Cybersecurity Headlines - podcast cover

Cybersecurity Headlines

CISO Seriescisoseries.com
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Week in Review: Fast acting Gamaredon, WormGPT AI weapon, Microsoft Azure mystery

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 17-21, is hosted by Rich Stroffolino with our guest, Dimitri van Zantvliet , CISO, Dutch Railways Thanks to our show sponsor, OpenVPN According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC's cybersecurity and IT department, "The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources," says Villalba. "Cloud Connexa was really easy and fast to se...

Jul 21, 202324 min

New Redis worm, more ColdFusion confusion, Estée Lauder breached

New P2PInfect worm targeting Redis servers on Linux and Windows systems Adobe releases new patches for exploited ColdFusion vulnerabilities Estée Lauder breached by two ransomware groups And now a word from our sponsor, OpenVPN According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC's cybersecurity and IT department, "The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources," says Villalba. " Cloud Connexa was really eas...

Jul 21, 20238 min

A rise in complex DDoS attacks, Mi6 warns of data traps, Microsoft expands log access

Complex DDoS attacks on the rise MI6 warns of Chinese data traps Microsoft expands cloud log access And now a word from our sponsor, OpenVPN Karim Hakim, CTO at Hakim Misr Paco, says that CloudConnexa has given him some long-sought peace of mind. " OpenVPN has helped my company to access remote nodes securely without worrying about security protocols," he says. "My company has been looking for a similar solution for years, and we finally got what we were looking for." Read more at the link in ou...

Jul 20, 20237 min

US launches IoT security labeling program, Renewable tech could pose electric grid risk, US blacklists two more spyware firms

US government launches IoT security labeling program Renewable technologies could pose risk to US electric grid US blacklists two spyware firms run by Israeli former general And now a word from our sponsor, OpenVPN Stephen Haecker, Chief Technology Officer at Carteras Colectivas, relies on Cloud Connexa customer support for his remote team. "I have used them about once per month to help with our growing networks," he says, "and the service quality is great with quick turnarounds." Haecker apprec...

Jul 19, 20237 min

JumpCloud Breach, LockBit attacks Wisconsin, Typos leak military emails

JumpCloud breached by APT Wisconsin allegedly hit by LockBit Typos leaking military emails And now a word from our sponsor, OpenVPN Zach Belhadri, the Infrastructure Manager at Knight Capital, shares why using Cloud Connexa for his team's security has been a game changer. With the Cybershield feature, he's able to prevent malware, phishing, and other threats by restricting access to only authorized and trusted internet destinations. He calls Cloud Connexa "an awesome product with huge potential....

Jul 18, 20237 min

Fast-acting Gamaredon, WormGPT improves phishing, Microsoft email mystery

Russia-linked Gamaredon starts stealing data 30 to 50 minutes after initial compromise New AI tool – WormGPT allows for sophisticated cyber attacks Microsoft still unsure how hackers stole Azure AD signing key And now a word from our sponsor, OpenVPN We asked Anthony Hook, the CTO at Dataweavers, if he would recommend Cloud Connexa to other companies. His response? A resounding yes! With Cloud Connexa, he says "we bypassed the clunky client-owned VPNs and networks, gaining a seamless, secure, an...

Jul 17, 20238 min

Week in Review: Threat actors access government email, USB drive attacks spiking, cloud environment breaches

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 10-14, is hosted by Sean Kelly with our guest, Yaron Levi , CISO, Dolby Thanks to our show sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Op...

Jul 14, 202327 min

USB malware spikes, Honeywell, Rockwell vulnerabilities, ransomware remains profitable

USB drive malware attacks spiking again in first half of 2023 Users of Honeywell Experion DCS platforms urged to patch 9 vulnerabilities immediately Ransomware gangs have extorted $449 million this year Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams...

Jul 14, 20239 min

NATO cyber pledges, tax prep data shared, a decrease in crypto crime

What we know about NATO cyber pledges Tax prep companies "recklessly" shared data Report finds decrease in crypto crime Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity...

Jul 13, 20237 min

Silk Road advisor sentenced, HCA Health data breach, Google hit with AI tool training lawsuit

Silk Road's senior advisor sentenced to 20 years in prison 11 million HCA patients impacted by data breach Google hit with lawsuit alleging it stole user data to train its AI tools Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like D...

Jul 12, 202310 min

JumpCloud resets API keys, Genesis Market for sale, an EU-US data transfer agreement

JumpCloud resets customer API keys Would you be interested in a slightly used dark web market? US and EU agree on new data transfer agreement Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use ...

Jul 11, 20237 min

BigHead Windows ransomware, RedEnergy targets utilities. more MOVEIt problems

New 'Big Head' ransomware displays fake Windows update alert RedEnergy stealer-as-a-ransomware threat targeting energy and telecom sectors Three new MOVEit bugs spur CISA warning as more victims report breaches Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best securi...

Jul 10, 20238 min

Week in Review: TSMC supplier attacked, cardiac device warning, hospital ransomware increasing

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 3-7, is hosted by Rich Stroffolino with our guest, Hadas Cassorla , CISO, M1 Thanks to today's episode sponsor, SlashNext SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, ...

Jul 07, 202324 min

Shell MOVEit breach, Pepsi bottler breach, INTERPOL nabs OPERA1ER

Shell confirms MOVEit-related breach after ransomware group leaks data 28,000 impacted by data breach at Pepsi Bottling Ventures INTERPOL nabs hacking crew OPERA1ER's leader behind $11 million cybercrime Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC)...

Jul 07, 20238 min

Japanese port hit with ransomware, EU court orders Meta data changes, White House can't contact social companies

Japan's major port hit with ransomware European court orders changes to Meta's data practices Injunction restricts White House contact with social media companies Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive imperso...

Jul 06, 20237 min

BlackCat pushes CobaltStrike, cardiac device warning, unpatched Fortigate firewalls

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads CISA issues warning for cardiac device system vulnerability 330,000 FortiGate firewalls still unpatched to CVE-2023-27997 RCE flaw Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply c...

Jul 05, 20238 min

Semiconductor giant attacked, State websites hacked, Russian Telecom infiltrated

Semiconductor giant says IT supplier was attacked, LockBit makes related claims Several US states investigating 'SiegedSec' hacking campaign Russian telecom confirms hack after group backing Wagner boasted about an attack Thanks to today's episode sponsor, SlashNext For the stories behind the headlines, head to CISOseries.com .

Jul 03, 20238 min

Week in Review: SolarWinds CISO blamed, Military smartwatch mystery, submarine cable risk

Link to Blog Post This week's Cyber Security Headlines – Week in Review , June 26-30, is hosted by Rich Stroffolino with our guest, Cassio Goldschmidt , CISO, ServiceTitan Thanks to our show sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS envi...

Jun 30, 202324 min

SolarWinds CISOs blamed, ThirdEye Windows malware, Government extends canary

SEC notice to SolarWinds CISO and CFO roils cybersecurity industry Newly uncovered ThirdEye Windows-based malware steals sensitive data Cyber Command to expand 'canary in the coal mine' unit working with private sector Thanks to today's episode sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and ...

Jun 30, 20238 min

Federal networks fail CISA rules, US AI chip bans, MOVEit victims grow

Federal network devices fail CISA requirements US considering more AI chip export bans The scope of MOVEit vulnerability Thanks to today's episode sponsor, AppOmni Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security. Take action with AppOmni . Secure your...

Jun 29, 20237 min

Over 6,500 arrested since EncroChat hack, Third-party vendor hack exposes American and Southwest data, Microsoft service outage woes continue

Thanks to today's episode sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com. For the stories ...

Jun 28, 20238 min

Monopoly darknet charges, Activision Blizzard DDoS, 5G aircraft deadline

Monopoly darknet operator charged Activision Blizzard games hit with DDoS 5G deadline could impact flights Thanks to today's episode sponsor, AppOmni Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security. Take action with AppOmni . Secure your organization'...

Jun 27, 20237 min

CISA adds vulnerabilities, mysterious military smartwatches, more Office problems

CISA adds 6 flaws to known exploited vulnerabilities catalog US military personnel report receiving smartwatches in the mail Microsoft 365 users new Outlook and Teams problems Thanks to today's episode sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and respond to suspicious activities within you...

Jun 26, 20238 min

Week in Review: Microsoft confirms cyberattack, more MOVEit damage, reddit hit with ransomware

Link to Blog Post This week's Cyber Security Headlines – Week in Review , June 19-23, is hosted by Rich Stroffolino with our guest, Janet Heins , CISO, iHeartMedia Thanks to our show sponsor, Wing Security The first step to securing your organization's SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card ne...

Jun 23, 202322 min

Canadian breaches increase, new China backdoor, kinetic warfare threat

Cybersecurity breaches more than double among Canadian businesses Experienced China-based hacking group has new backdoor tool Cyberattacks on OT, ICS lay groundwork for kinetic warfare Thanks to today's episode sponsor, Wing Security The first step to securing your organization's SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in th...

Jun 23, 20238 min

DoJ targets nation-state actors, Apple fixes Triangulation zero-day, Schumer unveils strategy to regulate AI

New DoJ cyber prosecution team will go after nation-state threat actors Apple fixes zero-days used to deploy Triangulation spyware Schumer unveils strategy to regulate AI Thanks to today's episode sponsor, Wing Security Shadow IT is an evolving pain and a security risk, especially in today's decentralized work environments. Now's the time to regain control of your SaaS usage by taking advantage of Wing's Free SaaS Shadow IT discovery solution. Check out wing.security to self-onboard today, no st...

Jun 22, 20238 min

Rorschach ransomware, Australian government data leak, security market outpaces tech

Rorschach ransomware takes the speed crown Data leak impacts Australian government Cyber security market growth outpaces tech sector Thanks to today's episode sponsor, Wing Security Can you answer these three questions confidently? 1. How many SaaS applications are used in your organization? 2. Which permissions did users provide these applications? and 3. What is the data that flows in and in between these applications? Wing provides the answers. In fact, it discovers your SaaS usage completely...

Jun 21, 20237 min

Reddit's ransom, UK shuffles cyber chief, Binance reaches SEC deal

Reddit hit with ransom demand UK's cyber chief moves on to organized crime Binance reaches deal with the SEC Thanks to today's episode sponsor, Wing Security The first step to securing your organization's SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. It takes minutes to discove...

Jun 20, 20237 min

Microsoft's June cyberattacks, third MOVEit vulnerability, US Clop bounty

Microsoft says early June service outages were cyberattacks Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted US govt offers $10 million bounty for info on Clop ransomware Thanks to today's episode sponsor, Wing Security The folks at Wing believe that SaaS Shadow IT discovery is the basic first step to securing your SaaS usage. They believe it so strongly that they launched a completely free SaaS Shadow IT Discovery solution. Check out wing.security to...

Jun 19, 20237 min

Week in Review: Microsoft banking warning, undetectable BatCloak malware, more MOVEit vulnerabilities

Link to Blog Post This week's Cyber Security Headlines – Week in Review , June 12-16, is hosted by Sean Kelly with our guest, Phil Beyer , former Head of Security, Etsy Thanks to our show sponsor, Conveyor Your scariest questionnaires that are hundreds of questions long are no match for Conveyor's GPT-questionnaire tool – now with a browser extension for complex portals. Get GPT-generated precise answers to entire questionnaires so your review takes seconds. Now you can spend 89% less time compl...

Jun 16, 202322 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android