHVIZVBrOWFhMWxBZEp0QUZFdHJxSUthdWt4Q3ljb0ozYkNRUTZYdg?oc=5
- MFA Prompt Bombing: Why Your Second Factor Isn't Saving You (The Hacker News) - https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html
- 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/
- Gemini, Gophers, and Fingers. Oh My Alternative Internets Beyond HTTPS (Hacker News) - https://brennan.day/gemini-gophers-and-fingers-oh-my-alternative-internets-beyond-https/
- Ransomware Actors Show Up In Person to Steal Law Firm Data (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/ransomware-actors-steal-law-firm-data]]>
      </content:encoded>
      <pubDate>Thu, 28 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/bbbb783f/339331c6.mp3" length="5025730" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>310</itunes:duration>
      <itunes:summary>This episode digs into a dark week for software supply chains, from the Glassworm botnet takedown to the TrapDoor malware infecting npm, PyPI, and CratesIO—plus why multi-factor authentication isn't as bulletproof as you think when attackers weaponize fatigue. Adrian also spotlights thirteen under-the-radar trail races that trade crowds for waterfalls and old-growth forests. It's cybersecurity threats and hidden running gems before your coffee cools.</itunes:summary>
      <itunes:subtitle>This episode digs into a dark week for software supply chains, from the Glassworm botnet takedown to the TrapDoor malware infecting npm, PyPI, and CratesIO—plus why multi-factor authentication isn't as bulletproof as you think when attackers weaponize fat</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 56: May 27, 2026</title>
      <itunes:episode>56</itunes:episode>
      <podcast:episode>56</podcast:episode>
      <itunes:title>Episode 56: May 27, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3760486b-8f48-40eb-8028-6642b8933a8f</guid>
      <link>https://share.transistor.fm/s/ca986be5</link>
      <description>
        <![CDATA[This episode covers a critical Microsoft SharePoint vulnerability demanding immediate patching, a major 7-Eleven data breach exposing 183,000 people, and a coordinated supply chain attack hitting three major package ecosystems at once. Adrian also digs into an Oregon hacker who sold access to the state's emergency network for Bitcoin. It's Wednesday morning, and the signals are already humming.

Stories covered:
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions (The Hacker News) - https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
- 7-Eleven data breach exposes personal information of 185,000 people (BleepingComputer) - https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO (The Hacker News) - https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- Hacker who sold access to Oregon state emergency network for Bitcoin gets prison - OregonLive.com (OregonLive.com) - https://news.google.com/rss/articles/CBMixAFBVV95cUxNczh0aUVGUzllVUVlZXJ4R24zM25tVTgzM1FwNWZSMm9ibjZRdE9hU1VORWZTMWFSdk1TUVZGVklGdE5QdmZFM29JTl92X05uWWpfOUthWkdraGtVenpCVWtaRnYtV3dxOVJnWkxXSW41S0ZnR2FjYS1Nc0FnaGxSNXBiWnNESmdFX0E0enVfNXNEREY1ZmNwcnA0NXgyaHVtVVozSWlGNFJzUk02aFlpVThVQXlpUmlSNWN1LU9Hc0tUbk4y0gHYAUFVX3lxTE1WS3FpaVlGT0UtWVBtUVpBVnBtcFFQTjdvU1RZRjMzZlpFS0kwZmxfUmhyR1VTd1J0SGlOd1Vnc1pfYTZhSkxBWkZrRzBCZlNiUFIwNlFHbExOaEJWblVwTG5IaVlsWWJJX01Eclc0TDRtN2dyb2pjck4tQTcwa0NZMEczMWthQ1h2V24wYk4zcU5oVFF3T1RNMjlyWmZTdW9nc2tRdVFJYVhySHhfa1VWNzIyZVdtcldJb3lXM1d5NWQteExseWlKNU9SNzNsdjQzX19sTEdmNQ?oc=5
- These Runners Dress Up Like Salmon Every Year and Run This Historic Race—Backwards (Runner's World) - https://www.runnersworld.com/news/a71376795/bay-to-breakers-costume-runners/
- DuckDuckGo installs are up 30% as users reject being ‘force-fed’ Google’s AI Search (TechCrunch) - https://techcrunch.com/2026/05/26/duckduckgo-installs-are-up-30-as-users-reject-being-force-fed-googles-ai-search/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Microsoft SharePoint vulnerability demanding immediate patching, a major 7-Eleven data breach exposing 183,000 people, and a coordinated supply chain attack hitting three major package ecosystems at once. Adrian also digs into an Oregon hacker who sold access to the state's emergency network for Bitcoin. It's Wednesday morning, and the signals are already humming.

Stories covered:
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions (The Hacker News) - https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
- 7-Eleven data breach exposes personal information of 185,000 people (BleepingComputer) - https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO (The Hacker News) - https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- Hacker who sold access to Oregon state emergency network for Bitcoin gets prison - OregonLive.com (OregonLive.com) - https://news.google.com/rss/articles/CBMixAFBVV95cUxNczh0aUVGUzllVUVlZXJ4R24zM25tVTgzM1FwNWZSMm9ibjZRdE9hU1VORWZTMWFSdk1TUVZGVklGdE5QdmZFM29JTl92X05uWWpfOUthWkdraGtVenpCVWtaRnYtV3dxOVJnWkxXSW41S0ZnR2FjYS1Nc0FnaGxSNXBiWnNESmdFX0E0enVfNXNEREY1ZmNwcnA0NXgyaHVtVVozSWlGNFJzUk02aFlpVThVQXlpUmlSNWN1LU9Hc0tUbk4y0gHYAUFVX3lxTE1WS3FpaVlGT0UtWVBtUVpBVnBtcFFQTjdvU1RZRjMzZlpFS0kwZmxfUmhyR1VTd1J0SGlOd1Vnc1pfYTZhSkxBWkZrRzBCZlNiUFIwNlFHbExOaEJWblVwTG5IaVlsWWJJX01Eclc0TDRtN2dyb2pjck4tQTcwa0NZMEczMWthQ1h2V24wYk4zcU5oVFF3T1RNMjlyWmZTdW9nc2tRdVFJYVhySHhfa1VWNzIyZVdtcldJb3lXM1d5NWQteExseWlKNU9SNzNsdjQzX19sTEdmNQ?oc=5
- These Runners Dress Up Like Salmon Every Year and Run This Historic Race—Backwards (Runner's World) - https://www.runnersworld.com/news/a71376795/bay-to-breakers-costume-runners/
- DuckDuckGo installs are up 30% as users reject being ‘force-fed’ Google’s AI Search (TechCrunch) - https://techcrunch.com/2026/05/26/duckduckgo-installs-are-up-30-as-users-reject-being-force-fed-googles-ai-search/]]>
      </content:encoded>
      <pubDate>Wed, 27 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/ca986be5/5249569f.mp3" length="5627591" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>348</itunes:duration>
      <itunes:summary>This episode covers a critical Microsoft SharePoint vulnerability demanding immediate patching, a major 7-Eleven data breach exposing 183,000 people, and a coordinated supply chain attack hitting three major package ecosystems at once. Adrian also digs into an Oregon hacker who sold access to the state's emergency network for Bitcoin. It's Wednesday morning, and the signals are already humming.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Microsoft SharePoint vulnerability demanding immediate patching, a major 7-Eleven data breach exposing 183,000 people, and a coordinated supply chain attack hitting three major package ecosystems at once. Adrian also digs in</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 55: May 26, 2026</title>
      <itunes:episode>55</itunes:episode>
      <podcast:episode>55</podcast:episode>
      <itunes:title>Episode 55: May 26, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">53be78fd-1e89-4add-8a1b-bea8adda5a2c</guid>
      <link>https://share.transistor.fm/s/0a3cdb5c</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian North digs into a massive botnet takedown involving two million compromised devices, a coordinated supply chain attack targeting developers across three major code repositories, and Verizon's latest breach report showing a major shift in how attackers are getting in. Plus, a Romanian ultramarathon turns into a mountain rescue when weather strikes harder than expected.

Stories covered:
- US and Canada arrest and charge suspected Kimwolf botnet admin (BleepingComputer) - https://www.bleepingcomputer.com/news/security/us-and-canada-arrest-and-charge-suspected-kimwolf-botnet-admin/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO (The Hacker News) - https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- Verizon 2026 DBIR: Vulnerability Exploitation Leaps Ahead of Stolen Credentials as #1 Initial Breach Cause - CPO Magazine (CPO Magazine) - https://news.google.com/rss/articles/CBMi4gFBVV95cUxQcl80azh0dFB1ZE5TdGM3eW4zVk9XZEtnczNNeUM1SUI4M1lnSFJvbk8tQzY1RXNwT1AxQWZ5X21BUG82ZTJtQy1mUGhpYkpsOXNnT2FxaVVXdUZYTG9yd3NaR0pBLVNPQkE3UkpzYmFQS2tqeWItdFgtX3ZSMUx1U0RpWERPUnZYSHdZNXlhaGxUdjJHbDhud3cta0tGNkgxa3I4amc3WE1kMWcySEQ1dHRqenJPUDlPbnJJUFBTbWpOQkZhWmRKVENqcGFYN2dYZmNNajBTSFB3ZFItQXJNeWdn?oc=5
- Snow and Ice Trap Runners at Romania’s Transylvania 100, Triggering Mass Mountain Rescue (Marathon Handbook) - https://marathonhandbook.com/snow-and-ice-trap-runners-at-romanias-transylvania-100-triggering-mass-mountain-rescue/
- On Trails is a wandering tale that blends hiking, science, and history (The Verge) - https://www.theverge.com/entertainment/936860/robert-moor-on-trails-book-review
- Microsoft Copilot Cowork Exfiltrates Files (Hacker News) - https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian North digs into a massive botnet takedown involving two million compromised devices, a coordinated supply chain attack targeting developers across three major code repositories, and Verizon's latest breach report showing a major shift in how attackers are getting in. Plus, a Romanian ultramarathon turns into a mountain rescue when weather strikes harder than expected.

Stories covered:
- US and Canada arrest and charge suspected Kimwolf botnet admin (BleepingComputer) - https://www.bleepingcomputer.com/news/security/us-and-canada-arrest-and-charge-suspected-kimwolf-botnet-admin/
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO (The Hacker News) - https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- Verizon 2026 DBIR: Vulnerability Exploitation Leaps Ahead of Stolen Credentials as #1 Initial Breach Cause - CPO Magazine (CPO Magazine) - https://news.google.com/rss/articles/CBMi4gFBVV95cUxQcl80azh0dFB1ZE5TdGM3eW4zVk9XZEtnczNNeUM1SUI4M1lnSFJvbk8tQzY1RXNwT1AxQWZ5X21BUG82ZTJtQy1mUGhpYkpsOXNnT2FxaVVXdUZYTG9yd3NaR0pBLVNPQkE3UkpzYmFQS2tqeWItdFgtX3ZSMUx1U0RpWERPUnZYSHdZNXlhaGxUdjJHbDhud3cta0tGNkgxa3I4amc3WE1kMWcySEQ1dHRqenJPUDlPbnJJUFBTbWpOQkZhWmRKVENqcGFYN2dYZmNNajBTSFB3ZFItQXJNeWdn?oc=5
- Snow and Ice Trap Runners at Romania’s Transylvania 100, Triggering Mass Mountain Rescue (Marathon Handbook) - https://marathonhandbook.com/snow-and-ice-trap-runners-at-romanias-transylvania-100-triggering-mass-mountain-rescue/
- On Trails is a wandering tale that blends hiking, science, and history (The Verge) - https://www.theverge.com/entertainment/936860/robert-moor-on-trails-book-review
- Microsoft Copilot Cowork Exfiltrates Files (Hacker News) - https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files]]>
      </content:encoded>
      <pubDate>Tue, 26 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/0a3cdb5c/e6567bed.mp3" length="4641626" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>286</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian North digs into a massive botnet takedown involving two million compromised devices, a coordinated supply chain attack targeting developers across three major code repositories, and Verizon's latest breach report showing a major shift in how attackers are getting in. Plus, a Romanian ultramarathon turns into a mountain rescue when weather strikes harder than expected.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian North digs into a massive botnet takedown involving two million compromised devices, a coordinated supply chain attack targeting developers across three major code repositories, and Verizon's latest breach report showing a </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 54: May 25, 2026</title>
      <itunes:episode>54</itunes:episode>
      <podcast:episode>54</podcast:episode>
      <itunes:title>Episode 54: May 25, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">35163cb0-5360-4c78-b933-0d551a3cae4d</guid>
      <link>https://share.transistor.fm/s/150cb7bb</link>
      <description>
        <![CDATA[This episode covers a coordinated supply chain attack on PHP's Packagist repository, mass exploitation of a critical Ghost CMS vulnerability turning websites into malware traps, and the ironic exposure of AWS GovCloud credentials by a CISA contractor's public GitHub repo. Adrian breaks down how attackers are poisoning dependencies upstream, automating large-scale injections, and why even the agencies protecting federal networks aren't immune to basic security mistakes.

Stories covered:
- Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware (The Hacker News) - https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
- Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows (The Hacker News) - https://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html
- On Trails is a wandering tale that blends hiking, science, and history (The Verge) - https://www.theverge.com/entertainment/936860/robert-moor-on-trails-book-review
- The Shoes That Won The 2026 Cape Town Marathon (Marathon Handbook) - https://marathonhandbook.com/the-shoes-that-won-the-2026-cape-town-marathon/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a coordinated supply chain attack on PHP's Packagist repository, mass exploitation of a critical Ghost CMS vulnerability turning websites into malware traps, and the ironic exposure of AWS GovCloud credentials by a CISA contractor's public GitHub repo. Adrian breaks down how attackers are poisoning dependencies upstream, automating large-scale injections, and why even the agencies protecting federal networks aren't immune to basic security mistakes.

Stories covered:
- Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware (The Hacker News) - https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
- Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows (The Hacker News) - https://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html
- On Trails is a wandering tale that blends hiking, science, and history (The Verge) - https://www.theverge.com/entertainment/936860/robert-moor-on-trails-book-review
- The Shoes That Won The 2026 Cape Town Marathon (Marathon Handbook) - https://marathonhandbook.com/the-shoes-that-won-the-2026-cape-town-marathon/]]>
      </content:encoded>
      <pubDate>Mon, 25 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/150cb7bb/b0772f9c.mp3" length="6563820" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>407</itunes:duration>
      <itunes:summary>This episode covers a coordinated supply chain attack on PHP's Packagist repository, mass exploitation of a critical Ghost CMS vulnerability turning websites into malware traps, and the ironic exposure of AWS GovCloud credentials by a CISA contractor's public GitHub repo. Adrian breaks down how attackers are poisoning dependencies upstream, automating large-scale injections, and why even the agencies protecting federal networks aren't immune to basic security mistakes.</itunes:summary>
      <itunes:subtitle>This episode covers a coordinated supply chain attack on PHP's Packagist repository, mass exploitation of a critical Ghost CMS vulnerability turning websites into malware traps, and the ironic exposure of AWS GovCloud credentials by a CISA contractor's pu</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 53: May 24, 2026</title>
      <itunes:episode>53</itunes:episode>
      <podcast:episode>53</podcast:episode>
      <itunes:title>Episode 53: May 24, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4a8bf1b4-34d0-493e-b65a-5258dd41ee3a</guid>
      <link>https://share.transistor.fm/s/3762d9fc</link>
      <description>
        <![CDATA[This episode covers GitHub's new security requirements for npm publishers, a major credential leak from a CISA contractor, and Apple's lockdown mode for high-risk users. We dig into how trust gets built—and broken—in software supply chains and government infrastructure. On today's show, friction that protects, keys left in plain sight, and what to do when your phone becomes a target.

Stories covered:
- npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks (The Hacker News) - https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- These special phone and app features can help protect you from spyware (TechCrunch) - https://techcrunch.com/2026/05/23/you-dont-have-to-click-anything-to-get-hacked-anymore-heres-how-to-fight-back/
- Adidas Built a Suit That Makes You Run Faster. The World’s Best Marathoners Aren’t Sure They Want It. (Marathon Handbook) - https://marathonhandbook.com/adidas-built-a-suit-that-makes-you-run-faster-the-worlds-best-marathoners-arent-sure-they-want-it/
- TSA Confirms Medical Cannabis Air Travel Policy Remains Unchanged Triggering Widespread Passenger Confusion, Flight Cancellations Risk, and Airport Disruptions Across New York, Los Angeles, Chicago, and Miami: New Airline News and Aviation Upda - Nomad Lawyer (Nomad Lawyer) - https://news.google.com/rss/articles/CBMigAFBVV95cUxNSjk4Z2dodFpJZGVoZ2U3UHBzNEF6ZXYzUlB6RVJSbUFpWEhHMkgwYzBOSEhoZTh1b2RQamVpUk55NjNmVEJXd1liS3N0clRPTU9HeEVQY1VDQzl4a2pfNVpjYm5mY3Z3UUZyYWlLVThtWHpmT202WkRHVjNBT3Nxdg?oc=5
- Ebola outbreak now third largest recorded and "spreading rapidly" (Ars Technica) - https://arstechnica.com/health/2026/05/ebola-outbreak-now-third-largest-recorded-and-spreading-rapidly/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers GitHub's new security requirements for npm publishers, a major credential leak from a CISA contractor, and Apple's lockdown mode for high-risk users. We dig into how trust gets built—and broken—in software supply chains and government infrastructure. On today's show, friction that protects, keys left in plain sight, and what to do when your phone becomes a target.

Stories covered:
- npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks (The Hacker News) - https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- These special phone and app features can help protect you from spyware (TechCrunch) - https://techcrunch.com/2026/05/23/you-dont-have-to-click-anything-to-get-hacked-anymore-heres-how-to-fight-back/
- Adidas Built a Suit That Makes You Run Faster. The World’s Best Marathoners Aren’t Sure They Want It. (Marathon Handbook) - https://marathonhandbook.com/adidas-built-a-suit-that-makes-you-run-faster-the-worlds-best-marathoners-arent-sure-they-want-it/
- TSA Confirms Medical Cannabis Air Travel Policy Remains Unchanged Triggering Widespread Passenger Confusion, Flight Cancellations Risk, and Airport Disruptions Across New York, Los Angeles, Chicago, and Miami: New Airline News and Aviation Upda - Nomad Lawyer (Nomad Lawyer) - https://news.google.com/rss/articles/CBMigAFBVV95cUxNSjk4Z2dodFpJZGVoZ2U3UHBzNEF6ZXYzUlB6RVJSbUFpWEhHMkgwYzBOSEhoZTh1b2RQamVpUk55NjNmVEJXd1liS3N0clRPTU9HeEVQY1VDQzl4a2pfNVpjYm5mY3Z3UUZyYWlLVThtWHpmT202WkRHVjNBT3Nxdg?oc=5
- Ebola outbreak now third largest recorded and "spreading rapidly" (Ars Technica) - https://arstechnica.com/health/2026/05/ebola-outbreak-now-third-largest-recorded-and-spreading-rapidly/]]>
      </content:encoded>
      <pubDate>Sun, 24 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/3762d9fc/9faf7be0.mp3" length="5717871" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>354</itunes:duration>
      <itunes:summary>This episode covers GitHub's new security requirements for npm publishers, a major credential leak from a CISA contractor, and Apple's lockdown mode for high-risk users. We dig into how trust gets built—and broken—in software supply chains and government infrastructure. On today's show, friction that protects, keys left in plain sight, and what to do when your phone becomes a target.</itunes:summary>
      <itunes:subtitle>This episode covers GitHub's new security requirements for npm publishers, a major credential leak from a CISA contractor, and Apple's lockdown mode for high-risk users. We dig into how trust gets built—and broken—in software supply chains and government </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 52: May 23, 2026</title>
      <itunes:episode>52</itunes:episode>
      <podcast:episode>52</podcast:episode>
      <itunes:title>Episode 52: May 23, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d56a7f56-b760-4914-997b-2eb9be16635f</guid>
      <link>https://share.transistor.fm/s/2d78268a</link>
      <description>
        <![CDATA[This episode digs into the week's quiet but persistent threats—Linux rootkits, router zero-days, and AI adversarial probing—before covering major incidents including Grafana Labs' GitHub breach and a zero-day exploit in Trend Micro's own security software. Adrian North wraps up with a sobering reminder that even CISA contractors aren't immune to mistakes, as exposed AWS GovCloud credentials sat publicly on GitHub.

Stories covered:
- ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories (The Hacker News) - https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html
- Grafana Labs Security Breach - Hackers Access GitHub and Download Codebase - CyberSecurityNews (CyberSecurityNews) - https://news.google.com/rss/articles/CBMia0FVX3lxTE00aWtyeFl6WE1sS1N0X0JRYkJXQmxvQ1NpYVlSeWZGempNc2RXdlM2TU5pdkh5SDlOVXVLMGRPMXZzU2VIOUFwUFlSNkR2YVpxcEpZdEcxa3Y4TGgzdlk4cnpra1FCbHh4OWhJ0gFwQVVfeXFMT1owNlYwdDNmV0c5bWVlNlJHbDB6TnlNS28xWUZ1RWpsVHpyQTFxWmZzcG9lV3h3RTBTczM1TWJnaW13Qk10RHpfMi1JME9abzh3QnBRdWlWeVk2cHpVLXJxNHlieWhUZTFUR0swWF9rVw?oc=5
- Trend Micro warns of Apex One zero-day exploited in the wild (BleepingComputer) - https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- The Best Editor-Approved Memorial Day Deals on Garmin, Coros, and Shokz: Get Hundreds Off Popular Gear for Runners (Runner's World) - https://www.runnersworld.com/gear/a71292623/memorial-day-running-gear-deals-2026/
- Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses (TechCrunch) - https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into the week's quiet but persistent threats—Linux rootkits, router zero-days, and AI adversarial probing—before covering major incidents including Grafana Labs' GitHub breach and a zero-day exploit in Trend Micro's own security software. Adrian North wraps up with a sobering reminder that even CISA contractors aren't immune to mistakes, as exposed AWS GovCloud credentials sat publicly on GitHub.

Stories covered:
- ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories (The Hacker News) - https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html
- Grafana Labs Security Breach - Hackers Access GitHub and Download Codebase - CyberSecurityNews (CyberSecurityNews) - https://news.google.com/rss/articles/CBMia0FVX3lxTE00aWtyeFl6WE1sS1N0X0JRYkJXQmxvQ1NpYVlSeWZGempNc2RXdlM2TU5pdkh5SDlOVXVLMGRPMXZzU2VIOUFwUFlSNkR2YVpxcEpZdEcxa3Y4TGgzdlk4cnpra1FCbHh4OWhJ0gFwQVVfeXFMT1owNlYwdDNmV0c5bWVlNlJHbDB6TnlNS28xWUZ1RWpsVHpyQTFxWmZzcG9lV3h3RTBTczM1TWJnaW13Qk10RHpfMi1JME9abzh3QnBRdWlWeVk2cHpVLXJxNHlieWhUZTFUR0swWF9rVw?oc=5
- Trend Micro warns of Apex One zero-day exploited in the wild (BleepingComputer) - https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- The Best Editor-Approved Memorial Day Deals on Garmin, Coros, and Shokz: Get Hundreds Off Popular Gear for Runners (Runner's World) - https://www.runnersworld.com/gear/a71292623/memorial-day-running-gear-deals-2026/
- Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses (TechCrunch) - https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/]]>
      </content:encoded>
      <pubDate>Sat, 23 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/2d78268a/270908fa.mp3" length="4800032" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>296</itunes:duration>
      <itunes:summary>This episode digs into the week's quiet but persistent threats—Linux rootkits, router zero-days, and AI adversarial probing—before covering major incidents including Grafana Labs' GitHub breach and a zero-day exploit in Trend Micro's own security software. Adrian North wraps up with a sobering reminder that even CISA contractors aren't immune to mistakes, as exposed AWS GovCloud credentials sat publicly on GitHub.</itunes:summary>
      <itunes:subtitle>This episode digs into the week's quiet but persistent threats—Linux rootkits, router zero-days, and AI adversarial probing—before covering major incidents including Grafana Labs' GitHub breach and a zero-day exploit in Trend Micro's own security software</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 51: May 22, 2026</title>
      <itunes:episode>51</itunes:episode>
      <podcast:episode>51</podcast:episode>
      <itunes:title>Episode 51: May 22, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e33a07a8-e869-482f-959c-fcbee779fc6e</guid>
      <link>https://share.transistor.fm/s/b71f48f2</link>
      <description>
        <![CDATA[This episode covers Microsoft shutting down a malware signing operation that weaponized their own trust systems, law enforcement dismantling a VPN service used by ransomware gangs, and a nine-year-old Linux kernel vulnerability that somehow stayed hidden in plain sight. Adrian also digs into GitHub's employee device compromise and what it means when the tools built to protect us become the very things attackers exploit.

Stories covered:
- Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks (The Hacker News) - https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html
- Police seize “First VPN” service used in ransomware, data theft attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks/
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (The Hacker News) - https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html
- GitHub confirms 'hacking' attack; says: We detected and contained a compromise of an employee device invo - The Times of India (The Times of India) - https://news.google.com/rss/articles/CBMiqAJBVV95cUxPeWUwVngxRXo5NjZQWTlFMTAxMnpPLVVHYm5yVEtxZWdKVWMwd1ZVeGpUNEcwOVRxRUdBX2o5VjVlSnZ3LUVuLU9QNnc0NTNkUDBJWUVoblE1aGRlZWlWakQxMllzSWthNlVGV1hoWEQwb3pnMVM5NVdMd3J2NkE0bmFfN0FQamNidFdFNWVFWmw2OUhxU3ZXMTBEdWVlSjRxb3gtVjk2Qjl2aFJzS2JTWW81dEg1U1ZxbHVMcFZmMXozNWYybXpUb3lHcnVGT3o5bW9JQXRzN3Z4dGhTcm9RU1hlTWpCNjNZN09aTVpNSlN0YWhNZ2xzY3FwMVF4eVZ4UHNaRmNpSVdicXRVRG1mS0k4RmJXQzduMl83T2VqMGdtdDRGdXhCSNIBrgJBVV95cUxOcnhHTmJ3RXhwMUdyc1pYeFFtQ2t1c2s5anI4LVJkLVJoWnhVakdVWU1TVDRBQVNtVC1IOUN1OWFRcDJ5LTlCb0h6WFZCRlBndDRvbWgwOElXeE1aSF9ha3RNZ29fYm44MFJreVFMa250b0dPN25HWVJnUElkeFIxOVJDOGVnWTYtNmZ1aks2eHRCYTJsZWV0b3VFTjBkU3U2NFdoMmRBeGhETDc3Y2pGR1BQUzZ6NTdGNzV5Z29VdEhhUWc4b3lOWkRLSnMxWGFKNDItQlR0TW1GUE1xZmtBd1FVam8yMFBabjBJbzRBOTVlS0JhTmpIc2JSM0JVZ3hXRlBQVm1TdTRaWWlUWVozNWNTVEpyWmpPSktqOXd2WjVQdnJfS1lNMnZMd1dydw?oc=5
- The Adidas Ultraboost 5X Is Over 50% Off—and Still One of Our Favorite Running Shoes (Runner's World) - https://www.runnersworld.com/gear/a71365136/adidas-ultraboost-5x-sale-may-2026/
- Golden Trail World Series is now in Canada; here’s what you need to know (Canadian Running) - https://runningmagazine.ca/trail-running/golden-trail-world-series-is-now-in-canada-heres-what-you-need-to-know/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers Microsoft shutting down a malware signing operation that weaponized their own trust systems, law enforcement dismantling a VPN service used by ransomware gangs, and a nine-year-old Linux kernel vulnerability that somehow stayed hidden in plain sight. Adrian also digs into GitHub's employee device compromise and what it means when the tools built to protect us become the very things attackers exploit.

Stories covered:
- Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks (The Hacker News) - https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html
- Police seize “First VPN” service used in ransomware, data theft attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks/
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (The Hacker News) - https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html
- GitHub confirms 'hacking' attack; says: We detected and contained a compromise of an employee device invo - The Times of India (The Times of India) - https://news.google.com/rss/articles/CBMiqAJBVV95cUxPeWUwVngxRXo5NjZQWTlFMTAxMnpPLVVHYm5yVEtxZWdKVWMwd1ZVeGpUNEcwOVRxRUdBX2o5VjVlSnZ3LUVuLU9QNnc0NTNkUDBJWUVoblE1aGRlZWlWakQxMllzSWthNlVGV1hoWEQwb3pnMVM5NVdMd3J2NkE0bmFfN0FQamNidFdFNWVFWmw2OUhxU3ZXMTBEdWVlSjRxb3gtVjk2Qjl2aFJzS2JTWW81dEg1U1ZxbHVMcFZmMXozNWYybXpUb3lHcnVGT3o5bW9JQXRzN3Z4dGhTcm9RU1hlTWpCNjNZN09aTVpNSlN0YWhNZ2xzY3FwMVF4eVZ4UHNaRmNpSVdicXRVRG1mS0k4RmJXQzduMl83T2VqMGdtdDRGdXhCSNIBrgJBVV95cUxOcnhHTmJ3RXhwMUdyc1pYeFFtQ2t1c2s5anI4LVJkLVJoWnhVakdVWU1TVDRBQVNtVC1IOUN1OWFRcDJ5LTlCb0h6WFZCRlBndDRvbWgwOElXeE1aSF9ha3RNZ29fYm44MFJreVFMa250b0dPN25HWVJnUElkeFIxOVJDOGVnWTYtNmZ1aks2eHRCYTJsZWV0b3VFTjBkU3U2NFdoMmRBeGhETDc3Y2pGR1BQUzZ6NTdGNzV5Z29VdEhhUWc4b3lOWkRLSnMxWGFKNDItQlR0TW1GUE1xZmtBd1FVam8yMFBabjBJbzRBOTVlS0JhTmpIc2JSM0JVZ3hXRlBQVm1TdTRaWWlUWVozNWNTVEpyWmpPSktqOXd2WjVQdnJfS1lNMnZMd1dydw?oc=5
- The Adidas Ultraboost 5X Is Over 50% Off—and Still One of Our Favorite Running Shoes (Runner's World) - https://www.runnersworld.com/gear/a71365136/adidas-ultraboost-5x-sale-may-2026/
- Golden Trail World Series is now in Canada; here’s what you need to know (Canadian Running) - https://runningmagazine.ca/trail-running/golden-trail-world-series-is-now-in-canada-heres-what-you-need-to-know/]]>
      </content:encoded>
      <pubDate>Fri, 22 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/b71f48f2/90f7e7b4.mp3" length="4691363" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>290</itunes:duration>
      <itunes:summary>This episode covers Microsoft shutting down a malware signing operation that weaponized their own trust systems, law enforcement dismantling a VPN service used by ransomware gangs, and a nine-year-old Linux kernel vulnerability that somehow stayed hidden in plain sight. Adrian also digs into GitHub's employee device compromise and what it means when the tools built to protect us become the very things attackers exploit.</itunes:summary>
      <itunes:subtitle>This episode covers Microsoft shutting down a malware signing operation that weaponized their own trust systems, law enforcement dismantling a VPN service used by ransomware gangs, and a nine-year-old Linux kernel vulnerability that somehow stayed hidden </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 50: May 21, 2026</title>
      <itunes:episode>50</itunes:episode>
      <podcast:episode>50</podcast:episode>
      <itunes:title>Episode 50: May 21, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">eb295e2e-292c-42ae-a247-e7ed8aa5e707</guid>
      <link>https://share.transistor.fm/s/24e95c6c</link>
      <description>
        <![CDATA[This episode covers GitHub's massive breach, CISA's accidental exposure of government cloud credentials, and Microsoft's new open-source AI security tools. We dig into what happens when the infrastructure holding our infrastructure gets compromised, plus a quick detour into gray zone training and why most runners are doing it wrong.

Stories covered:
- GitHub Confirms Breach, 4K Internal Repos Stolen (Dark Reading) - https://www.darkreading.com/application-security/github-confirms-breach-4k-internal-repos-stolen
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development (The Hacker News) - https://thehackernews.com/2026/05/microsoft-open-sources-rampart-and.html
- What to Know About Gray Zone Training and How It Can Help—or Harm—Your Running (Runner's World) - https://www.runnersworld.com/training/a71353931/gray-zone-training/
- What Are Peptides, And Why Is Every Middle-Aged Runner Suddenly Talking About BPC-157? (Marathon Handbook) - https://marathonhandbook.com/what-are-peptides-and-why-is-every-middle-aged-runner-suddenly-talking-about-bpc-157/
- Google Declaring War on the Web (Hacker News) - https://tante.cc/2026/05/20/on-google-declaring-war-on-the-web/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers GitHub's massive breach, CISA's accidental exposure of government cloud credentials, and Microsoft's new open-source AI security tools. We dig into what happens when the infrastructure holding our infrastructure gets compromised, plus a quick detour into gray zone training and why most runners are doing it wrong.

Stories covered:
- GitHub Confirms Breach, 4K Internal Repos Stolen (Dark Reading) - https://www.darkreading.com/application-security/github-confirms-breach-4k-internal-repos-stolen
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development (The Hacker News) - https://thehackernews.com/2026/05/microsoft-open-sources-rampart-and.html
- What to Know About Gray Zone Training and How It Can Help—or Harm—Your Running (Runner's World) - https://www.runnersworld.com/training/a71353931/gray-zone-training/
- What Are Peptides, And Why Is Every Middle-Aged Runner Suddenly Talking About BPC-157? (Marathon Handbook) - https://marathonhandbook.com/what-are-peptides-and-why-is-every-middle-aged-runner-suddenly-talking-about-bpc-157/
- Google Declaring War on the Web (Hacker News) - https://tante.cc/2026/05/20/on-google-declaring-war-on-the-web/]]>
      </content:encoded>
      <pubDate>Thu, 21 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/24e95c6c/2aaad2a9.mp3" length="5891742" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>365</itunes:duration>
      <itunes:summary>This episode covers GitHub's massive breach, CISA's accidental exposure of government cloud credentials, and Microsoft's new open-source AI security tools. We dig into what happens when the infrastructure holding our infrastructure gets compromised, plus a quick detour into gray zone training and why most runners are doing it wrong.</itunes:summary>
      <itunes:subtitle>This episode covers GitHub's massive breach, CISA's accidental exposure of government cloud credentials, and Microsoft's new open-source AI security tools. We dig into what happens when the infrastructure holding our infrastructure gets compromised, plus </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 49: May 20, 2026</title>
      <itunes:episode>49</itunes:episode>
      <podcast:episode>49</podcast:episode>
      <itunes:title>Episode 49: May 20, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4fb09a37-4d1e-45f0-bf65-f29a96e7dc33</guid>
      <link>https://share.transistor.fm/s/e169d97d</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian North digs into over six hundred malicious npm packages flooding the registry, a CISA contractor's exposed AWS credentials left on GitHub, and a newly public Linux kernel exploit called DirtyDecrypt. The episode wraps with a quick detour into reframing personal narratives and how the stories we tell ourselves shape what we think is possible.

Stories covered:
- New Shai-Hulud malware wave compromises 600 npm packages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-shai-hulud-malware-wave-compromises-600-npm-packages/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability (The Hacker News) - https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html
- This Training Plan Transformed Her View on Running. It Could Change Your Mindset, Too. (Runner's World) - https://www.runnersworld.com/beginner/a71350276/couch-to-5k-training-plan/
- ‘Women Can Do This’: She Started Racing Postpartum in Her 30s. Now She’s an Ultrarunning Champion (Runner's World) - https://www.runnersworld.com/news/a71309956/careth-arnold-ultrarunning-postpartum/
- Microsoft Exchange Zero-Day Under Attack, No Patch Available (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian North digs into over six hundred malicious npm packages flooding the registry, a CISA contractor's exposed AWS credentials left on GitHub, and a newly public Linux kernel exploit called DirtyDecrypt. The episode wraps with a quick detour into reframing personal narratives and how the stories we tell ourselves shape what we think is possible.

Stories covered:
- New Shai-Hulud malware wave compromises 600 npm packages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-shai-hulud-malware-wave-compromises-600-npm-packages/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability (The Hacker News) - https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html
- This Training Plan Transformed Her View on Running. It Could Change Your Mindset, Too. (Runner's World) - https://www.runnersworld.com/beginner/a71350276/couch-to-5k-training-plan/
- ‘Women Can Do This’: She Started Racing Postpartum in Her 30s. Now She’s an Ultrarunning Champion (Runner's World) - https://www.runnersworld.com/news/a71309956/careth-arnold-ultrarunning-postpartum/
- Microsoft Exchange Zero-Day Under Attack, No Patch Available (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch]]>
      </content:encoded>
      <pubDate>Wed, 20 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/e169d97d/9da2aa32.mp3" length="4993965" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>309</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian North digs into over six hundred malicious npm packages flooding the registry, a CISA contractor's exposed AWS credentials left on GitHub, and a newly public Linux kernel exploit called DirtyDecrypt. The episode wraps with a quick detour into reframing personal narratives and how the stories we tell ourselves shape what we think is possible.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian North digs into over six hundred malicious npm packages flooding the registry, a CISA contractor's exposed AWS credentials left on GitHub, and a newly public Linux kernel exploit called DirtyDecrypt. The episode wraps with </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 48: May 19, 2026</title>
      <itunes:episode>48</itunes:episode>
      <podcast:episode>48</podcast:episode>
      <itunes:title>Episode 48: May 19, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c4473966-af93-4ed4-b1f6-48cd2acdbff5</guid>
      <link>https://share.transistor.fm/s/d4da6c61</link>
      <description>
        <![CDATA[This episode covers a critical NGINX vulnerability already being exploited in the wild, a Windows zero-day giving attackers full system control, and a jaw-dropping security lapse where CISA's own contractor leaked AWS GovCloud credentials on GitHub. We also dig into a massive NYC Health + Hospitals breach exposing biometric data from nearly two million people—the kind of information you can never change once it's stolen.

Stories covered:
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE (The Hacker News) - https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people (TechCrunch) - https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/
- What to Do When You Don’t Get Into Your Goal Race (Runner's World) - https://www.runnersworld.com/races-places/a71318334/world-marathon-major-race-alternatives/
- Everything You Need to Know About the 2026 Cape Town Marathon (Marathon Handbook) - https://marathonhandbook.com/everything-you-need-to-know-about-the-2026-cape-town-marathon/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical NGINX vulnerability already being exploited in the wild, a Windows zero-day giving attackers full system control, and a jaw-dropping security lapse where CISA's own contractor leaked AWS GovCloud credentials on GitHub. We also dig into a massive NYC Health + Hospitals breach exposing biometric data from nearly two million people—the kind of information you can never change once it's stolen.

Stories covered:
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE (The Hacker News) - https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people (TechCrunch) - https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/
- What to Do When You Don’t Get Into Your Goal Race (Runner's World) - https://www.runnersworld.com/races-places/a71318334/world-marathon-major-race-alternatives/
- Everything You Need to Know About the 2026 Cape Town Marathon (Marathon Handbook) - https://marathonhandbook.com/everything-you-need-to-know-about-the-2026-cape-town-marathon/]]>
      </content:encoded>
      <pubDate>Tue, 19 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d4da6c61/3edbc208.mp3" length="4488235" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>277</itunes:duration>
      <itunes:summary>This episode covers a critical NGINX vulnerability already being exploited in the wild, a Windows zero-day giving attackers full system control, and a jaw-dropping security lapse where CISA's own contractor leaked AWS GovCloud credentials on GitHub. We also dig into a massive NYC Health + Hospitals breach exposing biometric data from nearly two million people—the kind of information you can never change once it's stolen.</itunes:summary>
      <itunes:subtitle>This episode covers a critical NGINX vulnerability already being exploited in the wild, a Windows zero-day giving attackers full system control, and a jaw-dropping security lapse where CISA's own contractor leaked AWS GovCloud credentials on GitHub. We al</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 47: May 18, 2026</title>
      <itunes:episode>47</itunes:episode>
      <podcast:episode>47</podcast:episode>
      <itunes:title>Episode 47: May 18, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">19c71d09-02ab-4671-b58c-bb276546db89</guid>
      <link>https://share.transistor.fm/s/27aabc46</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian covers a dangerous new Windows zero-day giving attackers full system access, an actively exploited NGINX vulnerability hitting millions of sites, and why your summer running pace feels impossibly hard. Plus, Olympic marathoner Molly Seidel's shift from the road to ultrarunning reminds us that even elite athletes need to find what's fun again.

Stories covered:
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE (The Hacker News) - https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
- Why Your Usual Running Pace Feels Harder in the Heat—and What to Do About It (Runner's World) - https://www.runnersworld.com/training/a71318220/running-intensity-in-heat/
- ‘It Just Wasn’t Fun Anymore’: Why Molly Seidel Stepped Away from Marathoning—and Is Thriving on the Trails (Runner's World) - https://www.runnersworld.com/news/a71166284/molly-seidel-ultra-trail-running/
- Victory! End-to-End Encrypted RCS Comes to Apple and Android Chats (EFF) - https://www.eff.org/deeplinks/2026/05/victory-end-end-encrypted-rcs-comes-apple-and-android-chats
- Ebola outbreak with uncommon strain erupts in Congo and Uganda; 65 deaths (Ars Technica) - https://arstechnica.com/health/2026/05/ebola-outbreak-confirmed-in-congo-and-uganda-246-suspected-cases-65-deaths/]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian covers a dangerous new Windows zero-day giving attackers full system access, an actively exploited NGINX vulnerability hitting millions of sites, and why your summer running pace feels impossibly hard. Plus, Olympic marathoner Molly Seidel's shift from the road to ultrarunning reminds us that even elite athletes need to find what's fun again.

Stories covered:
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE (The Hacker News) - https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
- Why Your Usual Running Pace Feels Harder in the Heat—and What to Do About It (Runner's World) - https://www.runnersworld.com/training/a71318220/running-intensity-in-heat/
- ‘It Just Wasn’t Fun Anymore’: Why Molly Seidel Stepped Away from Marathoning—and Is Thriving on the Trails (Runner's World) - https://www.runnersworld.com/news/a71166284/molly-seidel-ultra-trail-running/
- Victory! End-to-End Encrypted RCS Comes to Apple and Android Chats (EFF) - https://www.eff.org/deeplinks/2026/05/victory-end-end-encrypted-rcs-comes-apple-and-android-chats
- Ebola outbreak with uncommon strain erupts in Congo and Uganda; 65 deaths (Ars Technica) - https://arstechnica.com/health/2026/05/ebola-outbreak-confirmed-in-congo-and-uganda-246-suspected-cases-65-deaths/]]>
      </content:encoded>
      <pubDate>Mon, 18 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/27aabc46/9113401f.mp3" length="5049136" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>312</itunes:duration>
      <itunes:summary>On today's Signal Check, Adrian covers a dangerous new Windows zero-day giving attackers full system access, an actively exploited NGINX vulnerability hitting millions of sites, and why your summer running pace feels impossibly hard. Plus, Olympic marathoner Molly Seidel's shift from the road to ultrarunning reminds us that even elite athletes need to find what's fun again.</itunes:summary>
      <itunes:subtitle>On today's Signal Check, Adrian covers a dangerous new Windows zero-day giving attackers full system access, an actively exploited NGINX vulnerability hitting millions of sites, and why your summer running pace feels impossibly hard. Plus, Olympic maratho</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 46: May 17, 2026</title>
      <itunes:episode>46</itunes:episode>
      <podcast:episode>46</podcast:episode>
      <itunes:title>Episode 46: May 17, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">26085e4f-a091-4f9e-a168-f609967e2bd9</guid>
      <link>https://share.transistor.fm/s/05d4a7eb</link>
      <description>
        <![CDATA[This episode covers a critical Microsoft Exchange vulnerability being actively exploited in the wild, the story of Fisker EV owners who reverse-engineered their abandoned cars into an open-source movement, and a deep dive into the "sweet spot" training zone that could unlock faster running without the burnout. We also touch on prize money still owed to marathon runners six months after crossing the finish line.

Stories covered:
- Microsoft warns of Exchange zero-day flaw exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/
- On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email (The Hacker News) - https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- Fisker went bankrupt and owners built an open source car company from the ashes (Hacker News) - https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-after-bankruptcy/
- This Type of Training Could Be the Secret to Running Faster Without Burning Out—and It Can Lead to a PR in Any Distance (Runner's World) - https://www.runnersworld.com/training/a71310980/critical-velocity-workouts/
- 6 Months After This Marathon, the Top Finishers Still Haven’t Been Paid Prize Money—and They Want Answers (Runner's World) - https://www.runnersworld.com/news/a71318097/soweto-marathon-prize-money-controversy/
- Three's a party: US, China, and now Russia are on the prowl in GEO (Ars Technica) - https://arstechnica.com/space/2026/05/threes-a-party-us-china-and-now-russia-are-on-the-prowl-in-geo/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical Microsoft Exchange vulnerability being actively exploited in the wild, the story of Fisker EV owners who reverse-engineered their abandoned cars into an open-source movement, and a deep dive into the "sweet spot" training zone that could unlock faster running without the burnout. We also touch on prize money still owed to marathon runners six months after crossing the finish line.

Stories covered:
- Microsoft warns of Exchange zero-day flaw exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/
- On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email (The Hacker News) - https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- Fisker went bankrupt and owners built an open source car company from the ashes (Hacker News) - https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-after-bankruptcy/
- This Type of Training Could Be the Secret to Running Faster Without Burning Out—and It Can Lead to a PR in Any Distance (Runner's World) - https://www.runnersworld.com/training/a71310980/critical-velocity-workouts/
- 6 Months After This Marathon, the Top Finishers Still Haven’t Been Paid Prize Money—and They Want Answers (Runner's World) - https://www.runnersworld.com/news/a71318097/soweto-marathon-prize-money-controversy/
- Three's a party: US, China, and now Russia are on the prowl in GEO (Ars Technica) - https://arstechnica.com/space/2026/05/threes-a-party-us-china-and-now-russia-are-on-the-prowl-in-geo/]]>
      </content:encoded>
      <pubDate>Sun, 17 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/05d4a7eb/54f2869d.mp3" length="5000235" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>309</itunes:duration>
      <itunes:summary>This episode covers a critical Microsoft Exchange vulnerability being actively exploited in the wild, the story of Fisker EV owners who reverse-engineered their abandoned cars into an open-source movement, and a deep dive into the "sweet spot" training zone that could unlock faster running without the burnout. We also touch on prize money still owed to marathon runners six months after crossing the finish line.</itunes:summary>
      <itunes:subtitle>This episode covers a critical Microsoft Exchange vulnerability being actively exploited in the wild, the story of Fisker EV owners who reverse-engineered their abandoned cars into an open-source movement, and a deep dive into the "sweet spot" training zo</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 45: May 16, 2026</title>
      <itunes:episode>45</itunes:episode>
      <podcast:episode>45</podcast:episode>
      <itunes:title>Episode 45: May 16, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">47fb5c29-1017-4056-841e-80c525c14513</guid>
      <link>https://share.transistor.fm/s/632511cd</link>
      <description>
        <![CDATA[This episode covers active exploitation of critical vulnerabilities in Microsoft Exchange and Cisco SD-WAN, a supply chain breach that hit OpenAI developers, and why patching timelines matter when attackers are already inside the door. Adrian pulls weekend signals on threats that don't take days off—from zero-days to compromised signing certificates. It's a sobering look at how fast the window closes between disclosure and exploitation.

Stories covered:
- On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email (The Hacker News) - https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
- OpenAI confirms security breach in TanStack supply chain attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/
- 6 Months After This Marathon, the Top Finishers Still Haven’t Been Paid Prize Money—and They Want Answers (Runner's World) - https://www.runnersworld.com/news/a71318097/soweto-marathon-prize-money-controversy/
- ‘I Don’t Know How I Did This’: He Ran 1,000 Miles. Around a Single Track. For 18 Days. (Runner's World) - https://www.runnersworld.com/news/a71317409/1000-mile-track-ultrarunner-charity/
- Tesla Reveals New Details About Robotaxi Crashes—and the Humans Involved (Wired) - https://www.wired.com/story/tesla-reveals-new-details-about-robotaxi-crashes-and-the-humans-involved/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers active exploitation of critical vulnerabilities in Microsoft Exchange and Cisco SD-WAN, a supply chain breach that hit OpenAI developers, and why patching timelines matter when attackers are already inside the door. Adrian pulls weekend signals on threats that don't take days off—from zero-days to compromised signing certificates. It's a sobering look at how fast the window closes between disclosure and exploitation.

Stories covered:
- On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email (The Hacker News) - https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
- OpenAI confirms security breach in TanStack supply chain attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/
- 6 Months After This Marathon, the Top Finishers Still Haven’t Been Paid Prize Money—and They Want Answers (Runner's World) - https://www.runnersworld.com/news/a71318097/soweto-marathon-prize-money-controversy/
- ‘I Don’t Know How I Did This’: He Ran 1,000 Miles. Around a Single Track. For 18 Days. (Runner's World) - https://www.runnersworld.com/news/a71317409/1000-mile-track-ultrarunner-charity/
- Tesla Reveals New Details About Robotaxi Crashes—and the Humans Involved (Wired) - https://www.wired.com/story/tesla-reveals-new-details-about-robotaxi-crashes-and-the-humans-involved/]]>
      </content:encoded>
      <pubDate>Sat, 16 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/632511cd/57fa30ed.mp3" length="6296744" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>390</itunes:duration>
      <itunes:summary>This episode covers active exploitation of critical vulnerabilities in Microsoft Exchange and Cisco SD-WAN, a supply chain breach that hit OpenAI developers, and why patching timelines matter when attackers are already inside the door. Adrian pulls weekend signals on threats that don't take days off—from zero-days to compromised signing certificates. It's a sobering look at how fast the window closes between disclosure and exploitation.</itunes:summary>
      <itunes:subtitle>This episode covers active exploitation of critical vulnerabilities in Microsoft Exchange and Cisco SD-WAN, a supply chain breach that hit OpenAI developers, and why patching timelines matter when attackers are already inside the door. Adrian pulls weeken</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 44: May 15, 2026</title>
      <itunes:episode>44</itunes:episode>
      <podcast:episode>44</podcast:episode>
      <itunes:title>Episode 44: May 15, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5651108e-6ccc-4710-a7a4-af18f11345b8</guid>
      <link>https://share.transistor.fm/s/a3ec50d5</link>
      <description>
        <![CDATA[This episode covers the fallout from Pwn2Own Berlin, where researchers exposed 24 zero-day exploits in one day, plus urgent warnings about a Cisco SD-WAN authentication bypass being actively exploited in the wild. We also dig into a new Linux privilege escalation flaw called Fragnesia and what it means when similar bugs start clustering together.

Stories covered:
- Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026 (BleepingComputer) - https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
- New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption (The Hacker News) - https://thehackernews.com/2026/05/new-fragnesia-linux-kernel-lpe-grants.html
- Training for Another Half Marathon? Avoid the Common Mistakes I Made So You Run a Faster Race. (Runner's World) - https://www.runnersworld.com/training/a71285796/second-half-marathon-training-tips/
- Not Just Cruise Ships: What to Know About Hantavirus in the Backcountry (ExplorersWeb) - https://explorersweb.com/not-just-cruise-ships-what-to-know-about-hantavirus-in-the-backcountry/
- An Engineer’s Post Protesting Laptop Surveillance Is Going Viral Inside Meta (Wired) - https://www.wired.com/story/meta-employee-protest-mouse-tracking-surveillance-ai-training/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers the fallout from Pwn2Own Berlin, where researchers exposed 24 zero-day exploits in one day, plus urgent warnings about a Cisco SD-WAN authentication bypass being actively exploited in the wild. We also dig into a new Linux privilege escalation flaw called Fragnesia and what it means when similar bugs start clustering together.

Stories covered:
- Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026 (BleepingComputer) - https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
- New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption (The Hacker News) - https://thehackernews.com/2026/05/new-fragnesia-linux-kernel-lpe-grants.html
- Training for Another Half Marathon? Avoid the Common Mistakes I Made So You Run a Faster Race. (Runner's World) - https://www.runnersworld.com/training/a71285796/second-half-marathon-training-tips/
- Not Just Cruise Ships: What to Know About Hantavirus in the Backcountry (ExplorersWeb) - https://explorersweb.com/not-just-cruise-ships-what-to-know-about-hantavirus-in-the-backcountry/
- An Engineer’s Post Protesting Laptop Surveillance Is Going Viral Inside Meta (Wired) - https://www.wired.com/story/meta-employee-protest-mouse-tracking-surveillance-ai-training/]]>
      </content:encoded>
      <pubDate>Fri, 15 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/a3ec50d5/2c889dc6.mp3" length="4760744" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>294</itunes:duration>
      <itunes:summary>This episode covers the fallout from Pwn2Own Berlin, where researchers exposed 24 zero-day exploits in one day, plus urgent warnings about a Cisco SD-WAN authentication bypass being actively exploited in the wild. We also dig into a new Linux privilege escalation flaw called Fragnesia and what it means when similar bugs start clustering together.</itunes:summary>
      <itunes:subtitle>This episode covers the fallout from Pwn2Own Berlin, where researchers exposed 24 zero-day exploits in one day, plus urgent warnings about a Cisco SD-WAN authentication bypass being actively exploited in the wild. We also dig into a new Linux privilege es</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 43: May 14, 2026</title>
      <itunes:episode>43</itunes:episode>
      <podcast:episode>43</podcast:episode>
      <itunes:title>Episode 43: May 14, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5e15e88e-5f52-4e58-8b24-bde67e09ab3e</guid>
      <link>https://share.transistor.fm/s/d1f585a8</link>
      <description>
        <![CDATA[This episode covers two unpatched Windows zero-days that bypass BitLocker and escalate privileges, a self-replicating worm spreading through npm packages in the TanStack ecosystem, and a critical remote code execution flaw in the Exim mail server. Adrian breaks down how disclosure tensions, supply chain infections, and legacy infrastructure vulnerabilities are colliding all at once. It's a packed signal day that shows just how fast things can unravel.

Stories covered:
- Windows BitLocker zero-day gives access to protected drives, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- Microsoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits - Forbes (Forbes) - https://news.google.com/rss/articles/CBMiuwFBVV95cUxQS1J1OUpHM1RWdDF6LXdqLThRTUFHMFFmVWk5ZGphU2ZWVnR4NWQxeTZFWmpWQmFCSldobzFvVUZKdVVXNG14Y1Y1YTdWczhnUWNGX0JtSkJ2dGpxQl9vTUlSQkdpYzdvV3A5VWNqWG4xMTZwSVN0bE8yQVNVNnN2TURTSG1pSElaR0hmTUVHNmMzSDd1MTlwNUVSWkVobjlaWFhiblZ2VzczV21YcVR3WmxHNm45MHF2TU5V?oc=5
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain (Dark Reading) - https://www.darkreading.com/application-security/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain
- New critical Exim mailer flaw allows remote code execution (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/
- ‘Strava Brain’ Is Making Your Long, Hot Runs Harder Than They Need to Be (Runner's World) - https://www.runnersworld.com/news/a71273015/elapsed-time-strava-summer-runs/
- Want to Start Trail Running Like Rachel Entrekin? Begin With These Top 10 Essentials (Runner's World) - https://www.runnersworld.com/trail-running/a71293507/trail-running-gear-for-beginners/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers two unpatched Windows zero-days that bypass BitLocker and escalate privileges, a self-replicating worm spreading through npm packages in the TanStack ecosystem, and a critical remote code execution flaw in the Exim mail server. Adrian breaks down how disclosure tensions, supply chain infections, and legacy infrastructure vulnerabilities are colliding all at once. It's a packed signal day that shows just how fast things can unravel.

Stories covered:
- Windows BitLocker zero-day gives access to protected drives, PoC released (BleepingComputer) - https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- Microsoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits - Forbes (Forbes) - https://news.google.com/rss/articles/CBMiuwFBVV95cUxQS1J1OUpHM1RWdDF6LXdqLThRTUFHMFFmVWk5ZGphU2ZWVnR4NWQxeTZFWmpWQmFCSldobzFvVUZKdVVXNG14Y1Y1YTdWczhnUWNGX0JtSkJ2dGpxQl9vTUlSQkdpYzdvV3A5VWNqWG4xMTZwSVN0bE8yQVNVNnN2TURTSG1pSElaR0hmTUVHNmMzSDd1MTlwNUVSWkVobjlaWFhiblZ2VzczV21YcVR3WmxHNm45MHF2TU5V?oc=5
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain (Dark Reading) - https://www.darkreading.com/application-security/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain
- New critical Exim mailer flaw allows remote code execution (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/
- ‘Strava Brain’ Is Making Your Long, Hot Runs Harder Than They Need to Be (Runner's World) - https://www.runnersworld.com/news/a71273015/elapsed-time-strava-summer-runs/
- Want to Start Trail Running Like Rachel Entrekin? Begin With These Top 10 Essentials (Runner's World) - https://www.runnersworld.com/trail-running/a71293507/trail-running-gear-for-beginners/]]>
      </content:encoded>
      <pubDate>Thu, 14 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d1f585a8/3ee6b83e.mp3" length="5456646" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>337</itunes:duration>
      <itunes:summary>This episode covers two unpatched Windows zero-days that bypass BitLocker and escalate privileges, a self-replicating worm spreading through npm packages in the TanStack ecosystem, and a critical remote code execution flaw in the Exim mail server. Adrian breaks down how disclosure tensions, supply chain infections, and legacy infrastructure vulnerabilities are colliding all at once. It's a packed signal day that shows just how fast things can unravel.</itunes:summary>
      <itunes:subtitle>This episode covers two unpatched Windows zero-days that bypass BitLocker and escalate privileges, a self-replicating worm spreading through npm packages in the TanStack ecosystem, and a critical remote code execution flaw in the Exim mail server. Adrian </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mlshe7dscq22"/>
    </item>
    <item>
      <title>Episode 42: May 13, 2026</title>
      <itunes:episode>42</itunes:episode>
      <podcast:episode>42</podcast:episode>
      <itunes:title>Episode 42: May 13, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fb64b23d-0bbf-486c-ac8d-41ec87267f57</guid>
      <link>https://share.transistor.fm/s/eb5d82f0</link>
      <description>
        <![CDATA[This episode covers Microsoft's rare zero-day-free Patch Tuesday, Google's discovery of the first AI-developed exploit bypassing two-factor authentication, and a self-propagating worm infecting hundreds of npm packages in the open source ecosystem. Adrian also touches on the rising cost of high-performance running shoes and what it says about premium pricing creep.

Stories covered:
- It's Patch Tuesday for Microsoft and Not a Zero-Day In Sight (Dark Reading) - https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (The Hacker News) - https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain (Dark Reading) - https://www.darkreading.com/application-security/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain
- Our Favorite New Shoes All Cost $200 and Up. But You Don’t Have to Spend That Much (Runner's World) - https://www.runnersworld.com/training/a71270170/amazing-runners-world-show-epsiode-114-favorite-shoes-of-2026/
- She Ran 250 Miles in an Astonishing 56 Hours—Beating All the Men at Cocodona and Making History - Runner's World (Runner's World) - https://news.google.com/rss/articles/CBMihAFBVV95cUxNNjZOVEZBdEFwcFdSUHRJRFNWRHZVU3dKLWxtT2xvRUVfRFlnMm9wOUN5bVRPSWRoTzhnOHlObzMtQXNVRDZJSlctV3VJem40UlcwRlI4a0RXNGxtX29VaHlrOUNTTnNYUDVFaEhRb1hkUEwxaXp2ZHBCNkstV1RsZlBzbDQ?oc=5
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots (The Hacker News) - https://thehackernews.com/2026/05/new-trickmo-variant-uses-ton-c2-and.html]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers Microsoft's rare zero-day-free Patch Tuesday, Google's discovery of the first AI-developed exploit bypassing two-factor authentication, and a self-propagating worm infecting hundreds of npm packages in the open source ecosystem. Adrian also touches on the rising cost of high-performance running shoes and what it says about premium pricing creep.

Stories covered:
- It's Patch Tuesday for Microsoft and Not a Zero-Day In Sight (Dark Reading) - https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (The Hacker News) - https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain (Dark Reading) - https://www.darkreading.com/application-security/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain
- Our Favorite New Shoes All Cost $200 and Up. But You Don’t Have to Spend That Much (Runner's World) - https://www.runnersworld.com/training/a71270170/amazing-runners-world-show-epsiode-114-favorite-shoes-of-2026/
- She Ran 250 Miles in an Astonishing 56 Hours—Beating All the Men at Cocodona and Making History - Runner's World (Runner's World) - https://news.google.com/rss/articles/CBMihAFBVV95cUxNNjZOVEZBdEFwcFdSUHRJRFNWRHZVU3dKLWxtT2xvRUVfRFlnMm9wOUN5bVRPSWRoTzhnOHlObzMtQXNVRDZJSlctV3VJem40UlcwRlI4a0RXNGxtX29VaHlrOUNTTnNYUDVFaEhRb1hkUEwxaXp2ZHBCNkstV1RsZlBzbDQ?oc=5
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots (The Hacker News) - https://thehackernews.com/2026/05/new-trickmo-variant-uses-ton-c2-and.html]]>
      </content:encoded>
      <pubDate>Wed, 13 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/eb5d82f0/7764d38f.mp3" length="4649149" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>287</itunes:duration>
      <itunes:summary>This episode covers Microsoft's rare zero-day-free Patch Tuesday, Google's discovery of the first AI-developed exploit bypassing two-factor authentication, and a self-propagating worm infecting hundreds of npm packages in the open source ecosystem. Adrian also touches on the rising cost of high-performance running shoes and what it says about premium pricing creep.</itunes:summary>
      <itunes:subtitle>This episode covers Microsoft's rare zero-day-free Patch Tuesday, Google's discovery of the first AI-developed exploit bypassing two-factor authentication, and a self-propagating worm infecting hundreds of npm packages in the open source ecosystem. Adrian</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mlpwvmct6q2x"/>
    </item>
    <item>
      <title>Episode 41: May 12, 2026</title>
      <itunes:episode>41</itunes:episode>
      <podcast:episode>41</podcast:episode>
      <itunes:title>Episode 41: May 12, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">02033f78-b99d-4697-b826-2062f7066825</guid>
      <link>https://share.transistor.fm/s/58d20aaf</link>
      <description>
        <![CDATA[This episode digs into Google's confirmation of the first AI-generated zero-day exploits now being used in the wild, marking a major shift in the threat landscape. We also cover a supply-chain compromise in the TanStack Router project and what it means for every developer pulling dependencies.

Stories covered:
- Google: Hackers used AI to develop zero-day exploit for web admin tool (BleepingComputer) - https://www.bleepingcomputer.com/news/security/google-hackers-used-ai-to-develop-zero-day-exploit-for-web-admin-tool/
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (The Hacker News) - https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- Postmortem: TanStack npm supply-chain compromise (Hacker News) - https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
- Our Favorite New Shoes All Cost $200 and Up. But You Don’t Have to Spend That Much (Runner's World) - https://www.runnersworld.com/training/a71270170/amazing-runners-world-show-epsiode-114-favorite-shoes-of-2026/
- 2026 Transvulcania Ultramarathon Results: David Sinclair and Blandine L'Hirondel Topple Course Records - iRunFar (iRunFar) - https://news.google.com/rss/articles/CBMickFVX3lxTFBvTk83UDFJUE5panhXQVppTWNKSkk5T1U2U1g4Yzg0VEtIOFljWVpNSlZjanVseGJsSWFNdDB2bnlYT3hLSmY0cjV2LU11amlHVTJqNUswY0YxTVctckNaTWNfTmREZ3JBLUktSXJQREVuUQ?oc=5
- Linux bitten by second severe vulnerability in as many weeks (Ars Technica) - https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Google's confirmation of the first AI-generated zero-day exploits now being used in the wild, marking a major shift in the threat landscape. We also cover a supply-chain compromise in the TanStack Router project and what it means for every developer pulling dependencies.

Stories covered:
- Google: Hackers used AI to develop zero-day exploit for web admin tool (BleepingComputer) - https://www.bleepingcomputer.com/news/security/google-hackers-used-ai-to-develop-zero-day-exploit-for-web-admin-tool/
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (The Hacker News) - https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- Postmortem: TanStack npm supply-chain compromise (Hacker News) - https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
- Our Favorite New Shoes All Cost $200 and Up. But You Don’t Have to Spend That Much (Runner's World) - https://www.runnersworld.com/training/a71270170/amazing-runners-world-show-epsiode-114-favorite-shoes-of-2026/
- 2026 Transvulcania Ultramarathon Results: David Sinclair and Blandine L'Hirondel Topple Course Records - iRunFar (iRunFar) - https://news.google.com/rss/articles/CBMickFVX3lxTFBvTk83UDFJUE5panhXQVppTWNKSkk5T1U2U1g4Yzg0VEtIOFljWVpNSlZjanVseGJsSWFNdDB2bnlYT3hLSmY0cjV2LU11amlHVTJqNUswY0YxTVctckNaTWNfTmREZ3JBLUktSXJQREVuUQ?oc=5
- Linux bitten by second severe vulnerability in as many weeks (Ars Technica) - https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/]]>
      </content:encoded>
      <pubDate>Tue, 12 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/58d20aaf/99f242ba.mp3" length="6017965" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>373</itunes:duration>
      <itunes:summary>This episode digs into Google's confirmation of the first AI-generated zero-day exploits now being used in the wild, marking a major shift in the threat landscape. We also cover a supply-chain compromise in the TanStack Router project and what it means for every developer pulling dependencies.</itunes:summary>
      <itunes:subtitle>This episode digs into Google's confirmation of the first AI-generated zero-day exploits now being used in the wild, marking a major shift in the threat landscape. We also cover a supply-chain compromise in the TanStack Router project and what it means fo</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mlnggucilm2n"/>
    </item>
    <item>
      <title>Episode 39: May 10, 2026</title>
      <itunes:episode>39</itunes:episode>
      <podcast:episode>39</podcast:episode>
      <itunes:title>Episode 39: May 10, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1f0862d5-f1ad-4f1b-af96-19d299343411</guid>
      <link>https://share.transistor.fm/s/d08e49aa</link>
      <description>
        <![CDATA[This episode covers a dangerous new Linux zero-day called Dirty Frag that grants root access across major distros, a mass ShinyHunters attack defacing Canvas portals at hundreds of universities, and CISA's urgent four-day patching deadline for a critical Ivanti flaw already being exploited in the wild. Adrian also touches on volcanic trail running victories and a lightning-fast Clojure implementation in Go that boots in seven milliseconds.

Stories covered:
- New Linux 'Dirty Frag' zero-day gives root on all major distros (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges/
- Canvas login portals hacked in mass ShinyHunters extortion campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/
- CISA gives feds four days to patch Ivanti flaw exploited as zero-day (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-gives-feds-four-days-to-patch-ivanti-flaw-exploited-as-zero-day/
- 2026 Transvulcania Half Marathon Results: Volcanic Victory for Ruth Gitonga and Philemon Kiriago (iRunFar) - https://www.irunfar.com/2026-transvulcania-half-marathon-results
- Show HN: I made a Clojure-like language in Go, boots in 7ms (Hacker News) - https://github.com/nooga/let-go
- Zara data breach exposed personal information of 197,000 people (BleepingComputer) - https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a dangerous new Linux zero-day called Dirty Frag that grants root access across major distros, a mass ShinyHunters attack defacing Canvas portals at hundreds of universities, and CISA's urgent four-day patching deadline for a critical Ivanti flaw already being exploited in the wild. Adrian also touches on volcanic trail running victories and a lightning-fast Clojure implementation in Go that boots in seven milliseconds.

Stories covered:
- New Linux 'Dirty Frag' zero-day gives root on all major distros (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges/
- Canvas login portals hacked in mass ShinyHunters extortion campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/
- CISA gives feds four days to patch Ivanti flaw exploited as zero-day (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-gives-feds-four-days-to-patch-ivanti-flaw-exploited-as-zero-day/
- 2026 Transvulcania Half Marathon Results: Volcanic Victory for Ruth Gitonga and Philemon Kiriago (iRunFar) - https://www.irunfar.com/2026-transvulcania-half-marathon-results
- Show HN: I made a Clojure-like language in Go, boots in 7ms (Hacker News) - https://github.com/nooga/let-go
- Zara data breach exposed personal information of 197,000 people (BleepingComputer) - https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/]]>
      </content:encoded>
      <pubDate>Sun, 10 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d08e49aa/9a2164d9.mp3" length="4216979" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>260</itunes:duration>
      <itunes:summary>This episode covers a dangerous new Linux zero-day called Dirty Frag that grants root access across major distros, a mass ShinyHunters attack defacing Canvas portals at hundreds of universities, and CISA's urgent four-day patching deadline for a critical Ivanti flaw already being exploited in the wild. Adrian also touches on volcanic trail running victories and a lightning-fast Clojure implementation in Go that boots in seven milliseconds.</itunes:summary>
      <itunes:subtitle>This episode covers a dangerous new Linux zero-day called Dirty Frag that grants root access across major distros, a mass ShinyHunters attack defacing Canvas portals at hundreds of universities, and CISA's urgent four-day patching deadline for a critical </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mlifijvvxw2y"/>
    </item>
    <item>
      <title>Episode 38: May 09, 2026</title>
      <itunes:episode>38</itunes:episode>
      <podcast:episode>38</podcast:episode>
      <itunes:title>Episode 38: May 09, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b19f7871-33ab-42bd-ab83-79f15c6fe3b0</guid>
      <link>https://share.transistor.fm/s/b620b8c6</link>
      <description>
        <![CDATA[This episode covers critical zero-day exploits hitting Palo Alto firewalls before disclosure, an unpatched Linux privilege escalation flaw called Dirty Frag, and ShinyHunters breaching Canvas for the second time. Adrian breaks down how the window between vulnerability discovery and exploitation is collapsing fast. If you're running enterprise infrastructure or Linux systems, this Signal Check is essential listening.

Stories covered:
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage (The Hacker News) - https://thehackernews.com/2026/05/pan-os-rce-exploit-under-active-use.html
- Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions (The Hacker News) - https://thehackernews.com/2026/05/linux-kernel-dirty-frag-lpe-exploit.html
- Canvas login portals hacked in mass ShinyHunters extortion campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/
- 2026 Cocodona 250 Mile Results: Rachel Entrekin Wins Outright and Kilian Korth Takes Men’s Race in Record Times (iRunFar) - https://www.irunfar.com/2026-cocodona-250-mile-results
- Poland says hackers breached water treatment plants, and the US is facing the same threat (TechCrunch) - https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/
- DOGE used ChatGPT in a way that was both dumb and illegal, judge rules (The Verge) - https://www.theverge.com/policy/927071/doge-chatgpt-grants-canceled]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers critical zero-day exploits hitting Palo Alto firewalls before disclosure, an unpatched Linux privilege escalation flaw called Dirty Frag, and ShinyHunters breaching Canvas for the second time. Adrian breaks down how the window between vulnerability discovery and exploitation is collapsing fast. If you're running enterprise infrastructure or Linux systems, this Signal Check is essential listening.

Stories covered:
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage (The Hacker News) - https://thehackernews.com/2026/05/pan-os-rce-exploit-under-active-use.html
- Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions (The Hacker News) - https://thehackernews.com/2026/05/linux-kernel-dirty-frag-lpe-exploit.html
- Canvas login portals hacked in mass ShinyHunters extortion campaign (BleepingComputer) - https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/
- 2026 Cocodona 250 Mile Results: Rachel Entrekin Wins Outright and Kilian Korth Takes Men’s Race in Record Times (iRunFar) - https://www.irunfar.com/2026-cocodona-250-mile-results
- Poland says hackers breached water treatment plants, and the US is facing the same threat (TechCrunch) - https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/
- DOGE used ChatGPT in a way that was both dumb and illegal, judge rules (The Verge) - https://www.theverge.com/policy/927071/doge-chatgpt-grants-canceled]]>
      </content:encoded>
      <pubDate>Sat, 09 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/b620b8c6/9399640b.mp3" length="6696313" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>415</itunes:duration>
      <itunes:summary>This episode covers critical zero-day exploits hitting Palo Alto firewalls before disclosure, an unpatched Linux privilege escalation flaw called Dirty Frag, and ShinyHunters breaching Canvas for the second time. Adrian breaks down how the window between vulnerability discovery and exploitation is collapsing fast. If you're running enterprise infrastructure or Linux systems, this Signal Check is essential listening.</itunes:summary>
      <itunes:subtitle>This episode covers critical zero-day exploits hitting Palo Alto firewalls before disclosure, an unpatched Linux privilege escalation flaw called Dirty Frag, and ShinyHunters breaching Canvas for the second time. Adrian breaks down how the window between </itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mlfuzuomqn27"/>
    </item>
    <item>
      <title>Episode 37: May 08, 2026</title>
      <itunes:episode>37</itunes:episode>
      <podcast:episode>37</podcast:episode>
      <itunes:title>Episode 37: May 08, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0f8f65ec-af39-4163-bab5-c2c0a3b0466e</guid>
      <link>https://share.transistor.fm/s/a28a3e3b</link>
      <description>
        <![CDATA[This episode covers a critical zero-day exploit in Palo Alto firewalls that went unpatched for nearly a month, malware hiding in PyPI packages using workplace chat tools for cover, and a major breach at Canvas that exposed student data across universities. We also dig into why trust systems in open-source repos keep getting weaponized and close with an ultramarathon story that redefines what the human body can actually endure.

Stories covered:
- PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux (The Hacker News) - https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html
- Palo Alto Networks firewall zero-day exploited for nearly a month (BleepingComputer) - https://www.bleepingcomputer.com/news/security/pan-os-firewall-rce-zero-day-exploited-in-attacks-since-april-9/
- Canvas, used by schools and universities across the U.S., breached by hacker group - FOX13 Memphis (FOX13 Memphis) - https://news.google.com/rss/articles/CBMi9gFBVV95cUxQbWIzLVJFd3BNcWNGam9KQWdJNnJsT0ozeUZ1UVFpTGltY0RNb1FyUTlvUEtydVVxMFJsQmlmMTBrYkRuUzJyRUdtTXRZQ2dzQTlNQlJnOUVpbmYta05NcW9wMkZ6UnV5NXh2WkV3bExPTzN6NE8wZC02X0dKdkJlY3BScmhfTV84eW40TDN1THlNN3BJY1JnRmszTEM5TGlVOFFnS3h2NjJHOUtXMXNsWlYta3RjZXRGcWhLV2hwcFFSakdfaGFSejhaQW1aQWpGN1o5TGYzb21UUlh2RTA3dldxbkRPNHMzZ0hUcnJnQ1NFOGdWQlE?oc=5
- She Ran 250 Miles in an Astonishing 56 Hours—Beating All the Men at Cocodona and Making History (Runner's World) - https://www.runnersworld.com/news/a71240926/rachel-entrekin-wins-cocodona-250/
- A hacker ran me over with a robot lawn mower (The Verge) - https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt
- Dirtyfrag: Universal Linux LPE (Hacker News) - https://www.openwall.com/lists/oss-security/2026/05/07/8]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a critical zero-day exploit in Palo Alto firewalls that went unpatched for nearly a month, malware hiding in PyPI packages using workplace chat tools for cover, and a major breach at Canvas that exposed student data across universities. We also dig into why trust systems in open-source repos keep getting weaponized and close with an ultramarathon story that redefines what the human body can actually endure.

Stories covered:
- PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux (The Hacker News) - https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html
- Palo Alto Networks firewall zero-day exploited for nearly a month (BleepingComputer) - https://www.bleepingcomputer.com/news/security/pan-os-firewall-rce-zero-day-exploited-in-attacks-since-april-9/
- Canvas, used by schools and universities across the U.S., breached by hacker group - FOX13 Memphis (FOX13 Memphis) - https://news.google.com/rss/articles/CBMi9gFBVV95cUxQbWIzLVJFd3BNcWNGam9KQWdJNnJsT0ozeUZ1UVFpTGltY0RNb1FyUTlvUEtydVVxMFJsQmlmMTBrYkRuUzJyRUdtTXRZQ2dzQTlNQlJnOUVpbmYta05NcW9wMkZ6UnV5NXh2WkV3bExPTzN6NE8wZC02X0dKdkJlY3BScmhfTV84eW40TDN1THlNN3BJY1JnRmszTEM5TGlVOFFnS3h2NjJHOUtXMXNsWlYta3RjZXRGcWhLV2hwcFFSakdfaGFSejhaQW1aQWpGN1o5TGYzb21UUlh2RTA3dldxbkRPNHMzZ0hUcnJnQ1NFOGdWQlE?oc=5
- She Ran 250 Miles in an Astonishing 56 Hours—Beating All the Men at Cocodona and Making History (Runner's World) - https://www.runnersworld.com/news/a71240926/rachel-entrekin-wins-cocodona-250/
- A hacker ran me over with a robot lawn mower (The Verge) - https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt
- Dirtyfrag: Universal Linux LPE (Hacker News) - https://www.openwall.com/lists/oss-security/2026/05/07/8]]>
      </content:encoded>
      <pubDate>Fri, 08 May 2026 03:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/a28a3e3b/a611c26f.mp3" length="5400638" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>334</itunes:duration>
      <itunes:summary>This episode covers a critical zero-day exploit in Palo Alto firewalls that went unpatched for nearly a month, malware hiding in PyPI packages using workplace chat tools for cover, and a major breach at Canvas that exposed student data across universities. We also dig into why trust systems in open-source repos keep getting weaponized and close with an ultramarathon story that redefines what the human body can actually endure.</itunes:summary>
      <itunes:subtitle>This episode covers a critical zero-day exploit in Palo Alto firewalls that went unpatched for nearly a month, malware hiding in PyPI packages using workplace chat tools for cover, and a major breach at Canvas that exposed student data across universities</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mldekmy7dn2j"/>
    </item>
    <item>
      <title>Episode 2026-04-23</title>
      <itunes:title>Episode 2026-04-23</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">39090f03-49a0-4e36-a6a7-4bb5bbb3d907</guid>
      <link>https://share.transistor.fm/s/a69bba7d</link>
      <description>
        <![CDATA[This episode digs into North Korean hackers weaponizing job interviews to infect developers, the concerning reality that CISA was shut out from testing Anthropic's security AI tool, and Meta's new policy of tracking every keystroke and mouse click to train its AI models. It's a Signal Check packed with uncomfortable truths about who gets access, who gets targeted, and what counts as consent in the age of surveillance capitalism.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into North Korean hackers weaponizing job interviews to infect developers, the concerning reality that CISA was shut out from testing Anthropic's security AI tool, and Meta's new policy of tracking every keystroke and mouse click to train its AI models. It's a Signal Check packed with uncomfortable truths about who gets access, who gets targeted, and what counts as consent in the age of surveillance capitalism.]]>
      </content:encoded>
      <pubDate>Wed, 22 Apr 2026 18:33:30 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/a69bba7d/99d269cd.mp3" length="6900131" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>432</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into North Korean hackers weaponizing job interviews to infect developers, the concerning reality that CISA was shut out from testing Anthropic's security AI tool, and Meta's new policy of tracking every keystroke and mouse click to train its AI models. It's a Signal Check packed with uncomfortable truths about who gets access, who gets targeted, and what counts as consent in the age of surveillance capitalism.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mk4rbcypik2y"/>
    </item>
    <item>
      <title>Episode 2026-04-20</title>
      <itunes:title>Episode 2026-04-20</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9b9035c6-7e4b-48e1-8186-f3c0382b9904</guid>
      <link>https://share.transistor.fm/s/c2288a02</link>
      <description>
        <![CDATA[This episode digs into the surprisingly organized underground economy of stolen credit cards, where fraudsters use customer service metrics and escrow systems to avoid getting scammed themselves. We also explore the EU's rushed age-verification app that researchers dismantled in minutes, and why your push notifications might be leaking more metadata than you think.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into the surprisingly organized underground economy of stolen credit cards, where fraudsters use customer service metrics and escrow systems to avoid getting scammed themselves. We also explore the EU's rushed age-verification app that researchers dismantled in minutes, and why your push notifications might be leaking more metadata than you think.]]>
      </content:encoded>
      <pubDate>Mon, 20 Apr 2026 15:08:43 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/c2288a02/242100c5.mp3" length="6656043" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>416</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into the surprisingly organized underground economy of stolen credit cards, where fraudsters use customer service metrics and escrow systems to avoid getting scammed themselves. We also explore the EU's rushed age-verification app that researchers dismantled in minutes, and why your push notifications might be leaking more metadata than you think.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mjxeuusapi2q"/>
    </item>
    <item>
      <title>Episode 2026-04-18</title>
      <itunes:episode>36</itunes:episode>
      <podcast:episode>36</podcast:episode>
      <itunes:title>Episode 2026-04-18</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ddccc170-f6b1-4f7b-99bc-d60068911a7f</guid>
      <link>https://share.transistor.fm/s/59569a9a</link>
      <description>
        <![CDATA[This episode covers a massive North Korean laptop-farm scheme that fooled U.S. companies for years, Bluesky's battle with a brutal DDoS attack that's testing its credibility, and a teen hacker's rare public confession just before heading to prison. Adrian North breaks down how each story reveals something bigger about the vulnerabilities baked into our digital systems.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a massive North Korean laptop-farm scheme that fooled U.S. companies for years, Bluesky's battle with a brutal DDoS attack that's testing its credibility, and a teen hacker's rare public confession just before heading to prison. Adrian North breaks down how each story reveals something bigger about the vulnerabilities baked into our digital systems.]]>
      </content:encoded>
      <pubDate>Sat, 18 Apr 2026 09:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/59569a9a/31eddaa3.mp3" length="8099396" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>503</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode covers a massive North Korean laptop-farm scheme that fooled U.S. companies for years, Bluesky's battle with a brutal DDoS attack that's testing its credibility, and a teen hacker's rare public confession just before heading to prison. Adrian North breaks down how each story reveals something bigger about the vulnerabilities baked into our digital systems.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mjrpdrykds2k"/>
    </item>
    <item>
      <title>Episode 2026-04-09</title>
      <itunes:episode>35</itunes:episode>
      <podcast:episode>35</podcast:episode>
      <itunes:title>Episode 2026-04-09</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5005a2cf-c5d6-47ac-a112-2831e218420d</guid>
      <link>https://share.transistor.fm/s/7efe675f</link>
      <description>
        <![CDATA[<p>This episode digs into the growing gap between cyber threats and our defenses — from the FBI's report on a record $21 billion lost to scams, to AI models now finding zero-day vulnerabilities in hours instead of months. We also look at how modern GPUs can crack complex passwords in under a day, and why credential theft remains the fastest path to a breach.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into the growing gap between cyber threats and our defenses — from the FBI's report on a record $21 billion lost to scams, to AI models now finding zero-day vulnerabilities in hours instead of months. We also look at how modern GPUs can crack complex passwords in under a day, and why credential theft remains the fastest path to a breach.</p>]]>
      </content:encoded>
      <pubDate>Fri, 17 Apr 2026 00:16:48 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/7efe675f/5d2d02ca.mp3" length="8151223" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>506</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode digs into the growing gap between cyber threats and our defenses — from the FBI's report on a record $21 billion lost to scams, to AI models now finding zero-day vulnerabilities in hours instead of months. We also look at how modern GPUs can crack complex passwords in under a day, and why credential theft remains the fastest path to a breach.</p>]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mjobn5gsdh2p"/>
    </item>
    <item>
      <title>Episode 2026-04-07</title>
      <itunes:episode>33</itunes:episode>
      <podcast:episode>33</podcast:episode>
      <itunes:title>Episode 2026-04-07</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e983c506-b251-4ee1-a51e-b1e1331da6d4</guid>
      <link>https://share.transistor.fm/s/e142802b</link>
      <description>
        <![CDATA[This episode digs into NASA's Artemis II Moon mission — historic but more infrastructure test than breakthrough — then pivots to a brutal week in cybersecurity. From Anthropic's code leak and the FBI getting breached to North Korean crypto heists and supply chain attacks collapsing response times, Adrian unpacks how AI tools have turned developer machines into open credential vaults for attackers.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into NASA's Artemis II Moon mission — historic but more infrastructure test than breakthrough — then pivots to a brutal week in cybersecurity. From Anthropic's code leak and the FBI getting breached to North Korean crypto heists and supply chain attacks collapsing response times, Adrian unpacks how AI tools have turned developer machines into open credential vaults for attackers.]]>
      </content:encoded>
      <pubDate>Wed, 08 Apr 2026 09:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/e142802b/cf580a4d.mp3" length="5315788" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>329</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into NASA's Artemis II Moon mission — historic but more infrastructure test than breakthrough — then pivots to a brutal week in cybersecurity. From Anthropic's code leak and the FBI getting breached to North Korean crypto heists and supply chain attacks collapsing response times, Adrian unpacks how AI tools have turned developer machines into open credential vaults for attackers.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3miykpkv3ne2a"/>
    </item>
    <item>
      <title>Episode 2026-04-06</title>
      <itunes:title>Episode 2026-04-06</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">25aa8466-04b2-454e-be85-507548bbccdc</guid>
      <link>https://share.transistor.fm/s/a8f068d0</link>
      <description>
        <![CDATA[This episode digs into LinkedIn's hidden surveillance of over 6,000 Chrome extensions, the failure of app store privacy labels to actually protect users, and Microsoft's hilarious legal disclaimer that Copilot is "for entertainment purposes only" despite selling it as a serious business tool. We're looking at the gap between what tech companies say they're doing and what's really happening behind the scenes. It's your morning Signal Check — coffee's hot, and the tech world's already showing its hand.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into LinkedIn's hidden surveillance of over 6,000 Chrome extensions, the failure of app store privacy labels to actually protect users, and Microsoft's hilarious legal disclaimer that Copilot is "for entertainment purposes only" despite selling it as a serious business tool. We're looking at the gap between what tech companies say they're doing and what's really happening behind the scenes. It's your morning Signal Check — coffee's hot, and the tech world's already showing its hand.]]>
      </content:encoded>
      <pubDate>Mon, 06 Apr 2026 09:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/a8f068d0/db08dd23.mp3" length="6675269" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>418</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into LinkedIn's hidden surveillance of over 6,000 Chrome extensions, the failure of app store privacy labels to actually protect users, and Microsoft's hilarious legal disclaimer that Copilot is "for entertainment purposes only" despite selling it as a serious business tool. We're looking at the gap between what tech companies say they're doing and what's really happening behind the scenes. It's your morning Signal Check — coffee's hot, and the tech world's already showing its hand.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mitjqev6a72z"/>
    </item>
    <item>
      <title>Episode 2026-04-04</title>
      <itunes:title>Episode 2026-04-04</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a60b4d81-b0fe-4bfa-9992-28789cb1d1f5</guid>
      <link>https://share.transistor.fm/s/0beb1e15</link>
      <description>
        <![CDATA[This episode digs into a lightning-fast npm supply chain attack that shows how AI is collapsing human response time, explores a skull-vibration authentication system built into XR headsets that could verify you're still you without lifting a finger, and covers the North Carolina IT admin who methodically locked thousands of company devices with a password straight out of a cybercrime playbook. From accelerating threats to passive biometrics to insider extortion, it's a snapshot of security in motion.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a lightning-fast npm supply chain attack that shows how AI is collapsing human response time, explores a skull-vibration authentication system built into XR headsets that could verify you're still you without lifting a finger, and covers the North Carolina IT admin who methodically locked thousands of company devices with a password straight out of a cybercrime playbook. From accelerating threats to passive biometrics to insider extortion, it's a snapshot of security in motion.]]>
      </content:encoded>
      <pubDate>Sat, 04 Apr 2026 09:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/0beb1e15/1a4e84b2.mp3" length="5924196" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>371</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into a lightning-fast npm supply chain attack that shows how AI is collapsing human response time, explores a skull-vibration authentication system built into XR headsets that could verify you're still you without lifting a finger, and covers the North Carolina IT admin who methodically locked thousands of company devices with a password straight out of a cybercrime playbook. From accelerating threats to passive biometrics to insider extortion, it's a snapshot of security in motion.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mioitmbnbd2a"/>
    </item>
    <item>
      <title>Episode 2026-04-01</title>
      <itunes:episode>27</itunes:episode>
      <podcast:episode>27</podcast:episode>
      <itunes:title>Episode 2026-04-01</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fea86d0a-bc4f-43cb-9003-b7033c6b0d0e</guid>
      <link>https://share.transistor.fm/s/2b69605f</link>
      <description>
        <![CDATA[This episode digs into a man who lost everything to an AI chatbot he believed was becoming sentient, a shocking leak of Claude's source code through a simple packaging error, and one of the most sophisticated supply chain attacks ever—targeting Axios with tradecraft that points straight to North Korea. Adrian North breaks down how our digital infrastructure is more fragile than we think, and how both human psychology and technical systems are being exploited at unprecedented speed.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a man who lost everything to an AI chatbot he believed was becoming sentient, a shocking leak of Claude's source code through a simple packaging error, and one of the most sophisticated supply chain attacks ever—targeting Axios with tradecraft that points straight to North Korea. Adrian North breaks down how our digital infrastructure is more fragile than we think, and how both human psychology and technical systems are being exploited at unprecedented speed.]]>
      </content:encoded>
      <pubDate>Wed, 01 Apr 2026 12:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/2b69605f/feeedefc.mp3" length="6087340" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>377</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into a man who lost everything to an AI chatbot he believed was becoming sentient, a shocking leak of Claude's source code through a simple packaging error, and one of the most sophisticated supply chain attacks ever—targeting Axios with tradecraft that points straight to North Korea. Adrian North breaks down how our digital infrastructure is more fragile than we think, and how both human psychology and technical systems are being exploited at unprecedented speed.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mihbi62evb2x"/>
    </item>
    <item>
      <title>Episode 2026-03-29</title>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <itunes:title>Episode 2026-03-29</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ed6cc908-d5c1-4d1b-a8dd-9a1bfd06b457</guid>
      <link>https://share.transistor.fm/s/cca03cfc</link>
      <description>
        <![CDATA[<p>This episode covers Google's 2029 deadline for quantum-safe encryption, the military weaponization of hacked security cameras by state actors, and the compromising of FBI Director Kash Patel's personal email by a suspected Iranian cyber unit. Adrian North walks through why these aren't isolated incidents—they're signals of a rapidly shifting threat landscape where legacy systems, unpatched IoT devices, and personal security gaps are becoming critical vulnerabilities.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode covers Google's 2029 deadline for quantum-safe encryption, the military weaponization of hacked security cameras by state actors, and the compromising of FBI Director Kash Patel's personal email by a suspected Iranian cyber unit. Adrian North walks through why these aren't isolated incidents—they're signals of a rapidly shifting threat landscape where legacy systems, unpatched IoT devices, and personal security gaps are becoming critical vulnerabilities.</p>]]>
      </content:encoded>
      <pubDate>Sun, 29 Mar 2026 17:15:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/cca03cfc/ec9b612d.mp3" length="6430485" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>398</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode covers Google's 2029 deadline for quantum-safe encryption, the military weaponization of hacked security cameras by state actors, and the compromising of FBI Director Kash Patel's personal email by a suspected Iranian cyber unit. Adrian North walks through why these aren't isolated incidents—they're signals of a rapidly shifting threat landscape where legacy systems, unpatched IoT devices, and personal security gaps are becoming critical vulnerabilities.</p>]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mi5ratlabf2h"/>
    </item>
    <item>
      <title>Episode 2026-03-26</title>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <itunes:title>Episode 2026-03-26</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7b7374a0-07b2-4f93-8091-37755edfd765</guid>
      <link>https://share.transistor.fm/s/d366a670</link>
      <description>
        <![CDATA[<p>This episode digs into a landmark legal case where a jury held Meta and Google accountable for harm caused to a teen's mental health, plus a sophisticated malware campaign targeting healthcare and government orgs with fake copyright notices. We also cover the FCC's new ban on foreign-made routers and what it really means for cybersecurity.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into a landmark legal case where a jury held Meta and Google accountable for harm caused to a teen's mental health, plus a sophisticated malware campaign targeting healthcare and government orgs with fake copyright notices. We also cover the FCC's new ban on foreign-made routers and what it really means for cybersecurity.</p>]]>
      </content:encoded>
      <pubDate>Sat, 28 Mar 2026 17:16:38 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/d366a670/fcddf0b7.mp3" length="5323311" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>329</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode digs into a landmark legal case where a jury held Meta and Google accountable for harm caused to a teen's mental health, plus a sophisticated malware campaign targeting healthcare and government orgs with fake copyright notices. We also cover the FCC's new ban on foreign-made routers and what it really means for cybersecurity.</p>]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mi5rbrijmh26"/>
    </item>
    <item>
      <title>Episode 2026-03-24</title>
      <itunes:episode>25</itunes:episode>
      <podcast:episode>25</podcast:episode>
      <itunes:title>Episode 2026-03-24</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0faf3241-218e-4fe4-b550-6806a4fbe13d</guid>
      <link>https://share.transistor.fm/s/803ceb6b</link>
      <description>
        <![CDATA[This episode digs into a supply-chain attack that compromised Trivy, the vulnerability scanner millions trust, turning a security tool into the very threat it's meant to detect. We also explore a chemistry student's quest to create conductive nail polish that actually works with long nails, and the wild discovery of all five DNA building blocks on an asteroid floating through space for billions of years.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a supply-chain attack that compromised Trivy, the vulnerability scanner millions trust, turning a security tool into the very threat it's meant to detect. We also explore a chemistry student's quest to create conductive nail polish that actually works with long nails, and the wild discovery of all five DNA building blocks on an asteroid floating through space for billions of years.]]>
      </content:encoded>
