Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Mea

A decentralized prediction market platform, Polymarket, recently experienced a security incident, highlighting a significant failure to anticipate its own vulnerability despite its business model revolving around predicting future events. This incident was discussed on the Smashing Security podcast, episode 474, featuring cybersecurity expert Graham Cluley and special guest Quentyn Taylor, who heads information security, product security, and global response at Canon.
Polymarket's core function is to allow users to bet on the outcomes of future events, ranging from political elections to cryptocurrency prices. The irony of such a company falling victim to a hack, thereby failing to predict its own security breach, was a central point of discussion. Cluley drew a parallel to an astrologer's convention being canceled due to unforeseen weather, emphasizing the embarrassment of a prediction-based entity being blindsided.
The podcast also touched upon another significant security issue: FortiBleed, which has reportedly left approximately 75,000 Fortinet firewall devices vulnerable. This vulnerability is described as having the potential for widespread and long-lasting damage. While the specifics of the FortiBleed exploit were not detailed in the provided material, its scale suggests a broad impact on organizations relying on Fortinet's security appliances.
Quentyn Taylor shared insights into his role at Canon, where he oversees information security, product security, and global response. He noted the unique integration of these functions within his department, suggesting it could be a model for future cybersecurity team structures. Taylor explained the benefit of having product security and cybersecurity under one umbrella, allowing his team to not only secure Canon's own products, such as printers, cameras, and CCTV systems, but also to provide customers with practical, internally tested hardening guides. This approach ensures that security recommendations are based on real-world application and internal defense strategies.
Taylor elaborated on how this integrated approach fosters a feedback loop between security and product development. Previously ad hoc, this process is now formalized, enabling his team to influence product design by identifying and advocating for security improvements, such as making ubiquitous encryption a default feature on devices and restricting access to potentially exploitable functionalities.
The discussion also briefly mentioned other cybersecurity news items that were *not* covered in depth on the podcast, including a Danish privacy activist doxxing his prime minister, a UK hospital reporting unauthorized access to a child's medical records, and an attacker named Snoopy being imprisoned for hacking a fantasy sports betting website.
The podcast episode was sponsored by several companies, including CoreView, Proton, LastPass, and Vanta. Proton Pass, a password manager from the creators of ProtonMail, was highlighted for its end-to-end encryption, open-source nature, Swiss jurisdiction, and nonprofit backing, positioning it as a secure solution for businesses to manage and share credentials, particularly in light of common insecure practices like using spreadsheets or Post-it notes. The service is noted for its adherence to compliance standards like NIS 2 and DORA.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a