Talkin' Bout [Infosec] News

Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29

June 30, 2026·1h 6m
Episode Description from the Publisher

This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&amp;CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Next Webcast Thing (00:14) - Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29 (03:56) - Story #1 - It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns (07:49) - Story #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive users (08:55) - Story #3 - heavener: This is what happens when you can't afford EDR licenses (18:50) - Story #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues (31:59) - Story #5 - I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. (36:14) - Story #6 - CISA Adds Four Known Exploited Vulnerabilities to Catalog (37:09) - Story #7 - Victory! 702 has Expired! (37:43) - Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of Trial (40:52) - Story #9 - Polymarket customers lose $3 million in supply-chain attack (44:56) - Story #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general says (49:31) - Story #11 - How Android Earthquake Alerts System Works (53:47) - Story #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invites (59:34) - Story #13a - The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines (59:59) - Story #13b - Order-tracking app Shop abused to push callback phishing attacks (01:04:29) - Chinese AI vs. Anthropic Mythos | BHIS [In Focus] LinksStory #1 - It’s looking like a hot, messy summer for security teams as AI finds countless previously hidden vulnsStory #2 - FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive usersStory #3 - heavener: This is what happens when you can’t afford EDR licensesStory #4 - Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensuesStory #5 - I Could’ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.Story #6 - CISA Adds Four Known Exploited Vulnerabilities to CatalogStory #7 - Victory! 702 has Expired!Story #8 - Scattered Spider Hackers Plead Guilty on Day 1 of TrialStory #9 - Polymarket customers lose $3 million in supply-chain attackStory #10 - Bad cybersecurity by Secret Service agents put US officials at risk, inspector general saysStory #11 - How Android Earthquake Alerts System WorksStory #12 - Cybersecurity firms targeted by fraudulent OpenAI organization invitesStory #13a - <a href="ht

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of Talkin' Bout [Infosec] News and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.