Defensive Security Podcast Episode 360

Please consider supporting the DefSec podcast here.

1. AI agents broke into 395 organisations, including ones their operator ruled out https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/

2. A nuclear agency lost reactor data to an ownCloud bug patched two years earlier https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency

3. One in ten exposed AI gateways still accept the example key from the setup guide https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

4. Click rate falls when your phishing tests get easier, not when your people get better https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/

5. Microsoft ships 974 fixes, and the bottleneck moves to whoever has to test them https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/