Scylla &Charybdis, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland - SWN #575

Security Weekly News (Audio)32mApril 24, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Scylla &Charybdis, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland - SWN #575” inside PodZeus.

AI-Generated Summary

The Security Weekly News episode 575 dives into a high-stakes cybersecurity landscape where emerging threats are outpacing defensive capabilities. Doug White highlights a troubling trend: AI adoption in enterprises is accelerating faster than security teams can keep up, leading to a dangerous gap where high-risk AI applications are being deployed without proper remediation—only 15% of practitioners believe their organizations meet remediation SLAs, despite 57% of C-suite executives claiming they do. The episode then shifts to alarming ransomware developments, including Kyber ransomware using post-quantum Kyber 1024 encryption and Trigonia deploying custom, evasive data exfiltration tools that rotate connections every two gigabytes to avoid detection. A major supply chain compromise via the 'Canister Worm' attack exploited NPM package updates to distribute malware through the legitimate publisher of Mastic's Labs, corrupting AI tools like Namastix.ai—demonstrating how trusted open-source libraries can become vectors for widespread infection. Meanwhile, GitHub quietly began collecting pseudo-anonymous telemetry from CLI users without clear opt-out, raising privacy concerns. The episode also warns of fake crypto wallet apps impersonating legitimate ones on the App Store, designed to steal recovery phrases and drain wallets.

Key Takeaways
1

AI adoption is outpacing security remediation, with 57% of C-suite executives claiming SLA compliance while only 15% of practitioners agree.

2

Kyber ransomware now uses post-quantum Kyber 1024 encryption, signaling attackers are preparing for a quantum future.

3

Trigonia ransomware uses a custom tool called 'uploader_client.exe' that rotates connections every 2GB to evade detection.

4

The 'Canister Worm' attack compromised NPM packages via stolen publishing access, corrupting AI tools like Namastix.ai through malicious updates.

5

GitHub silently began collecting CLI user telemetry by default with no clear opt-out, raising privacy red flags.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

AI Adoption vs. Security Readiness

AI enterprise adoption is moving a lot faster than security practices can be developed, tested and implemented. I was like, yeah, you think?

Highlight
2:00
3 min

Kyber & Trigonia Ransomware Evolution

They're getting out in front of it. Now, Rapid7 provided an analysis of two forks of this back in March. The Windows one was written in Rust and includes a quote, self-described experimental feature.

Highlight
5:00
5 min

Canister Worm Supply Chain Attack

It got corrupted because there was an update push to that software that you installed and used for two years. And all of a sudden it corrupts, which to me is very, very scary.

Highlight
10:00
5 min

GitHub CLI Telemetry Controversy

GitHub quietly began collecting pseudo-anonymous client-side telemetry from CLI users by default, with no clear opt-out, sparking privacy concerns despite claims of improving AI agent usability.

15:00
5 min

Fake Crypto Wallet Apps & Scams

Kaspersky reports 26 fake crypto wallet apps impersonating legitimate ones on the App Store, designed to steal recovery phrases and private keys via Trojanized downloads.

High-Impact Quotes
It does not give you a system on its own. What it does is this one's so cool. What it does is it quietly interferes with defenders update path.
Doug White26:44
Viral: 88.0
It got corrupted because there was an update push to that software that you installed and used for two years. And all of a sudden it corrupts, which to me is very, very scary.
Doug White10:29
Viral: 85.0
they're getting out in front of it. Now, Rapid7 provided an analysis of two forks of this back in March. The Windows one was written in Rust and includes a quote, self -described experimental
Doug White5:26
Viral: 82.0
Speakers

Host

Doug White

Guest

Aaron Leyland
Topics Discussed
defender exploits95%ai security risks92%ransomware evolution90%supply chain attacks88%crypto wallet scams85%post-quantum encryption80%software telemetry78%zero trust security75%
People & Brands

Doug White

person

12xNeutral

Microsoft Defender

product

10xNeutral

GitHub

organization

5xNeutral

Kyber

other

4xNegative

Trigonia

other

4xNegative

App Store

other

3xNegative

Aaron Leyland

person

3xNeutral

Canister Worm

other

3xNegative

NPM

other

3xNeutral

Kaspersky

organization

2xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Scylla &Charybdis, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland - SWN #575” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime