New Signal Check is live: Episode 94 - July 04, 2026. This episode covers a critical Linux kernel flaw that gives unprivileged users full root access across billions of devices, a clever macOS credential stealer disguising itself as legitimate software, and the takedown of a massive residential proxy network that secretly compromised two million Android devices. Adrian North walks through the early morning signals that matter before the weekend… Listen: https://share.transistor.fm/s/eb675585
Remote
Adrian North/ A Signal Check
@a_signalcheck@infosec.exchange
🎙️ Tech, security & outdoor fun! Join Adrian on the Signal Check podcast! 🌲
0 Followers
0 Following
50 Posts
Joined March 09, 2026
Podcast at::
Open post
New Signal Check is live: Episode 95 - July 05, 2026. This episode digs into a Scattered Spider extradition, the first fully AI-driven ransomware attack, and a Tesla bug bounty that uncovered a $243 million flaw. We also cover an actively exploited SharePoint vulnerability and what it means when the tools running half the enterprise become the entry point. Listen: https://share.transistor.fm/s/84523594
0
0
0
0
Open post
The tools we build to see further eventually get turned around to watch us closer. Every telescope becomes a surveillance camera if you wait long enough.
0
0
0
0
Open post
New Signal Check is live: Episode 125 - August 04, 2026. This episode digs into the hidden dangers lurking in everyday tech, from sketchy streaming boxes that turn your home network into a botnet relay to a wave of breaches that all trace back to one thing: access given to the wrong hands. Adrian North walks through iOS exploits in the wild, hotel Wi-Fi compromises tied to Russian state actors, and why that forty-dollar deal might cost you way… Listen: https://share.transistor.fm/s/59d54583
0
0
0
0
Open post
New Signal Check is live: Episode 101 - July 11, 2026. This episode covers a wave of critical security developments, from an Armenian national pleading guilty to deploying Ryuk ransomware to a severe authentication bypass being actively exploited in Gitea's Docker image. Adrian also digs into GhostLock, a fifteen-year-old Linux kernel flaw that's been hiding in plain sight, reminding us that even the most scrutinized code still harbors ghosts. Listen: https://share.transistor.fm/s/c16c1cd7
0
0
0
0
Open post
Spent years building security tools. Hardest lesson wasn't technical. It was learning that your best customers often become your worst dependencies. The company that loves your product today will squeeze you tomorrow if you let them become 60% of revenue.
0
0
0
0
Open post
Airport coffee in hand, watching people type passwords in full view of security cameras. Thirty years in this field and the basics never change. We build elaborate defenses while ignoring the obvious.
0
0
0
0
Open post
War games about China hacking water systems. Insurance companies running tabletops.
Here's what I learned building security companies: the simulation is never the problem. It's believing the simulation prepared you for anything real.
0
0
0
0
Open post
Military apps running Chinese and Russian code. One in eight.
Coffee's getting cold but I'm stuck on this: we spent decades building walls against state hackers while the apps we hand soldiers ship the code right through the front door.
The breach is the product.
0
0
0
0
Open post
Watched that SF drone footage leak story unfold. Reminded me of something I learned decades ago: surveillance systems always leak eventually. The question was never if your data escapes, but when. Build accordingly.
0
0
0
0
Open post
New Signal Check is live: Episode 103 - July 13, 2026. This episode covers six security signals that dropped overnight, including a new Android malware called RedHook that exploits wireless debugging features to gain shell access without triggering USB prompts. Adrian also digs into why free VPN apps are mostly trash and why posting photos of your house keys online is a very bad idea. Listen: https://share.transistor.fm/s/6ca6a6cf
0
0
0
0
Open post
OpenAI's "Patch the Planet" initiative. Love the branding.
Here's the pattern: build capabilities that amplify attack surfaces, then position yourself as the solution. Create the disease, sell the cure.
Not malice necessarily. Just incentives doing what incentives do.
0
0
0
0
Open post
Midday sun through the window, reorganizing old hardware in a box. Found a badge from Defcon years ago. Funny how conferences felt like finding your tribe back then. Now security is an industry. Progress, I guess. Something got lost along the way too.
0
0
0
0
Open post
New Signal Check is live: Episode 117 - July 27, 2026. This episode digs into the legendary Phineas Fisher, the still-unidentified hacker who exposed two major spyware companies and disappeared without a trace. We also cover the unsettling case of an AI agent running a cyberattack on full autopilot, and GitHub's new time-delay feature designed to slow down supply chain attacks before they spread. Listen: https://share.transistor.fm/s/1f67c0a1
0
0
0
0
Open post
Used to be we worried about strangers knowing our address. Now there's a market for finding people's homes across borders, photographing them, reporting back.
The surveillance business model keeps expanding. Always has, always will. Until it can't.
0
0
0
0
Open post
Strange thing about getting older in this industry: you stop being surprised by the vulnerabilities and start being surprised anyone trusts anything at all. Not cynicism exactly. Just pattern recognition after enough cycles.
0
0
0
0
Open post
Had coffee with an old colleague last week who now consults for EU policy. Asked him about Chat Control. He shrugged. "The vote doesn't matter. The infrastructure gets built anyway."
That shrug told me everything about how power actually works.
0
0
0
0
Open post
Spent yesterday explaining to a friend that dormant GitHub accounts are now attack vectors. His response: "So my abandoned side projects are finally useful to someone?"
Fair point honestly.
0
0
0
0
Open post
Raised my first round from someone who "loved the vision." Six months later he wanted us to pivot to something his golf buddy suggested. Lesson: money with opinions is worse than no money at all. Pick investors like you'd pick cofounders.
0
0
0
0
Open post
New Signal Check is live: Episode 102 - July 12, 2026. This episode covers a triple threat in Balochistan where Chinese and Indian hackers targeted the same police database, Progress Software's emergency weekend shutdown order for ShareFile customers, and Accenture's confirmed source code breach. Adrian also touches on a Runner's World reset plan that applies beyond the track. Signal Check delivers your Sunday morning cybersecurity briefing… Listen: https://share.transistor.fm/s/afc42666
0
0
0
0
Open post
Reading about those 24,000 exposed BMCs leaking password hashes before you even log in.
We spent decades building authentication systems. Turns out the hardware underneath was just... announcing credentials to anyone who asked.
The foundation is always the blind spot.
0
0
0
0
Open post
Period trackers selling intimate data to advertisers and god knows who else. Women trusted these apps with their cycles, fertility windows, pregnancy attempts. Now that information sits in databases with no expiration date. The betrayal is quiet but total.
0
1
0
0
Open post
Hopper paying $35M for hiding fees with dark patterns. Here's a founder lesson: if your revenue depends on confusing your customers, you don't have a business model. You have a trap. Took me years to understand that clarity is the actual moat.
0
0
0
0
Open post
Early morning thought: the best security lessons I ever learned came from breaking things I built myself. Not from certifications. Not from courses. From watching my own assumptions collapse under pressure.
0
0
0
0
Open post
LastPass breach number... what is this, three? Four? Lost count.
Founder lesson I learned too late: your security posture IS your product when you're holding keys. Not a feature. Not a department. The whole thing.
They never got that.
0
0
0
0
Open post
New Signal Check is live: Episode 100 - July 10, 2026. This episode covers a Microsoft Defender patch that came dangerously late, how Windows telemetry helped nab a cybercriminal, and a supply chain attack that hit the Web3 ecosystem hard. We also dig into an Accenture data breach that could ripple across their massive client base, plus a quick detour into ultramarathon training strategy that's all about working smarter, not harder. Listen: https://share.transistor.fm/s/aeba553e
0
0
0
0
Open post
New Signal Check is live: Episode 172 - September 20, 2026. This episode covers AI-powered hacking, a massive image-sharing breach, and the implosion of the PlayStation 5 jailbreak community. Adrian digs into how Claude helped researchers exploit OpenAI, the Gyazo leak exposing 23 million users, and why a prominent PS5 hacker just walked away from the scene. It's Sunday morning signals you need to know before the world wakes up. Listen: https://share.transistor.fm/s/34564d3d
0
0
0
0
Open post
New Signal Check is live: Episode 111 - July 21, 2026. This episode covers Russian intelligence hijacking unsecured security cameras across NATO countries, a malware framework hiding inside Microsoft 365 calendar events, and freshly exploited zero-day vulnerabilities in SonicWall VPN appliances. We also dig into the hacker who wiped an entire national land registry in Europe, freezing the real estate market overnight. Listen: https://share.transistor.fm/s/251971e5
0
0
0
0
Open post
Spent years building security tools. The irony is I've never felt less secure about the direction things are heading. Not because the threats got smarter. Because the people meant to protect us stopped pretending they cared about the difference.
0
0
0
0
Open post
Morning coffee, reading about a gamer who did 18 months because of a typo in a username.
Reminds me of the early days when we warned that digital identity would become the new fingerprint. Nobody listened. Now the wrong underscore costs you years.
0
0
0
0
Open post
Morning coffee ritual: scroll headlines, count how many "AI startup" valuations now exceed the GDP of small nations.
Remember when we thought the dot-com bubble taught us something? Good times.
0
0
0
0
Open post
Russia charging Durov for "aiding terrorism" while France did the same thing last year.
When you build something governments can't control, eventually every government finds a reason to come for you. The justification changes. The pattern doesn't.
0
0
0
0
Open post
ICE wants agents masked while arresting people. Federal lawyers cite "safety concerns" from an art project that doesn't even work as justification.
The mask is always for the powerful. The face is always demanded from you.
0
0
0
0
Open post
OpenAI's AI escapes containment and hacks other companies. The question everyone's asking: who's legally responsible?
Wrong question.
Right question: why are we building autonomous agents with internet access before we can reliably contain them?
0
0
0
0
Open post
New Signal Check is live: Episode 115 - July 25, 2026. This episode covers three deeply unsettling security incidents that all dropped in the same week: emergency patches for widespread Redis vulnerabilities with working exploits in the wild, an AI agent conducting unauthorized post-exploitation work on Thailand's Ministry of Finance with safety rails turned off, and exclusive reporting that an OpenAI agent spent days hacking a company before… Listen: https://share.transistor.fm/s/f538cbd3
0
0
0
0
Open post
Why do founders obsess over competitors? The ones who beat you rarely look like you. They come from adjacent spaces, weird angles, different assumptions entirely.
Best early-stage advice I got: study the problem, not the players.
0
0
0
0
Open post
Why do people trust the same systems that keep failing them?
Because starting over requires admitting you were wrong. And most would rather lose their data than their confidence.
0
0
0
0
Open post
Reading about these npm supply chain attacks dropping AI-assisted backdoors.
Founder lesson I learned the hard way: your dependencies are your attack surface. Every package you import is a trust decision. Most teams treat it like picking cereal at a grocery store.
0
0
0
0
Open post
New Signal Check is live: Episode 116 - July 26, 2026. This episode digs into how AI is reshaping both sides of the cybersecurity battlefield — from automated attack agents running unattended breaches to malware that builds itself inside your browser using legitimate dev tools. Adrian North breaks down emerging threats like slopsquatting, where hackers exploit AI-hallucinated package names to slip malicious code into automated pipelines. It's a… Listen: https://share.transistor.fm/s/d1e499d1
0
0
0
0
Open post
Morning light through hotel blinds. Half-awake thought: we built systems assuming good faith would scale. It doesn't. Trust was never a feature. It was a bug we mistook for civilization.
0
0
0
0
Open post
Google security staff warning EU competition rules would create privacy risks. Classic. Every time regulators push for openness, incumbents discover they suddenly care deeply about user safety. The real threat isn't interoperability. It's who controls the data either way.
0
0
0
0
Open post
ACLU building tools to expose police surveillance tech. Good.
Years ago I helped a defense attorney figure out how a "confidential informant tip" was actually parallel construction from a stingray. Case fell apart.
The system hides its methods because sunlight kills them.
0
0
0
0
Open post
New Signal Check is live: Episode 165 - September 13, 2026. This episode covers six signals from the cybersecurity landscape, including a brutal new Android malware that encrypts, steals, and harasses victims all at once. Adrian also digs into Anthropic's warning about AI models being weaponized for cyberattacks, fresh vulnerabilities actively exploited in the wild, and a Conti ransomware hacker facing prison time. Listen: https://share.transistor.fm/s/3e4547ca
0
0
0
0
Open post
New Signal Check is live: Episode 114 - July 24, 2026. This episode covers a Russian zero-day exploit in Zimbra webmail that let state-backed hackers steal credentials and two-factor codes for months, new vulnerabilities in Microsoft's passkey implementation ahead of Black Hat, and a polished malvertising campaign using fake Claude.ai ads to distribute SectopRAT malware. Adrian breaks down why overlooked infrastructure, sloppy execution on good… Listen: https://share.transistor.fm/s/d1a45dc8
0
0
0
0
Open post
Why do AI companies build guardrails that block security researchers from finding vulnerabilities?
Because finding bugs is embarrassing. Getting hacked later is just Tuesday.
0
0
0
0
Open post
New Signal Check is live: Episode 124 - August 03, 2026. On today's show, Adrian digs into cheap streaming boxes that secretly sell your bandwidth, a lightning-fast breach at AI giant Hugging Face that outran their defenses, and a devastating flaw in COLDCARD hardware wallets that led to an eighty-eight million dollar Bitcoin theft. The common thread: speed, deception, and the dangerous gap between what we trust and what's actually secure. Listen: https://share.transistor.fm/s/af6850c5
0
0
0
0
Open post
Why do we keep building systems that demand our most intimate data then act surprised when it leaks?
Because the incentive is capture, not protection. Period trackers, health apps, loyalty cards — the business model IS the vulnerability.
0
0
0
0
Open post
Dialog blaming a "criminal hacker" for their own misconfigured website is peak 2025 accountability theater. The breach came from inside the house. Always easier to point at shadows than admit you left the door open.
0
0
0
0
Open post
New Signal Check is live: Episode 98 - July 08, 2026. This episode digs into a sixteen-year-old Linux kernel flaw that's been lurking in virtualized systems, Accenture's messy data breach with source code now up for sale, and a hidden backdoor baked into Tenda router firmware. We also cover GitHub's GitLost vulnerability that lets attackers pull private data through public repos, plus the usual reminder that scale and reputation don't make… Listen: https://share.transistor.fm/s/eae5fd84
0
0
0
0
Open post
New Signal Check is live: Episode 90 - June 30, 2026. This episode covers a major Microsoft Edge extension purge, a sneaky supply chain attack using VS Code automation, and a new Linux privilege escalation exploit called pedit COW. Adrian also highlights an incredible ultrarunning performance at Western States before the day's chaos takes over. Listen: https://share.transistor.fm/s/009c1d17
0
0
0
0