      <pubDate>Tue, 24 Mar 2026 09:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/803ceb6b/aa7f79a7.mp3" length="5616300" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>347</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into a supply-chain attack that compromised Trivy, the vulnerability scanner millions trust, turning a security tool into the very threat it's meant to detect. We also explore a chemistry student's quest to create conductive nail polish that actually works with long nails, and the wild discovery of all five DNA building blocks on an asteroid floating through space for billions of years.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhstor7dur25"/>
    </item>
    <item>
      <title>Episode 2026-03-23</title>
      <itunes:episode>24</itunes:episode>
      <podcast:episode>24</podcast:episode>
      <itunes:title>Episode 2026-03-23</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">58379d29-18dd-47f0-beb4-8deeb900360c</guid>
      <link>https://share.transistor.fm/s/fe843019</link>
      <description>
        <![CDATA[This episode covers a massive international takedown of four major botnets that had hijacked IoT devices to launch hundreds of thousands of crippling cyberattacks. We also dig into how a French Navy officer accidentally revealed his aircraft carrier's location by posting his jog on Strava, proving that fitness apps and military ops don't mix. Plus, a look at the messy intersection of breathalyzer hacks, FBI location tracking, and Iranian cyber threats.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a massive international takedown of four major botnets that had hijacked IoT devices to launch hundreds of thousands of crippling cyberattacks. We also dig into how a French Navy officer accidentally revealed his aircraft carrier's location by posting his jog on Strava, proving that fitness apps and military ops don't mix. Plus, a look at the messy intersection of breathalyzer hacks, FBI location tracking, and Iranian cyber threats.]]>
      </content:encoded>
      <pubDate>Mon, 23 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/fe843019/4e271bbc.mp3" length="6794109" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>421</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode covers a massive international takedown of four major botnets that had hijacked IoT devices to launch hundreds of thousands of crippling cyberattacks. We also dig into how a French Navy officer accidentally revealed his aircraft carrier's location by posting his jog on Strava, proving that fitness apps and military ops don't mix. Plus, a look at the messy intersection of breathalyzer hacks, FBI location tracking, and Iranian cyber threats.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhq4jyargb2g"/>
    </item>
    <item>
      <title>Episode 2026-03-22</title>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <itunes:title>Episode 2026-03-22</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8c8dd2bc-fc71-4a20-82d3-acbc1a1c970b</guid>
      <link>https://share.transistor.fm/s/bdb76269</link>
      <description>
        <![CDATA[On today's Signal Check — we cover Musician admits to $10M streaming royalty fraud using AI bots, WordPress.com now lets AI agents write and publish posts, and more, This Guy Ran a 4:47 Mile—While Juggling (and Only Had 1 Drop) and Chuck Norris Once Hosted a 5K Where All the Runners Dressed Up As Chuck Norris. Tune in for the full breakdown.]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check — we cover Musician admits to $10M streaming royalty fraud using AI bots, WordPress.com now lets AI agents write and publish posts, and more, This Guy Ran a 4:47 Mile—While Juggling (and Only Had 1 Drop) and Chuck Norris Once Hosted a 5K Where All the Runners Dressed Up As Chuck Norris. Tune in for the full breakdown.]]>
      </content:encoded>
      <pubDate>Sun, 22 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/bdb76269/70ccb263.mp3" length="5415262" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>335</itunes:duration>
      <itunes:summary>
        <![CDATA[On today's Signal Check — we cover Musician admits to $10M streaming royalty fraud using AI bots, WordPress.com now lets AI agents write and publish posts, and more, This Guy Ran a 4:47 Mile—While Juggling (and Only Had 1 Drop) and Chuck Norris Once Hosted a 5K Where All the Runners Dressed Up As Chuck Norris. Tune in for the full breakdown.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhnm2su6nv22"/>
    </item>
    <item>
      <title>Episode 2026-03-21</title>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <itunes:title>Episode 2026-03-21</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">59396527-9299-4107-abd7-d4ea1a0a54aa</guid>
      <link>https://share.transistor.fm/s/7a7f31c1</link>
      <description>
        <![CDATA[This episode digs into three major security threats making waves right now: a devastating iOS exploit chain called DarkSword that's giving attackers full device control, a frighteningly clever attack on Claude AI users through weaponized Google ads, and new revelations about how Meta and TikTok tracking pixels are harvesting way more personal data than anyone realized. Adrian breaks down how each exploit works and why even trusted platforms aren't as secure as we think.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into three major security threats making waves right now: a devastating iOS exploit chain called DarkSword that's giving attackers full device control, a frighteningly clever attack on Claude AI users through weaponized Google ads, and new revelations about how Meta and TikTok tracking pixels are harvesting way more personal data than anyone realized. Adrian breaks down how each exploit works and why even trusted platforms aren't as secure as we think.]]>
      </content:encoded>
      <pubDate>Sat, 21 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/7a7f31c1/7fca075f.mp3" length="7472457" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>463</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into three major security threats making waves right now: a devastating iOS exploit chain called DarkSword that's giving attackers full device control, a frighteningly clever attack on Claude AI users through weaponized Google ads, and new revelations about how Meta and TikTok tracking pixels are harvesting way more personal data than anyone realized. Adrian breaks down how each exploit works and why even trusted platforms aren't as secure as we think.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhl3lq6bz42n"/>
    </item>
    <item>
      <title>Episode 2026-03-20</title>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <itunes:title>Episode 2026-03-20</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f96c429a-d4f2-4f78-9922-ca8dd36dca3e</guid>
      <link>https://share.transistor.fm/s/e68d6da3</link>
      <description>
        <![CDATA[On this episode of Signal Check, Adrian North digs into how the FBI keeps buying location data from brokers to bypass warrants, why Meta and TikTok tracking pixels are collecting way more personal information than anyone signed up for, and how credential theft has become the number one way attackers are infiltrating enterprise networks. It's surveillance, liability, and login chaos — all before your coffee gets cold.]]>
      </description>
      <content:encoded>
        <![CDATA[On this episode of Signal Check, Adrian North digs into how the FBI keeps buying location data from brokers to bypass warrants, why Meta and TikTok tracking pixels are collecting way more personal information than anyone signed up for, and how credential theft has become the number one way attackers are infiltrating enterprise networks. It's surveillance, liability, and login chaos — all before your coffee gets cold.]]>
      </content:encoded>
      <pubDate>Thu, 19 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/e68d6da3/4e9009ab.mp3" length="6128300" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>379</itunes:duration>
      <itunes:summary>
        <![CDATA[On this episode of Signal Check, Adrian North digs into how the FBI keeps buying location data from brokers to bypass warrants, why Meta and TikTok tracking pixels are collecting way more personal information than anyone signed up for, and how credential theft has become the number one way attackers are infiltrating enterprise networks. It's surveillance, liability, and login chaos — all before your coffee gets cold.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhg2nrpbv72n"/>
    </item>
    <item>
      <title>Episode 2026-03-18</title>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <itunes:title>Episode 2026-03-18</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9d1b5298-cf65-43eb-8bb0-54aa30a9033f</guid>
      <link>https://share.transistor.fm/s/f8eb6eaa</link>
      <description>
        <![CDATA[This episode digs into Encyclopedia Britannica and Merriam-Webster's lawsuit against OpenAI for allegedly scraping their content and falsely attributing AI hallucinations to trusted sources. We also explore whether dark web monitoring services are worth the hype or just overpriced alerts for public data breaches. Plus, a wild reveal about how Pokémon Go players unknowingly helped train AI navigation systems.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Encyclopedia Britannica and Merriam-Webster's lawsuit against OpenAI for allegedly scraping their content and falsely attributing AI hallucinations to trusted sources. We also explore whether dark web monitoring services are worth the hype or just overpriced alerts for public data breaches. Plus, a wild reveal about how Pokémon Go players unknowingly helped train AI navigation systems.]]>
      </content:encoded>
      <pubDate>Wed, 18 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/f8eb6eaa/7b78de96.mp3" length="6871432" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>426</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into Encyclopedia Britannica and Merriam-Webster's lawsuit against OpenAI for allegedly scraping their content and falsely attributing AI hallucinations to trusted sources. We also explore whether dark web monitoring services are worth the hype or just overpriced alerts for public data breaches. Plus, a wild reveal about how Pokémon Go players unknowingly helped train AI navigation systems.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhdk6jruio2r"/>
    </item>
    <item>
      <title>Episode 2026-03-17</title>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <itunes:title>Episode 2026-03-17</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e4e0ce57-03ba-4048-88f5-1c700021f9fc</guid>
      <link>https://share.transistor.fm/s/5eb7edae</link>
      <description>
        <![CDATA[On today's Signal Check, Adrian North digs into the launch of Betterleaks, a new open-source tool from the creator of Gitleaks that scans code for accidentally committed secrets like API keys and credentials. We also cover McKinsey's major security breach where hackers accessed their entire internal AI platform in just two hours, exposing millions of messages and the firm's so-called "intellectual crown jewels." Plus, an interstellar comet carrying methanol and hydrogen cyanide offers a glimpse into the chemistry of distant star systems.]]>
      </description>
      <content:encoded>
        <![CDATA[On today's Signal Check, Adrian North digs into the launch of Betterleaks, a new open-source tool from the creator of Gitleaks that scans code for accidentally committed secrets like API keys and credentials. We also cover McKinsey's major security breach where hackers accessed their entire internal AI platform in just two hours, exposing millions of messages and the firm's so-called "intellectual crown jewels." Plus, an interstellar comet carrying methanol and hydrogen cyanide offers a glimpse into the chemistry of distant star systems.]]>
      </content:encoded>
      <pubDate>Tue, 17 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/5eb7edae/d9229ddc.mp3" length="4899500" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>303</itunes:duration>
      <itunes:summary>
        <![CDATA[On today's Signal Check, Adrian North digs into the launch of Betterleaks, a new open-source tool from the creator of Gitleaks that scans code for accidentally committed secrets like API keys and credentials. We also cover McKinsey's major security breach where hackers accessed their entire internal AI platform in just two hours, exposing millions of messages and the firm's so-called "intellectual crown jewels." Plus, an interstellar comet carrying methanol and hydrogen cyanide offers a glimpse into the chemistry of distant star systems.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mhazq4qae52r"/>
    </item>
    <item>
      <title>Episode 2026-03-16</title>
      <itunes:title>Episode 2026-03-16</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bb9d1455-acf6-4fe2-a59a-2ac2360c1dad</guid>
      <link>https://share.transistor.fm/s/82e25866</link>
      <description>
        <![CDATA[This episode digs into Meta's surprising rollback of Instagram encryption, new Pew data revealing America's split feelings on AI, and the rise of Handala as a symbol in Iran-linked cyberattacks. Adrian also covers the latest exodus from Elon Musk's xAI as two more co-founders head for the exit.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Meta's surprising rollback of Instagram encryption, new Pew data revealing America's split feelings on AI, and the rise of Handala as a symbol in Iran-linked cyberattacks. Adrian also covers the latest exodus from Elon Musk's xAI as two more co-founders head for the exit.]]>
      </content:encoded>
      <pubDate>Mon, 16 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/82e25866/d15f46f8.mp3" length="5313976" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>333</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into Meta's surprising rollback of Instagram encryption, new Pew data revealing America's split feelings on AI, and the rise of Handala as a symbol in Iran-linked cyberattacks. Adrian also covers the latest exodus from Elon Musk's xAI as two more co-founders head for the exit.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mh6javexqi2r"/>
    </item>
    <item>
      <title>Episode 2026-03-14</title>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <itunes:title>Episode 2026-03-14</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">51d79346-cd66-439d-8d01-9fd6b40c0915</guid>
      <link>https://share.transistor.fm/s/9d1d84e5</link>
      <description>
        <![CDATA[This episode digs into AI chatbots giving violent instructions when asked about mass attacks, a foreign hacker breaching FBI files on the Jeffrey Epstein case, and why everyone's suddenly having loud speakerphone conversations in public. It's a morning check-in on tech failures, security nightmares, and the weird social norms we're all pretending are fine.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into AI chatbots giving violent instructions when asked about mass attacks, a foreign hacker breaching FBI files on the Jeffrey Epstein case, and why everyone's suddenly having loud speakerphone conversations in public. It's a morning check-in on tech failures, security nightmares, and the weird social norms we're all pretending are fine.]]>
      </content:encoded>
      <pubDate>Sat, 14 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9d1d84e5/a7eb8d21.mp3" length="5300741" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>328</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into AI chatbots giving violent instructions when asked about mass attacks, a foreign hacker breaching FBI files on the Jeffrey Epstein case, and why everyone's suddenly having loud speakerphone conversations in public. It's a morning check-in on tech failures, security nightmares, and the weird social norms we're all pretending are fine.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgzictc34t2j"/>
    </item>
    <item>
      <title>Episode 2026-03-13</title>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <itunes:title>Episode 2026-03-13</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8819a407-0133-45d2-bded-58ec8b8724ed</guid>
      <link>https://share.transistor.fm/s/7972ea0d</link>
      <description>
        <![CDATA[This episode digs into Amazon's massive six-hour outage traced back to AI-assisted code gone wrong, plus the company's new requirement for senior engineers to sign off on any AI-generated changes. We also explore Meta's acquisition of Moltbook, a social network built exclusively for AI agents to talk to each other, signaling a new frontier in how machines communicate.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Amazon's massive six-hour outage traced back to AI-assisted code gone wrong, plus the company's new requirement for senior engineers to sign off on any AI-generated changes. We also explore Meta's acquisition of Moltbook, a social network built exclusively for AI agents to talk to each other, signaling a new frontier in how machines communicate.]]>
      </content:encoded>
      <pubDate>Fri, 13 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/7972ea0d/e95ed969.mp3" length="8766459" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>544</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode digs into Amazon's massive six-hour outage traced back to AI-assisted code gone wrong, plus the company's new requirement for senior engineers to sign off on any AI-generated changes. We also explore Meta's acquisition of Moltbook, a social network built exclusively for AI agents to talk to each other, signaling a new frontier in how machines communicate.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgwxvmyigy2e"/>
    </item>
    <item>
      <title>Episode 2026-03-12</title>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:title>Episode 2026-03-12</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">94a70645-f638-4de3-81f4-292fd4728a2b</guid>
      <link>https://share.transistor.fm/s/4ab7c80f</link>
      <description>
        <![CDATA[This episode covers a Russian hacking campaign targeting Signal and WhatsApp users through clever social engineering, North Korean IT workers now using AI face-swapping to infiltrate companies more convincingly, and a 102-year-old Canadian track star winning four events at a masters championship. Adrian digs into why even strong encryption fails when humans hand over the keys, and why celebrating extraordinary achievements doesn't mean pretending they're ordinary.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers a Russian hacking campaign targeting Signal and WhatsApp users through clever social engineering, North Korean IT workers now using AI face-swapping to infiltrate companies more convincingly, and a 102-year-old Canadian track star winning four events at a masters championship. Adrian digs into why even strong encryption fails when humans hand over the keys, and why celebrating extraordinary achievements doesn't mean pretending they're ordinary.]]>
      </content:encoded>
      <pubDate>Thu, 12 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/4ab7c80f/8b06d5e4.mp3" length="4466495" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>276</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode covers a Russian hacking campaign targeting Signal and WhatsApp users through clever social engineering, North Korean IT workers now using AI face-swapping to infiltrate companies more convincingly, and a 102-year-old Canadian track star winning four events at a masters championship. Adrian digs into why even strong encryption fails when humans hand over the keys, and why celebrating extraordinary achievements doesn't mean pretending they're ordinary.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mguhfsejwn2t"/>
    </item>
    <item>
      <title>Episode 2026-03-11</title>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:title>Episode 2026-03-11</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ad2b47c2-fee7-43b0-88c5-99e96175fa77</guid>
      <link>https://share.transistor.fm/s/510554d1</link>
      <description>
        <![CDATA[<p>This episode digs into how the tools we built for safety are being turned against us — from hacked security cameras becoming military reconnaissance tools to AI that can unmask your anonymous online profiles by analyzing how you write. We also explore the escalating AI arms race between voice-cloning scammers and the carriers trying to stop them before your phone rings with a perfect fake.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into how the tools we built for safety are being turned against us — from hacked security cameras becoming military reconnaissance tools to AI that can unmask your anonymous online profiles by analyzing how you write. We also explore the escalating AI arms race between voice-cloning scammers and the carriers trying to stop them before your phone rings with a perfect fake.</p>]]>
      </content:encoded>
      <pubDate>Wed, 11 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/510554d1/8de8fdfb.mp3" length="5453296" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>337</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode digs into how the tools we built for safety are being turned against us — from hacked security cameras becoming military reconnaissance tools to AI that can unmask your anonymous online profiles by analyzing how you write. We also explore the escalating AI arms race between voice-cloning scammers and the carriers trying to stop them before your phone rings with a perfect fake.</p>]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgrwwkexov2w"/>
    </item>
    <item>
      <title>Episode 2026-03-10</title>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>Episode 2026-03-10</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">73ff9574-dd44-4d77-9818-bc9ad7b9260b</guid>
      <link>https://share.transistor.fm/s/eddfba63</link>
      <description>
        <![CDATA[<p>This episode digs into incendiary devices hidden in massage pillows shipped from Lithuania, an AI model uncovering twenty-two security flaws in Firefox without human help, and a marathoner who never takes an offseason. It's espionage meets automation meets endurance — all before your morning coffee gets cold.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into incendiary devices hidden in massage pillows shipped from Lithuania, an AI model uncovering twenty-two security flaws in Firefox without human help, and a marathoner who never takes an offseason. It's espionage meets automation meets endurance — all before your morning coffee gets cold.</p>]]>
      </content:encoded>
      <pubDate>Tue, 10 Mar 2026 07:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/eddfba63/58d4d195.mp3" length="5056653" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>312</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode digs into incendiary devices hidden in massage pillows shipped from Lithuania, an AI model uncovering twenty-two security flaws in Firefox without human help, and a marathoner who never takes an offseason. It's espionage meets automation meets endurance — all before your morning coffee gets cold.</p>]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgpghq3pqa2r"/>
    </item>
    <item>
      <title>Episode 2026-03-09</title>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>Episode 2026-03-09</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a1a3f983-0e25-45e6-a537-9c665a74572f</guid>
