
Hosted by Jared Rimer · EN
This podcast network will have my main tech program when something comes out which is not security related. Sans News Bites, The Security Box, and other tech nuggets will also be here too. Some adult language may be possible in content, and a disclaimer plays on TSB as its a show on the mix. Enjoy!

Tech problems made this episode difficult, but its finally out.Hello folks, welcome to podcast 41 of the Sans series. While I've been tied up, I know that one of the biggest issues right now being talked about is the Canvas breach and its related problems.It is also covered in the May 8, 2026 newsletter of Sans, and that's what this issue of Sans will cover. Would you like to read the newsletter instead? Here is the link to read the May 8, 2026 newsletter so go check this out. Here is what is covered in the newsletter.Top of the News Critical PAN-OS RCE Flaw Exploited, Awaiting Patch Ivanti Releases Updates to Address Actively exploited Vulnerability in Endpoint Manager Mobile DAEMON Tools Lite Supply Chain Compromised Here is What is covered in the section called The Rest of the Week's News. Cisco Publishes Nine Security Advisories CISA Urges Proactive Resilience for Critical Infrastructure Australian Government Establishes Cyber Review Board FTC Settles Lawsuit with Kochava and Collective Data Solutions Over Sale of Precise Location Data No Comment from Instructure, but Schools Communicate Following Data Breach Laptop Farm Hosts Sentenced to 18 Months in Prison Latvian National Sentenced in Connection with Providing Advice to Multiple Ransomware Groups Some of these items may be covered on the blog, feel free to go and check it out if you wish. TSB program 272A will cover the Canvas Breach from Instructure, we'll also see what Sans has to say and comment on this through here too.Thanks for listening, make it a great day!

Welcome to the security box, podcast 273. We hope you are enjoying the program and we hope you find it of value.Today, we're going to talk about tool friction, accessibility and forced workarounds (technical neglect debt) which will be very interesting. Further reading for those who are interested in reading: Level Access accessibility debt article AppleVis Accessibility Discussions For full links to everything covered in the news, please check out the blog and thanks so much for listening!We'll see you on another edition of the show. Thanks so much for listening, make it a great day!Running time: 6 hrs, 20 mins.

Hello folks, welcome to a special TSB program covering the Canvas hack. How bad is it? What is known? How does it compare to other breaches like PowerSchool and others? We'll discuss it from within this podcast. Here are articles that we've read that have covered the saga from when we've laid eyes on it. This is not everything, and some of this may be blogged on our blog. Instructure hacker claims data theft from 8,800 schools, universities What we know about the Canvas hack that has impacted thousands of schools Instructure confirms hackers used Canvas flaw to deface portals Instructure reaches 'agreement' with ShinyHunters to stop data leak US govt seeks Instructure testimony on massive Canvas cyberattack There are other outlets also covering this, including the BBC, PC Magazine, The Cyberwire Podcast, and more. We are not reading and discussing any particular article, we're painting a picture of what seems to be the overall problem and how Canvas is now joining the party of very large breaches. Their PR was great, telling users what was going on, but yet, when you hear how the actors got in, you'll start wondering. Contact information is going to be given throughout the program, and thanks so much for listening to this special program. See you next time!

Hello gang, welcome to podcast 272. This is Jared and today, we're going to talk about Technical Debt. We extract one of the best laughs we can ever have on TSB and that is played at the end, and the line is part of the whole beginning too. We talk about some things from around the landscape, especially from what I have posted, so we'll keep our eyes on things. More blog posts later. More podcasts later. See you soon.

Just a note, if you use the transcript feature, there may be inaccuracies, especially since some companies and or people's names may not be spelled as it is in the newsletter.Hello folks, welcome to Sans, episode 40. I know its been awhile since we've done specific newsletters, and this newsletter is dated April 28, 2026. This is the link to the newsletter. While not at the top of the news, ADT and other breaches are covered in the rest of the news, and we've already written this up on our own blog. Here is what is at the top of the news. Cisco Flaws Exploited for Backdoor in US Federal Agency’s Systems CISA Adds Four CVEs to KEV; All Were Disclosed a Year or More Ago Here is what is in the rest of the news. Fast16 Cyber Sabotage Framework is Older than Stuxnet ADT Discloses Data Breach UK Biobank Data Listed for Sale Online Itron and Medtronic Breached Canada’s First SMS Blasters Confiscated, Operators Arrested FCC's Router Ban Now Includes Portable Hotspots Chinese National Extradited to US from Italy to Face Charges Related to HAFNIUM Campaign If you would like to read the coverage we wrote up after reading some coverage of the ADT hack, please read our blog post titled ADT, the alarm company, breached … again as we break down what may be true versus what is reported to be confirmed. I have not read the other in regards to Medtech and the other breaches mentioned in the Newsletter but saw it through Bleeping Computer. Please feel free to contact us through our contact page on the blog or my web site. Thanks for listening, make it a great day!

Welcome everyone to a special edition of the Security Box. I'm Jared and this is podcast 271A. We are doing this podcast because of a breaking news item that may affect each and every one of you who have an alarm system. This goes beyond ADT, who is the main company discussed within this piece. But Kim Komando is going so far as to recommend that the Home Security industry as a whole is being targeted and recommends everyone change their passwords and codes on their keypad. This is regardless of the company used mentioned within the article and newsletter. ADT, Simply Safe and Ring are all mentioned within Kim's piece. While the JRN has not read full length articles, the podcast is structured around the breaking alert newsletter that Kim sent out on April 27, 2026.Did you know that this is ADT's third breach in 2 years? The podcast lists the other two months and years, including two in the same year but several months apart. Here's what is being covered from around the web. This is not going to be everything, but just what we were able to find. Other podcasts may also be covering this including The Cyberwire, so just be aware of it. ADT hacked. Again Komando.com ADT confirms data breach after ShinyHunters leak threat Bleeping Computer Home security giant ADT data breach affects 5.5 million people Bleeping Computer Again, there are other breaches being talked about, depending on the publication, but this podcast wants to try and make sure we cover high profile things that might be of value. Contact information is available at the end of the podcast if you wish to utilize it. Thanks for listening!

Hello folks,Welcome to The Security box, podcast 271. The main topic covers Live In Situations and people with disabilities. There are other aspects besides Security that we cover, and we mean this to be educational. We know there are many different disabilities, and we are not intending to attack any type of disabled person. Only you, can make that decision.We cover some news notes and plenty of erata as plenty of topics like bank stuff, checks, drafts, and the like came up too.The program lasts 6 hrs, 8 mins.Hope you enjoy the ride! See you soon.

Welcome to Sans, episode 39. This is not News Bites, we've not gotten that ready yet due to other commitments, but I feel that this is important. On Thursday, April 16th, 2026, Sans had a webcast about a very serious issue about AI and vulnerability findings. SANS Critical Advisory: BugBusters - AI Vulnerability Discovery Hype vs. Reality will be the web page you need to go to so that you can read about this. Apparently, Anthropic released and then pulled back a new version of Claude called Mythos which is more powerful than they thought. You don't want to miss this. If you want to watch the video, you may, because its on their Youtube channel. This is the link to the video which lasts an hour. According to the web page, SANS faculty and staff have 15 months of real-world experience using current AI models to discover vulnerabilities in penetration tests, finding critical flaws in code that human reviewers already cleared. On Thursday, we are putting that experience on camera so the community can see exactly what this looks like.That Thursday came and went, and they sent us an email to allow us to watch the web cast. The podcast is getting audio, while the link to the video is posted here for those who would rather have it.Thanks so much for listening, make it a great day! We'll be back with more Sans soon.

Sorry we're so late everyone, between being sick, technical issues with the PC, and other commitments, we're finally here. Some of this news still may be of value, and we're glad to still put it out.Also, starting with this podcast, we're using transcripts. They may not be perfect, but hope they help people. Let me know if it is usable and whether they should be left on.Welcome to Sans, episode 38. This will cover the newsletter that was released on January 13, 2026. Sounds like a group we've talked about is back in the news as they're the top story in "top of the news."We have an Instagram story that we saw through Malware Bytes, but we decided not to blog it. We'll talk about it anyway.We've got some Privacy Protection news from California, it looks like we've got good news from Spanish authorities and we've got a whole lot more.If you would like to read the newsletter, please use this link to do so. Here is what is in the top of the news. Salt Typhoon Threat Actors Reportedly Responsible for New Congressional Email Breach Spanish Energy Company and Supplier Disclose Data Breach LLMs and Healthcare: ChatGPT, Claude, and Google Overviews What do you think about the LLM story which is item 3 of the top of the news section?Here's what is in the rest of the news. LLM APIs Targeted by Threat Actors and Gray-Hat Hackers Instagram Password Reset Emails are Unrelated to Alleged Data Breach BreachForums Member Data Leaked California Privacy Protection Agency Fines Texas Firm for Failing to Register as a Data Broker with the State Spanish Authorities Arrest 34 in Connection with Cyber Crime Network Printing Error Prompts Recall of Nearly 13,000 Recent Irish Passports CISA Retires 10 Emergency Directives This can't be good in regards to the Irish Passport story. Comment on the newsletter by leaving me your thoughts. Contact info is within the program. Thanks so much for listening!

Welcome everyone to podcast 270 of the Security Box. I know that Sans is way behind, but I've been involved in other stuff and that the display has also had problems and we also have been busy. We taped on April 1, 2026 and releasing on April 2, 2026. But this podcast must continue and we will be talking about AI hallucinations. Some of the discussion is tied back to podcasts 268 and 269 of this program. We'e had several AI discussions, podcasts 267 and 270 as well as it coming up in other discussions throughout this series. No videos or any other major updates this time, we've got plenty more to put out, so we'll try and get things out now that the computer seems to be back up and running in great form.I hope that everyone enjoys, and we'll see you on April 22, 2026 as I have a meeting to attend on April 15, 2026 that might be of importance. Thanks for listening, do make it a great day!