Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572

Security Weekly News (Audio)36mApril 14, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572” inside PodZeus.

AI-Generated Summary

The Security Weekly News episode 572 dives into a cascade of high-stakes cyber threats, from the massive data wipe at Striker Medical—where attackers allegedly exploited a compromised Microsoft 365 account to erase tens of thousands of machines—to a fake Claude AI site distributing the PlugX malware via a deceptive MSI installer. The episode underscores how attackers now operate in 3D: compromising third-party vendors like Anodot to breach high-profile targets like Rockstar Games, exposing 78.6 million records including in-game economies and support tickets. A stark warning emerges: even with MFA, credentials can be bypassed through email forwarding, SIM swapping, or malicious browser extensions—especially AI-powered ones, which are 60% more likely to contain known CVEs. The show stresses that zero trust isn’t optional; it’s essential. Kieran Heumann from ThreatLocker emphasizes that assuming breach is the foundation of resilience, and that tools like ZTCA (Zero Trust Cloud Access) can block unauthorized logins even from privileged accounts by enforcing device trust. The episode ends with a satirical yet chilling look at Meta’s AI Zuckbot—training an AI avatar of Zuckerberg to replace human leadership—hinting at a future where AI billionaires outlive their creators, and the real danger isn’t just data theft, but the erosion of human oversight in critical systems.

Key Takeaways
1

AI browser extensions are 60% more likely to contain known vulnerabilities than non-AI extensions, making them a top attack vector.

2

Attackers are using 3D attack chains—compromising third parties like Anodot to breach Rockstar Games and Striker Medical.

3

Even with MFA, attackers can bypass security via email forwarding rules, SIM swapping, or phishing via malicious extensions.

4

Striker Medical’s breach was likely enabled by a single compromised Microsoft 365 account with no additional controls beyond MFA.

5

Zero trust must include device-level verification—like ThreatLocker’s ZTCA—to prevent privileged account abuse.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

Welcome to Security Weekly News #572

Doug White kicks off the episode with a humorous intro, teasing the week’s topics including Zuckbot, Rockstar breach, fake Claude, and Striker data wipe. He highlights the show’s mission to keep security pros informed with expert analysis.

2:00
3 min

Rockstar Games Breach via Anodot Compromise

You need to be thinking in 3D rather than 2D when it comes to your security posture because if MrFooFoo.com is compromised and that allows them to get into HappyTentacle.org which is linked to your customer site, well, we all know what happens then.

Highlight
5:00
3 min

Fake Claude AI Site Delivers PlugX Malware

It looks like a legitimate MSI fall file that you would download and install so that you could have Claude and turn Claude loose on your local machine, which is terrifying to me, but it basically installs PlugX.

Highlight
8:00
4 min

AI Browser Extensions Are 60% More Vulnerable

AI extensions had 16.31%... that's about 60% more likely than just all extensions in general to have a CVE already out.

Highlight
12:00
4 min

Microsoft 365 Inbox Rules: The Silent Threat

Attackers abuse mailbox rules to hide, delete, or forward emails—including MFA codes and security alerts—without detection. Proofpoint reports 10% of compromised accounts had malicious rules post-breach.

High-Impact Quotes
AI Zuck has replaced most all of the employees with forked instances of itself and is now talking with itself. And yes, this is how the world ends. Not with a bang, but with AI billionaires run amok.
Doug White35:19
Viral: 95.0
It looks like a legitimate MSI fall file that you would download and install so that you could have Claude and turn Claude loose on your local machine, which is terrifying to me, but it basically installs PlugX.
Doug White5:37
Viral: 88.0
you need a response. And it's not just how do I fix it? It's legal. It's who's going to be... I mean, I'll tell you... I went to all this FEMA training, which sounds really boring. And it was, but it actually helped
Doug White32:42
Viral: 82.0
Speakers

Host

Doug White

Guest

Kieran Heumann
Topics Discussed
zero trust95%supply chain attack90%data wipe attack88%incident response planning87%AI browser extension security85%MFA bypass83%device trust82%malicious AI80%
People & Brands

Kieran Heumann

person

18xPositive

Striker Medical

organization

14xNegative

Doug White

person

12xNeutral

Microsoft 365

product

11xNeutral

Rockstar Games

organization

10xNegative

ThreatLocker

organization

9xPositive

PlugX

other

7xNegative

Shiny Hunters

organization

6xNegative

Outlook Lite

product

6xNegative

Pine

product

6xPositive

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime