Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer” inside PodZeus.
In this episode of Cybersecurity Headlines, host Sarah Lane leads a deep dive into several high-impact security stories from the past week, featuring insights from CISOs Adam Palmer of First Hawaiian Bank and Jack Kufal of Michigan Medicine. The discussion centers on the leak of Anthropic’s Claude source code via a public NPM registry, which both guests agree highlights growing risks in AI governance and insider threats. Apple’s new macOS Terminal warning system for malicious commands is seen as a minor but useful step in user awareness, while the emergence of AI-powered malware like DeepLoad signals a shift toward more efficient, polymorphic attacks. The revival of Iran’s pay2key ransomware operation and its collaboration with criminal groups underscores the accelerating convergence of nation-state tactics and cybercrime, increasing baseline threat levels for all enterprises. The hijacking of the Axios NPM library by UNC 1069 and the Team PCP supply chain campaign reveal systemic vulnerabilities in open source dependencies, with attackers exploiting stolen credentials within hours. Both CISOs emphasize that resilience now hinges on rapid response, continuous monitoring, and rethinking third-party risk management. The episode concludes with a call for CISOs to evolve from purely defensive roles to strategic digital risk leaders who focus on observability, governance, and speed in response. Key takeaways include: 1) AI adoption demands parallel governance maturity to protect intellectual property and infrastructure; 2) Supply chain attacks are no longer slow-moving—they can lead to cloud exploitation within a day; 3) Third-party risk must be assessed dynamically, not just during contracting; 4) Security maturity is defined by response speed, not just prevention; 5) Open source risk stems not from open source itself, but from unverified trust and market concentration; 6) CISOs must shift from 'blocking and tackling' to leading digital risk conversations around AI and data flows; 7) Resilience is now measured in hours, not weeks; 8) The line between nation-state and criminal cyber operations is blurring, making all organizations potential collateral damage.
AI adoption must be matched with governance maturity to protect intellectual property and infrastructure.
Supply chain attacks now enable cloud exploitation within hours, demanding rapid response capabilities.
Third-party risk must be assessed continuously, not just during contract negotiations.
Security maturity is defined by response speed, not just prevention.
Open source risk stems from unverified trust and market concentration, not open source itself.
…and 3 more takeaways available in PodZeus
Opening: CISO Priorities & Episode Overview
Host Sarah Lane introduces the episode with guest CISOs Adam Palmer and Jack Kufal, setting the stage for a deep dive into recent cybersecurity threats. They discuss their current priorities—business acceleration and Microsoft Fabric/Purview adoption—before launching into the week’s top stories.
Claude Source Code Leak: Governance vs. Noise
“This is a K-N-O-W for me and my team because it highlights for me the growing gap between AI adoption and governance maturity.”
Apple’s Terminal Security Warning: Incremental or Strategic?
Apple’s new macOS Tahoe 26.4 feature warns users about dangerous commands in Terminal. Both CISOs agree it’s a useful awareness tool but not a strategic shift—users remain the last-mile vulnerability.
DeepLoad Malware: AI-Powered Attack Evolution
“AI hasn't changed attacker intent, but it's changing attacker efficiency.”
Iran’s Pay2Key Revival: Nation-State & Crime Convergence
“You're not being targeted because you're important. You're being targeted because you're connected and that's important.”
“Cybersecurity is no longer about just preventing bad things from happening. It's about operating safely in an environment where compromise is inevitable.”
“The reason here is that open source isn't the risk. It's unverified trust is the risk.”
“You're not being targeted because you're important. You're being targeted because you're connected and that's important.”
Host
Guests
Adam Palmer
person
Jack Kufal
person
NPM
other
Sarah Lane
person
Anthropic
organization
Claude
product
Apple
organization
Axios
product
Vanta
organization
Team PCP
other
The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes
Cybersecurity Headlines • 38m • 4/17/2026
The Department of Know: Vercel breach, a "Contagious Interview," and ghost breaches
Cybersecurity Headlines • 40m • 4/24/2026
The Department of Know: GitHub drama, AI deletes production data, Claude Security Beta
Cybersecurity Headlines • 39m • 5/1/2026
The Department of Know: AI "transformation paradox," Copy Fail chaos, hacked lawnmowers
Cybersecurity Headlines • 38m • 5/8/2026
The Department of Know: GemStuffer attack, AI SBOMs, and AI-created zero-days
Cybersecurity Headlines • 34m • 5/15/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
