Patching can't wait.
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Patching can't wait.” inside PodZeus.
The CyberWire Daily episode 'Patching can't wait' delivers a comprehensive overview of urgent cybersecurity threats and systemic challenges facing organizations in 2026. A critical Fortinet vulnerability is already being exploited in the wild, prompting emergency patches and highlighting the dangers of delayed remediation. A major outage in Russia’s banking infrastructure—impacting millions across Moscow and other regions—exposes the fragility of centralized digital systems, while a new SANS/GIAC report reveals that workforce skills gaps now pose a greater threat than hiring shortages, with 60% of organizations lacking necessary capabilities. Meanwhile, cybercriminals are evolving: QR code scams impersonating courts, AI privacy violations via Perplexity’s data sharing, and violent 'wrench attacks' targeting crypto holders underscore the physical-digital convergence of cyber threats. On the innovation front, Microsoft’s Kevin McGee discusses the rise of agentic AI and the importance of startups focusing on specific customer problems rather than broad markets. Allie Mellon’s new book, 'Code War,' reframes nation-state cyber operations as extensions of national identity, with Russia’s attention-seeking attacks contrasting with the U.S.’s stealthy approach. The episode closes with warnings about overreliance on AI tools like Copilot, whose terms of use emphasize entertainment over reliability. Key takeaways include: 1) Immediate patching of critical vulnerabilities is non-negotiable; 2) Skills gaps are now a primary security risk, requiring structured training and certification; 3) Startups should focus on a narrow ICP before scaling; 4) Nation-state cyber operations reflect national culture and strategic priorities; 5) QR code scams and physical attacks are expanding the threat surface; 6) AI tools must be used with caution due to disclaimers and potential inaccuracies; 7) Zero-trust principles are essential, especially for small teams; 8) Supply chain attacks remain a top vector for large-scale breaches. The episode maintains a cautiously urgent tone, emphasizing proactive defense and systemic resilience.
Immediate patching of critical vulnerabilities like the Fortinet FortiClient flaw is essential to prevent enterprise compromise.
Skills gaps in cybersecurity teams now pose a greater risk than staffing shortages, with 60% of orgs lacking necessary capabilities.
Startups should focus on a specific ideal customer profile (ICP) rather than trying to sell to everyone.
Nation-state cyber operations reflect national identity—Russia’s loud attacks contrast with the U.S.’s stealthy approach.
QR code scams impersonating courts are evading detection and enabling large-scale credential theft.
…and 3 more takeaways available in PodZeus
Emergency Patching Urged for Critical Fortinet Flaw
“The improper access control flaw lets unauthenticated attackers execute code through crafted requests.”
Russia’s Banking Outage and Systemic Risk
“Centralized payment infrastructure can create systemic disruption risk.”
Cybersecurity Workforce Crisis: Skills Gaps Over Shortages
“Workforce capability gaps now represent a direct security risk, especially in critical infrastructure environments.”
Scammers Evolve: QR Codes, AI Privacy, and Physical Threats
“Scammers impersonate state courts in new text message campaigns that pressure recipients to scan QR codes tied to fake traffic violation notices.”
Startup Trends and AI-Driven Cybersecurity Innovation
Kevin McGee from Microsoft for Startups discusses the rise of agentic AI and the importance of startups focusing on specific customer problems. He emphasizes platform partnerships, team strength, and avoiding 'everything to everyone' pitches.
“The large print giveth, and the small print taketh away.”
“Workforce capability gaps now represent a direct security risk, especially in critical infrastructure environments.”
“The improper access control flaw lets unauthenticated attackers execute code through crafted requests.”
Host
Guests
Dave Bittner
person
Kevin McGee
person
Allie Mellon
person
Microsoft
organization
Fortinet
organization
Copilot
product
Perplexity
organization
CyberCore
organization
RSAC 2026
other
Sberbank
organization
Water sector feels the pressure.
CyberWire Daily • 26m • 3/31/2026
A war of missiles and messages.
CyberWire Daily • 30m • 4/1/2026
The WhatsApp impostor.
CyberWire Daily • 30m • 4/2/2026
War comes for the cloud.
CyberWire Daily • 30m • 4/3/2026
Startup surge sparks spy interest. [Research Saturday]
CyberWire Daily • 19m • 4/4/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Patching can't wait.” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
