


Episode description:
Show notes:
- Story one focuses on a wild BGP hijacking incident that compromised updates for a vendor that makes hypervisor management software (Virtualizor by Softaculous). Attackers were able to take over part of hosting company Hetzner’s IP space, create a valid TLS certificate for Softaculous’s website and serve up an identical copy of the website. Softaculous didn’t cryptographically check the integrity of updates, so the attack succeeded in compromising customers.
- In story two, the Financial Stability Board, an organization created by the G20 after the 2008 financial crisis, warns of risks from AI. The risks were twofold: the AI bubble and threats directly from rogue AI agents.
- In story three, Alexandre shares an observation that, at least in Latin America, financial institutions are writing inside-out scanning into their MSAs.
- Finally, in story four, UK politicians propose to amend the Cyber Security and Resilience bill to expand restrictions on tech suppliers seen as ‘risky’. A troubling addition aims to remove transparency at the same time.
Links - for reference:
- Story 1: https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/
- Story 2: https://therecord.media/cyber-risk-from-frontier-ai-most-immediate-concern-to-global-finance
- Story 3: No link
- Story 4: https://therecord.media/uk-technology-national-security
.png)