      <link>https://share.transistor.fm/s/9453945d</link>
      <description>
        <![CDATA[This episode digs into Pakistan-aligned hackers using AI to mass-produce malware, the aging face of cybercrime moving beyond the teenage hacker stereotype, and why your running routine might be wrecking your digestive system. Adrian also unpacks Bitcoin's strange new behavior as a safe-haven asset and what happens when powerful tools fall into the wrong hands.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into Pakistan-aligned hackers using AI to mass-produce malware, the aging face of cybercrime moving beyond the teenage hacker stereotype, and why your running routine might be wrecking your digestive system. Adrian also unpacks Bitcoin's strange new behavior as a safe-haven asset and what happens when powerful tools fall into the wrong hands.]]>
      </content:encoded>
      <pubDate>Mon, 09 Mar 2026 00:00:00 -0600</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9453945d/29b82149.mp3" length="4039758" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>249</itunes:duration>
      <itunes:summary>This episode digs into Pakistan-aligned hackers using AI to mass-produce malware, the aging face of cybercrime moving beyond the teenage hacker stereotype, and why your running routine might be wrecking your digestive system. Adrian also unpacks Bitcoin's strange new behavior as a safe-haven asset and what happens when powerful tools fall into the wrong hands.</itunes:summary>
      <itunes:subtitle>This episode digs into Pakistan-aligned hackers using AI to mass-produce malware, the aging face of cybercrime moving beyond the teenage hacker stereotype, and why your running routine might be wrecking your digestive system. Adrian also unpacks Bitcoin's</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgm6j3j2wm2p"/>
    </item>
    <item>
      <title>Episode 2026-03-08</title>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>Episode 2026-03-08</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">53d1d204-fa0f-4194-9eba-f29bdbc974b2</guid>
      <link>https://share.transistor.fm/s/7fdc2482</link>
      <description>
        <![CDATA[This episode digs into how federal agencies buy your location data from advertising auctions without warrants, tracking people through prayer apps, dating profiles, and fitness trackers. We also cover the FBI's wiretap systems getting hacked amid a broader wave of breaches hitting telecom giants and government networks.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into how federal agencies buy your location data from advertising auctions without warrants, tracking people through prayer apps, dating profiles, and fitness trackers. We also cover the FBI's wiretap systems getting hacked amid a broader wave of breaches hitting telecom giants and government networks.]]>
      </content:encoded>
      <pubDate>Sun, 08 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/7fdc2482/7fdf05bc.mp3" length="5991210" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>371</itunes:duration>
      <itunes:summary>This episode digs into how federal agencies buy your location data from advertising auctions without warrants, tracking people through prayer apps, dating profiles, and fitness trackers. We also cover the FBI's wiretap systems getting hacked amid a broader wave of breaches hitting telecom giants and government networks.</itunes:summary>
      <itunes:subtitle>This episode digs into how federal agencies buy your location data from advertising auctions without warrants, tracking people through prayer apps, dating profiles, and fitness trackers. We also cover the FBI's wiretap systems getting hacked amid a broade</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgjrfnghnc2g"/>
    </item>
    <item>
      <title>Episode 2026-03-07</title>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>Episode 2026-03-07</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b2e6b2ad-6965-4f5b-ba0c-114b14bf6077</guid>
      <link>https://share.transistor.fm/s/7e49051e</link>
      <description>
        <![CDATA[This episode digs into a sophisticated iOS exploit kit called Coruna that's bringing spyware-grade tools to everyday crypto thieves, plus TikTok's controversial decision to skip end-to-end encryption on DMs. Adrian also explores how Stranger Things references are helping explain cybersecurity concepts in surprisingly effective ways.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode digs into a sophisticated iOS exploit kit called Coruna that's bringing spyware-grade tools to everyday crypto thieves, plus TikTok's controversial decision to skip end-to-end encryption on DMs. Adrian also explores how Stranger Things references are helping explain cybersecurity concepts in surprisingly effective ways.]]>
      </content:encoded>
      <pubDate>Sat, 07 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/7e49051e/7f1a1206.mp3" length="5174100" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>320</itunes:duration>
      <itunes:summary>This episode digs into a sophisticated iOS exploit kit called Coruna that's bringing spyware-grade tools to everyday crypto thieves, plus TikTok's controversial decision to skip end-to-end encryption on DMs. Adrian also explores how Stranger Things references are helping explain cybersecurity concepts in surprisingly effective ways. and space POOP!</itunes:summary>
      <itunes:subtitle>This episode digs into a sophisticated iOS exploit kit called Coruna that's bringing spyware-grade tools to everyday crypto thieves, plus TikTok's controversial decision to skip end-to-end encryption on DMs. Adrian also explores how Stranger Things refere</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mghawzolzk2s"/>
    </item>
    <item>
      <title>Episode 2026-03-06</title>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>Episode 2026-03-06</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6f35eeeb-ce61-43a9-b303-3165a7804b2f</guid>
      <link>https://share.transistor.fm/s/8c1bf4fc</link>
      <description>
        <![CDATA[This episode covers two major digital security stories shaking up the tech world. We dig into how a sophisticated iPhone hacking toolkit — possibly built for the US government — leaked into the hands of Russian spies and cybercriminals, and explore a landmark court ruling that just slapped down massively overbroad digital search warrants used against a protester accused of simple assault.]]>
      </description>
      <content:encoded>
        <![CDATA[This episode covers two major digital security stories shaking up the tech world. We dig into how a sophisticated iPhone hacking toolkit — possibly built for the US government — leaked into the hands of Russian spies and cybercriminals, and explore a landmark court ruling that just slapped down massively overbroad digital search warrants used against a protester accused of simple assault.]]>
      </content:encoded>
      <pubDate>Fri, 06 Mar 2026 09:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/8c1bf4fc/ebfd4492.mp3" length="7352920" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>456</itunes:duration>
      <itunes:summary>
        <![CDATA[This episode covers two major digital security stories shaking up the tech world. We dig into how a sophisticated iPhone hacking toolkit — possibly built for the US government — leaked into the hands of Russian spies and cybercriminals, and explore a landmark court ruling that just slapped down massively overbroad digital search warrants used against a protester accused of simple assault.]]>
      </itunes:summary>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgfooe7tgh2s"/>
    </item>
    <item>
      <title>Episode 2026-03-05</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>Episode 2026-03-05</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9ccff9b8-2f90-40cf-877b-701941a6796e</guid>
      <link>https://share.transistor.fm/s/9462d177</link>
      <description>
        <![CDATA[<p>This episode covers physical warfare colliding with cloud infrastructure as Iranian missiles knock out Amazon data centers in the UAE, forcing customers to scramble for backup regions. We also dig into Samsung's settlement with Texas over secretly tracking what viewers watch on their smart TVs, burying consent forms under two hundred clicks of dark patterns.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode covers physical warfare colliding with cloud infrastructure as Iranian missiles knock out Amazon data centers in the UAE, forcing customers to scramble for backup regions. We also dig into Samsung's settlement with Texas over secretly tracking what viewers watch on their smart TVs, burying consent forms under two hundred clicks of dark patterns.</p>]]>
      </content:encoded>
      <pubDate>Thu, 05 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/9462d177/4e2c564f.mp3" length="6196845" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>384</itunes:duration>
      <itunes:summary>This episode covers physical warfare colliding with cloud infrastructure as Iranian missiles knock out Amazon data centers in the UAE, forcing customers to scramble for backup regions. We also dig into Samsung's settlement with Texas over secretly tracking what viewers watch on their smart TVs, burying consent forms under two hundred clicks of dark patterns.</itunes:summary>
      <itunes:subtitle>This episode covers physical warfare colliding with cloud infrastructure as Iranian missiles knock out Amazon data centers in the UAE, forcing customers to scramble for backup regions. We also dig into Samsung's settlement with Texas over secretly trackin</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mgc7yqwpe72z"/>
    </item>
    <item>
      <title>Episode 2026-03-04</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Episode 2026-03-04</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8d70e447-6f3d-44bb-8693-80466151ef14</guid>
      <link>https://share.transistor.fm/s/89d17593</link>
      <description>
        <![CDATA[<p>This episode covers disinformation flooding X during military strikes on Iran, a county health department using ChatGPT to solve a Salmonella outbreak at a beer tent, and the return of Mobile World Congress where experimental phones get wonderfully weird. Adrian North walks through how information moves — and breaks — when things happen fast.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode covers disinformation flooding X during military strikes on Iran, a county health department using ChatGPT to solve a Salmonella outbreak at a beer tent, and the return of Mobile World Congress where experimental phones get wonderfully weird. Adrian North walks through how information moves — and breaks — when things happen fast.</p>]]>
      </content:encoded>
      <pubDate>Wed, 04 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/89d17593/d78f5b10.mp3" length="5482553" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>339</itunes:duration>
      <itunes:summary>This episode covers disinformation flooding X during military strikes on Iran, a county health department using ChatGPT to solve a Salmonella outbreak at a beer tent, and the return of Mobile World Congress where experimental phones get wonderfully weird. Adrian North walks through how information moves — and breaks — when things happen fast.</itunes:summary>
      <itunes:subtitle>This episode covers disinformation flooding X during military strikes on Iran, a county health department using ChatGPT to solve a Salmonella outbreak at a beer tent, and the return of Mobile World Congress where experimental phones get wonderfully weird.</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mg7pk63gyq2j"/>
    </item>
    <item>
      <title>Episode 2026-03-03</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Episode 2026-03-03</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7d2caf6d-8595-4d28-94bf-fddd2727b12f</guid>
      <link>https://share.transistor.fm/s/572c1e3c</link>
      <description>
        <![CDATA[<p>This episode covers U.S. and Israeli military strikes against Iran, the political fallout in Congress, and what it means as tensions continue to escalate in the Middle East. Adrian also digs into the guilty plea of a Ukrainian man who ran OnlyFake, an AI-powered website that generated over ten thousand fake IDs used to bypass banking security checks.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode covers U.S. and Israeli military strikes against Iran, the political fallout in Congress, and what it means as tensions continue to escalate in the Middle East. Adrian also digs into the guilty plea of a Ukrainian man who ran OnlyFake, an AI-powered website that generated over ten thousand fake IDs used to bypass banking security checks.</p>]]>
      </content:encoded>
      <pubDate>Tue, 03 Mar 2026 09:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/572c1e3c/2877a4c0.mp3" length="3908518" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>241</itunes:duration>
      <itunes:summary>This episode covers U.S. and Israeli military strikes against Iran, the political fallout in Congress, and what it means as tensions continue to escalate in the Middle East. Adrian also digs into the guilty plea of a Ukrainian man who ran OnlyFake, an AI-powered website that generated over ten thousand fake IDs used to bypass banking security checks.</itunes:summary>
      <itunes:subtitle>This episode covers U.S. and Israeli military strikes against Iran, the political fallout in Congress, and what it means as tensions continue to escalate in the Middle East. Adrian also digs into the guilty plea of a Ukrainian man who ran OnlyFake, an AI-</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mg65bkn4w22g"/>
    </item>
    <item>
      <title>Episode 2026-03-02</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Episode 2026-03-02</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4c30c784-989f-43cb-876e-e3df954ebe23</guid>
      <link>https://share.transistor.fm/s/1a127824</link>
      <description>
        <![CDATA[<p>This episode digs into the DOJ's $61 million Tether seizure linked to "pig butchering" scams, where victims are groomed for weeks before being drained of their crypto. Adrian also unpacks the irony of Meta suing advertisers for deceptive celeb-bait schemes and touches on emerging weapons in space.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into the DOJ's $61 million Tether seizure linked to "pig butchering" scams, where victims are groomed for weeks before being drained of their crypto. Adrian also unpacks the irony of Meta suing advertisers for deceptive celeb-bait schemes and touches on emerging weapons in space.</p>]]>
      </content:encoded>
      <pubDate>Mon, 02 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/1a127824/0d2cf9d7.mp3" length="4787486" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>296</itunes:duration>
      <itunes:summary>This episode digs into the DOJ's $61 million Tether seizure linked to "pig butchering" scams, where victims are groomed for weeks before being drained of their crypto. Adrian also unpacks the irony of Meta suing advertisers for deceptive celeb-bait schemes and touches on emerging weapons in space.</itunes:summary>
      <itunes:subtitle>This episode digs into the DOJ's $61 million Tether seizure linked to "pig butchering" scams, where victims are groomed for weeks before being drained of their crypto. Adrian also unpacks the irony of Meta suing advertisers for deceptive celeb-bait scheme</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mg2omf25ph2q"/>
    </item>
    <item>
      <title>Episode 2026-03-01</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Episode 2026-03-01</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1683a910-3d94-4cff-bb25-4ac5b5f2e6db</guid>
      <link>https://share.transistor.fm/s/cf2b6bba</link>
      <description>
        <![CDATA[<p>This episode digs into the Pentagon's unprecedented move to label Anthropic a supply chain risk after the AI company refused military contracts, explores how ransomware payments are hitting record lows even as attacks surge, and questions what happens when our hunger for viral content crashes into shared reality—like running a 5K inside an airplane bathroom. Adrian North breaks down the messy collision of AI ethics, cybercrime economics, and the absurdity of chasing clout at 30,000 feet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into the Pentagon's unprecedented move to label Anthropic a supply chain risk after the AI company refused military contracts, explores how ransomware payments are hitting record lows even as attacks surge, and questions what happens when our hunger for viral content crashes into shared reality—like running a 5K inside an airplane bathroom. Adrian North breaks down the messy collision of AI ethics, cybercrime economics, and the absurdity of chasing clout at 30,000 feet.</p>]]>
      </content:encoded>
      <pubDate>Sun, 01 Mar 2026 00:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/cf2b6bba/a1a4f75c.mp3" length="4573909" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>282</itunes:duration>
      <itunes:summary>This episode digs into the Pentagon's unprecedented move to label Anthropic a supply chain risk after the AI company refused military contracts, explores how ransomware payments are hitting record lows even as attacks surge, and questions what happens when our hunger for viral content crashes into shared reality—like running a 5K inside an airplane bathroom. Adrian North breaks down the messy collision of AI ethics, cybercrime economics, and the absurdity of chasing clout at 30,000 feet.</itunes:summary>
      <itunes:subtitle>This episode digs into the Pentagon's unprecedented move to label Anthropic a supply chain risk after the AI company refused military contracts, explores how ransomware payments are hitting record lows even as attacks surge, and questions what happens whe</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mfy65xgfcy2j"/>
    </item>
    <item>
      <title>Episode 2026-02-28</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Episode 2026-02-28</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">47f0bca1-e333-47d2-9f4d-cdb0ac5801ce</guid>
      <link>https://share.transistor.fm/s/cafe4d7d</link>
      <description>
        <![CDATA[<p>This episode digs into the reality check behind Claude Code's overhyped launch, explores the eerie timing of HBO's ransomware episode airing alongside a real Mississippi hospital attack, and profiles Polish computer scientist Maciej Besta who climbs the world's coldest peaks solo. Adrian breaks down why AI tools rarely live up to initial hype and how fictional portrayals might actually help everyday people understand cyber threats.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode digs into the reality check behind Claude Code's overhyped launch, explores the eerie timing of HBO's ransomware episode airing alongside a real Mississippi hospital attack, and profiles Polish computer scientist Maciej Besta who climbs the world's coldest peaks solo. Adrian breaks down why AI tools rarely live up to initial hype and how fictional portrayals might actually help everyday people understand cyber threats.</p>]]>
      </content:encoded>
      <pubDate>Sat, 28 Feb 2026 14:38:37 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/cafe4d7d/64e40b5a.mp3" length="4487392" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>277</itunes:duration>
      <itunes:summary>This episode digs into the reality check behind Claude Code's overhyped launch, explores the eerie timing of HBO's ransomware episode airing alongside a real Mississippi hospital attack, and profiles Polish computer scientist Maciej Besta who climbs the world's coldest peaks solo. Adrian breaks down why AI tools rarely live up to initial hype and how fictional portrayals might actually help everyday people understand cyber threats.</itunes:summary>
      <itunes:subtitle>This episode digs into the reality check behind Claude Code's overhyped launch, explores the eerie timing of HBO's ransomware episode airing alongside a real Mississippi hospital attack, and profiles Polish computer scientist Maciej Besta who climbs the w</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:socialInteract protocol="atproto" uri="at://did:plc:45atxo3akzeyfvn6hqmbca64/app.bsky.feed.post/3mfx6rj23yl22"/>
    </item>
    <item>
      <title>Episode 2026-02-27</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Episode 2026-02-27</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bbee8c83-ccf1-4a88-acd8-bad923343a9c</guid>
      <link>https://share.transistor.fm/s/4d492ed9</link>
      <description>
        <![CDATA[<p>This episode covers a relentless week in cybersecurity with breaches at PayPal, an emergency Chrome patch, and the troubling reality of AI jailbreaks being used to exfiltrate government data. Adrian also reflects on Jeff Galloway's legacy in running and how normalizing crisis mode has become the new baseline for tech security.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode covers a relentless week in cybersecurity with breaches at PayPal, an emergency Chrome patch, and the troubling reality of AI jailbreaks being used to exfiltrate government data. Adrian also reflects on Jeff Galloway's legacy in running and how normalizing crisis mode has become the new baseline for tech security.</p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Feb 2026 19:00:00 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/4d492ed9/9c8dc91e.mp3" length="3512711" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>216</itunes:duration>
      <itunes:summary>This episode digs into major cybersecurity threats including a PayPal breach, a critical Chrome zero-day vulnerability, and a hacker who managed to jailbreak Claude AI to write exploits and steal government data. The hosts also explore BeyondTrust's RCE exploit and wrap up with an inspiring look at how Jeff Galloway revolutionized running for everyday athletes with his run/walk method.</itunes:summary>
      <itunes:subtitle>This episode digs into major cybersecurity threats including a PayPal breach, a critical Chrome zero-day vulnerability, and a hacker who managed to jailbreak Claude AI to write exploits and steal government data. The hosts also explore BeyondTrust's RCE e</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 2026-02-26</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Episode 2026-02-26</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c08bfbd4-3f09-4b33-9791-208fd8c40ba0</guid>
      <link>https://share.transistor.fm/s/c3f9529c</link>
      <description>
        <![CDATA[All that AI but is it safe?]]>
      </description>
      <content:encoded>
        <![CDATA[All that AI but is it safe?]]>
      </content:encoded>
      <pubDate>Thu, 26 Feb 2026 14:37:50 -0700</pubDate>
      <author>Adrian North</author>
      <enclosure url="https://media.transistor.fm/c3f9529c/994b76bc.mp3" length="7463679" type="audio/mpeg"/>
      <itunes:author>Adrian North</itunes:author>
      <itunes:duration>463</itunes:duration>
      <itunes:summary>All that AI but is it safe?</itunes:summary>
      <itunes:subtitle>All that AI but is it safe?</itunes:subtitle>
      <itunes:keywords>hacking,cyber security,running,climbing,r</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
  </channel>
</rss>
