Security Now (Video)

SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

Oct 15, 2025
Texas is pushing strict age verification laws for app downloads—could this harm privacy? An alarming global botnet is targeting U.S. RDP services, with over 100,000 infected. A major breach linked to Discord exposes thousands of government IDs, raising concerns about outsourced support risks. The EU cancels a controversial chat control vote, while Salesforce faces significant data leakage after refusing a ransom. Plus, Apple's new iOS 26 features draw critique for usability challenges.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ANECDOTE

Elevator Code Mnemonic Prevents Wandering

  • A memory care elevator used a visible mnemonic that requires asking staff to get the code, preventing wandering patients from leaving unsupervised.
  • Steve and Leo praised the clever staff practice that forces accompaniment for visits.
INSIGHT

Support-Platform Compromise Multiplies Impact

  • Attackers abused a third-party Zendesk/BPO support account to exfiltrate ~1.6 TB of Discord support tickets affecting 5.5M users.
  • API-linked integrations magnified the breach by allowing massive automated data pulls across services.
ADVICE

Harden BPO Accounts And API Integrations

  • Treat outsourced BPO and support accounts as high-risk and enforce MFA, least privilege, and strict API permissions.
  • Log and monitor all cross-service API queries and limit what support integrations can retrieve.
Get the Snipd Podcast app to discover more snips from this episode
Get the app